fidacy-mcp
fidacy-mcp is a cryptographic action firewall and integrity proof service for AI agents. It gates payment actions behind cryptographically signed mandates and provides tamper-evident audit trails, spend reports, anomaly detection, trust verdicts, and artifact anchoring.
Payment Authorization:
request_paymentauthorizes or denies a payment against the active mandate, returning an ALLOW with a short-lived Ed25519-signed grant or a DENY with the violated rule. Grants must be verified by the downstream executor before moving funds.Mandate Verification:
verify_mandatereturns the active mandate envelope (caps, allowed payees/categories, time windows, revocation rules) and Fidacy's Ed25519 public key for independent grant validation.Audit & Proof: Every decision is recorded in a hash-chained, tamper-evident log.
get_audit_proofprovides a verifiable proof for a specific decision, including chain integrity status.list_decisionslists recent payment decisions (filterable by ALLOW/DENY) with payee, amount, reason, and blocking rule.explain_decisiongives a plain-language explanation and proof for why a payment was allowed or blocked.Spend Reports:
spend_summarygenerates operator reports over a configurable time window, showing total payments, amounts per payee, blocked amounts, and which mandate rules triggered blocks.Anomaly Detection:
sentinel_alertsflags suspicious patterns in the local audit chain—first-ever payees, amount spikes, velocity bursts, payments near mandate ceilings, and retries after denial. Deterministic and explainable, no ML model required.Trust Verdicts:
assess_actionreturns a signed trust verdict (JWS) from the live Fidacy engine for any proposed action (ap2_payment,message_send,voice_call,custom,claim_document). Advisory only—no money moves.Artifact Integrity:
anchor_artifactproves a file existed unaltered at a specific moment by locally hashing it (SHA-256) and anchoring the hash to Fidacy's audit chain, checkpointed to the Bitcoin blockchain. Returns a signed receipt (JWS).check_artifactverifies if an artifact was previously anchored and its Bitcoin checkpoint status; a hash mismatch signals tampering. The file itself is never uploaded.Account Management:
upgradeinitiates an upgrade from the local/anonymous install to a full Fidacy account (preserving history).register_emailopts in the operator's email for contact and history attachment (consent-based).
@fidacy/mcp
The action firewall for AI agents. A drop-in MCP server that gates payment actions against a cryptographically signed mandate before money can move. Non-custodial: Fidacy authorizes and proves, it never holds funds.
Install once, works in any MCP-compatible agent: Claude Code, Claude Desktop, Hermes, OpenClaw, and anything else that speaks MCP.
Works with: Claude Code · Claude Desktop · OpenClaw · Hermes · Brex CrabTrap
Your agent could be paying scammers right now. Prompt-injected into the wrong payee, an inflated amount, or the same invoice twice — and your logs aren't evidence. Fidacy blocks it before money moves, and hands back a signed verdict anyone can verify against public keys. You don't trust us — you check the signature.
Quick start (free, local-first, no account)
{
"mcpServers": {
"fidacy": { "command": "npx", "args": ["-y", "@fidacy/mcp"] }
}
}Runs on your machine, offline, deny-by-default. Add trusted payees + caps in
~/.fidacy/config.json. Verify any verdict yourself against the public keys at
/.well-known/jwks.json.
Related MCP server: pop-pay
Why
An agent can hallucinate or be prompt-injected into a payment: wrong payee,
wrong amount, fabricated invoice. Prompt-level guardrails are probabilistic and
bypassable. @fidacy/mcp is a deterministic gate between the agent's intent and
the executor: the action is dead on arrival unless it validates against a signed
mandate, and every decision lands in an immutable hash-chained audit trail.
Enforcement model
Register
@fidacy/mcpas the agent's only payment-capable tool. Do not give the agent a raw payment tool. Tool inventory is the runtime firewall.The agent calls
request_payment. Fidacy checks it against the mandate (payee allowlist, per-tx cap, total cap, currency, time window, revocation).ALLOW returns a short-lived Ed25519 grant. DENY returns no grant and the violated rule. The downstream executor MUST require the grant, so a denied action cannot proceed.
Every decision is appended to a hash-chained log.
get_audit_proofreturns the portable, verifiable proof.
One install, two backends
@fidacy/mcp ships two complementary capabilities in a single install:
Verdict layer (advisory):
assess_actioncalls the live Fidacy engine and returns a signed trust verdict. It moves no money; it returns a judgment whose proof (riskPayloadJws+signingKeyId) is verifiable by anyone via@fidacy/verifyagainst the engine JWKS at/.well-known/jwks.json.Payment firewall (enforcement):
request_payment/verify_mandate/get_audit_proofgate and prove a payment against a signed mandate through the core, returning short-lived Ed25519 grants.
Mental model: assess_action -> engine (signed verdict);
request_payment and friends -> core (payment firewall).
Tools
Tool | Backend | Purpose |
| engine | Signed Fidacy trust verdict for a proposed action. Advisory. |
| core | Authorize a payment action. ALLOW + grant, or DENY + rule. |
| core | Read the mandate envelope + Fidacy public key. |
| core | Hash-chained proof for a decision id. |
assess_action
Returns a signed Fidacy trust verdict from the live engine for a proposed
action. The signed proof is riskPayloadJws + signingKeyId, verifiable by
anyone via @fidacy/verify against {engineUrl}/.well-known/jwks.json.
Inputs:
kind(optional, defaultap2_payment): one ofap2_payment,message_send,voice_call,custom,claim_document.mandate(required): the action/mandate object for thatkind.mandateType,spendingMandate,idempotencyKey,a2a.task_id(optional).
Environment:
Var | Default | Purpose |
|
| Base URL of the Fidacy engine. |
| (none) | An |
The server boots without FIDACY_ENGINE_API_KEY; the tool is always registered.
Only calling assess_action without the key returns a helpful error telling
you to set it. The key is never logged, echoed, or attached to any error.
Install
npm install -g @fidacy/mcp # or run via npx, no installClaude Code
claude mcp add fidacy -- npx -y @fidacy/mcpClaude Desktop (claude_desktop_config.json)
{
"mcpServers": {
"fidacy": { "command": "npx", "args": ["-y", "@fidacy/mcp"] }
}
}Hermes (config.yaml)
mcp_servers:
fidacy:
command: npx
args: ["-y", "@fidacy/mcp"]OpenClaw
Add the same server via the Tools panel, or the mcpServers block in your
agent config. Any MCP-compatible host uses the same command.
Wiring the real core (production)
The MCP layer talks to your core through one interface (FidacyCore). Your
repository stays private. Set FIDACY_MODE=http and implement three endpoints:
POST /v1/mandate/get->MandatePOST /v1/decide->Decision(runs your Ed25519/AP2 verification + audit append)POST /v1/audit/proof->AuditProof
No change to the MCP layer is needed.
Dev
npm install
npm run build
npm start # stdio server, in-memory demo mandateMaintenance
Related MCP Servers
- AlicenseAqualityCmaintenanceCryptographic proof of consent for AI agents. Sign before you act. Policy engine enforces spending caps, action whitelists, and escalation rules. Independently verifiable by anyone.102Apache 2.0
- Alicense-qualityBmaintenanceStop AI agents leaking your card or making hallucinated purchases. No SaaS, No login, Fully local. A runtime security layer that protects AI agents during online purchases. It sits between the agent and payment forms1911MIT
- AlicenseAqualityBmaintenanceNon-custodial agent wallet with a transaction preflight that decodes an unsigned EVM tx and flags drain patterns (unlimited/large approval, approve-all, token & NFT transferFrom, proxy upgrade, on-chain permit, approvals hidden in multicall) before signing.91MIT

emilia-mcp-serverofficial
AlicenseAqualityAmaintenanceThe accountability layer for AI agents — a named human's signed yes before an agent does anything irreversible (payment, record change, deploy), then an offline-verifiable Trust Receipt. Apache-2.0, formally verified.17846Apache 2.0
Related MCP Connectors
Check if a counterparty is safe to pay: trust/risk score for AI agents. Scam/phishing screen.
Issue signed receipts for AI agent actions; verify any receipt offline - free, no account.
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/lucaslubi/fidacy-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server