{"_id":"@agentwalletcompany/mcp","name":"@agentwalletcompany/mcp","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@agentwalletcompany/mcp","version":"0.1.0","description":"AgentWallet MCP server — governed agent spend with Ed25519-signed, hash-chained evidence. One command, zero config.","license":"MIT","type":"module","main":"dist/tools.js","types":"dist/tools.d.ts","exports":{".":"./dist/tools.js"},"bin":{"agentwallet-mcp":"dist/cli.js"},"engines":{"node":">=22.5.0"},"scripts":{"build":"tsc -p tsconfig.json","test":"vitest run"},"dependencies":{"@agentwalletcompany/core":"^0.1.0","@agentwalletcompany/engine":"^0.1.0","@modelcontextprotocol/sdk":"^1.29.0","zod":"^4.4.3"},"gitHead":"f95dcea90916adac1db159ab60952671bc6f4019","_id":"@agentwalletcompany/mcp@0.1.0","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-bMD2nRhp6+gRt2a7/IQCEukp1TbzdNScg/F+iWwmM4yEJAjE8dX6zSb9K4doa+jgrVMsobVo6RjFH9DzxSDv+Q==","shasum":"8dfff7c4ad4771fabacb9cba0dca32c1f63bf836","tarball":"https://registry.npmjs.org/@agentwalletcompany/mcp/-/mcp-0.1.0.tgz","fileCount":14,"unpackedSize":95941,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIG/WPORT73KtgXhCcSfnvUVhBRxnXsUbSlKnSoxWitM7AiBQY4dL9wmG+BsFOXdv/dhN193MAUFoPQEv4WEidXuIfA=="}]},"_npmUser":{"name":"jackd720","email":"jack@browniibytes.com"},"directories":{},"maintainers":[{"name":"jackd720","email":"jack@browniibytes.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.1.0_1783089204029_0.032508379035909085"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-03T14:33:23.847Z","0.1.0":"2026-07-03T14:33:24.173Z","modified":"2026-07-03T14:33:24.408Z"},"maintainers":[{"name":"jackd720","email":"jack@browniibytes.com"}],"description":"AgentWallet MCP server — governed agent spend with Ed25519-signed, hash-chained evidence. One command, zero config.","license":"MIT","readme":"# @agentwalletcompany/mcp\n\nThe AgentWallet MCP server: give any MCP-capable agent (Claude Desktop, Cursor, Cline, ...)\ngoverned spending with tamper-evident, Ed25519-signed, hash-chained evidence — with **one\ncommand and zero config**:\n\n```sh\nnpx -y @agentwalletcompany/mcp\n```\n\n> **Not yet published to npm.** Until it is, run from a source checkout instead:\n> `npm install && npm run build` at the repo root, then use\n> `node /path/to/agentwallet/packages/mcp/dist/cli.js` wherever the configs below\n> say `npx -y @agentwalletcompany/mcp` (as `\"command\": \"node\"`, `\"args\": [\"/path/to/agentwallet/packages/mcp/dist/cli.js\"]`),\n> and `node /path/to/agentwallet/packages/verify/bin/agentwallet-verify.js` in place\n> of `npx agentwallet-verify`.\n\nEvery action the agent takes through these tools — creating agents, setting rules,\nauthorizing spend, triggering kill switches — appends a signed record to an append-only\nevidence log that answers *who authorized this, under what policy*. Export the log at any\ntime and verify it independently with `npx agentwallet-verify` (no AgentWallet software or\naccount required).\n\n## Claude Desktop\n\nAdd to `claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"agentwallet\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentwalletcompany/mcp\"]\n    }\n  }\n}\n```\n\n## Cursor / Cline\n\nAdd to your `mcp.json` (Cursor: `.cursor/mcp.json`, Cline: `cline_mcp_settings.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"agentwallet\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentwalletcompany/mcp\"]\n    }\n  }\n}\n```\n\n## Embedded vs remote\n\nBy default the server runs **embedded**: a full `GovernanceEngine` in-process, persisting\nits evidence log, signing key, and state under `~/.agentwallet/mcp` (override with\n`AGENTWALLET_DATA_DIR`). Nothing leaves your machine — no server, no account, no network —\nwhich is the fastest way to get signed evidence for a single developer or a local agent.\nSet `AGENTWALLET_API_URL` to switch the same tools to **remote** mode, where every call is\nproxied to a deployed `@agentwalletcompany/server` REST API; use this when a team or fleet of\nagents must share one policy set and one evidence log, with the signing key held by the\nserver rather than each laptop.\n\n### Environment variables\n\n| Variable | Effect |\n| --- | --- |\n| `AGENTWALLET_API_URL` | If set, run in remote mode against this base URL (e.g. `https://wallet.example.com`) |\n| `AGENTWALLET_API_KEY` | Bearer token sent as `Authorization: Bearer ...` in remote mode |\n| `AGENTWALLET_DATA_DIR` | Embedded mode data directory (default `~/.agentwallet/mcp`) |\n\nRemote mode config example:\n\n```json\n{\n  \"mcpServers\": {\n    \"agentwallet\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentwalletcompany/mcp\"],\n      \"env\": {\n        \"AGENTWALLET_API_URL\": \"https://wallet.example.com\",\n        \"AGENTWALLET_API_KEY\": \"awo_...\"\n      }\n    }\n  }\n}\n```\n\nKeys are issued by `@agentwalletcompany/server`: the owner key (`awo_...`) is printed **once**\nat the server's first boot, and each created agent gets its own scoped `awa_...` key in\nthe `POST /v1/agents` response.\n\n## Tools\n\n| Tool | Purpose |\n| --- | --- |\n| `create_agent` | Register a governed agent |\n| `list_agents` | List agents with status and lineage |\n| `spawn_agent` | Spawn a child that inherits rules (overrides can only tighten) |\n| `set_agent_status` | Pause / reactivate / terminate an agent |\n| `set_rule` | Attach one of the 10 rule types (limits, allow/deny lists, time window, approval threshold) |\n| `list_rules` / `list_rule_types` | Inspect rules and the rule catalog |\n| `authorize_spend` | Policy check before money moves — returns decision, rule-by-rule reasons, signed receipt |\n| `record_execution` | Record that money moved; mismatches are flagged as unauthorized |\n| `list_approvals` / `decide_approval` | Human-in-the-loop escalations |\n| `kill_switch` | Arm automatic triggers, trigger an emergency stop (cascades to descendants), reset, status |\n| `get_audit_log` | Recent signed events, counts by type, or a full compliance report |\n| `export_evidence` | Write `events.jsonl`, `checkpoints.jsonl`, `public-key.pem` for independent verification |\n| `verify_chain` | Recompute every hash, signature, and checkpoint root |\n\n## Verifying an export\n\n```sh\nnpx agentwallet-verify <dir>/events.jsonl --key <dir>/public-key.pem --checkpoints <dir>/checkpoints.jsonl\n```\n","readmeFilename":"README.md","_rev":"1-c611a1e89684b9a8d155108b7d27b2e6"}