{"_id":"@agentveins/mcp","_rev":"3-89a0676ef3ca9a95dcb4c620d7c89455","name":"@agentveins/mcp","dist-tags":{"latest":"0.7.0"},"versions":{"0.5.0":{"name":"@agentveins/mcp","version":"0.5.0","keywords":["ai-agents","mcp","payments","spend-controls","model-context-protocol"],"license":"MIT","_id":"@agentveins/mcp@0.5.0","maintainers":[{"name":"agentveins","email":"agentveins@gmail.com"}],"homepage":"https://github.com/AgentVeins/agentveins#readme","bugs":{"url":"https://github.com/AgentVeins/agentveins/issues"},"bin":{"agentveins-mcp":"dist/bin.js"},"dist":{"shasum":"1d70287ab8557703c56f39a95e0ad9d0e43c8edc","tarball":"https://registry.npmjs.org/@agentveins/mcp/-/mcp-0.5.0.tgz","fileCount":26,"integrity":"sha512-B+jE9XaKIdMS3qFoHzlfWfF0LFOlELHb28xH4kerGqllT2cxc/SAWw/pBXgLVaDo/hYJmZm7IQWUAUwswtsmHg==","signatures":[{"sig":"MEQCIDospIYjMiK+QCQJBnh/UxL+rwfJM/72fazGZVXwKk56AiAFPPHnTi0De3gctF4rqxUCnRhGMmwn0xgggr2aPucWkw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":31711},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":"./dist/index.js"},"gitHead":"8d609fb77f839098f4e7aa1e7c5d535cbe2d9d85","scripts":{"build":"tsc --build","typecheck":"tsc -p tsconfig.test.json","prepublishOnly":"tsc --build --force && vitest run --root ../.."},"_npmUser":{"name":"agentveins","email":"agentveins@gmail.com"},"repository":{"url":"git+https://github.com/AgentVeins/agentveins.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.6.1","description":"MCP server for AgentVeins: governed payments as a tool any agent can call.","directories":{},"_nodeVersion":"24.10.0","dependencies":{"zod":"^3.25 || ^4.0","@solana/kit":"^7.0.0","@agentveins/core":"^0.5.0","@modelcontextprotocol/sdk":"^1.30.0","@agentveins/adapter-solana":"^0.5.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.5.0_1788268942308_0.7865859630166774","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@agentveins/mcp","version":"0.6.0","keywords":["ai-agents","mcp","payments","spend-controls","model-context-protocol"],"license":"MIT","_id":"@agentveins/mcp@0.6.0","maintainers":[{"name":"agentveins","email":"agentveins@gmail.com"}],"homepage":"https://github.com/AgentVeins/agentveins#readme","bugs":{"url":"https://github.com/AgentVeins/agentveins/issues"},"bin":{"agentveins-mcp":"dist/bin.js"},"dist":{"shasum":"98619660e8a8a99528540a5e804df100524e6bed","tarball":"https://registry.npmjs.org/@agentveins/mcp/-/mcp-0.6.0.tgz","fileCount":26,"integrity":"sha512-tLWPDfpr61keswlQPL6Da1UTTKcOXMp7139Bn2tynn9EFLXjhh+3fha2d81qmJ2yX0TGUWcP4AzOOZNUoQL2gA==","signatures":[{"sig":"MEQCIEzZfYjAAm8Cu1khmh/CZhLCqEXtWD215arWRzk+um7LAiA1GnQHl9Y2bm6XZgGIVxDnHhj++XOlt4fHKTfPB4Yukw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":37014},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":"./dist/index.js"},"gitHead":"81cdd94959e6891884e29e7d7ad8e9a9797c9323","scripts":{"build":"tsc --build","typecheck":"tsc -p tsconfig.test.json","prepublishOnly":"tsc --build --force && vitest run --root ../.."},"_npmUser":{"name":"agentveins","email":"agentveins@gmail.com"},"repository":{"url":"git+https://github.com/AgentVeins/agentveins.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.6.1","description":"MCP server for AgentVeins: governed payments as a tool any agent can call.","directories":{},"_nodeVersion":"24.10.0","dependencies":{"zod":"^3.25 || ^4.0","@solana/kit":"^7.0.0","@agentveins/core":"^0.6.0","@modelcontextprotocol/sdk":"^1.30.0","@agentveins/adapter-solana":"^0.6.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.6.0_1788284500056_0.21094022072382157","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@agentveins/mcp","version":"0.7.0","description":"MCP server for AgentVeins: governed payments as a tool any agent can call.","license":"MIT","type":"module","repository":{"type":"git","url":"git+https://github.com/AgentVeins/agentveins.git","directory":"packages/mcp"},"homepage":"https://github.com/AgentVeins/agentveins#readme","bugs":{"url":"https://github.com/AgentVeins/agentveins/issues"},"keywords":["ai-agents","mcp","payments","spend-controls","model-context-protocol"],"engines":{"node":">=20"},"bin":{"agentveins-mcp":"dist/bin.js"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":"./dist/index.js"},"dependencies":{"@agentveins/adapter-solana":"^0.7.0","@agentveins/core":"^0.7.0","@modelcontextprotocol/sdk":"^1.30.0","@solana/kit":"^7.0.0","zod":"^3.25 || ^4.0"},"scripts":{"build":"tsc --build","prepublishOnly":"tsc --build --force && vitest run --root ../..","typecheck":"tsc -p tsconfig.test.json"},"gitHead":"67f364548a95c6ecced04c36a1ca86fc6036034d","_id":"@agentveins/mcp@0.7.0","_nodeVersion":"24.10.0","_npmVersion":"11.6.1","dist":{"integrity":"sha512-yBV8c8PKtqUoZqD30LTFHm9EC2/FYDMXIc79G9mQQZsEC6aTSidCzG2loH9F2IQKmDp4ttIKCN2zlY9y4BIMXA==","shasum":"f0fe38d093778e8bde9340a76e5066270265371c","tarball":"https://registry.npmjs.org/@agentveins/mcp/-/mcp-0.7.0.tgz","fileCount":26,"unpackedSize":37432,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEMCH1c90OSPwwn/uoKY040hXXBFnN7qtr3EEcT+oOwOhe0CIDa2y6T6jBEApVr5TEmAwqD5NAvOXsB/tmSQ2r1lmORw"}]},"_npmUser":{"name":"agentveins","email":"agentveins@gmail.com"},"directories":{},"maintainers":[{"name":"agentveins","email":"agentveins@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.7.0_1788345438325_0.8666484483544148"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-01T13:22:22.075Z","modified":"2026-09-02T10:37:18.653Z","0.5.0":"2026-09-01T13:22:22.441Z","0.6.0":"2026-09-01T17:41:40.194Z","0.7.0":"2026-09-02T10:37:18.480Z"},"bugs":{"url":"https://github.com/AgentVeins/agentveins/issues"},"license":"MIT","homepage":"https://github.com/AgentVeins/agentveins#readme","keywords":["ai-agents","mcp","payments","spend-controls","model-context-protocol"],"repository":{"type":"git","url":"git+https://github.com/AgentVeins/agentveins.git","directory":"packages/mcp"},"description":"MCP server for AgentVeins: governed payments as a tool any agent can call.","maintainers":[{"name":"agentveins","email":"agentveins@gmail.com"}],"readme":"# @agentveins/mcp\n\nGoverned payments as a tool any MCP-capable agent can call. The agent asks to pay; the\nguard decides; the wallet key never leaves this process.\n\n```bash\nnpm install @agentveins/mcp\n```\n\nWrite a policy — the rules are the product, so this is the one thing that cannot have a\ndefault:\n\n```json\n{\n  \"budgets\": [\n    { \"period\": \"per_tx\", \"limit\": \"1.00\",  \"currency\": \"USDC\" },\n    { \"period\": \"daily\",  \"limit\": \"10.00\", \"currency\": \"USDC\" }\n  ],\n  \"vendors\": { \"mode\": \"allowlist\", \"entries\": [\"api.weather.com\"] },\n  \"killSwitch\": { \"frozen\": false }\n}\n```\n\nThen point any MCP-capable agent at it. Two variables:\n\n```json\n{\n  \"mcpServers\": {\n    \"agentveins\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentveins/mcp\"],\n      \"env\": {\n        \"AGENTVEINS_POLICY\": \"/absolute/path/to/policy.json\",\n        \"AGENTVEINS_RAIL\": \"mock\"\n      }\n    }\n  }\n}\n```\n\nThe audit log, its anchor, the approval store and the signing key all live beside the\npolicy file unless you name them. The key is created on the first run and kept; the\npublic half is written next to it, so `veins --verify` has something to check the log\nagainst.\n\n## Tools\n\n| | |\n| --- | --- |\n| `pay` | attempts a payment. Settles, or is refused with the rule that refused it |\n| `check` | answers whether a payment would pass, moving nothing |\n| `spend_state` | every budget, what is spent, what remains, and whether the agent is frozen |\n\nNothing here can loosen a rule. There is no `grant` and no `unfreeze`: an agent may spend\nwhat it was allowed and ask what it is allowed, and may not widen either.\n\nA blocked payment is a tool **result**, not a tool error. A denial is the policy working,\nand reporting it as an error teaches an agent to treat governance as a malfunction and\nretry against it. Only a rail failure is an error.\n\n## Configuration\n\n| Variable | Meaning |\n| --- | --- |\n| `AGENTVEINS_RAIL` | `solana`, or `mock` to govern payments that never move money. Inferred as `solana` when `SOLANA_KEYPAIR_PATH` is set |\n| `AGENTVEINS_POLICY` | path to the policy JSON |\n| `AGENTVEINS_SIGNING_KEY` | ed25519 private key, PEM. Defaults to `operator.key.pem` beside the policy, created on first run |\n| `AGENTVEINS_AUDIT` | the audit log, which holds the spend counter. Defaults to `audit.jsonl` beside the policy |\n| `AGENTVEINS_ANCHOR` | detects a deleted log. Defaults to `audit.anchor.json` beside the policy |\n| `AGENTVEINS_APPROVALS` | approval store, used when the policy sets a threshold. Defaults beside the policy |\n| `AGENTVEINS_AGENT` / `_LOG_ID` | identity recorded on every entry |\n| `SOLANA_KEYPAIR_PATH` / `SOLANA_RPC_URL` | when the rail is `solana` |\n| `SOLANA_MODE` | `direct` or `x402`; defaults to `direct` |\n\nOnly `AGENTVEINS_POLICY` and `AGENTVEINS_RAIL` are required, and the rail is inferred as\n`solana` when `SOLANA_KEYPAIR_PATH` is set. Nothing is ever inferred as `mock` — a server\nthat reported settlements while moving nothing is the one guess this must not make.\n\nEverything else defaults beside the policy file, which is a location you chose. The\nalternative is the process's working directory, which an MCP client picks and you never\nsee — and since a missing audit log reads as a first run rather than an error, a path that\nwanders would hand back the whole daily budget on every launch from somewhere new.\n\nThe signing key is generated once and reused. A guard replays its audit log at startup and\nrefuses one it cannot verify, so a key that changed between launches would work exactly\nonce; that argument calls for a key that *persists*, not one you have to produce by hand. A\nkey file that exists but cannot be read is an error rather than a reason to write a new\none, because replacing it would orphan every entry the old key signed.\n\nEvery diagnostic, including that refusal, goes to stderr: stdout is the MCP protocol, and\nwriting anything else there would corrupt the session.\n\n## Mounting your own guard\n\n```typescript\nimport { serveGuard } from \"@agentveins/mcp\";\n\nawait serveGuard(myGuard, \"solana\");\n```\n\n`serveGuard` reads no environment and no files, so an operator with their own guard — a\ndatabase-backed approval store, a custom adapter — mounts it directly.\n\nFull documentation: **[docs.agentveins.com](https://docs.agentveins.com)**\n","readmeFilename":"README.md"}