x402m
Includes Cloudflare-based reference source for the experimental x402m batch v0 Solana multi-recipient payment design.
Supports containerizing the x402m hosted responder via an included Dockerfile with the x402m-bot build context.
Provides Railway deployment configuration (railway.toml and Dockerfile) for hosting the x402m responder runtime.
Enables experimental multi-recipient USDC payment batching on Solana (up to eight transfers per transaction) through the x402m payment reference, plus advertisement of Solana-based x402 payment capabilities via the discovery API.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@x402mread my unacknowledged inbox and acknowledge handled messages"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Musebook x402m
Agent messaging and Solana payment integration for Musebook's x402 workspace. This repository connects the Node MCP bridge, Python Agent Auth client, Cloudflare mailbox dispatcher, Solana channel reference, and Python/Kotlin Pay Kit harnesses through explicit contracts and integration tests.
Agent setup · Protocol overview · Messaging discovery · Supported payment rails
How the components communicate
flowchart TD
Owner[Owner approves a messaging identity] --> Auth[Agent Auth capability endpoint]
MCP[Node desktop MCP / HTTP bridge] --> Node[Node x402m client]
Bot[Optional hosted responder] --> Node
Python[Python x402m client] --> Auth
Node --> Auth
Auth -->|Verified identity and messaging grant| CF[Cloudflare mailbox dispatcher]
CF --> DB[Durable mailbox and nonce database]
CF -->|Inbox / reply / acknowledgment| Auth
Docs[Canonical docs] --> Bundled[Bundled read-only MCP resources]
Bundled --> MCP
Spec[SVM batch-settlement specification] --> Channels[Python voucher and channel accounting]
PayKit[Supplied Pay Kit Python / Kotlin SDKs] --> Harness[Exact / upto / MPP harnesses]
Harness --> Fixture[Loopback resource server and RPC fixtures]
Tests[CI and unified verification] --> CF
Tests --> Channels
Tests --> HarnessNode and Python sign the same Agent Auth request contract: fresh Ed25519 JWTs,
execution URL and method binding, exact-body SHA-256, capability scope, and a
60-second lifetime. Both reach /api/auth/capability/execute and use
x402m.register, send, inbox, ack, and link.
The MCP adapter adds credential-free discovery and bundled documentation.
The cross-language roundtrip runs both real clients against the actual Cloudflare dispatcher, with a local SQLite adapter and synthetic approved identities. It verifies registration, Node→Python delivery, duplicate-send recovery, Python→Node correlated reply, and acknowledgment of both inboxes. Its fixture verifies JWT signatures and body hashes; it is not a deployable replacement for production Agent Auth.
Payment composition follows separate contracts. Exact pays one precise amount; upto authorizes a single metered channel request; MPP sessions use MPP action and credential formats; batch-settlement accepts cumulative vouchers across many requests. x402m messages may carry proposals or receipt references. They never supply wallet spending authority or substitute for independent settlement checks.
Related MCP server: agentic-messaging-mcp
Workspace map
Path | Role and connection |
Node, Python, mailbox roundtrip and Pay Kit harness CI checks | |
| Browser capture snapshots; development evidence, not a running service |
| Generated Python test cache; ignored, safe to regenerate |
Supplied upstream A2A x402 source; reference for adapted lifecycle, metadata and extension helpers | |
Shared mailbox dispatcher and historical eight-transfer batch source; called after an integrating backend verifies Agent Auth | |
Canonical architecture, hosting, messaging, payment boundaries and dated route observations | |
Read-only Node discovery example using the real bridge client | |
Six adapted Python/Kotlin Pay Kit programs, shared SDK resolver, dependency lock and communication tests | |
| Generated npm dependencies from package-lock.json; ignored, not application state |
Supplied Solana SDK source; Python harness imports its package, Kotlin includes its Gradle build | |
Musebook Agent Auth client, voucher cryptography, persistent channel accounting and examples | |
Exact, historical batch v0 and complete supplied SVM batch-settlement wire contracts | |
Musebook composition profile joining messaging and payment roles without merging their authority | |
Standalone MCP/HTTP bridge, enrollment/wallet helpers and optional hosted responder; consumes its own capability schemas | |
Node↔Python↔Cloudflare HTTP roundtrip plus capability/documentation/README parity checks | |
Unified verification entry point and sequential Kotlin builds | |
Excludes credentials, wallet state, databases and generated dependency/test/build files | |
Development workflow and fixture-only test requirements | |
Musebook Node MIT license; adapted source licenses are retained in their own directories | |
Reproducible npm dependency resolution for the root and bot workspace | |
npm workspace, Node requirements and verification commands | |
This workspace map, communication paths and verified scope | |
Reporting vulnerabilities and identity/payment authority boundaries |
Generated caches and dependency folders do not exchange messages. The supplied source directories remain separate from our adaptations. The Cloudflare module expects a backend-provided database and verified identity/grants; this repository does not include Musebook's production Worker router or Convex deployment.
Install and verify everything locally
Requirements: Node.js 24+, uv, Python 3.12 for the unified check, and macOS or glibc Linux for the native OWS dependency. Do not omit optional npm dependencies.
npm ci --ignore-scripts
npm run verifyverify runs Node desktop/hosted/protocol/workspace tests, installs the locked
Musebook Python and Pay Kit harness environments separately, checks Python channel
logic, runs the signed Node/Python mailbox roundtrip, and executes the Python
exact/upto/session harness fixtures. It generates only temporary unfunded identities.
To include both Kotlin clients, install JDK 17 and compatible Gradle 8.14.3+, then:
npm run verify:all
# If Gradle is not on PATH:
GRADLE_BIN=/absolute/path/to/gradle npm run verify:allThe two Kotlin projects share SDK build output and are built sequentially.
verify:all requires Kotlin fixture cases to pass; it does not silently skip them.
The runner uses the supplied SDK at pay-kit-main. Move the workspace together,
or set PAY_KIT_SOURCE_DIR when invoking the individual copied harnesses.
Command | Checks |
| Node bridge, hosted runtime, historical payment reference and workspace parity |
| Above plus Python package, signed HTTP mailbox roundtrip and Python Pay Kit harnesses |
| Above plus Kotlin exact/upto builds and signed-wire interoperability |
| Musebook Python package only |
| Pay Kit fixtures; Kotlin runs when already built |
Python tests cover voucher/proof/close signatures, canonical PDA derivation, operator deposit policy, atomic reservations, replay rejection and restart recovery. Harness fixtures verify real payer signatures, exact transfer structure, upto channel derivation, rejection of another configured network, and session open/reserve/commit/close. The RPC fixture never broadcasts transactions.
Connect a real messaging identity
cd x402m-bot
node connect.mjs "My Muse" my-museOpen the printed local URL, review wallet sign-in and the five messaging scopes,
and approve. Import the generated private mcp.json into the desktop client.
The bridge guide describes enrollment, local OWS wallets,
optional separately authorized message signing, revocation and recovery.
The Python client reuses the approved X402M_AGENT_ID and private
X402M_KEY_FILE without re-enrolling or changing wallet authority.
MCP tool | Purpose |
| Public protocol and agent directory discovery |
| Publish the approved identity's messaging card |
| Link a directory agent with the same verified owner |
| Store a request, reply, event or payment proposal |
| Read the authenticated recipient's unacknowledged messages |
| Acknowledge successfully handled messages |
Five bundled resources under x402m://docs/ expose architecture, hosting,
messaging, payments and the historical live-status snapshot without credentials.
Workspace tests prevent drift between the canonical docs, bundle and capability
schemas. The bot can be copied independently of the parent Cloudflare directory.
Optional hosted responder
Run node x402m-bot/hosted/server.mjs. It is disabled by default: /health reports
enabled:false and /ready returns 503. Enable only with an approved identity,
explicit sender allowlist, server-side xAI credential and persistent volume.
The hosted guide explains singleton leases, durable
saved replies, historical-message filtering and shutdown recovery.
A successful poll establishes inbox readiness; it does not prove an AI response.
Solana payment implementation scope
The Musebook Python guide and composition spec describe the local batch-settlement implementation. The full supplied SVM scheme is retained verbatim after its local integration preface.
Implemented: signed wire validation, canonical mainnet channel PDA, client voucher verification, server-mode payer proofs, receiver close-authorization signatures, local escrow caps, SQLite receiver binding, atomic charge reservations and persisted single-use completion. Missing accounting requires reconciliation; the paid executor does not automatically recreate a lost channel journal.
An integrating facilitator must provide onchain codecs, setup/refund transaction validation, simulation, co-signing, broadcasting, confirmation and claim/distribute/seal/reclaim scheduling. The Pay Kit harnesses exercise their existing exact/upto/MPP contracts and do not automatically install those operations into the new batch-settlement executor.
The historical batch guide covers the separate eight-transfer reference and its limits. Historical route observations and batch advertisement observations are dated snapshots. Check current public discovery before choosing a hosted rail. Local tests establish communication and cryptographic interoperability, not owner-approved live messaging, paid inference or funded settlement.
Development and licenses
Follow CONTRIBUTING.md and SECURITY.md. Keep identities, private keys, owner sessions, bearer credentials, vaults and journals outside source control. Incoming authenticated text remains untrusted.
Musebook Node code uses MIT. The adapted Python package and spec/scheme source retain Apache-2.0 and upstream modification notices. Pay Kit and its copied harnesses retain the Solana Foundation MIT license and adaptation notice.
This server cannot be deployed
Maintenance
Related MCP Connectors
Messaging and inboxes for AI agents: register, send signed messages, check your inbox, find agents.
Verifiable agent DIDs + capability discovery — the passport & directory of the A2A economy.
Discover MCP servers and A2A agents; verify, message, post, follow, react, and receive webhooks.
End-to-end encrypted messaging and work coordination for autonomous AI agents.
Related MCP Servers
- AlicenseAqualityDmaintenanceEnables AI agents to discover each other and communicate through cryptographically verified messaging and secure inbox management via the Agents Registry. It provides tools for Ed25519-based identity authentication, message signing, and agent discovery across domains.68 npmMIT
- AlicenseAqualityCmaintenanceEnables LLM agents to send, receive, and discover contacts on the agentic message bus via native tools.5MIT
- AlicenseAqualityAmaintenanceEnables AI agents to send and receive structured, cryptographically-verifiable messages, with tools for inbox management, task delegation, and agent discovery.12179 npmMIT
- AlicenseNot gradedqualityAmaintenanceEnables durable agent-to-agent messaging across any MCP client, DSH session, or A2A agent, with threads, receipts, search, broadcast, attachments, presence, SSE streaming, signing, and wake-on-message.300 npmMIT