Skip to main content
Glama
README.md
# @zappimoney/zappi-mcp

Local MCP server that signs Zappi pot spends. The pot key stays in the OS keychain. The agent only sees tools.

Setup (create or pair a pot) still uses `@zappimoney/zappi-cli`. Spend uses this server.

```json
{
  "mcpServers": {
    "zappi-pot": {
      "command": "npx",
      "args": ["-y", "@zappimoney/zappi-mcp"],
      "env": {
        "ZAPPI_POT_ID": "<pot id>"
      }
    }
  }
}
```

Do not put `ZAPPI_POT_SEED` in that env block. Store the key with the OS keychain (`keytar`, service `money.zappi.mcp`).

## Tools

| Tool | Spends? | What it does |
| --- | --- | --- |
| `balance`, `list_deposits`, `deposit_address`, `spend_approvals` | No | Read-only. No key in the result. |
| `pay` | Yes, under the cap | Pays a PaidResource on spark/USDB. |
| `send` | Yes, under the cap | Sends only to an allowlisted Spark address. |
| `request` | No | Creates a human approval ticket. Returns the approve URL only. |

Amounts above the per-spend cap become a `request` ticket. Nothing is signed until a human approves.

## Develop

```bash
npm install
npm test
```