@arispay/payagent-mcp
OfficialThis MCP server lets an AI agent pay for HTTP calls to x402-protected APIs and inspect the wallet used for those payments.
Call any URL via
pay_apiwith method, headers, and body; if the endpoint responds HTTP 402, the server pays it through x402 (USDC on Base) and returns the response.Check wallet info via
check_wallet— deposit address and balance.Payments can be signed locally from a private key (
PAYAGENT_PRIVATE_KEY) or delegated to ArisPay with server-enforced limits.The README also describes additional tools such as wallet/agent management, merchant payments, paid-API discovery, and end-user controls, though the provided server schema only exposes
pay_apiandcheck_wallet.
Provides tools for making paid API calls via the x402 protocol, leveraging Coinbase CDP for secure signing and settlement of USDC payments on Base.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@arispay/payagent-mcpFetch paid API data from https://api.example.com/report"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@arispay/payagent-mcp
One coherent USDC payment product for AI agents: call x402-paid APIs, with spend mandates, receipts, and idempotency. Works with Claude Desktop, Cursor, Windsurf, or any MCP client. A thin wrapper around the payagent SDK.
Two ways to hold the wallet:
Local key (zero signup). Set
PAYAGENT_PRIVATE_KEYto a funded EOA key.paysigns EIP-3009 locally — no ArisPay account, no email. The only guardrail is the wallet balance; use a dedicated low-balance wallet.Delegated custody (managed, recommended).
setup({ email })self-provisions an account, a CDP-managed wallet, and a spend mandate in one call. ArisPay enforces per-transaction, daily, and monthly limits server-side before signing; no private key ever lives in this process.
Tools
Seven core tools (the default surface):
Tool | What it does | Money |
| Create or recover an account + payer wallet in one call (delegated mode) | moves none |
| Search the paid-API catalog by intent + budget | read-only |
| Read a URL's price and payment requirements without paying | read-only |
| The complete machine path: request → 402 → select variant → validate policy → pay → structured receipt. Requires an | spends real money |
| Active identity, deposit address, on-chain USDC balance, mandate limits | read-only |
| Recent payments — server feed (delegated) or local receipts (self-custody) | read-only |
| Buy ArisPay Signal: recent signed probe evidence about an x402 resource (did a real paid probe settle and deliver?). A still-valid cached artifact returns without spending; an unknown resource is answered free | spends 1¢ per uncached call |
Wallet administration (create_agent, fund_agent, list_agents, rename_agent) loads only when the host config sets PAYAGENT_MCP_PROFILE=admin.
Every tool declares MCP safety annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); pay and check_payment_signal are the only destructive tools — both spend real money.
Related MCP server: obol-mcp
Support matrix
Asset | Network | Local key (self-custody) | Delegated (managed mandate) |
USDC | Base (default) | ✅ | ✅ |
USDC | Ethereum, Polygon | ✅ | ✅ |
USDC | Base Sepolia (testnet) | ✅ | ✅ |
USDC (SPL) | Solana, Solana devnet | ❌ (EVM signing only) | ✅ (live on |
USD1 | BNB Chain | ✅ | ✅ |
Notes:
All prices are quoted by sellers in the 402 challenge;
payprefers an EVM variant and falls back to Solana when the seller offers no EVM option.Delegated mandates are integer cents, validated server-side before any signature exists. Local mode has no server-side cap.
Settlement is a single on-chain
transferWithAuthorization(EIP-3009): it succeeds or reverts atomically. When the seller returnsX-PAYMENT-RESPONSE, the receipt carries the settlement transaction hash.ArisPay's own facilitator (
facilitator.arispay.app) charges no facilitator fee; sellers may use any facilitator, and their fee/finality policy applies.
Setup
Add the server to your MCP client config. No environment variables are required — pick a wallet mode later, from inside the chat, or set one of the env options below.
Claude Desktop
Edit ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"arispay": {
"command": "npx",
"args": ["-y", "@arispay/payagent-mcp"]
}
}
}For the zero-signup mode, add the key to the env block:
"env": { "PAYAGENT_PRIVATE_KEY": "0x..." }Cursor
Same server block in .cursor/mcp.json. Windsurf: same pattern in ~/.codeium/windsurf/mcp_config.json.
Cold start, from nothing
Zero signup: generate a key with
npx payagent wallet new, put it in the host config asPAYAGENT_PRIVATE_KEY, send USDC on Base to the printed address.balanceshows the deposit address;paypays.Managed: ask the agent to run
setup({ email: "you@example.com" })— it returns the wallet address and mandate. Fund the wallet with USDC, confirm withbalance, thenpay. Credentials persist to~/.payagent/config.jsonand are shared with thepayagentCLI.
Environment variables (all optional)
Variable | Description |
| Funded EOA key for local self-custody signing (zero-signup mode). |
| Developer key — usually unneeded; |
| ArisPay API base URL. Default |
|
|
| Legacy single-agent pair for v2.0.x hosts. |
Migrating from v3
v4 is a breaking release: the surface collapsed to one x402/USDC product.
v3 tool | v4 |
|
|
|
|
|
|
|
|
|
|
— |
|
| unchanged, behind |
| removed — the fiat funding and platform (end-user) surfaces left the public MCP |
Receipts and idempotency
pay requires a caller-chosen idempotencyKey (min 8 chars — use a UUID). Every completed payment writes a machine-readable receipt (amount, asset, network, wallet, settlement tx, remaining mandate) to ~/.payagent/mcp-receipts.json. Re-calling pay with a key that already paid returns the stored receipt and does not pay again — including when the paid request failed mid-flight. history lists receipts in self-custody mode; delegated mode reads the authoritative server feed.
How it works
The agent calls
paywith a URL and anidempotencyKey; the seller answers HTTP 402 with its price.With
PAYAGENT_PRIVATE_KEYset,payagentsigns the EIP-3009 authorization locally. Otherwise ArisPay validates the request against the agent's mandate and signs via Coinbase CDP.payagentretries with the signed payment header; the seller's facilitator settles USDC on-chain.The tool returns the paid response plus a structured receipt.
In delegated mode, no private key lives in this process and payments that breach the mandate are rejected before any on-chain action. In local mode, the key is yours and stays in your process.
Install
npm install @arispay/payagent-mcpOr invoke directly via npx @arispay/payagent-mcp from an MCP client config — no pre-install required. npx buyforme-mcp is the same server under the consumer brand.
Related
payagent — the SDK + CLI for programmatic use
facilitator.arispay.app — ArisPay's open x402 facilitator, where paid 402s settle
x402 protocol — HTTP 402 payment standard
License
MIT
Available Tools
7 toolsbalanceARead-onlyIdempotent
Read-only: shows the active payment identity — the stored ArisPay agent (delegated) or the PAYAGENT_PRIVATE_KEY-derived address (self-custody) — with its USDC deposit address, on-chain balance, and (delegated) spend-mandate limits. Spends no money, never pays. Select this to find where to send USDC, to confirm a deposit landed, or when a payment fails.
| Name | Required | Description | Default |
|---|---|---|---|
| agent | No | Optional name of a locally-stored x402 agent. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, and non-destructive, and the description reinforces this with 'never pays.' Beyond annotations, it adds rich context about the two identity modes (delegated ArisPay agent vs self-custody key-derived address), what data is returned, and the concept of spend-mandate limits, so an agent knows what behavior to expect.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences with no filler: the first establishes safety and output scope, the second gives concrete use cases. Every clause contributes information and the critical 'Read-only / never pays' signal is front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple tool with one optional parameter, rich annotations, and no output schema, the description covers safety, returned content, and when to use it. The only notable gap is the exact default behavior when the agent parameter is omitted, which would make the identity-selection semantics fully unambiguous.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already covers the optional agent parameter with 100% coverage. The description adds meaning by relating a stored agent to delegated custody and the PAYAGENT_PRIVATE_KEY to self-custody, which helps clarify the parameter's role. However, it does not explicitly state what happens when the agent parameter is omitted versus provided.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description starts with 'Read-only: shows the active payment identity' and enumerates exactly what is returned: USDC deposit address, on-chain balance, and spend-mandate limits. It also links the tool to concrete tasks like finding where to send USDC and confirming a deposit, making it easy to distinguish from siblings such as pay, history, or check_payment_signal.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly gives three trigger conditions: find where to send USDC, confirm a deposit landed, and diagnose a failed payment. It does not name alternative sibling tools or state when not to use it, so it falls short of a 5, but the usage context is clear and actionable.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
check_payment_signalADestructiveIdempotent
SPENDS REAL MONEY — 1¢ (USDC, Base mainnet) per UNCACHED call; a still-valid cached artifact returns WITHOUT spending, and an unknown resource is answered free. Buys ArisPay Signal: recent signed probe evidence about an x402 resource (did a real paid probe settle and deliver?) as an arispay.signal.v1 artifact, verified against the published JWKS. Use it BEFORE a material first payment to an unfamiliar resource, or after cached evidence expires. The decision denominator is CUMULATIVE exposure before the artifact expires — planned spend across all intended calls, or the expected cost of one failure, whichever is larger — not the price of the next call: an agent planning 100 calls to a 1¢ endpoint should check; an agent making a single 1¢ call should not. Skip it when cumulative exposure is at or below the 1¢ check price. Returns signed observational evidence with explicit freshness — NOT a guarantee, insurance, or endorsement. Network side effect: one HTTPS request to the Signal endpoint; payment side effect: the 1¢ x402 purchase on uncached calls.
| Name | Required | Description | Default |
|---|---|---|---|
| agent | No | Optional name of a stored x402 payer agent (delegated mode). | |
| resource | Yes | The exact absolute HTTPS URL of the x402 resource you are about to pay. Signal evidence is keyed by this exact URL. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description thoroughly discloses behavior beyond the annotations: real-money spend per uncached call, free cached/unknown responses, network and payment side effects, verification against published JWKS, and the caveat that the result is observational evidence, not a guarantee. This meaningfully enriches the annotation hints and contradicts nothing.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long, but almost every sentence earns its place given the unusual cost model and decision heuristic. It is front-loaded with the most critical information (SPENDS REAL MONEY) and organized from cost to functionality to usage to side effects. Slight over-density keeps it from a 5.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Despite having no output schema or nested object schema, the description explains what the tool returns (signed arispay.signal.v1 artifact with explicit freshness), how it is verified, the exact side effects, the caching behavior, and the usage threshold. This is complete enough for an agent to call it correctly and interpret its result.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents both parameters. The description reinforces that the resource must be the exact absolute HTTPS URL because evidence is keyed by that URL, but it does not add meaningfully new parameter-level semantics beyond what the schema states.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: check_payment_signal buys and returns ArisPay Signal evidence about an x402 resource before payment. It clearly distinguishes this from siblings by framing it as a pre-payment verification step ('Use it BEFORE a material first payment') rather than the payment itself.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when-to-use and when-not-to-use guidance: use before material first payments or after cached evidence expires, and skip when cumulative exposure is at or below the 1¢ check price. It also explains the decision denominator (cumulative exposure vs. cost of one failure) with a concrete example.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
discoverARead-onlyIdempotent
Searches the ArisPay marketplace for paid APIs by capability or plain-language intent, optionally budget-bounded (integer cents). Read-only — spends no money, needs no API key. Returns ranked candidates with endpoint URL, price in cents, health and verification flags. Select this to FIND an endpoint; then inspect to price a specific URL, then pay to call it.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max results (default 5, max 20). | |
| query | Yes | Capability or plain-language intent, e.g. 'flight search'. | |
| category | No | Optional category filter (inference, data, media, search, social, infrastructure, trading, other). | |
| budgetCentsMax | No | Maximum acceptable price in INTEGER CENTS (500 = $5.00). Free listings always pass. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark the tool readOnly, openWorld, idempotent, and non-destructive. The description adds meaningful context beyond annotations: it states 'Read-only — spends no money, needs no API key' and discloses the return shape ('ranked candidates with endpoint URL, price in cents, health and verification flags'). No contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is compact and front-loaded: the first sentence states the core purpose, and the second gives the operational safety and output summary. The final sentence provides clear workflow guidance. Every clause earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only discovery tool, the description covers what is searched, optional budget constraints, safety, output contents, and the correct next tool to use. The input schema fully documents parameters, and annotations cover safety, so no critical context is missing even though there is no output schema.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so query, limit, category, and budgetCentsMax are already fully documented by the input schema. The description adds only a plain-language framing and the budget bound, which does not significantly exceed the schema's own descriptions. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb ('Searches') and resource ('ArisPay marketplace'), then defines the search style as 'capability or plain-language intent.' It also distinguishes discover from its siblings by naming the find → inspect → pay workflow.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly instructs when to use the tool: 'Select this to FIND an endpoint; then inspect to price a specific URL, then pay to call it.' This positions discover as the exploration step and clearly separates it from subsequent sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
historyARead-onlyIdempotent
Read-only: lists recent payments — the server-side activity feed in delegated mode (newest first), or locally recorded receipts in self-custody mode. Spends no money. Select this to reconcile what was paid, retrieve a past receipt, or audit an agent's spending.
| Name | Required | Description | Default |
|---|---|---|---|
| agent | No | Optional stored agent name — limits the feed to that wallet (delegated mode). | |
| limit | No | Max entries (default 10, max 50). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the readOnly/idempotent annotations, the description discloses that it spends no money, that the data source differs by mode, and that results are newest-first. This adds meaningful behavioral context that the annotations alone do not provide.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the core behavior and is information-dense without wasted words. Each clause contributes: mode behavior, ordering, safety, and use cases.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With only two optional parameters fully covered by the schema and annotations covering safety properties, the description supplies the missing decision-relevant context: what data is shown, where it comes from, ordering, and when to use the tool. Nothing critical is missing for correct selection and invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so both the agent and limit parameters are already well documented. The description does not add parameter-specific detail, but it does provide surrounding context about delegated vs. self-custody modes, which weakly relates to the agent parameter. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: it lists recent payments. It further clarifies the two modes (server-side feed vs. locally recorded receipts) and provides concrete use cases, making its purpose unambiguous and distinct from sibling tools like balance or pay.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit guidance on when to use the tool: to reconcile payments, retrieve a past receipt, or audit spending. It does not explicitly name alternatives or state when not to use it, but the context is clear enough for an agent to select it correctly.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
inspectARead-onlyIdempotent
Fetches an x402-protected URL WITHOUT paying and reports its price, asset, network, and payment requirements. Read-only — spends no money, sends no payment header, needs no API key or account. Always safe. Select this before pay to know exactly what a resource costs.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | The URL to inspect. Expected to return HTTP 402 with an x402 challenge. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Although annotations already declare readOnlyHint, openWorldHint, idempotentHint, and destructiveHint=false, the description adds meaningful operational detail: it spends no money, sends no payment header, needs no API key or account, and is always safe. This goes well beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences with no wasted words. The core behavior and cost-relevant outputs are front-loaded, followed by safety guarantees and the explicit routing to 'pay'. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a single-parameter, read-only inspection tool with rich annotations, the description covers what the tool does, what it returns conceptually, and when to invoke it. No important behavioral or usage information is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema fully documents the single 'url' parameter with a clear description, so the baseline is 3. The tool description reinforces that the URL should be x402-protected but adds little parameter-specific meaning beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Fetches'), a specific resource ('x402-protected URL'), and the key scope ('WITHOUT paying'). It clearly differentiates from the sibling 'pay' by emphasizing that this tool reports price and requirements without spending money.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It explicitly tells the agent to use this before 'pay' to know costs, which is clear usage context. It does not mention other sibling tools like 'check_payment_signal' or 'discover' as alternatives, so it lacks full when-not guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
payADestructiveIdempotent
SPENDS REAL MONEY — on-chain and irreversible. The complete machine payment path: makes the HTTP request, and if the server answers 402, selects the supported asset/network variant (USDC on Base/Ethereum/Polygon; delegated mode also settles Solana and BNB Chain variants), validates policy, pays, retries the request, and returns the response plus a structured machine-readable receipt. Requires an idempotencyKey: re-calling with a key that already paid returns the cached receipt and does NOT pay again. Mode selection: PAYAGENT_PRIVATE_KEY set → signs locally (self-custody; wallet balance is the only cap); otherwise pays through the stored ArisPay agent whose per-tx/daily/monthly mandate is enforced server-side BEFORE signing. Use inspect first to see the price. Do not use for ordinary unpaid HTTP requests.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | The full URL of the API endpoint to call. | |
| body | No | ||
| agent | No | Optional name of a stored x402 payer agent (delegated mode). | |
| method | No | GET | |
| headers | No | ||
| idempotencyKey | Yes | Caller-chosen unique key for this payment intent (min 8 chars, e.g. a UUID). Re-calling with a key that already paid returns the cached receipt WITHOUT paying again. Use a fresh key for each new payment intent. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations, the description discloses irreversibility, the 402-triggered payment flow, idempotency-key caching behavior, local vs. delegated signing, and balance/mandate constraints. These details are consistent with destructiveHint=true and idempotentHint=true; no contradiction exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense yet front-loaded with the most important warning ('SPENDS REAL MONEY'), then the workflow, idempotency behavior, mode selection, and usage guidance. Every sentence carries necessary information without fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with no output schema, the description clearly explains the complete payment cycle, idempotency guarantees, both execution modes, and the shape of the result (response plus machine-readable receipt). It is thorough enough for an agent to invoke it correctly and safely.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema covers only 50% of parameters with descriptions, and the description strongly compensates by thoroughly explaining idempotencyKey, agent mode, and the payment path. Method, headers, and body are not detailed in prose, but they are standard HTTP concepts and largely self-explanatory.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific action with a critical warning: it spends real money, handles the x402 payment flow, retries the request, and returns response plus receipt. It clearly distinguishes itself from siblings by mentioning 'Use inspect first' and 'Do not use for ordinary unpaid HTTP requests.'
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly tells the agent to call inspect first for pricing and warns not to use this for ordinary unpaid HTTP requests. It also explains the two modes of operation and the server-side mandate restrictions, giving clear when-to-use versus when-not-to-use guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
setupAIdempotent
Creates or recovers an ArisPay account for delegated custody and provisions a USDC payer wallet in one call (side effects: registers the email, creates a Coinbase CDP-managed wallet, writes credentials to ~/.payagent/config.json on this machine). Moves no money — it does NOT spend funds. Idempotent: re-running with the same email recovers the existing account and its wallets. Not needed in self-custody mode: if PAYAGENT_PRIVATE_KEY is set, skip setup entirely — pay works with the local key alone.
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Human name. Falls back to the email local-part. | |
| Yes | Email to register the account under. It is also the recovery key — use a real address. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already carry idempotentHint=true, readOnlyHint=false, destructiveHint=false, and openWorldHint=true. The description goes further by itemizing side effects (registers email, creates Coinbase CDP-managed wallet, writes credentials to ~/.payagent/config.json), stating that no money moves, and explaining the idempotent recovery behavior. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three dense sentences: purpose and side effects, money-safety, idempotency, and the self-custody exclusion. Every sentence earns its place, and the main verb and resource are front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with no output schema and only two simple parameters, the description covers what happens, side effects, safety, idempotency, and when to skip it. Nothing needed for correct invocation is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents name and email. The description adds that email is also the recovery key and advises 'use a real address,' which is critical context for correct parameter choice. It does not add much about the optional name, but the schema already covers its fallback behavior.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Creates or recovers an ArisPay account for delegated custody and provisions a USDC payer wallet in one call.' It enumerates concrete side effects and clearly distinguishes setup from siblings like pay, history, and balance by framing it as the account/wallet provisioning step.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states when not to use: 'if PAYAGENT_PRIVATE_KEY is set, skip setup entirely — pay works with the local key alone.' This routes the agent to the pay sibling and self-custody mode. It also implies the right context for setup (delegated custody).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
9 tool updates
v4.1.0- Added
balance - Added
check_payment_signal - Removed
check_wallet - Added
discover - Added
history - Added
inspect - Added
pay - Removed
pay_api - Added
setup
2 tool updates
v2.0.1- First observed
check_wallet - First observed
pay_api
TDQS
Each tool has a clearly distinct role: discover searches, inspect prices, pay executes, history reconciles, setup provisions, balance checks funds, and check_payment_signal buys verification evidence. Even the two pre-payment tools (inspect and check_payment_signal) are cleanly separated by cost and purpose.
Most names are terse, lowercase, and command-like (discover, inspect, pay, setup), with check_payment_signal as a clear verb_noun exception. history and balance are nouns rather than list_history/get_balance, creating minor inconsistency, but the pattern remains readable and predictable.
Seven tools is well-scoped for a payment-agent server: discovery, inspection, execution, account setup, balance lookup, history, and signal verification each earn their place. There is no bloat or sense of a thin surface.
The tool surface covers the full workflow an agent needs: discover an API, inspect its price, pay for it idempotently, check prior payments, verify resources via signal, manage account setup, and confirm balance. There are no obvious dead ends or missing critical operations for the stated purpose.
Maintenance
Related MCP Connectors
Pay for HTTP APIs and charge for your own: x402 micropayments in USDC on Base.
Pay-per-call tools for autonomous agents, settled in USDC on Base via x402.
161Pay-per-call DeFi intelligence API for AI agents on Base blockchain with x402 micropayments
Pay-per-action access to APIs and MCP tools over Lightning L402 and Base USDC x402.
Related MCP Servers
- AlicenseAqualityFmaintenanceEnables AI agents to access paid tools like crypto prices, weather, translation, and web intelligence via per-request USDC payments on Base, with no API keys or subscriptions.1545MIT
- AlicenseAqualityBmaintenanceLets AI agents discover, pay for, and call any HTTP API per request using USDC, with gasless nanopayments and no API keys or accounts needed.558MIT

@hpp-io/x402-mcp-bridgeofficial
AlicenseNot gradedqualityBmaintenanceEnables AI agents to autonomously pay for and discover services using HPP USDC.e over the x402 protocol, without API keys or manual signing.148Apache 2.0- AlicenseNot gradedqualityCmaintenanceEnables pay-per-call access control for AI agents using HTTP 402 and on-chain settlement, allowing microtransactions for API usage.MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/arispay-inc/payagent-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server