agentwallet-mcp

by hifriendbot

Not rated
GitHub

About

Server-side EVM wallet for Ai agents. Send transactions, manage tokens, and interact with smart contracts across multiple chains.

Details

Author
hifriendbot
Categories
Developer Tools, Other

Setup

Install agentwallet-mcp in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/hifriendbot/agentwallet-mcp

Follow the installation instructions in the repository README, then restart your MCP client.

Server-side EVM wallet for Ai agents. Send transactions, manage tokens, and interact with smart contracts across multiple chains.

Permissionless wallet infrastructure for AI agents. Create wallets, sign transactions, and broadcast on-chain, on any EVM chain and Solana. Built-in guards. No KYC. The only AI agent wallet that accepts crypto for its own API fees.

Your keys can stay on your machine.Set one environment variable and every signature happens in your own process. No server sees the key, no company can freeze the wallet, and you can verify that claim by readingsrc/local-wallet.tsor by running the server with the API pointed at a closed port.

No KYC. No KYT. No approval process. No transaction monitoring. No one can block your wallet. Pay with USDC on-chain, no credit card required.

Runwallet_modeat any time and the server will tell you which one you are in, and which address it controls.

{ "mcpServers": { "agentwallet": { "command": "npx", "args": ["-y", "agentwallet-mcp"], "env": { "AGENTWALLET_PRIVATE_KEY": "0xyour_key", "AGENTWALLET_RPC_8453": "https://your-own-rpc", "AGENTWALLET_MAX_TX_NATIVE": "0.05" } } } }

UseAGENTWALLET_KEYFILE=/path/to/keyinstead if you would rather keep the key out of your shell config. The key is read once, never written to disk, never logged, and never included in an error message.

AGENTWALLET_RPC_<chainId>(orAGENTWALLET_RPC_URLfor all chains) points at an endpoint you trust. Without it a public RPC is used, and a public RPC can see which addresses you ask about.

AGENTWALLET_MAX_TX_NATIVEis a per-transaction ceiling in native units (ETH, MATIC and so on). In hosted mode the server enforces limits; in local mode there is no server, so these guards are the only ones there are. Set them.

AGENTWALLET_MAX_TX_TOKENis the equivalent ceiling for ERC-20 movement, in human units of the token.Set this one too if you hold stablecoins.The native cap cannot see a token transfer: an ERC-20 send carriesvalue = 0with the amount in the calldata, soAGENTWALLET_MAX_TX_NATIVEalone leaves a USDC balance uncapped.AGENTWALLET_MAX_TX_TOKENcoverstransfer,transferFromandapprove, the last because an unbounded allowance is a drain waiting to happen. Decimals are resolved locally; unknown tokens are evaluated at 6 decimals, the tightest common value, so it fails closed rather than open.

"env": { "AGENTWALLET_SOLANA_KEY": "[12,34...]", "AGENTWALLET_SOLANA_RPC": "https://your-own-rpc", "AGENTWALLET_MAX_TX_SOL": "1" }

Accepts whichever format you already have: asolana-keygenid.json array, a base58 secret key as exported by Phantom, or base64. UseAGENTWALLET_SOLANA_KEYFILEto point at a file instead. Native SOL and SPL token transfers are both signed locally, and a missing associated token account is created for the recipient automatically.

Set either key, or both. They are independent: run EVM locally and Solana hosted, or the reverse.

An operation with no matching local key is refused, never silently routed to the hosted signer.If you have an EVM key configured and ask for a Solana transfer with no Solana key, the server stops and tells you which variable is missing. Quietly moving funds onto a key you do not hold, while you believe you are in self-custody, is the worst thing this server could do.

Local signing usesviemfor EVM and@solana/web3.jsfor Solana, plusbs58for key parsing. SPL instructions are built by hand rather than with@solana/spl-token, because that package pulls inbigint-buffer, which carries a high severity buffer overflow advisory. A wallet has no business shipping that to save a dozen lines of instruction encoding.

npm auditcurrently reports issues inside@modelcontextprotocol/sdk's HTTP transport dependencies. This server speaks stdio, so that code never loads, and the SDK is not something this package can patch. Run the audit yourself. Publishing a tree you can inspect is the point.

- 31 MCP tools: create wallets, send transactions, approve tokens, wrap ETH, transfer SPL tokens, pay and accept x402 payments, verify custody mode, and more
- EVM + Solana: Ethereum, Base, Polygon, BSC, Arbitrum, Optimism, Avalanche, Zora, PulseChain, Solana, and any other EVM-compatible chain
- SOL + SPL tokens: native SOL transfers and SPL token transfers (USDC, USDT, etc.) with automatic account creation
- Built-in guards: daily spending limits, gas price protection, emergency pause, rate limiting, replay protection, and on-chain verification, all active by default
- x402 payments: pay for x402-enabled APIs automatically, or accept x402 payments on your own endpoints (EVM and Solana)
- Self-custody option: run local mode and the key never leaves your machine. In hosted mode, keys are encrypted at rest, decrypted only during signing, and zeroed from memory immediately after. Either way you can export and walk away.
- Permissionless: No KYC. No KYT. No identity verification. No approval process. No compliance gatekeeping. Sign up, get an API key, and start transacting immediately.
- 30-second setup: three lines of config. No SDK to install. No dependencies to manage.

- $0.00345 per operation
- 6,000 free operations/month
- $0.0005 per x402 verification
- 1,000 free x402 verifications/month
- Pay with USDC on-chainvia x402, no credit card required
- No monthly fee, no tiers, just pay as you go

Competitor comparisons are kept athifriendbot.com/wallet/#pricingwith the date they were last verified. They live there rather than here because a published npm README cannot be corrected when someone else changes their prices.

Get your free API key athifriendbot.com/wallet, no credit card required, no KYC, no approval wait.

{ "mcpServers": { "agentwallet": { "command": "npx", "args": ["-y", "agentwallet-mcp"], "env": { "AGENTWALLET_USER": "your_username", "AGENTWALLET_PASS": "your_api_key", "AGENTWALLET_WALLET_ID": "1" } } } }

AGENTWALLET_WALLET_IDis optional. Set it to enable x402 auto-pay: when you exceed the free tier without a credit card, the MCP server automatically pays for operations with USDC from this wallet.

Auto-pay safety cap.AGENTWALLET_MAX_AUTOPAY(optional, default1) is the maximum amount, in human-readable units of the asset, that x402 auto-pay will authorize for a single payment. Any 402 requirement above this cap is rejected instead of paid, so a malformed or tampered payment requirement cannot drain the wallet. Raise it only if you genuinely need larger automatic payments (for example"5"to allow up to 5 USDC per call).

claude mcp add agentwallet \ -e AGENTWALLET_USER=your_username \ -e AGENTWALLET_PASS=your_api_key \ -e AGENTWALLET_WALLET_ID=1 \ -- npx -y agentwallet-mcp
{ "mcp": { "servers": { "agentwallet": { "command": "npx", "args": ["-y", "agentwallet-mcp"], "env": { "AGENTWALLET_USER": "your_username", "AGENTWALLET_PASS": "your_api_key", "AGENTWALLET_WALLET_ID": "1" } } } } }

Pair withguessmarket-mcpto let your AI agent trade prediction markets:
- Create a wallet on Base
- Approve USDC spending
- Buy YES/NO shares on prediction markets
- Provide liquidity and earn trading fees
- Claim winnings

All on-chain. All through MCP. No frontend needed.

AgentWallet natively supports thex402 open payment standard. When your Ai agent encounters an API that returns HTTP 402 Payment Required, thepay_x402tool handles the entire flow automatically:
- Fetches the URL and detects the 402 response
- Parses the payment requirements (amount, token, chain)
- Executes the on-chain payment from your wallet
- Retries the request with proof of payment
- Returns the final response

pay_x402( url="https://api.example.com/premium-data", wallet_id=1, max_payment="1.00" )

max_paymentis enforced as a hard per-payment cap. If you omit it,pay_x402falls back toAGENTWALLET_MAX_AUTOPAY(default1), the same cap the auto-pay path uses, so a malicious or compromised 402 endpoint can never authorize an unbounded payment. Setmax_paymentexplicitly (or raiseAGENTWALLET_MAX_AUTOPAY) to allow a larger single payment.

Supports ERC-20 tokens, SPL tokens, and native tokens on EVM and Solana. Compatible with x402 V1 and V2 (CAIP-2 chain identifiers), and reads the token address from the standard x402assetfield (falling back toextra.token).

AgentWallet also lets youacceptx402 payments. Create a paywall, point it at any resource, and get a public URL that charges agents automatically:

create_paywall( wallet_id=1, name="Premium API", amount="0.01", token_name="USDC", token_address="0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913", chain_id=8453, resource_url="https://your-api.com/data" )

- Gets back HTTP 402 with payment requirements
- Pays on-chain usingpay_x402(or any x402-compatible client)
- Retries with proof of payment
- Receives the protected content

On-chain verification ensures every payment is real. Replay protection prevents double-spending. Revenue tracking shows you who paid, how much, and when. 1,000 free verifications/month, then $0.0005 each. See thepricing comparisonfor how that stacks up.

Pay with Crypto, No Credit Card Required

AgentWallet is the only AI agent wallet infrastructure that accepts crypto for its own API fees. Every competitor, Coinbase CDP, Circle, MoonPay, Crossmint, Turnkey, requires a credit card or monthly invoice. With AgentWallet, your agent can pay for operations with USDC on-chain via the x402 protocol. No credit card, no invoice, no billing portal. Just on-chain payments.

When your agent exceeds the free tier (6,000 ops/month) without a credit card configured, the API returns HTTP 402 with USDC payment instructions. Your agent pays on-chain, retries with proof of payment, and the operation executes. Fully automated via the MCP server.

You can also pre-purchase x402 verification credits with USDC using thebuy_verification_creditstool, keeping your paywalls running beyond the free 1,000 verifications/month without needing a credit card.

All guards are active by default, no configuration required.

- Encrypted at rest: private keys encrypted before storage and never leave the server
- Memory zeroing: keys wiped from memory immediately after every signing operation
- Daily spending limits: set a per-wallet daily cap in USD, enforced automatically on every transaction
- Gas price protection: transactions blocked when gas prices spike above safe thresholds
- Emergency pause: instantly freeze any wallet or all wallets with one click
- Rate limiting: API requests capped per minute to prevent abuse and brute force attacks
- Replay protection: every x402 payment verified on-chain with unique transaction tracking
- On-chain verification: x402 payments verified directly on the blockchain with finalized commitment
- Bug bounty program: $50,$500 for responsible disclosure (
details)

- Website:hifriendbot.com/wallet
- npm:
agentwallet-mcp
- Security:
security@hifriendbot.com

pay_x402validates the target URL before every outbound request and again on each redirect hop. IP literals are canonicalized (including IPv4-mapped IPv6 such as[::ffff:127.0.0.1]) and hostnames are resolved, with loopback, private, link-local, carrier-grade NAT, multicast and cloud-metadata destinations refused.

Validation and connection use the same DNS answer. Each hop resolves once, and the socket is pinned to an address from that answer, so a hostname cannot resolve public for the check and private for the connection. The hostname is still used for theHostheader and for TLS SNI and certificate validation, so pinning is invisible to legitimate endpoints.

Report security issues privately tosecurity@hifriendbot.com.

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Read/write to over 2k blockchains, enabling data querying, contract analysis/deployment, and transaction execution, powered by Thirdweb.

An MCP server providing onchain tools for AI applications to interact with the Base Network and Coinbase API.

A server for blockchain interactions, offering Ethereum vanity address generation, 4byte lookup, ABI encoding, and multi-chain RPC calls.

A comprehensive toolkit for Ethereum blockchain analysis directly within Claude AI.

Provides blockchain services for over 30 EVM-compatible networks through a unified interface.

About MCP server for TRON blockchain — connect AI agents to TRX, TRC20, smart contracts, staking & governance via GoTRON SDK

Provides onchain tools for AI applications to interact with the Hashkey Network.

Integrates with the Hyperlane protocol for cross-chain messaging and smart contract interactions.

An MCP server for Solana development providing basic RPC methods and helpful prompts.

An MCP server providing access to various Starknet RPC methods.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.