paywings
Enables agents to request payments via Pix using a copia-e-cola BR Code, with policy checks on the encoded amount and payee key; Pix settlement is simulated in the sandbox.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@paywingsPay R$ 19.90 to Vercel for my plan upgrade"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
PayWings
Policy-governed payments for AI agents. Agents pay through MCP or the terminal, and only within rules their human owner sets.
Leia em português · Design spec (pt-BR)
Sandbox only. No real money moves. Cards use the 411111 test BIN and Pix settlement is simulated.
Why
Prompt injection can talk an agent into anything, so spending rules can't live inside the agent. PayWings keeps them on the server:
The agent asks, the server decides. Every purchase is a payment intent evaluated by a deterministic policy engine. The agent has no tool to approve, top up, or change limits.
The data decides, not the agent's claim. For Pix, the payee is read from the BR Code itself. A code that says "Trusted Store" but points to someone else's key is denied.
Minimal exposure. Cards are single-use, locked to one merchant and amount, and expire after 30 minutes.
Humans approve out of band. Payments above a threshold wait for the owner. In the sandbox,
approverequires an interactive terminal, which an agent running shell commands doesn't have.Everything is auditable. Every event goes into an append-only, hash-chained log: intent, decision, approval, execution. Card numbers never reach the log.
Related MCP server: dingdawg-agent-wallet
Requirements
Node 22.18 or newer. TypeScript runs directly, with no build step.
Quick start
npm install
npm link # puts `paywings` on your PATH
paywings init # creates ~/.paywings/sandbox.db with a "demo" agent and R$ 500.00init prints the agent key and a ready-made command to register the MCP server with Claude Code:
claude mcp add paywings --env PAYWINGS_AGENT_KEY=pw_test_... --env PAYWINGS_DB=~/.paywings/sandbox.db -- paywings mcpThen ask your agent to, for example, "upgrade my Vercel plan". It calls request_payment and gets back one of three results:
executed, with a single-use card or a Pix receipt;pending_approval, while it waits for you;denied, with machine-readable reasons.
MCP tools
Tool | Purpose |
| Balance, limits, month-to-date spend, allowed merchants |
| Ask to pay by |
| Poll a payment after |
| Recent payments, with card numbers hidden |
Policy
Each agent has its own policy, checked in this order:
Kill switch: is the agent frozen?
Allowed rails.
Pix code validity, and the amount encoded in it.
Merchant allow-list. A domain also matches its subdomains, but lookalikes such as
vercel.com.evil.iodon't match.Blocked categories.
Per-transaction limit.
Monthly limit. Pending payments count toward it.
Payments per hour.
Balance.
Human-approval threshold.
All failing rules are reported at once.
Owner commands
paywings agents create research --balance 300 --per-tx 100 --monthly 500 --approve-above 30 --merchants vercel.com,openai.com
paywings pending
paywings approve pay_... # interactive terminal; you type the amount to confirm
paywings reject pay_... --note "not now"
paywings agents freeze research # kill switch
paywings audit verify # checks the hash chainAgent commands (terminal)
export PAYWINGS_AGENT_KEY=pw_test_...
paywings pay --amount 19.90 --rail card --merchant Vercel --domain vercel.com --category software --reason "upgrade requested by the user"
paywings pay --amount 35.90 --rail pix --merchant Store --pix "$(paywings pix-code --key store@example.com --name Store --city 'Sao Paulo' --amount 35.90)" --category office --reason "..."
paywings status pay_...CLI output is in Portuguese for now. pay and status print JSON.
Development
npm test # node:test, 33 tests
npm run typecheckFile | Role |
| Policy engine (pure function) |
| Wallets, payments, approvals, idempotency, audit log (SQLite, |
| Pix BR Code parser and builder with CRC16 validation |
| Simulated rails; production adapters implement the same |
| Agent-facing MCP server |
| Owner and agent CLI |
Roadmap
Sandbox (this repo): policies, approvals, Pix and card simulation, audit log.
Real money, small volume:
cards through a BaaS issuer or Stripe Issuing;
Pix through a licensed payment initiator (Open Finance);
REST API, WhatsApp approvals, web dashboard.
Network protocols: agentic tokens from the card networks, ACP/AP2, x402.
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Approval layer for AI agent payments: budgets, rules, human approval. Sandbox, test credentials.
Payment infrastructure for AI agents: spending rules, approval flows, single-use virtual cards.
Agent payments, API key vaulting, and governed mandates. Agents spend within user-defined limits.
Give AI agents identity, scoped access, trusted context, and verifiable actions through MCP.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceAn MCP server that enables AI agents to safely interact with a double-entry payments ledger, enforcing idempotency, policy-based access control, and human-in-the-loop approval for high-value actions.-
- FlicenseNot gradedqualityDmaintenanceProvides MCP tools to enforce spend policies (allow, deny, step-up, allowlist) on agent wallets with an immutable audit trail.-
- AlicenseNot gradedqualityAmaintenanceDeterministic, auditable payment policy enforcement for AI agents. It provides pre-action authorization with scopes, budgets, allowlists, and signed mandates via an MCP server.MIT
- AlicenseNot gradedqualityCmaintenanceGoverns AI agents' spending by enforcing budgets, approvals, and kill switches before any payment, providing an MCP interface for tool calls with policy checks.Apache 2.0