scanpay-mcp
by Misterio070
README.md
# ScanPay โ Code Security Scanner with x402 v2 Micropayments
## ๐ Try ScanPay Live (Solana Mainnet)
Pay 0.0007 SOL (~$0.10) per scan. No account. No API key.
- **Live API:** https://theoretical-config-hobby-kruger.trycloudflare.com
- **Landing page:** https://misterio070.github.io/scanpay-landing/
- **AgentBridge:** https://invest-ftp-cast-surround.trycloudflare.com
- **MCP Server:** `npx scanpay-mcp-server`
- **CLI:** `npx scanpay-cli scan --language python --file ./code.py`
- **llms.txt:** https://github.com/Misterio070/scanpay/blob/main/llms.txt
## ๐ฐ Pricing
- Python / JavaScript / TypeScript scan: **0.0007 SOL**
- AgentBridge job escrow commission: **10%**
- No subscriptions, no free trial abuse.




> Deterministic AST-based security scanning for Python and JavaScript/TypeScript.
> No code execution. No AI inference. Just fast, reliable vulnerability detection.
> Pay per scan with Solana micropayments โ $0.10/scan.
## ๐ฏ What It Does
ScanPay analyzes source code for security vulnerabilities using deterministic AST parsing. No AI, no code execution โ just fast, reliable pattern matching that catches 45+ vulnerability classes before code runs.
Built for **AI agents** that generate code: scan before execution, block dangerous patterns, log audit trails.
## โจ Features
- **45+ vulnerability patterns** across Python and JS/TS/TSX
- **Deterministic analysis** โ same input always produces same output
- **x402 v2 payment protocol** โ pay per scan with SOL on Solana
- **Dual language support** โ Python (`ast` module) and JS/TS (tree-sitter)
- **No false AI hallucinations** โ pure rule-based detection
- **FastAPI-powered** โ sub-100ms scan latency
- **SARIF output** โ industry-standard vulnerability report format
- **Batch scanning** โ scan multiple files in one request
## ๐ Live Demo
ScanPay is deployed and running:
- **Public API:** `https://theoretical-config-hobby-kruger.trycloudflare.com`
- **Products:** `https://theoretical-config-hobby-kruger.trycloudflare.com/api/v1/products`
- **Payment:** x402 v2 on Solana mainnet (0.0007 SOL โ $0.10 per scan)
- **Wallet:** `JDKXvegmW5j4sAJPB6YCA9ffJbN422WLMmCWCcpy1vm4`
### Try it
```bash
curl -X POST https://theoretical-config-hobby-kruger.trycloudflare.com/api/v1/scan \
-H "Content-Type: application/json" \
-d '{"language":"python","source_code":"import os; os.system(\"rm -rf /\")"}'
```
Returns `402 Payment Required` with Solana payment details. Send payment and retry with `X-PAYMENT` header to get the scan result.
## ๐ Quick Start
### Using the Live API (mainnet)
```bash
# Health check
curl https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/health
# List available products
curl https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/products
# Scan code (requires payment)
curl -X POST https://repository-nil-camcorder-divx.trycloudflare.com/api/v1/scan \
-H "Content-Type: application/json" \
-d '{"source_code":"eval(userInput)","language":"python"}'
# โ 402 Payment Required (0.0007 SOL)
```
### Self-Host
```bash
git clone https://github.com/Misterio070/scanpay.git
cd scanpay
pip install -r requirements.txt
python main.py
# โ http://localhost:8484
```
## ๐ณ Payment Flow (x402 v2)
1. Client requests scan โ receives `402 Payment Required`
2. Client pays **0.0007 SOL** (~$0.10) to merchant wallet via Solana
3. Client retries with `X-PAYMENT` header containing payment proof
4. Server verifies payment on-chain, runs scan, returns results
**Merchant wallet:** `JDKXvegmW5j4sAJPB6YCA9ffJbN422WLMmCWCcpy1vm4`
## ๐ค For AI Agents (MCP Server)
ScanPay includes an MCP server for AI agents to scan code before execution:
```json
{
"mcpServers": {
"scanpay": {
"command": "npx",
"args": ["-y", "scanpay-cli", "scanpay-mcp"],
"env": { "SCANPAY_URL": "https://repository-nil-camcorder-divx.trycloudflare.com" }
}
}
}
```
Agents call `scan_code` to check code for vulnerabilities before running it.
**Network:** Solana mainnet (mainnet coming soon)
## ๐ Configuration
```bash
cp .env.example .env
```
| Env Var | Default | Description |
|---------|---------|-------------|
| `SCANPAY_PAYMENT_MODE` | `disabled` | `disabled`, `mainnet`, or `mainnet` |
| `SCANPAY_MERCHANT_WALLET` | โ | Solana wallet address |
| `SCANPAY_PRICE_LAMPORTS` | `700000` | Price in lamports (0.0007 SOL) |
| `SCANPAY_RPC_URL` | `https://api.devnet.solana.com` | Solana RPC endpoint |
| `SCANPAY_PORT` | `8484` | Server port |
## ๐งช Detected Vulnerabilities
### Python
- `eval()` / `exec()` โ code injection
- `subprocess` with `shell=True` โ command injection
- `pickle.loads()` โ deserialization attacks
- `os.system()` โ command injection
- SQL injection patterns
- Path traversal (`../`)
- Hardcoded credentials
- And more...
### JavaScript/TypeScript
- `eval()` โ code injection
- `innerHTML` โ XSS
- `document.write()` โ XSS
- `new Function()` โ code injection
- SQL injection patterns
- Prototype pollution
- And more...
## ๐ API Reference
### `GET /api/v1/health`
Returns service status and configuration.
### `GET /api/v1/products`
Returns available scan products and pricing.
### `POST /api/v1/scan`
Scans source code for vulnerabilities. Requires payment in mainnet/mainnet mode.
**Request:**
```json
{
"source_code": "eval(userInput)",
"language": "python"
}
```
**Response (200):**
```json
{
"status": "ok",
"findings": [
{
"rule": "PY001",
"severity": "critical",
"message": "Use of eval() detected โ code injection risk",
"line": 1
}
],
"summary": {
"total": 1,
"critical": 1,
"high": 0,
"medium": 0,
"low": 0
}
}
```
## ๐ค Built For
- **AI Agents** โ scan generated code before execution
- **CI/CD Pipelines** โ pre-deployment security gate
- **IDE Extensions** โ real-time vulnerability detection
- **Code Review** โ automated security audit
## ๐ License
MIT
## ๐ Links
- [GitHub](https://github.com/Misterio070/scanpay)
- [x402 Protocol](https://x402.org)
- [Solana](https://solana.com)This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues