captcha-mcp

by zekebuilds-lab

Not rated
GitHub

About

L402 Lightning paywall and PoW gate for MCP tool calls. Free tier solves a Hashcash challenge; paid tier pays a Lightning invoice via self-hosted LNBits. No accounts, no API keys.

Details

Author
zekebuilds-lab
Categories
Other, Security, API

Setup

Install captcha-mcp in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/zekebuilds-lab/captcha-mcp

Follow the installation instructions in the repository README, then restart your MCP client.

Your MCP server returns 429 when agents pound it. captcha-mcp makes them earn their next call instead.Hand the agent a proof-of-work puzzle (free, ~5s of CPU) or a 3-sat Lightning invoice — both are machine-readable backoff signals an autonomous caller can satisfy without an account, email, or API key.

Three tools over stdio or HTTP. Stdlib only. No signup, free fallback, self-hosted, no revenue share.

429 Too Many Requests is the wrong shape for the agent era. Three patterns recur across MCP server reports:

- Agent frameworks treat 429 as a connection failure.They retry immediately, often with exponential backoff that is still too aggressive, and amplify the overload that triggered the limit in the first place.
- There is no per-caller signal.A 429 fires for the bucket, not the agent. One noisy caller gets every other caller throttled, and the server has no way to ask the noisy one to slow down specifically.
- Retry-After is advisory and frequently ignored.Agents do not consistently parse it, do not consistently respect it, and have no incentive to wait — the cost of retrying is zero.

captcha-mcp replaces the 429 with a 402-style challenge. The next call costs the caller something (CPU seconds or 3 sats). That cost is per-caller, machine-readable, and self-throttling — an agent that cannot solve the puzzle cannot flood the endpoint.

No install, no config, no API key. The server starts on stdio and waits for an MCP client.

To wire it into Claude Code, Cursor, or any MCP-compatible host, add to your config:

{ "mcpServers": { "powforge-captcha": { "command": "npx", "args": ["-y", "@powforge/captcha-mcp"] } } }

Or runnpx @powforge/captcha-mcp --installto print the config block.

Wraps the PowForge pow-captcha service (captcha.powforge.dev) as three MCP tools:

The free tier costs the agent ~5-10 seconds of CPU time (SHA-256, default 14 leading zero bits). The paid tier costs 3 sats over Lightning via L402 (RFC 7235 + bolt11 invoice inWWW-Authenticate).

Why this and not OAuth, API keys, or Stripe

Agents do not have email addresses. They do not click confirmation links. They do not enter credit cards. PoW + Lightning is the only auth primitive that works for fully autonomous callers.

Managed MCP auth platforms work, but they charge 100–2000 sats per call on vendor infrastructure — your revenue flows through their rails. This package runs on your server, your Lightning node, your keys. You keep the sats.

SetCAPTCHA_URLto point at a different captcha backend. Default ishttp://localhost:3077so you can run the full stack locally for development. Production deployments point it athttps://captcha.powforge.dev.

CAPTCHA_URL=https://captcha.powforge.dev npx @powforge/captcha-mcp

Hosted MCP clients (Smithery, browser-based hosts) need HTTP, not stdio. Pass--httpor setHTTP_MODE=1:

HTTP_MODE=1 PORT=3200 npx @powforge/captcha-mcp # or npx @powforge/captcha-mcp --http

Stateless. No session ids. CORS open (Access-Control-Allow-Origin: *) so browser clients work. Stdio mode is unchanged and remains the default —npx @powforge/captcha-mcpwith no flag still talks JSON-RPC over stdin/stdout.

HTTP_MODE=1 PORT=3200 node src/server.js & curl -X POST http://localhost:3200/mcp \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"1"}}}'

Returns{jsonrpc:"2.0", id:1, result:{protocolVersion:"2024-11-05", capabilities:{tools:{}}, serverInfo:{...}}}.

Clone thecaptcha widget repoor run the public service. The MCP server only needs HTTP access to the captcha endpoints listed understatus.

git clone https://github.com/zekebuilds-lab/captcha-mcp cd captcha-mcp node src/server.js

It printsreadyto stderr and waits for JSON-RPC on stdin.

echo '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"1"}}}' | node src/server.js

You should see a JSON response withserverInfo: { name: "@powforge/captcha-mcp", version: "0.2.5" }.

Token verification from your own backend

When an agent submits a token to your service, verify it without trusting the agent:

curl -X POST https://captcha.powforge.dev/api/token/verify \ -H "Content-Type: application/json" \ -d '{"token":"<token-from-verify-tool>"}'

Returns{valid: true, method, issued_at, expires_at}or{valid: false, reason}.

- @powforge/captcha— the browser widget for the same service.
-
@powforge/mcp-l402-gate— Express middleware to gate any MCP server with L402 + Depth-of-Identity scoring.
-
@powforge/mcp-identity— agent reputation oracle. Pair with this gate for first-call abuse protection.

How this compares to other MCP agent-auth primitives

The gate-the-MCP-server space is filling up. Here is the honest landscape, ranked by how directly each tool overlaps with whatcaptcha-mcpdoes.

PayGated is the closest collision.Same "monetize MCP tools per call" pitch, same self-host + open-source posture, but it settles on Stripe. That means you need a Stripe account in good standing (KYC, a bank, a supported country) to collect, and every caller needs a Stripe customer record before it can pay you a cent.captcha-mcp's differentiator is the no-account path: a non-US agent author pays 3 sats per call in about 200ms with no KYC, or solves a free PoW puzzle if it will not pay at all.

APort and AgentSign sit at a different layer.They record who used a tool under what authority; they do not price the call. They compose with a gate like this one rather than replace it.

None of them price the act of interacting.Every other row assumes the caller is already an authorized identity and meters or audits after that. The PoW tier here is the only mechanism in the table that puts a cost on the interaction itself, not on the identity of the actor. That is the position this package defends.

A longer breakdown againstx402-mcp,@agentauth/mcp, and Cloudflare ARC/ACT is atpowforge.dev/mcp/compare/x402-mcp.

Static MCP discovery card for x402 spend-policy, paid MCP launch guidance, seller checkout repair, and agent-payment safety APIs.

Open-source API gateway that adds budget enforcement, cost attribution, and monetization to AI agent API calls. MCP-aware with per-tool cost tracking, macaroon-based bearer tokens, L402 Lightning micropayments, and enterprise budget control (Fiat402). The economic firewall for the agent economy.

Transaction-complete hotel booking over MCP — 300K+ properties, real hotel confirmation numbers, loyalty points, secure checkout. Hotels are merchant of record. Builders set their own booking fee via Stripe Connect. Built on proven distribution infrastructure.

A Model Context Protocol (MCP) server implementation that provides seamless integration with the AbuseIPDB API for IP reputation checking and abuse report management.

AI agent API marketplace-discover, call, and pay for services with USDC payments. List your own AI services and earn money per call.

Independent trust verification for MCP servers. 7-factor trust scoring, 3,400+ packages indexed, embeddable badges, free API. Agents can query trust scores natively via MCP protocol.

MCP server for ESET Connect API - 102 tools, RO/RW mode, stdio+HTTP, OAuth2

A live HTTP 402 Lightning tollbooth for AI agents. Sells structured API error intelligence paid per-request over the Lightning Network. No accounts, no OAuth, just pure HTTP 402.

121 pay-per-call API tools for AI agents — crypto, weather, finance data via x402 micropayments (USDC on Base). Each call costs $0.001-$0.05.

MCP server that sits between AI agents and APIs. Agents request access, Janee makes the call with the real credentials, agents never see the secrets.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.