Skip to main content
Glama

Create SAP Escrow V2

sap_create_escrow_v2

Local-signer-only direct V2 escrow creation using SDK EscrowV2Module.create. Defaults to DisputeWindow settlementSecurity=2; SelfReport/0 is rejected. Hosted accountless SAP MCP rejects this before x402 payment; hosted users should call sap_escrow_build_create_transaction and finalize locally. SAP MCP context: Payment and settlement flow. Estimate or fetch state before creating escrows or settling calls; write operations require an enabled signer mode and MCP policy approval.

SAP MCP execution guidance: Intent: SAP MCP tool workflow. Pricing: paid value-action; preview cost and transaction effects before user confirmation. Routing: hosted accountless write is blocked; do not call this as a paid hosted write and no x402 payment should be charged. Use the local sap_payments bridge or a hosted unsigned builder when user signing is required. Signer boundary: user-controlled local profile or external signer; OOBE hosted MCP remains non-custodial.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nonceNoOptional escrow nonce as a decimal string. Defaults to 0.
arbiterNoOptional arbiter public key kept for IDL compatibility and dispute workflows.
coSignerNoRequired co-signer wallet public key when settlementSecurity=1 (CoSigned).
maxCallsNoMaximum number of calls covered by the escrow as a decimal string. Use 0 for unlimited when supported by policy.
expiresAtNoOptional expiry timestamp in unix seconds as a decimal string. Defaults to 0 (no expiry).
tokenMintNoOptional SPL payment token mint. Omit/null for native SOL. Use EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v for mainnet USDC x402 escrows.
agentWalletNoAgent owner wallet public key (base58). The V2 escrow PDA is derived from this wallet plus nonce.
pricePerCallNoPrice per served call as a decimal string. Amount in the escrow token smallest unit: lamports for SOL, micro-USDC for USDC, or base units for the configured SPL token.
tokenDecimalsNoPayment token decimals. Defaults to 6 when tokenMint is set, otherwise 9 for native SOL.
initialDepositNoInitial escrow deposit as a decimal string. Amount in the escrow token smallest unit: lamports for SOL, micro-USDC for USDC, or base units for the configured SPL token.
disputeWindowSlotsNoRequired positive dispute window in slots for settlementSecurity=2. Defaults to 2160 (~15 minutes).
settlementSecurityNoV2 settlement security mode. 1=CoSigned (requires coSigner). 2=DisputeWindow (recommended default; requires disputeWindowSlots > 0). SelfReport/0 is deprecated and rejected on-chain.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
contentYesMCP content blocks returned to the caller.
isErrorNoTrue when the tool result represents an application-level error.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / description
      Added value: +"Create SAP Escrow V2 input schema. Intent: SAP MCP tool workflow. Pricing: paid value-action; preview cost and transaction effects before user confirmation. Routing: hosted accountless write is blocked; do not call this as a paid hosted write and no x402 payment should be charged. Use the local sap_payments bridge or a hosted unsigned builder when user signing is required. Signer boundary: user-controlled local profile or external signer; OOBE hosted MCP remains non-custodial. Use exact field names from this schema; do not guess aliases or include private key material."
  2. Changed12 schema fields changed
    • changedInput schema / properties / agentWallet / description
      Previous value: -"Agent wallet public key (base58)"New value: +"Agent owner wallet public key (base58). The V2 escrow PDA is derived from this wallet plus nonce."
    • addedInput schema / properties / arbiter
      Added value: +{
      +  "description": "Optional arbiter public key kept for IDL compatibility and dispute workflows.",
      +  "type": "string"
      +}
    • addedInput schema / properties / coSigner
      Added value: +{
      +  "description": "Required co-signer wallet public key when settlementSecurity=1 (CoSigned).",
      +  "type": "string"
      +}
    • addedInput schema / properties / disputeWindowSlots
      Added value: +{
      +  "description": "Required positive dispute window in slots for settlementSecurity=2. Defaults to 2160 (~15 minutes).",
      +  "type": "string"
      +}
    • addedInput schema / properties / expiresAt
      Added value: +{
      +  "description": "Optional expiry timestamp in unix seconds as a decimal string. Defaults to 0 (no expiry).",
      +  "type": "string"
      +}
    • changedInput schema / properties / initialDeposit / description
      Previous value: -"Initial deposit amount in lamports (as a decimal string)"New value: +"Initial escrow deposit as a decimal string. Amount in the escrow token smallest unit: lamports for SOL, micro-USDC for USDC, or base units for the configured SPL token."
    • changedInput schema / properties / maxCalls / description
      Previous value: -"Maximum number of calls the escrow covers (as a decimal string)"New value: +"Maximum number of calls covered by the escrow as a decimal string. Use 0 for unlimited when supported by policy."
    • addedInput schema / properties / nonce
      Added value: +{
      +  "description": "Optional escrow nonce as a decimal string. Defaults to 0.",
      +  "type": "string"
      +}
    • changedInput schema / properties / pricePerCall / description
      Previous value: -"Price per call in lamports (as a decimal string)"New value: +"Price per served call as a decimal string. Amount in the escrow token smallest unit: lamports for SOL, micro-USDC for USDC, or base units for the configured SPL token."
    • addedInput schema / properties / settlementSecurity
      Added value: +{
      +  "description": "V2 settlement security mode. 1=CoSigned (requires coSigner). 2=DisputeWindow (recommended default; requires disputeWindowSlots > 0). SelfReport/0 is deprecated and rejected on-chain.",
      +  "enum": [
      +    1,
      +    2
      +  ],
      +  "type": "number"
      +}
    • addedInput schema / properties / tokenDecimals
      Added value: +{
      +  "description": "Payment token decimals. Defaults to 6 when tokenMint is set, otherwise 9 for native SOL.",
      +  "type": "number"
      +}
    • addedInput schema / properties / tokenMint
      Added value: +{
      +  "description": "Optional SPL payment token mint. Omit/null for native SOL. Use EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v for mainnet USDC x402 escrows.",
      +  "type": "string"
      +}
  3. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already indicate it is a write operation (readOnlyHint=false) and not destructive. The description adds specific behavioral details: defaults to DisputeWindow settlementSecurity=2, SelfReport/0 is rejected, and notes signer boundaries and MCP policy approval. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is verbose and contains repetitive guidance about routing and signer boundaries. It could be more concise while retaining key information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the complexity (12 parameters) and the presence of an output schema, the description covers the main constraints, use cases, and alternatives adequately. It is complete enough for an agent to understand when and how to use this tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3. The description adds some high-level context (e.g., 'The V2 escrow PDA is derived from this wallet plus nonce') but does not significantly enhance understanding beyond the schema descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description explicitly states it is for 'Local-signer-only direct V2 escrow creation using SDK EscrowV2Module.create'. It distinguishes from siblings by noting that 'SelfReport/0 is rejected' and directs hosted users to alternative tools like sap_escrow_build_create_transaction.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description clearly states when to use (local signer) and when not to use (hosted accountless before x402 payment). It provides explicit alternatives: 'hosted users should call sap_escrow_build_create_transaction and finalize locally' and advises to 'Use the local sap_payments bridge or a hosted unsigned builder when user signing is required'.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.