zshield-mcp
Exposes a zcash_pay tool for agent-initiated shielded ZEC payments under policy, enforcing per-call spending caps and recipient allow-lists, with viewing-key fingerprinted audit logging. Chain interactions are currently mocked, with a live light-wallet adapter stubbed and refused at startup.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@zshield-mcpsend 0.05 ZEC to the demo merchant with memo 'invoice 123'"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
zshield-mcp
Open-source MCP server that exposes one tool — zcash_pay — for agent-initiated shielded ZEC payments under human policy:
Hard per-call spending cap
Recipient allow-list
Append-only viewing-key fingerprinted audit log
Spend keys never belong in the model. Chain is mocked first; a live light-wallet adapter is stubbed and refused at startup.
Purpose
Agents need a payment tool they can call safely. This server enforces policy before any payment attempt, records an audit row for every call (success or reject), and fingerprints viewing-key material so auditors can correlate receipts without storing raw keys in the log.
Built as a concrete, minimal artifact for design-partner review of shielded agent-payment MCP surfaces (see Zcash Community Grants discussions around agent/MCP payment tooling).
Related MCP server: wwall
Quickstart
git clone <this-repo> zshield-mcp && cd zshield-mcp
cp .env.example .env
npm install
npm test
npm run build
npm start # stdio MCP serverPoint your MCP client (Cursor, Claude Desktop, etc.) at:
{
"mcpServers": {
"zshield": {
"command": "node",
"args": ["/absolute/path/to/zshield-mcp/dist/index.js"],
"env": {
"SPENDING_CAP_ZEC": "0.1",
"ALLOWLIST_PATH": "/absolute/path/to/zshield-mcp/allowlists/recipients.example.json",
"CHAIN_MODE": "mock",
"AUDIT_DIR": "/absolute/path/to/zshield-mcp/audits"
}
}
}
}Or during development: "command": "npx", "args": ["tsx", "src/index.ts"] with cwd set to the repo.
Tool: zcash_pay
Arg | Type | Required | Description |
| number | yes | Must be |
| string | yes | Must exactly match an allow-list |
| string | no | Optional memo (mock) |
Resource zshield://policy returns the active cap, allow-list path, and chain mode.
Config: caps & allow-list
Precedence: environment variables override config/default.yaml.
Variable | Default | Meaning |
|
| Hard max ZEC per tool call |
|
| JSON allow-list |
|
|
|
|
| JSONL audit directory |
| from yaml | Salt for view-key fingerprints |
Allow-list shape:
{
"recipients": [
{ "address": "u1…", "label": "Demo merchant" }
]
}Audit log format
JSONL per day: audits/YYYY-MM-DD.jsonl. Example success line:
{"ts":"2026-10-05T19:00:00.000Z","tool":"zcash_pay","amount_zec":0.05,"recipient":"u1…","allowlist_hit":true,"cap_zec":0.1,"status":"ok","mock_txid":"mock_…","view_key_fingerprint":"a1b2c3d4e5f60718","memo":"test"}Raw viewing-key material is never written — only a short fingerprint. See docs/AUDIT.md.
Layout
src/policy/ caps + allow-list
src/chain/ mock adapter + live stub
src/audit/ JSONL writer + fingerprint
src/tools/ zcash_pay
src/server.ts MCP registration
tests/ happy path + rejectionsStatus / non-goals
✅ Mock payments, policy enforcement, audit
❌ Live Zcash chain / wallet wiring (stub only)
❌ Custody of user spend keys
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Scoped agent execution. Server-side credentials, policy, budgets and verifiable receipts.
Advisory policy preflight for AI-agent spend requests; never executes payments or accesses wallets.
Agent payments, API key vaulting, and governed mandates. Agents spend within user-defined limits.
Agent-native MCP for governed commerce, x402 payments, paid capabilities, and verifiable receipts.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceDeterministic, auditable payment policy enforcement for AI agents. It provides pre-action authorization with scopes, budgets, allowlists, and signed mandates via an MCP server.MIT
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to propose wallet payments while a local, human-authored policy decides whether each transaction is approved, requires human confirmation, or is refused, and records every decision in a signed, append-only ledger.-
- AlicenseAqualityAmaintenancePolicy-gated agent spend with signed receipts and rail-extract audit: a fail-closed gate issues a COSE receipt for every allowed payment, and the audit reconciles those receipts against a rail extract so a settlement with no receipt is named rather than assumed. It settles on a mock rail, holding no wallet and signing no transaction.51Apache 2.0
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to pay x402 endpoints on Cardano through a policy-gated wallet with spend caps, payee allowlists, human approval, and an audit log.832 npmApache 2.0