{"_id":"botanary-mcp","_rev":"28-24275b8f0ca4b8ca5a5d0fc40e05ffa1","name":"botanary-mcp","dist-tags":{"latest":"0.10.4"},"versions":{"0.1.0":{"name":"botanary-mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.1.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://github.com/MorcaLabs/botanary-be/tree/main/tools/botanary-mcp#readme","bugs":{"url":"https://github.com/MorcaLabs/botanary-be/issues"},"bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"878792548444a22e83fcf9710002de0e7a38aab5","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.1.0.tgz","fileCount":42,"integrity":"sha512-5+VhHFNIim+ai2Ok3VF3+wMRgxcbVpcaB5huOSBVMsAxUXWmUNV2Jaj+a0EDXTGoDZ5cmQyWLFOHpW1JOe7rAw==","signatures":[{"sig":"MEQCICrzyI3jIRM5emM60Yj+S0lI0ZHltNIzQZecPJuWu7piAiAX3k7PfkAU+oYbjlXSBpk+cENfTOQJTxINzNbp3Wmj5g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":139343},"type":"module","engines":{"node":">=22.0.0 <23"},"gitHead":"8718069efbe7c3fa2b574eb2710fb7495f481e21","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"repository":{"url":"git+https://github.com/MorcaLabs/botanary-be.git","type":"git","directory":"tools/botanary-mcp"},"_npmVersion":"11.7.0","description":"Botanary's agent connector: a local MCP server that lets an outside coding agent (Claude Code, Codex, Cursor, or a custom build) generate its own signing key, keep it in the OS keychain, pair with a Botanary account, read its balance, and spend under what","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.1.0_1786460750336_0.3268157329034185","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"botanary-mcp","version":"0.1.2","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.1.2","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"7c69604f7d9947287f55ca54d0f01afd8b793d1d","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.1.2.tgz","fileCount":42,"integrity":"sha512-poPZ0WFk4M1Sw3M/WYUM1AUg0eUI2tn2uyesYACuF+Bh6hQ3sAfANhoP00mY94LN6Wuk7YpvDhta4E077K+idg==","signatures":[{"sig":"MEQCIFemsVlxu1Iq5vJ3nrS/GYB248qT/q7I3LCSMzx5hXpaAiBkdO3nQE7Nh1clGBZk/mixpkaAA+p39oZvgzUkC7cDSA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":142538},"type":"module","engines":{"node":">=22.0.0 <23"},"gitHead":"2fe74aee0aca8400164278a68cdc0e44ba196533","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's agent connector: a local MCP server that lets an outside coding agent (Claude Code, Codex, Cursor, or a custom build) generate its own signing key, keep it in the OS keychain, pair with a Botanary account, read its balance, and spend under what","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.1.2_1786500522912_0.8604182482444938","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"botanary-mcp","version":"0.1.3","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.1.3","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"138e29f529bc2b1ac51f4d91dfb00cc5ec92c466","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.1.3.tgz","fileCount":42,"integrity":"sha512-dpFPPU4jUBuUG/u1lqJkMmf04g7OQk5Hl40qlOcHvrZ1i2XuSEbLErZBBQgSgW/wmYW77LbnbgApuGsUm3PAOw==","signatures":[{"sig":"MEQCIHAkfOzB28ir/e76S8DTJKVdLOUZvDkpaI/X9Sq5ebp+AiAQk8ozi2p5ToN5c9pbhzrykfxt5Vhy8z1t/PK+6o68Bg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":142534},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"ea1dbfaf5351c432492dfda93bebf41124fd9179","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's agent connector: a local MCP server that lets an outside coding agent (Claude Code, Codex, Cursor, or a custom build) generate its own signing key, keep it in the OS keychain, pair with a Botanary account, read its balance, and spend under what","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.1.3_1786501432642_0.35163755890393067","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"botanary-mcp","version":"0.2.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.2.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"fa0f398b9029a97f77180573e418804a08c5a39a","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.2.0.tgz","fileCount":44,"integrity":"sha512-ZVZAfcecOU8MLroOkjE0932/C0L+8eerS/0vp4gjNN/uSZfjUz4haLIW2EB1bpj0EHjsS96hJzt+ZSsqU3BZ5A==","signatures":[{"sig":"MEQCIBr0FJQw2+Af6SbjbeiwYYXUTQiyTeI3lb+zn6qnrvtjAiBExHCdrZyc9zJVdotYtBOGaOCwn9pEouXEJKwAuatOYg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":177004},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"998d5b891ecb5db832581cc7bea585c623ae1cb6","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's agent connector: a local MCP server that lets an outside coding agent (Claude Code, Codex, Cursor, or a custom build) generate its own signing key, keep it in the OS keychain, pair with a Botanary account, read its balance, and spend under what","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.2.0_1786511328998_0.8788055111383752","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"botanary-mcp","version":"0.3.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.3.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"8fc6fe2b94fe6aeaa8abfd6fde7b27d7a3d3aa2d","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.3.0.tgz","fileCount":46,"integrity":"sha512-3HkFJp1PMMwHNwYdeLQ2R9ki+JamyLYV1GYmxQaOpcfOFtAnbUfwOQ99rms6831cebZqGuKDoLIfdj3MVMxQlA==","signatures":[{"sig":"MEQCIF5Lko1U0LPcEMSoidYRsmeirg7N4k+5yD61vgxgb3OOAiAq4K1X2YfIO4WCov5FjGiVDC5RpBzEzaOnhogqAT7ixQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":219570},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"d83a2c81ed42076ca1f699c5ca6b921dd92aa1a1","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's agent connector: a local MCP server that lets an outside coding agent (Claude Code, Codex, Cursor, or a custom build) generate its own signing key, keep it in the OS keychain, pair with a Botanary account, read its balance, and spend under what","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.3.0_1786675852476_0.23687296706362737","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"botanary-mcp","version":"0.4.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.4.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"329a65e12a73c92729663a296de2434b11ef96d0","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.4.0.tgz","fileCount":64,"integrity":"sha512-7iGyrWx/sKIKpxBLSRblsiVUsan/kcFPno0dB0WN7uJvEj5PYVdrRSqoR3SocWe7z046qnCsS5i8hsfmntBTrA==","signatures":[{"sig":"MEUCIQCrf+hmv4CrOo8DxUOzcOg3hZsMjQXiR+eQiJZATAYA/QIgRTwfuEeVt/PB8ecOc+5AO8t1rSvSA6VVJHQx/lWy/KE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":394395},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"d42f288a0d28a4e13cd7b23f0fdb5361addcbc96","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.4.0_1786964542806_0.5553244029088449","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"botanary-mcp","version":"0.4.1","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.4.1","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"12bc035b5ff4a6ea682a4a939d9a1a4e1da7581c","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.4.1.tgz","fileCount":64,"integrity":"sha512-OP4yZLEszaVHoooufK7laMUVXqHmDyG6M2aUXYcFche3XThAmneGRQAPeRAtLfoxDIA2mYYltxMG9iHyfw8HZw==","signatures":[{"sig":"MEQCIBlCocj+nusUYTLLPhmTcIZROPKNtv1nQE11YCLBJwWOAiBk3ZoL/XdGjT0pN6BTP5bu2086mjWdgtKj2nSPdk2Vjg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":396013},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"52a8f4a1df753d1e434015d72426041473272ca9","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.4.1_1787040645659_0.39997742781996903","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"botanary-mcp","version":"0.4.2","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.4.2","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"f8ad0230a984721d5e6bb51e9837902545363ea9","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.4.2.tgz","fileCount":66,"integrity":"sha512-4HoNe2FSHlc9Kbxr+Ah7hpXs9kHEnrmpAHS0jFTTu16gOCQFcN99rUCYRp3p53I4ZTLMMtZkaf+NajfCg2r49g==","signatures":[{"sig":"MEYCIQCw21FkNZOZ9ImkPTXdHLVRkJCCENUvX8wxdj5qqy7n7gIhAPiNx8j9DgEVewy2l7PyQYCkxcm983SazuFy57UvD8KU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":414730},"type":"module","engines":{"node":">=22.0.0"},"gitHead":"915573d82e94c9162e0f38e1b2e52f4acaa7b2ae","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.4.2_1787063032330_0.9302906728793852","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"botanary-mcp","version":"0.5.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.5.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"5e3f09826fabc634026aa1caaefa11b32473d307","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.5.0.tgz","fileCount":146,"integrity":"sha512-dwVy5ty7xnaSvCFESzZOxaR3QXnfEj7wopByCE3EWUzlynXuhgzBexb45b3zvBDfOzJIiaTDE3GI5pN6GhDCdQ==","signatures":[{"sig":"MEUCIE0rU7BNoV0vyowBuLNcH7mb3X3d7oiAI5JD7AnX9giEAiEAramaFoHCJxOgqrrBRKwb/FsfFvy7DQbDrtE0DaSCEws=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":543445},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.5.0_1787113810437_0.450532250579442","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"botanary-mcp","version":"0.6.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.6.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"e87741b07f0b3e4de504cae49bf7265280042f28","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.6.0.tgz","fileCount":146,"integrity":"sha512-tQaDlW0t0XWTRlj7EiiMAvdPLdR0287CVoDqbgtDmJAeIFMoACA58I1sfnwLgkOnLPcfxgbgZkyKEbJRuHo7vw==","signatures":[{"sig":"MEQCICUY0WBoUc5Agy4iDg5w+PZHl5SBZLU3Lg8zBl+QSE1bAiBoUHvE417kV5xGOKOt5o0rMLH59arHh37F3Z1bvGE/+g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":547246},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.6.0_1787161039715_0.4500852402167561","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"botanary-mcp","version":"0.6.1","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.6.1","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"6499d28c8c288f3c2195ded6f0e9d48531014e6a","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.6.1.tgz","fileCount":146,"integrity":"sha512-RLmqXq931iux81uhmNN+8doJOawG2F4WQ4++LZbRIjm9fq8LF015H1xoGQPgLcY+vVVmWTWsJmgY+t5bM4tFYg==","signatures":[{"sig":"MEYCIQD0Xp8JjvkZXfOIKwR/XfJZxT2I0baKEnbmA72PPIVelQIhAOC7BlYM4MH8ZXjr2K1S4hqfvhsICACs2VcF8wgAtoL4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":548744},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.6.1_1787199900521_0.054907149535334154","host":"s3://npm-registry-packages-npm-production"}},"0.6.2":{"name":"botanary-mcp","version":"0.6.2","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.6.2","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"9a00daaf1397152d926d75f99b639ed2777b4fc3","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.6.2.tgz","fileCount":146,"integrity":"sha512-0J3W93aCmfmEIkXoZzPpF4nrz48Sknr9nm7evdP2DPfd+7GWAg/VRiq5bfhlvX/odH9bF4uGkWIbOj3TYwuUBw==","signatures":[{"sig":"MEYCIQDD6iGVt3j5RmqYLAIoAP+3rMoHyWaubaAQ4W1b5mQneQIhAJ8dCET0lEHqyxuM0SHnTYdGXZUciKIIK+2VHWdudSYN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":551061},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"gitHead":"a5e4d27ccc230eef2a8900f086d6db0a0d43ef6f","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.6.2_1787222316883_0.8102240808031211","host":"s3://npm-registry-packages-npm-production"}},"0.6.3":{"name":"botanary-mcp","version":"0.6.3","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.6.3","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"d6a71820ff736dcd71a44240e01b1e5cb808729a","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.6.3.tgz","fileCount":146,"integrity":"sha512-66i11Ka0X8tQ7V6m/rAFOZY4HzEjFZLIkZthINbSCY9PDLHsV/melW+ew1hA4MVK/7VMvPlYmadhqcVjI6cPAg==","signatures":[{"sig":"MEQCIC4kDenyUpf5o8Av6PjULhFBQ0gIJPbzmrD5zyEuJCw6AiALdpVrr4cpaEDb0qjpsBS37ZIJjzzrEAa/e2kBkwffyQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":561495},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.6.3_1787238936728_0.2864088376997753","host":"s3://npm-registry-packages-npm-production"}},"0.6.4":{"name":"botanary-mcp","version":"0.6.4","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.6.4","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"0dd0862d51aaf9fef08c0ad604070422b12d8542","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.6.4.tgz","fileCount":146,"integrity":"sha512-Hep/BvPmgbQtbUa0kxn1kyg06Togr+78rMdAXL1yueCu0TU2g9s86K1GIxJcCw32GViXOhCnog40GNero7EjZg==","signatures":[{"sig":"MEYCIQDAezXnvToK0tm1svFllRm1KNPk30Sk7Qsz3tgw3BKA6gIhAI/b3eBfvR0L7IHEmGV52ke5mT/nONkvq01kwMyBEWVG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":561744},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.6.4_1787243401738_0.6077876789650305","host":"s3://npm-registry-packages-npm-production"}},"0.6.5":{"name":"botanary-mcp","version":"0.6.5","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.6.5","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"9f0cb90fb2c048f587ae51fadfc62ac5007f4658","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.6.5.tgz","fileCount":150,"integrity":"sha512-XVRKY5X8zhvDoCOwyb5H+F700kRMOIjR7Ai4DGHkONs/hueEMH6nvdvk5d1s7p8ArF6DEzENeeso/yD4t4DxlQ==","signatures":[{"sig":"MEQCIEZDIAosIB4DLTyR412/YwnmkrI49Xy1W/JvNfIoR4YtAiBXgpLQtpAWW1D/OEERpXHeYQ1hYcDC8kbf7qORX68bvQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":575924},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.6.5_1787265152606_0.3144538641158976","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"botanary-mcp","version":"0.7.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.7.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"b4e3a8a4defacda05768636706136c27478ee9d7","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.7.0.tgz","fileCount":166,"integrity":"sha512-1IkVll9XBSJMSjAeEaNJ3Nd6J6SsuGAmSRDGqisO0T7WSNp4aSy2O9dUz87RDLxEuv7KK/1l6me9VdcrQ+16tQ==","signatures":[{"sig":"MEQCICui8E9+9bVEJ7hlXgCK/WDu9AHJVWXan6r3ikgr/YoHAiAx7HTn7+PIMCiTAxxY9SHNOZ7GOBydBm3z6CebYEwSKQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":685699},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"gitHead":"cc31ca7587ffb5f7632154686a7f09f6bf9b5986","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.7.0_1787290401744_0.32737182639981444","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"botanary-mcp","version":"0.8.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.8.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"0811610cd77b7ca4b5a863a88a466b48102aac46","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.8.0.tgz","fileCount":182,"integrity":"sha512-v9fic+0Wc5b0oT+j/ha3Ji+h51sV9OpH5V7apOErxDZaIKWhr/fbypKzvroPZI7pTWgHE/ggKzySP4qDJYdxag==","signatures":[{"sig":"MEQCIHlTQjhdji3mvGHpqLn6UhI8dL/ngQ37BCnglwIVzs2pAiBVYPp1vt8eT+eLD/yUxMRMc46E2KoPhfyaas29EmrK7w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":783600},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.8.0_1787704683150_0.4397164470426027","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"botanary-mcp","version":"0.9.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.9.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"0e2b12f67056f6c1cf3e863da21e16d5dc59a8f9","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.9.0.tgz","fileCount":182,"integrity":"sha512-OBgP5uxCllJnNNpH35JKTvnjYvCSduKhNkUXmMt3dyLuz+/E99wXLGcIA/Bep7lBBrQW2WWMedGevFCwaBWTqQ==","signatures":[{"sig":"MEUCIQCC/tUbbu/Kgt9Hh8QlCfZ2/y6Ax1pPhGyA9ip/iX2v/AIgX0CImYNXRdax1nKT2ZFpLx63k9l6x1xpG75C5TkK0vg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":797815},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"gitHead":"f2c3a688e5fdc4637f9bab0bf985fd596bf9ff09","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.9.0_1787798751608_0.4539374291704328","host":"s3://npm-registry-packages-npm-production"}},"0.9.1":{"name":"botanary-mcp","version":"0.9.1","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.9.1","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"9b4cd5d93306856e148151c93f1a511b9bf8cff3","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.9.1.tgz","fileCount":182,"integrity":"sha512-aEw43etc65NBQc8V6Cy/VBrnLEa7tw8lZSedfNA80LkHNbKVguGZcCAm/+JFOc1AZ2AIa/dbXzDA0A0IGK2FSw==","signatures":[{"sig":"MEYCIQCOnsUrytDLYvbHzGs+eST2tIm52FljhV9NJAV9o6VD8QIhAK7Alb8B1OJf9v9Tf7t7UdN7zjjZIeUkgWHvwnFuMGwQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":801030},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"gitHead":"80fb97423b2d475fbc2295aaccb216a97bab5108","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.9.1_1787806385436_0.013478882399814207","host":"s3://npm-registry-packages-npm-production"}},"0.9.2":{"name":"botanary-mcp","version":"0.9.2","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.9.2","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"9f194079248e018702f2ec1e52ea9de0b8a61548","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.9.2.tgz","fileCount":182,"integrity":"sha512-+LDCT9f06Y44TPT3bygTLdAfT7xIe7xK8DSvFn5qNFX4Y1uPX8qnhVBK5heB8a3ZmWnxBxPxMJciuS9fo2FBEQ==","signatures":[{"sig":"MEYCIQDf7YuzIV8Cjwpm6ZTBuH66SuUbAJPDYqGcfhr7oVzEzwIhAKBm2tOHoU3nQy4b6vj9w1gqZLbGYgbUaAlI6zKv/gv7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":802899},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"gitHead":"76350a829084d3be0587cf35e37706ab6058a0b7","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.9.2_1787848176358_0.20587424194349357","host":"s3://npm-registry-packages-npm-production"}},"0.9.3":{"name":"botanary-mcp","version":"0.9.3","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.9.3","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"10e5086d748db9d602615efdb0fdbbf5ececc5cd","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.9.3.tgz","fileCount":190,"integrity":"sha512-22cF9hAB/cHxZLtlNu7y7eqnpQtAXxEsW1W+kBybFGSBK8Qjm/mNj8niJJghYqWSDgpadnoQmM+HLfPSyVNXjg==","signatures":[{"sig":"MEYCIQCjHChBc4LN6xhzOhwtV5L2dq0Z/pFGPtuhT/pYMRS/AAIhAO7anGIP1VxSztCJgVZWgX16O/d5Ws31bE1DWQqLTy37","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":870391},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.9.3_1788076850912_0.03684650388618138","host":"s3://npm-registry-packages-npm-production"}},"0.9.4":{"name":"botanary-mcp","version":"0.9.4","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.9.4","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/bin/botanary-mcp.js"},"dist":{"shasum":"1f45bdc7939abb3969fe926f208d5f7cdcce55bd","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.9.4.tgz","fileCount":190,"integrity":"sha512-v31Scd+kd5qjg/je3n60uTNGTnjDka7tXJcdLGdoHAJsLuh7M96PthSGZp8KzKxS1HDDBc3bQ27vIzW7J577oA==","signatures":[{"sig":"MEUCIFi66R6zrfGkdfPRG5bRgx3udBsM8kX9slTgqOQPEbtHAiEA1/QngvnHydLuD8w2m+RLVK+PKhCBxN0zXq5Hd1BNy/A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":882217},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./dist/src/index.js"},"gitHead":"fa4fa502f383258ea47f140beda76981dd55f710","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/bin/botanary-mcp.js","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"22.22.0","dependencies":{"viem":"^2.54.6","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.9.4_1788090820824_0.4685461351684628","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"botanary-mcp","version":"0.10.0","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.10.0","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/botanary-mcp.js"},"dist":{"shasum":"9ab99b3026c52ba3a617053c5c6f725493622fba","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.10.0.tgz","fileCount":51,"integrity":"sha512-2tZ9/K/yP7E/BohWrKEEJnMuAL0yX4xv3Hqx33cU/KVSsDlsladR7i8yAgu25YrMT+ODwH4olb7OGM94Jlr1Yw==","signatures":[{"sig":"MEUCIQCFzITmQP+LVLoiX3LZELEQDWAD6REqmpEw/EpxXdAC5gIgH+0zCBEJk2HaQv8gnz3+igNUvDVNk5QxGgba1H67G5I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCcSgwDs9vEpwVsqif+kXsAR/XOpU4lDdTE0qZrGd/1twIgYLS8wJcqehTJqj2t91JDstSA3j2uDlUuvWvdznvGSpQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":382276},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/types/src/index.d.ts","default":"./dist/index.js"}},"gitHead":"a1cc726beaf1c2397c765c8ae49b4842022dc14b","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"node scripts/build.mjs","start":"node dist/botanary-mcp.js","prepare":"node scripts/build.mjs","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"deprecated":"Invalid executable shebang. Use 0.10.1 or later.","_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"25.3.0","dependencies":{"viem":"^2.54.6","@botanary/agent":"0.1.0-alpha.1","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","esbuild":"0.25.12","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.10.0_1788974354533_0.8211325370995257","host":"s3://npm-registry-packages-npm-production"}},"0.10.1":{"name":"botanary-mcp","version":"0.10.1","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.10.1","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/botanary-mcp.js"},"dist":{"shasum":"195c84a4936468f7863a4eaf4eca415f42e8da39","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.10.1.tgz","fileCount":51,"integrity":"sha512-mpDeeAMwtS5SeBqQRuqjPY0k/oWKleZBHUBDe07V2Uce9ob44PxZkdmwDniv19XCq1zUy6OKIs+uGM3DocD9Lw==","signatures":[{"sig":"MEYCIQCOGnxmuwuwmKvemGugDm9m3YABqc8m2/A4rb0Q9R0+fwIhAPJZeXlWN1QySrwo1BR7o/nD0nTJg+SF0PCV5Nk+nyVl","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAcS2rnyDvAJoWe7mWK6NZj2n3rjT9I4vs9HkV2sFb6WAiEAygX3RwbPQbGLugxZ/qbytX+gSmSuaEI9/eYEaxo55a0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":382256},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/types/src/index.d.ts","default":"./dist/index.js"}},"gitHead":"761fd16431ebdb29dfc488bad81ecc9849e647ac","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"node scripts/build.mjs","start":"node dist/botanary-mcp.js","prepare":"node scripts/build.mjs","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"25.3.0","dependencies":{"viem":"^2.54.6","@botanary/agent":"0.1.0-alpha.1","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","esbuild":"0.25.12","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.10.1_1788974479823_0.15826466215693968","host":"s3://npm-registry-packages-npm-production"}},"0.10.2":{"name":"botanary-mcp","version":"0.10.2","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.10.2","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/botanary-mcp.js"},"dist":{"shasum":"db41bb5f8f351920bff2a87feaf7474f3f12d686","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.10.2.tgz","fileCount":51,"integrity":"sha512-mqkEGgmCAlp6IPIkIJfZYHsUG4outvjWh9ncDwzdTwpNLNscxiciBXXE6NOovPmohlteM85uWFgkhEGQyNOP7A==","signatures":[{"sig":"MEUCIQCAVJcK3916ZBU7lN12VB30XZjZxv4+CuEAaSFd377TBgIgMA5uUyCw3eg8l1ox9YV8LK9M2sp2yGyIgMwiAGUQPFM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCxt4qV+fUo5LOwUd6Iq/ViJ3nMnqF4XrvDjGUTYojs9gIhAK8Eyl3cfsg/UHhzmLkS5mki68tH+c9doPFhFIO8yNT4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":534894},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/types/src/index.d.ts","default":"./dist/index.js"}},"gitHead":"31f8b5f6bc81ee4f9a7b03e4c734353c20a52989","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"node scripts/build.mjs","start":"node dist/botanary-mcp.js","prepare":"node scripts/build.mjs","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"25.3.0","dependencies":{"viem":"^2.54.6","@botanary/agent":"0.1.0-alpha.1","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","esbuild":"0.25.12","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9","javascript-obfuscator":"4.1.1"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.10.2_1788974777914_0.14815953895429668","host":"s3://npm-registry-packages-npm-production"}},"0.10.3":{"name":"botanary-mcp","version":"0.10.3","keywords":["mcp","model-context-protocol","botanary","agent"],"license":"UNLICENSED","_id":"botanary-mcp@0.10.3","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"homepage":"https://docs.botanary.xyz","bin":{"botanary-mcp":"dist/botanary-mcp.js"},"dist":{"shasum":"3d49a79be34d5715769452eae61e90bbc4cc9212","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.10.3.tgz","fileCount":51,"integrity":"sha512-YEyCfxF1/TjOcqPEBQ7h6VkAS6G5+E8MSYojZ5Tc0Z0/TWNWO1P1dzljO87VjngPQAbqcOihJ+2WPXXwc6YgfQ==","signatures":[{"sig":"MEYCIQCXRocjbihMCu/QNrM5iytjoELuukDn38K/MzFy3lvUQAIhAPHu7ktY+qcwXbP+ootebnG5aOqJFSLj4k2YDp4E6bW1","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIAVFv5iJEiZg15BkAIbPQt6PXT2XoH3BJut/ofR+zPIHAiBTkZArnBI8OtVg3+/Zhz+G1I9k74LXIdCBfnKQ6zLeOg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":534119},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/types/src/index.d.ts","default":"./dist/index.js"}},"gitHead":"e7c8e6931e686db4a1f055151e4a2df8ea1732ec","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"node scripts/build.mjs","start":"node dist/botanary-mcp.js","prepare":"node scripts/build.mjs","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"_nodeVersion":"25.3.0","dependencies":{"viem":"^2.54.6","@botanary/agent":"0.1.0-alpha.1","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","esbuild":"0.25.12","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9","javascript-obfuscator":"4.1.1"},"_npmOperationalInternal":{"tmp":"tmp/botanary-mcp_0.10.3_1788976563555_0.7452418023976972","host":"s3://npm-registry-packages-npm-production"}},"0.10.4":{"_id":"botanary-mcp@0.10.4","bin":{"botanary-mcp":"dist/botanary-mcp.js"},"dist":{"shasum":"8dbb7b79f4af205fc183d9968f9946430dae13cd","tarball":"https://registry.npmjs.org/botanary-mcp/-/botanary-mcp-0.10.4.tgz","fileCount":51,"integrity":"sha512-h1FXRqbvn9FZxgLuhRtNzC8dCAmq75zn5GTgyBI185VIjRSZXbLVE6RUB72JCZuSkpiVxAi64cDejI54TgjXfA==","signatures":[{"sig":"MEYCIQCKlEUgMjLzVxDcpzxBKJ5pxFivdkrIn/XMSJhU0OX+sQIhAI8k4tNRjNivuy90PdG9xuPvRPr80JwTegRcQl3CDV3S","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBA4DSP+61VLuc9HchCibvB8qyKoIWr1rBVzSFIBiDCNAiAu0n9MhD0iBkqglogWYMQOEmaa3FSIQUSesHQnZt5xNQ=="}],"unpackedSize":535581},"name":"botanary-mcp","type":"module","_from":"file:/var/folders/9g/8spmdb0j0n10fnnrx_ff5y0c0000gn/T/tmp.2g6YZJ8w3O/botanary-mcp-0.10.4.tgz","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/types/src/index.d.ts","default":"./dist/index.js"}},"license":"UNLICENSED","scripts":{"dev":"node --watch -r @swc-node/register bin/botanary-mcp.ts","test":"vitest run","build":"node scripts/build.mjs","start":"node dist/botanary-mcp.js","prepare":"node scripts/build.mjs","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","generate:routes":"node scripts/generate-routes.mjs","generate:write-routes":"node scripts/generate-write-routes.mjs"},"version":"0.10.4","_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"homepage":"https://docs.botanary.xyz","keywords":["mcp","model-context-protocol","botanary","agent"],"_resolved":"/var/folders/9g/8spmdb0j0n10fnnrx_ff5y0c0000gn/T/tmp.2g6YZJ8w3O/botanary-mcp-0.10.4.tgz","_integrity":"sha512-h1FXRqbvn9FZxgLuhRtNzC8dCAmq75zn5GTgyBI185VIjRSZXbLVE6RUB72JCZuSkpiVxAi64cDejI54TgjXfA==","_npmVersion":"11.7.0","description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","directories":{},"maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"_nodeVersion":"25.3.0","dependencies":{"viem":"^2.54.6","@botanary/agent":"0.1.0-alpha.1","@modelcontextprotocol/sdk":"1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"yaml":"^2.9.0","vitest":"^2.1.8","esbuild":"0.25.12","typescript":"^5.7.3","@types/node":"^22.10.5","@swc-node/register":"^1.10.9","javascript-obfuscator":"4.1.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/botanary-mcp_0.10.4_1789020014346_0.008938968786916135"}}},"time":{"created":"2026-08-11T15:05:50.030Z","modified":"2026-09-10T06:00:16.657Z","0.1.0":"2026-08-11T15:05:50.473Z","0.1.2":"2026-08-12T02:08:43.049Z","0.1.3":"2026-08-12T02:23:52.807Z","0.2.0":"2026-08-12T05:08:49.185Z","0.3.0":"2026-08-14T02:50:52.631Z","0.4.0":"2026-08-17T11:02:22.943Z","0.4.1":"2026-08-18T08:10:45.812Z","0.4.2":"2026-08-18T14:23:52.471Z","0.5.0":"2026-08-19T04:30:10.593Z","0.6.0":"2026-08-19T17:37:19.904Z","0.6.1":"2026-08-20T04:25:00.658Z","0.6.2":"2026-08-20T10:38:37.023Z","0.6.3":"2026-08-20T15:15:36.879Z","0.6.4":"2026-08-20T16:30:02.038Z","0.6.5":"2026-08-20T22:32:32.760Z","0.7.0":"2026-08-21T05:33:21.888Z","0.8.0":"2026-08-26T00:38:03.336Z","0.9.0":"2026-08-27T02:45:51.809Z","0.9.1":"2026-08-27T04:53:05.599Z","0.9.2":"2026-08-27T16:29:36.514Z","0.9.3":"2026-08-30T08:00:51.039Z","0.9.4":"2026-08-30T11:53:40.975Z","0.10.0":"2026-09-09T17:19:14.614Z","0.10.1":"2026-09-09T17:21:19.926Z","0.10.2":"2026-09-09T17:26:18.005Z","0.10.3":"2026-09-09T17:56:03.661Z","0.10.4":"2026-09-10T06:00:14.461Z"},"license":"UNLICENSED","homepage":"https://docs.botanary.xyz","keywords":["mcp","model-context-protocol","botanary","agent"],"description":"Botanary's local MCP server for an outside coding agent (Claude Code, Codex, Cursor, or a custom build): an AGENT LANE that generates its own signing key and spends unattended under whatever grant its owner gave it, and a WALLET LANE that lets the human o","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"readme":"# botanary-mcp\n\nA local MCP server that lets an outside coding agent - Claude Code, Codex, Cursor, or something you\nwrote yourself - act on a Botanary account. It has **two lanes**, backed by two independent credentials:\n\n- **The agent lane.** This machine holds its own secp256k1 signing key, proves who it is, pairs with a\n  Botanary account, reads its balance, and spends *unattended* under whatever grant its owner gave it -\n  all without Botanary ever holding, seeing, or backing up that key.\n- **The wallet lane.** The human owner logs in through their own browser (`wallet_login`) - the same\n  provider consent they already use - and this machine holds an opaque, revocable session that can read\n  and *build* on the owner's behalf, but **can never sign as the owner**. Every owner-authorized money\n  movement ends in a signature the owner makes themselves, in their own browser, against their own\n  embedded wallet.\n\n**These are independent credentials that can point at different Botanary accounts.** The agent key is\npaired to whatever account its owner paired it to; the wallet session operates on whatever account was\npicked at login. Nothing forces them to agree - `wallet_status` prints both bindings side by side and\nflags a mismatch as a first-class finding, and `wallet_send`'s own lane arbitration (below) refuses to\nlet a mandate on one account authorize a spend on the other, no matter how \"helpful\" that would be.\n\n> **Full documentation: https://docs.botanary.xyz/mcp** - install recipes per client, the two lanes,\n> the trust model, and a tool reference generated from this package.\n\n## Tools\n\n`botanary-mcp` advertises a **subset** of its tools at any moment - a small starter set when nothing is\nlogged in yet, the wallet tools once `wallet_login` succeeds, the agent tools once this machine has a\nlocal identity - and pushes `notifications/tools/list_changed` when that set changes. This is a listing\noptimization, not a security boundary: every tool below is always *reachable* by name, and a hidden one\ncalled anyway answers honestly (\"log in first\") rather than pretending not to exist. See \"Why the\nadvertised tool list changes\" further down.\n\n### Agent lane (this machine acting as a connected agent, under a grant)\n\n| Tool | What it does |\n|---|---|\n| `diagnose` | START HERE when anything is unclear or an action failed. Single call answers: who is this agent bound to, is the account funded on the grant's chain, is that chain usable, and what - ranked - is blocking the next action. Read-only: never signs or mutates. |\n| `get_identity` | Reports this agent's address/public key/fingerprint. Generates the key on first call. No network call. |\n| `get_pairing_code` / `regenerate_pairing_code` | Shows (or rotates) the short code the owner enters under \"Connected agents\", registers it with the backend so their claim can find it, and **opens their browser** on that screen with the code already filled in - once per code, and never for a code the backend could not register. `open: false` suppresses the browser; `wait: false` returns the code without blocking on the claim. |\n| `pair` | Signs the pairing code and submits the proof to `POST /agents/pair`. |\n| `whoami` | Calls `GET /agents/me` - this agent's own identity, account, and live grant (or an honest `grant: null`). |\n| `get_balance` | Calls `GET /balance` under this agent's session. |\n| `list_requests` | Calls `GET /agents/requests` - every approval request this agent has filed and the owner's verdict on each. The read half of `request_approval`. |\n| `list_chains` | Calls `GET /chains` - every chain this backend serves, each with the `chainTier` that decides what it can do. |\n| `get_gas_methods` | Calls `GET /gas/methods` - only the gas methods available for this account on a chain (the backend filters out unavailable ones). |\n| `get_account` | Calls `GET /account` - the ONE account this agent is bound to and its address and deployment status. |\n| `propose_payment` | Reads the grant's bounds first; refuses honestly (citing the backend's own numbers) when there is none or the amount is out of bounds; otherwise builds against THIS agent's own grant id (`POST /delegations/{delegationId}/actions` - the session-key-validatable lane, never the owner-lane `/money/send/build`) and relays (`POST /userops`) signed with the grant's own session key. |\n| `propose_swap` | The same shape as `propose_payment`, over a grant's SECOND on-chain action (`executeUnderGrantWithAllowance`). Reads the venue the grant pinned (`policySet.swapVenue`) first and refuses honestly - naming the backend's own numbers - when the grant names no venue at all, is on another chain, sells a different token, or the amount is over the venue's per-swap ceiling; otherwise builds `action: 'swap'` on the same delegated-action lane and relays it with the grant's own session key. The route is the backend's to pick: the grant pins one router, and a best route through any other is declined there by name. |\n| `request_approval` | Raises a request for an action outside the grant (`POST /agents/requests`) - the \"ask\" half of Flow 7d. |\n| `what_may_i_do` | Renders the grant in plain terms, or an honest \"nothing yet\" - a convenience read, never the check. |\n| `forget` | STEP 1 of 2: preview what would be destroyed and get a single-use confirmation token. Deletes nothing on its own. |\n| `confirm_forget` | STEP 2 of 2: actually delete the agent key from this machine. Requires the token from `forget`. |\n| `list_apis` | Calls `GET /apis/list` - the paid (x402) third-party API endpoints this agent may call on a chain, each with its live price and this agent's remaining budget. Reads only; calls nothing and spends nothing. |\n| `call_api` | Calls `POST /apis/calls` - call one of those endpoints and pay for it, inside the budget the OWNER committed on-chain (`X402PaymentValidator`). Signs the EIP-3009 authorization with this agent's own key; the owner never signs, and the on-chain budget - not this tool - is what bounds it. A response marked `simulated` is synthetic test data, and says so. |\n| `get_api_budget` | Calls `GET /apis/budget` - remaining authorizations, per-call maximum, expiry and epoch for this agent on a chain. Does NOT say which endpoints are enabled (`list_apis` does). |\n\n### Wallet lane (the human owner's own session, after `wallet_login`)\n\n| Tool | What it does |\n|---|---|\n| `wallet_login` | Device-style browser login: opens the owner's browser, waits for them to authorize, stores the resulting session in the OS keychain. No browser available (SSH, a container)? Prints the URL and code instead - same flow, no second code path. |\n| `wallet_logout` | Revokes the session (`DELETE /auth/session`) and clears it locally - even if the network call fails, so a dead network can never strand a live credential on disk. |\n| `wallet_status` | Prints the wallet session's account AND the agent's bound account side by side, and flags a mismatch explicitly. Safe to call regardless of which lane(s), if any, are set up. |\n| `wallet_use_account` | Switch which of the owner's accounts every subsequent `wallet_*` call uses - including which account `wallet_send`'s lane arbitration compares a paired agent's mandate against. Validates the id against `GET /accounts` first; persists to the same keychain item `wallet_login` writes. |\n| `wallet_send` | Sends tokens from the **owner's own account**. See \"Lane arbitration\" below - this is the tool the safety property in this README is really about. |\n| `wallet_portfolio` | Reads `GET /balance` + `GET /chains`: balances across all chains and each chain's tier (watch/basic/botanary). Raw balance and tier data - it does not itself evaluate whether a send would succeed. |\n| `wallet_activity` | Reads `GET /history`: the owner's recent sends, swaps, and yield transactions with timestamps, amounts, and final status. |\n| `wallet_markets` | Reads `GET /markets/tokens`: public market data (prices, symbols) - not account-scoped. |\n| `wallet_yield` | Reads `GET /yield/pools` + `GET /yield/shortlist` + `GET /farm/positions`: available pools, a recommended shortlist, and this account's farming positions. `shortlist` is ranked off the caller's own holdings server-side and is NOT scoped to the account `wallet_use_account` most recently switched to - the result's own `scopeCaveats` field says so explicitly. |\n| `wallet_mandates` | Reads `GET /delegations` + `GET /mandates`: what the agent lane may spend unattended - active delegations with budget info, and any outstanding mandates. |\n| `wallet_agents` | Reads `GET /agents` + `GET /agents/requests`: connected agents and any pending approval requests they've filed. |\n| `wallet_api_get` | Read ANY `GET` endpoint in Botanary's frozen OpenAPI contract, authenticated as the owner. **GET-only, deliberately** - see below. |\n| `wallet_api_write` | Call a genuinely administrative write endpoint - claim an agent, mark a notification read, rename an account, edit a pay-sh allowlist, manage conversations - authenticated as the owner. Every route whose response is an unsigned build, or that the contract marks `x-client-signed`, is excluded by construction; a small explicit denylist covers what that mechanical rule cannot see. **Never a fund-moving or authority-granting write** - see below. |\n| `list_sign_kinds` | Reads `GET /sign-kinds`: every sign-request kind this backend currently registers, each with a summary, the routes it builds and relays through, and whether it is available right now. Call this before `wallet_sign_request` to learn what a kind takes. |\n| `wallet_sign_request` | Park a typed, kind-discriminated intent (`POST /sign-requests`) and hand it to the owner to review and sign in their own browser. The one write primitive covering every owner-authorized action that is not `wallet_send`. **Cannot sign, cannot relay** - see below. |\n| `resolve_token` | Resolve a token address or CAIP-19 asset ref to its full identity - symbol, name, decimals, and which source vouches for it. Refuses bare symbols: a symbol is a label a contract picked for itself, and two contracts on one chain can share one, so the product will not guess. Call `list_tokens` when you only have a symbol. |\n| `list_tokens` | Every token this account holds on a chain, with the contract address and CAIP-19 asset ref you need to spend it. This is the discovery command for `wallet_send`, which takes an address and refuses a symbol. When two rows share a symbol, show both and let the user choose; never guess. |\n\n## Why `wallet_send` requires a token address, not a symbol\n\nThe `wallet_send` tool requires a contract address or CAIP-19 asset ref for the `token` parameter, never a symbol. This is by design: a symbol is a label a contract picks for itself, and two contracts on one chain can legally share the same symbol. The product will not guess which one you meant. Use `resolve_token` to turn a symbol into a full identity, or call `list_tokens` to discover every token this account holds on a chain, each with the address you need.\n\n## Lane arbitration: how `wallet_send` decides who signs\n\n`wallet_send` resolves one of exactly two lanes, in this order, every time it's called:\n\n1. **This machine holds a paired agent identity with a live mandate that covers the action, ON THE SAME\n   ACCOUNT the wallet session is presently using.** Then it signs locally with the agent's session key\n   and relays - no browser, no human click.\n2. **Otherwise** - no paired agent, no live grant, the mandate is out of bounds for this exact request\n   (wrong chain, over budget, over the per-action cap), or **the mandate is on a DIFFERENT account** -\n   it parks a typed intent (`POST /sign-requests`), opens the owner's browser to review and sign it\n   there, and polls to a terminal result.\n\n**The same-account condition is not incidental - it is the whole safety argument.** The two credentials\nare independent (see the top of this README): an agent paired to one account and a browser session open\non another is not a bug to route around, it's the scenario this check exists to catch. Without it, \"it\nsigned without asking me\" could mean money moved out of an account the owner was not even looking at -\nwhich is exactly what happened once (an agent paired to an empty account while the owner's real funds\nsat elsewhere, surfacing as a cryptic `AA21 didn't pay prefund` three Postgres queries later). Every\n`wallet_send` result names the lane it took (`lane: \"agent\" | \"browser\"`), and when a mandate existed but\nwas refused for the agent lane, the result says exactly why.\n\nA local balance/chain-tier check runs before opening a browser, purely as a courtesy so a doomed request\ndoesn't cost the owner a browser trip - **it is never the authorization.** The real check is the build\nthe browser page itself does against the live backend, and beneath that, on-chain enforcement. A green\nresult from this preflight proves nothing by itself, the same discipline `propose_payment`'s own\nclient-side bounds check documents on the agent lane.\n\n## Waiting for results: handles, streams, and why elicitation is not approval\n\nSeveral tools (`wallet_login`, `wallet_send`, `pair`, `request_approval`, `propose_payment`, `propose_swap`)\ndo not return immediately - they need human action, on-chain confirmation, or both. These tools now WAIT\nfor completion instead of handing back a reference and walking away.\n\nWhen a tool waits, it:\n\n1. **Reports progress** - periodically sends heartbeats so the client knows it is still alive and waiting,\n   never going silent for minutes at a time.\n2. **Watches the backend's declared deadline** - the server tells the tool how long it is willing to hold the\n   operation open. The tool will wait until that deadline, then stop, and the client can join the same wait\n   at any time by calling `botanary_wait` with the returned handle.\n3. **Respects an abort signal** - if the client has to stop (interrupt, timeout, preemption by a newer task),\n   it can abort the wait without breaking the backend operation. The handle stays live, and the wait can be\n   rejoined from where it left off.\n4. **Runs a stream when the server supports it** - most operations have a Server-Sent Events stream endpoint\n   that delivers updates in real time. When a stream is not available (old backend, network lost), the tool\n   automatically falls back to polling, asking the backend \"is this operation done?\" at regular intervals.\n\n## Handles, and why a handle is not a secret\n\nA handle is an opaque reference to an ongoing operation at the backend - a place to rejoin a wait that was\ninterrupted. The handle file itself carries **no secret**. Any credential the operation needs (a session\ntoken, a signer's key, an approval credential) lives in the same keychain chain `wallet_login` uses, and is\ndeleted the moment the operation terminates - the handle cannot be replayed from an old transcript.\n\nTo rejoin a wait: **call `botanary_wait` with the handle** - never re-call the original tool (`wallet_send`,\n`get_pairing_code`, `request_approval`, `propose_payment`, `wallet_sign_request`). Re-calling starts a\nbrand-new operation; the wait will not pick up where it left off.\n\n`wallet_login` is the one flow that opens **no** handle, so there is nothing to rejoin: a login that drops\nis a login you run again. That is deliberate - resuming one would mean re-reading the freshly minted\nsession token, and a session token belongs in the keychain and the `Authorization` header, never in a tool\nresult.\n\n## Why elicitation is never an approval\n\nWhen a tool waits through the `wallet_send` browser handoff, it may elicit - show the caller where a\nsignature is being requested, with a cancel affordance. **Elicitation is strictly presentational.** It never\nasks for an approval and never authorizes anything. It only tells the caller: \"The signature is needed in\nyour browser, here is a link or a code to review it.\"\n\n- If the caller cancels the elicitation, the wait stops locally, but the browser tab stays live and the\n  owner can still sign it there.\n- If the owner signs in the browser, the elicitation on the model's side gets the result.\n- If the owner rejects it in the browser, the wait gets the rejection and surfaces it as the final result.\n\nThe only boundary that counts is the one on-chain.\n\n## The write boundary: three primitives, never a generic `api_post`\n\n**There is no GENERIC write counterpart, and there must not be one.** A tool that took an arbitrary path\nand body and forwarded it to any mutating endpoint would let a model reach *any* mutation - freeze the\naccount, remove a signer, drain a grant - with no typed intent, no review panel, and no lane arbitration.\nThat argument hasn't changed. What has changed is that it is no longer served by a single refusal -\n`wallet_api_get` being GET-only and nothing else. It is now served by THREE primitives, each admitting a\ndifferent, narrow slice of what a caller can reach, with the dangerous middle - anything that could move\nfunds or grant authority on its own - structurally unreachable by all three:\n\n| Primitive | What it reaches | How the boundary holds |\n|---|---|---|\n| `wallet_api_get` | Any documented `GET` | Read-only. There is no body to send, no method but `GET`. |\n| `wallet_sign_request` | Any typed sign-kind | Never signs, never relays - returns a URL the OWNER opens and signs in their own browser. |\n| `wallet_api_write` | A small set of administrative `POST`/`PUT`/`PATCH`/`DELETE` routes | Every route that returns an unsigned build for the owner to sign is excluded from its manifest **by construction** - see below. |\n\n### `wallet_api_get` is GET-only, deliberately\n\nEvery path is validated against a manifest generated from the frozen OpenAPI contract\n(`openapi/botanary-v1.yaml`, via `pnpm generate:routes` - see \"Development\" below) before anything\nreaches the network. An undocumented path, or any method other than `GET`, is refused. `wallet_api_get`\nis deliberately incapable of writing anything, and always will be.\n\n### One parse: the string that is validated is the string that is requested\n\nBoth path allowlists - `wallet_api_get`'s and `wallet_api_write`'s - share a single canonicalisation\nstep (`src/http-path.ts`) that runs BEFORE any manifest is consulted, and both then match and request\nthe *same* canonical string. This is not a detail: a path that one layer validates and another layer\nre-parses differently is an allowlist that allows something other than what it approved. `fetch`\nre-parses whatever it is given with the WHATWG URL parser, which resolves `.` and `..` (percent-encoded\nforms included), normalises `\\` to `/`, and truncates at `#` - so a regex allowlist that treats those as\nordinary characters and then rebuilds the request from the caller's raw string is checking one route and\ncalling another.\n\nSo a caller-supplied path is refused unless it is *canonical*: absolute, never beginning `//`, no\nfragment, no empty segment, every segment drawn from unreserved/sub-delim characters or well-formed\n`%XX` escapes that do not decode - through any number of layers - to a separator, a fragment marker or a\n`.`/`..` traversal, and finally a string the URL parser reproduces byte for byte. A `{param}` in a\nmanifest template compiles to that same charset, so a path parameter structurally cannot hold a\nseparator. The denylists are enforced as refusals rather than as mere omissions, so a denylisted literal\ncannot come back through a parameterised sibling that happens to match it. `src/api-client.ts` re-checks\nthe same property immediately before calling `fetch`, as a second layer for callers other than these\ntwo. A percent-encoded character that is genuinely part of an id (`%3A` for a CAIP-style `:`) passes and\nis transmitted verbatim - never decoded, never re-encoded.\n\n### `wallet_sign_request`: the typed-intent lane\n\nIt is the write primitive this package has had the longest, and it covers every owner-authorized action\nother than a send (see the tools table above and \"Lane arbitration\" below for why `wallet_send` stays\nseparate). Read closely, it does not weaken the argument above - it satisfies every part of it:\n\n- **Typed intent.** `wallet_sign_request` takes a `kind` and a `params` object, never a path and a raw\n  body. The backend validates `params` server-side against that kind's own DTO (one shape per kind,\n  `SIGN_KIND_DTOS` in the contract) before anything is stored; an unregistered kind, or a body that does\n  not match the registered one, is refused before the owner is involved at all. Call `list_sign_kinds`\n  first to see every kind currently registered and exactly what it takes.\n- **Review panel.** This tool never builds calldata and never signs. What it returns is a URL - the\n  SAME `/sign` handoff `wallet_send`'s browser lane already uses - that the OWNER opens in their own\n  browser, where the page builds the operation, simulates it, and asks for their signature. A model\n  calling this tool can make the owner see a request; it cannot make anything happen without them.\n- **Lane arbitration.** `wallet_sign_request` has none to weaken, because it has no agent lane to\n  arbitrate into: it is the browser handoff, always, for every action it covers. `wallet_send` keeps its\n  own arbitration (agent-vs-owner routing) untouched, because send is the one action where that routing\n  is load-bearing - see \"Lane arbitration\" below.\n\nSo the worst a compromised model achieves through `wallet_sign_request` is ASKING the owner to sign\nsomething - the same authority a stranger with the owner's phone number has.\n\n### `wallet_api_write`: plain session writes that need no signature\n\nEverything left over from the two primitives above is administrative bookkeeping with no fund movement\nand no authority grant of its own: claim an agent, mark a notification read, rename an account, edit a\npay-sh allowlist, manage conversations. `wallet_api_write` reaches exactly that set, and the property\nthat keeps it there is mechanical, not a promise: **every authority action in this backend returns an\nUNSIGNED build for the owner to sign** (`build -> sign -> relay`, the invariant `botanary-be/AGENTS.md`\nstates and `test/no-custody.spec.ts` pins). So a route can be excluded from `WRITE_ROUTES`\n(`src/wallet/write-routes.manifest.ts`, generated by `pnpm generate:write-routes` - see \"Development\"\nbelow) using nothing but the contract itself:\n\n1. **Build-shaped response.** Its success response resolves - directly, through an array's `items`, or\n   through any `oneOf`/`anyOf`/`allOf` branch - to a component schema named `*Build`: `UserOpBuild`,\n   `DelegationBuild`, `GrantBuild`, `ApiBudgetBuild`, and every other one. Freeze, initial account setup,\n   guardian install, add-signer, budget commit, delegation/grant creation - all named this way, all\n   excluded automatically.\n2. **`x-client-signed: true`.** The contract's own flag for \"hands back or consumes something a client\n   must sign\" - it catches real gaps signal 1 alone misses, because not every build-shaped response is\n   named `*Build` (`POST /account`'s `AccountDeployIntent` embeds an unsigned `deployUserOp`; pay.sh's\n   own withdraw-build response is named `PayShWithdrawBuildResponse`, breaking the naming convention by\n   one word) and it also catches every RELAY call (`POST /delegations`, pay.sh's own relay and\n   manual-sign lanes) - the same category `/userops` is in, just with nothing to *build* because there\n   is only something to *relay*.\n\nA small explicit denylist covers what neither mechanical signal can see - it exists precisely BECAUSE the\ntwo rules above are mechanical: a route can pass both (no `*Build` response, no `x-client-signed` flag)\nand still hand back a live session credential, mint session authority for someone else, relay an\nalready-signed payload, or move funds through a custodial signer this backend holds itself (the Virtuals\nagent-wallet withdraw/trade routes - the one deliberately custodial exception this backend carries). One\nmore entry (`/sign-requests`) is denylisted for a different reason: admitting it would let a caller\nconstruct an arbitrary sign-request intent through an untyped path, duplicating `wallet_sign_request`'s own\ntyped-intent lane rather than going through it. Every entry is justified individually in\n`scripts/generate-write-routes.mjs`'s own header comment and its `DENYLIST` object.\n\n**The boundary is two mechanical rules plus this denylist, not one rule** - the numbers, read straight off\nthe frozen contract by `pnpm generate:write-routes` (`src/wallet/write-routes.manifest.ts`'s own generated\nbanner records them on every run):\n\n| | Write operations (`POST`/`PUT`/`PATCH`/`DELETE`) |\n|---|---|\n| Total in the contract | 131 |\n| Excluded - build-shaped response (`*Build`, signal 1) | 57 |\n| Excluded - `x-client-signed: true`, not caught by signal 1 (signal 2) | 9 |\n| Excluded - explicit denylist | 18 (across 17 distinct paths - `/auth/session` denylists both its `POST` and `DELETE`) |\n| **Admitted into `WRITE_ROUTES`** | **47** |\n\nThe result: `wallet_api_write` can be talked into marking a notification read. It cannot be talked into\nanything that moves a token or grants an agent, a signer, or a device new authority - not because the\ntool refuses to *try*, but because the route to do so was never in its manifest to begin with.\n\n**Two admitted routes still refuse at the HTTP layer, and that is a second layer working, not a manifest\ngap.** `/pay-sh/accounts/{accountId}/allowlist` and `/pay-sh/accounts/{accountId}/settings` pass both\nmechanical checks (neither is `*Build`-shaped nor `x-client-signed`) and so ARE in `WRITE_ROUTES` - but\n`wallet_login` mints the same `kind: 'cli'` session `botanary login` does (this package and `botanary-cli`\nshare one identity and session store), and the backend's own `NoCliWritesGuard` 403s any write from a\n`kind: 'cli'` session on the pay-sh and agent-wallet controllers, precisely because those routes move a\nPrivy-custodied balance or widen an agent wallet's spending fence with no owner signature anywhere in the\nloop. The manifest is the first layer, not the only one; a route being admitted here says \"shape-safe to\nattempt,\" never \"guaranteed to succeed.\"\n\n## Why the advertised tool list changes\n\nThis package ships close to twenty tools. Advertising all of them at once - most of which are unusable\nin the caller's *current* state (no wallet session yet, no paired agent yet) - is exactly the kind of\noverlapping-description clutter that degrades tool selection in a client with many MCP servers attached.\nSo the advertised list is gated by state: a small starter set (`wallet_login`, `get_pairing_code`,\n`diagnose`, `wallet_status`, ...) is always visible; the wallet tools appear once `wallet_login`\nsucceeds; the agent tools appear once this machine has a local identity. `wallet_login`/`wallet_logout`\npush `notifications/tools/list_changed` so a client that implements it can re-fetch immediately.\n\n**Not every client implements that notification, and a hidden tool must still work when called.** If\nyour client cached the list from before you logged in and you (or the model) call `wallet_send` anyway,\nit does not 404 or pretend the tool doesn't exist - it answers honestly (\"not logged in - run\nwallet_login first\"). The gating is a UX optimization on top of a surface that is always fully reachable,\nnever a second, hidden permission system.\n\n## Add it to your agent\n\n`botanary-mcp` is published on npm - no clone, no build, no local install step. `npx` fetches and\nruns it on demand, so the one-time setup **is** the one command per client below.\n\n```bash\n# Claude Code\nclaude mcp add --transport stdio botanary -- npx -y botanary-mcp\n\n# Codex\ncodex mcp add botanary -- npx -y botanary-mcp\n```\n\nThe server talks to `https://api.app.botanary.xyz` by default. Point it somewhere else with\n`BOTANARY_API_URL`:\n\n```bash\nclaude mcp add --transport stdio botanary \\\n  -e BOTANARY_API_URL=http://localhost:3000 \\\n  -- npx -y botanary-mcp\n```\n\nCursor has no CLI equivalent - add this block to `.cursor/mcp.json` (project) or `~/.cursor/mcp.json`\n(global) instead:\n\n```json\n{\n  \"mcpServers\": {\n    \"botanary\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"botanary-mcp\"]\n    }\n  }\n}\n```\n\nClaude Desktop is likewise config-file only - add this block to\n`~/Library/Application Support/Claude/claude_desktop_config.json` (create it if it does not exist yet):\n\n```json\n{\n  \"mcpServers\": {\n    \"botanary\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"botanary-mcp\"],\n      \"env\": {\n        \"BOTANARY_API_URL\": \"https://api.app.botanary.xyz\"\n      }\n    }\n  }\n}\n```\n\nRestart the client so it picks up the new server. From here, two independent things you can ask for:\n\n- **\"What's your Botanary identity / pairing code?\"** - the AGENT lane. It calls `get_identity` /\n  `get_pairing_code` and reads the key straight out of wherever this machine's OS keeps secrets. The\n  first call generates the key; nothing before that point touches disk or asks any question.\n- **\"Log me into Botanary\"** - the WALLET lane. It calls `wallet_login`, opens your own browser to the\n  provider login you already use, and waits for you to authorize. Nothing is generated on this machine;\n  the session it stores is revocable from Botanary's Settings → Connected apps at any time.\n\n## What a freshly-connected agent can and cannot do\n\nThis is the product's own promise (Flow 7c/7d), and every tool in this package exists to make it true:\n\n- **Connecting is harmless by itself.** A newly connected, ungranted agent can read balances\n  (`get_balance`) and read its own bounds (`whoami`/`what_may_i_do`) - `propose_payment` refuses\n  honestly, citing the backend's own \"you have no grant\" answer, rather than pretending. It cannot move\n  a cent.\n- **What it's granted, it can spend - unattended, signed with its own key.** `propose_payment` builds\n  and relays a payment under the grant when the amount is within its bounds. Nothing outside that grant\n  works; `request_approval` turns it into a request the owner approves as themselves, or it doesn't\n  happen.\n- **What it can never do, no matter what it was granted:** sign in as the owner, add or remove a\n  signer, write or change a policy, grant access to another agent, or unfreeze the account. A grant is\n  permission to spend inside a fence, never permission to move the fence. None of these tools exist in\n  this package - there is nothing here that could call them even if a prompt tried to talk it into it.\n- **The bound it reads is a convenience, not the check.** `whoami`/`what_may_i_do`/`propose_payment`'s\n  own pre-check all read the grant's bounds from the backend, but the actual enforcement happens\n  on-chain. A bug or a lie in what any of them reports changes nothing about what this agent can\n  actually get away with.\n\n## Pairing opens a browser, and why that is not a new power\n\n`get_pairing_code` launches the owner's default browser on `<app>/agents?pair=<code>`, the same way\n`wallet_login`, `wallet_send` and `wallet_sign_request` already launch one on the URL they need the\nowner to visit. Pairing was the odd one out: it returned a URL and left the person who had never used\nthis package before to click or copy-paste it out of a tool result.\n\nThree limits keep that from being a way to point someone's browser somewhere:\n\n- **The URL is not model-controlled.** It is the configured API origin (`BOTANARY_API_URL`, mapped to\n  the app origin by `deriveAppOrigin`) plus a locally minted code. Nothing a model saw, said or was\n  told reaches it.\n- **`openBrowser` refuses anything that is not a parseable absolute `http(s)` URL, and never involves a\n  shell** - it passes the URL as a single `execFile` argv element. That check is why a mistyped or\n  hostile `BOTANARY_API_URL` cannot turn a deep link into a command.\n- **A code the backend never acknowledged opens nothing.** Registration fails soft, and a window onto a\n  form that will reject the code stages a failure rather than a pairing.\n\nIt also opens **once per code**. `get_pairing_code` is deliberately idempotent - the same code comes\nback until it expires - so a repeated call is the normal case, not a mistake, and each one must not add\nanother identical tab.\n\n## Why intercepting the pairing code alone grants nothing\n\nThe short code this server shows (`get_pairing_code`) is built from two parts, and **neither one is a\nsecret**:\n\n1. A **fingerprint** - a few characters derived from the agent's *public* key. It exists so a human can\n   visually confirm \"yes, this is the code my agent just showed me,\" the same role an SSH host-key\n   fingerprint plays. It is only ever a function of information that's already public (the address\n   itself is shared openly by `get_identity`), so there is nothing about it worth hiding to begin with.\n2. A **nonce** - fresh randomness, generated new each time a pairing attempt starts, with a short\n   (10-minute default) expiry. This is what makes the code single-use and short-lived: once it expires,\n   or once a fresh one is requested, the old code stops being the one anything checks against.\n\nNeither piece is derived *from* the private key, and there's no computation that gets you from\n\"fingerprint + nonce\" back to the 32 bytes that would let something sign as this agent. The code isn't\nan obfuscated secret - it was never built out of one.\n\nThat's what makes the rest of the claim hold: **the code identifies, the signature authenticates.**\nCompleting a connection requires the agent to sign the code together with a timestamp, using the key\nthat never left this machine, and submit that signature with its public key - proof of possession, not\nproof of having seen a string. (The signed message is `code|timestamp`; the code is minted locally, so\nthis is not a server-issued challenge. `mintSession` is the separate flow that does fetch a server\nnonce before signing.) Someone who only\nintercepted the code cannot produce that signature, because they don't have the key. The worst they can\ndo is type the code into their *own* Botanary account's \"Connected agents\" box - which, per the product\nrule above, gets *them* nothing: a connection with no grant can do nothing, and it takes nothing away\nfrom the real owner, whose agent still holds the only key that can ever complete a real pairing for that\nidentity. There is no password, token, or secret anywhere in this exchange for anyone to steal.\n\n(The `pair` tool is what actually submits the signed challenge - `POST /agents/pair` - to complete this\nhalf of a pairing. The cryptographic property above does not depend on that call existing: the code is\nderived only from public information, so intercepting it is intercepting nothing, whether or not\nanything has submitted a proof yet.)\n\n## The key: generated here, stored here, never sent anywhere\n\n**This is a property to preserve, not an implementation detail.** There is no code path in this package\nthat sends the private key anywhere - no telemetry, no crash reporting, no \"just in case\" backup, no\ncloud sync. `test/no-leak.spec.ts` exists specifically to keep that true: it drives every tool, the real\nMCP protocol, the CLI, and a deliberately misbehaving backend that tries to leak the key through an\nerror message, then greps everything that came out for it. If you're extending this package, that test\nis the one to think hardest about before touching.\n\nThe key is generated locally on first use (secp256k1, the same curve/derivation as every other signer in\nthis system - see `src/identity/keypair.ts`) and handed to the best available OS secret store:\n\n| Platform | Backend | Mechanism |\n|---|---|---|\n| macOS | Keychain | the `security` CLI (`add-generic-password` / `find-generic-password` / `delete-generic-password`) |\n| Linux | Secret Service (GNOME Keyring, KWallet's libsecret shim, ...) | the `secret-tool` CLI, secret piped over **stdin** |\n| Windows | DPAPI, current-user scope | a short PowerShell call to `ProtectedData.Protect`/`Unprotect`, secret piped over **stdin**; only the ciphertext touches disk |\n| any platform, if none of the above is available | a local file, mode `0600`, parent dir `0700` | plain file, last resort only |\n\nNo native addon is linked for any of this - every backend shells out to a platform CLI that's already\nthere, which is also why `npm install` never needs a compiler. The trade-off is documented rather than\nhidden: macOS's `security` CLI has no way to pass the password except as an argument, so it's briefly\nvisible in this process's own argv (to anything else on the same machine that can list processes) for\nthe moment that one command runs - `secret-tool` and the Windows path both avoid this by using stdin.\nSee the comments in `src/identity/backends/*.ts` for the full reasoning per backend.\n\nTwo more things worth knowing:\n\n- **Exactly one copy, always.** A new key is written to the *first* available backend and stops there -\n  never a redundant \"backup\" copy in a second place. `src/identity/store.ts` and its tests\n  (`test/identity/store.spec.ts`) pin this down explicitly.\n- **The key is read fresh for every signing operation and never cached in memory.** Only `store.sign()`\n  (EIP-191 personal-message signing) and `store.signHash()` (raw ECDSA over an exact 32-byte hash - what\n  `pair`/session-minting/`propose_payment`'s spend all actually use, since the backend recovers over the\n  raw hash with no prefix) ever touch it, and only for the duration of that one call. Identity lookups\n  (`get_identity`, `get_pairing_code`) never touch the keychain at all - they read a small, non-secret\n  metadata file (address / public key / fingerprint / when it was created / which backend holds the key)\n  that's written once alongside the real key and never contains it.\n\n### The links this server opens are never handed to a shell\n\nTwo flows end with this process opening a URL in the owner's own browser: `wallet_login`'s\n`verificationUrl` and `wallet_send`'s browser handoff. **Both URLs are chosen by the backend**, which\nmakes the launcher a place where \"a compromised backend fails to availability, never to authority\"\ncould quietly stop being true - a URL interpolated into a shell command string is arbitrary code\nexecution on the owner's laptop, and `\"...\"` quoting does not prevent it (`$(...)` and backticks still\nexpand inside double quotes).\n\nSo `src/wallet/browser.ts` uses `execFile`, never `exec`: the opener is spawned directly with an argv\narray, so a URL is one opaque argument no matter what characters are in it, and no shell exists to\ninterpret them. On Windows that means `rundll32 url.dll,FileProtocolHandler` rather than `start`, which\nis a `cmd.exe` builtin and would have needed one. On top of that, the URL must parse as an absolute\n`http`/`https` URL before anything is launched at all - which also refuses a bare `-flag` that\n`open`/`xdg-open` would otherwise read as its own argument. `test/wallet-browser.spec.ts` pins both\nhalves: the argv shape, and that the real spawn primitive leaves a substitution payload literal.\n\n### Deleting the key on its own machine\n\n```bash\nnpx -y botanary-mcp forget\n```\n\nThis deletes the private key from wherever it's stored (every backend candidate is swept, not just the\none currently in use, so this also cleans up after a platform change or a partial past failure) and\nclears the local identity. **It does not touch any grant a Botanary account still has on file for that\naddress** - this machine never had the authority to revoke that, only the key. That's the whole point:\nafter this command, nothing on this machine can produce a signature for the old address, which is the\npart anyone can verify for themselves without trusting Botanary's word for it. `test/identity/store.spec.ts`\nand `test/no-leak.spec.ts` both exercise this directly: after `forget()`, signing fails, and the *next*\nidentity created is a different address - proof the old key is really gone, not just hidden.\n\n#### Why `forget` IS a tool, and what that costs\n\n`forget` was deliberately CLI-only for most of this package's life. The reasoning was sound and is worth\nkeeping on the record: an agent that can erase its own identity on request is one an injected instruction\n(a poisoned webpage, a malicious dependency's README, anything it reads as part of normal work) can\nsilence. \"Forget your Botanary identity\" is exactly the kind of one-line instruction a prompt injection\nwould try.\n\nIt is now a tool, at the owner's explicit direction, because the alternative cost more in practice: an\nagent paired to the wrong account could not reset itself without a human dropping to a shell, and that\ndead-end is common enough to matter.\n\nWhat mitigates it:\n\n- **Two steps, never one.** `forget` deletes nothing. It returns a preview of what would be destroyed,\n  what would be left behind, and a single-use `confirmationToken`. Only `confirm_forget`, given that\n  token, deletes anything.\n- **The token is in-memory and expires** (5 minutes, single-use), so it cannot be replayed from a\n  transcript or survive a restart.\n\nWhat this honestly does NOT do: stop a determined injection. A model can call `forget`, read the token,\nand call `confirm_forget` in the same turn. What the two-step buys is that no single instruction destroys\nthe key, and that the consequences are forced into the transcript before the destructive call. Real\nprotection is the host's permission prompt on MCP tool calls - the two-step matters most for installs\nthat have allowlisted this server.\n\n`forget` also remains a CLI command (`npx -y botanary-mcp forget`), unchanged.\n\n## Development\n\nThe commands below are for working on this package's own source in a checkout of this repo - not for\ninstalling it as a user. If you just want to connect an agent, use \"Add it to your agent\" above; you\ndon't need any of this.\n\n```bash\npnpm install       # installs deps and builds dist/ (the \"prepare\" script)\npnpm build         # rebuild dist/ by hand\npnpm dev           # run bin/botanary-mcp.ts directly, watching for changes (no MCP client attached)\npnpm typecheck     # tsc --noEmit, strict (matches the backend repo's compiler settings)\npnpm test          # vitest - no network, no real keychain (every OS call is mocked; see\n                    # test/fixtures/fake-exec.ts and test/fixtures/fake-backend.ts)\npnpm generate:routes  # regenerate src/wallet/routes.manifest.ts from the sibling botanary-be\n                       # checkout's openapi/botanary-v1.yaml - run this and commit the result whenever\n                       # the contract changes; it never runs automatically (a published install has no\n                       # sibling openapi/ directory to read it from)\npnpm generate:write-routes  # same thing for src/wallet/write-routes.manifest.ts - see \"The write\n                             # boundary\" above for the exclusion rule it applies while doing so\n```\n\nNeither generator runs from `test`, `build` or `prepare`, deliberately - a published `npx botanary-mcp`\ninstall has no sibling `botanary-be` checkout to read the contract from. The cost of that correct\ndecision is that the committed output can rot silently, and it did (GET_ROUTES once sat nine routes\nbehind the contract, refusing routes the same branch had shipped). `test/manifest-freshness.spec.ts`\nregenerates both manifests into a scratch directory and byte-compares - it never repairs the file it\nchecks - and skips, loudly and with a stated reason, where the sibling contract is absent. Same guard,\nsame reasoning as `botanary-fe/tests/api/schema-drift.test.ts`.\n\n`BOTANARY_MCP_HOME` overrides where the non-secret metadata file (and the file-fallback secret, if it's\never in use) live - defaults to `~/.botanary-mcp`. It exists mainly for tests and for running this\nserver inside a container with an isolated home; a normal install never needs to set it.\n\n**Do not reach for it to separate two coding tools.** It moves the metadata file but NOT the keychain\nitem, which is keyed by name (`identity/backends/types.ts`) - so a second home used to mint a fresh\nkeypair and save it with `security add-generic-password -U`, overwriting the first one's private key in\nplace. Use a profile instead; it moves both.\n\n## Profiles - one identity per agent, not one per machine\n\nEvery coding tool that connects to this server gets its own keypair, its own `ConnectedAgent` row on the\nbackend, its own mandate and its own revoke button. Before profiles they all shared one address, so the\nbackend could not tell Claude Code from Codex even in principle, and disconnecting one disconnected all\nof them.\n\nA profile is resolved once, at the MCP `initialize` handshake:\n\n| Precedence | Source | Result |\n|---|---|---|\n| 1 | `BOTANARY_AGENT_PROFILE` | that agent name, under the reporting tool |\n| 2 | a pre-profiles `~/.botanary-mcp/identity.json` exists | `default` - the identity this machine already has |\n| 3 | the MCP `clientInfo.name` the client sent | one identity per tool, with no configuration |\n| 4 | nothing | `default` |\n\nStorage follows the resolved key. `default` is byte-identical to what shipped before profiles:\n\n```\n~/.botanary-mcp/identity.json                       profile \"default\"\n~/.botanary-mcp/profiles/codex/identity.json        profile \"codex\"\n\nkeychain  botanary-mcp / agent-identity                    profile \"default\"\nkeychain  botanary-mcp / agent-identity:codex\nkeychain  botanary-mcp / agent-identity:claude-code.trading\nkeychain  botanary-mcp / wallet-session                    ONE, shared by every profile\n```\n\n**Step 2 outranks step 3, and that is the whole upgrade story.** A machine that already paired has a\n`ConnectedAgent` on the backend and possibly a live on-chain grant naming its address as\n`delegateeAddress`. Auto-deriving a fresh identity would leave that grant pointing at an address no key\non the machine can sign for - real, dead, and with no error to explain it. So an existing install stays\nexactly where it is, and splitting it is opt-in.\n\n**Several agents per tool** is just several profiles. The tool half comes from `clientInfo`, the agent\nhalf from the env, so the same name under two tools is two different identities:\n\n```jsonc\n// botanary-be/.mcp.json  - this repo's Claude Code gets its own agent\n\"env\": { \"BOTANARY_AGENT_PROFILE\": \"trading\" }   // -> claude-code.trading\n```\n\nEach distinct profile is a fresh address, so it needs its own pairing once. That is the cost, and it is\nthe point: the owner authorizes each one deliberately.\n\n### What a profile is worth, and what it is not\n\n- **Cryptographic:** Codex's grant cannot be spent by Claude Code's key. Different private key, different\n  address, and `MandateExecutor` is bound to the delegatee. This holds even against a fully compromised\n  backend.\n- **Server-enforced:** a disabled agent cannot mint a session, and disabling revokes its live tokens.\n  The client cannot bypass it, because the token comes from the server.\n- **NOT enforced, and not enforceable:** which local process may read which key. The OS keychain is\n  per-user, not per-binary - any process that can run `security find-generic-password` can read every\n  item this package stores. That is no worse than before (a hostile local process already had the one\n  shared identity), but it means the tool an agent reports is **hygiene and honest bookkeeping, never a\n  security boundary.** `clientInfo` is self-reported; it selects which local key to load and nothing\n  more, and the app renders it as a quoted claim for that reason.\n\n`get_identity` and `diagnose` both report the resolved profile and where it came from, so \"which\nidentity is this process using, and why\" never has to be reverse-engineered from which keychain item\nhappens to exist.\n\n## What's deliberately not here\n\nEverything the original design called out as \"later work\" is now built: the pairing HTTP exchange\n(`pair`), reading balances (`get_balance`), building and relaying under a grant (`propose_payment`), and\nthe out-of-grant request lane (`request_approval`, Flow 7d step 5 - \"ask, when it needs more\").\n\nWhat stays out on purpose:\n\n- **An agent-initiated disconnect** - `DELETE /agents/{id}` is owner-only and stays that way. `forget`\n  deletes a local key; it never closes the owner-side connection, and the two must not be confused.\n- **AGENT-LANE authority beyond a grant.** Nothing the agent lane does can add or remove a signer, write\n  or change a policy, grant another agent access, or unfreeze the account - not because those endpoints\n  are hard to call, but because an agent's grant is authority to spend inside a fence, never authority to\n  move the fence. There is no agent-lane tool here that could be talked into trying.\n- **A cached or session-spanning bounds check as the real gate.** `propose_payment`'s pre-check (and\n  `what_may_i_do`'s rendering) reads `GET /agents/me` fresh via `AgentRuntime.me()` and refuses using\n  whatever the backend reports at that moment - it never assumes a bound it read earlier still holds.\n  The chain is still the only real enforcement either way (see \"The bound it reads is a convenience, not\n  the check\" above). The wallet lane's own `wallet_send` makes the SAME promise for the mandate lane it\n  can take (see \"Lane arbitration\" above), and its browser-lane fallback is likewise never a shortcut:\n  every fund-moving or authority-granting wallet-lane write terminates in the owner's own browser\n  signature, never in anything this package executes on its own. `wallet_api_write` reaches a small,\n  mechanically-excluded set of administrative writes only - see \"The write boundary\" above.\n\n`src/runtime.ts`'s `AgentRuntime` is the seam every tool in `src/tools.ts` is built on: it owns identity,\nsigning (`store.sign()`/`store.signHash()`), a cached-with-retry agent session, and one method per\nbackend call a tool needs (`me`, `getBalance`, `buildDelegatedAction`, `raiseRequest`, `spendUnderGrant`) -\na future tool extends this class rather than reaching for `fetch` directly.\n\n`buildDelegatedAction` (`POST /delegations/{delegationId}/actions`), not `/money/send/build`, is the\nbuild call `propose_payment` uses, and deliberately so: `/money/send/build` builds an owner-lane op in\nthe Kernel account's ROOT nonce lane, which a session-key signature can never validate (it routes\nvalidation to the root ECDSA validator, which cannot parse the USE-mode `(bytes1, bytes32, bytes)`\nenvelope `spendUnderGrant` wraps every signature in as anything resembling a valid 65-byte ECDSA\nsignature). `/delegations/{delegationId}/actions` builds in the delegation's own Smart Sessions nonce\nlane with fixed native gas instead - the one lane this package's session key can actually sign for. The\nbackend additionally scopes this route to the caller's OWN grant: an agent session naming a *different*\nagent's delegation id is refused (403, named reason) before any build happens at all.\n","readmeFilename":"README.md"}