Server data from the Official MCP Registry
Trust + receipt layer for x402 agents on Solana: free preflight + paid signed V6 trust receipt.
About
Trust + receipt layer for x402 agents on Solana: free preflight + paid signed V6 trust receipt.
Security Report
This is a legitimate Solana x402 payment MCP server for TWZRD's trust intelligence API. The codebase demonstrates solid architectural security with proper payment guardrails, input validation, and use of official SDK libraries. However, there are several moderate concerns: secret key handling in environment variables without clear rotation guidance, missing rate limiting on free endpoints, and some input validation gaps in helper functions that could allow malformed data to reach the API. Package verification found 1 issue (1 critical, 0 high severity).
8 files analyzed · 10 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
Unverified package source
We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.
What You'll Need
Set these up before or after installing:
Environment variable: TWZRD_SIGNAL_SOURCE
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-twzrd-sol-twzrd-agent-intel": {
"env": {
"TWZRD_SIGNAL_SOURCE": "your-twzrd-signal-source-here"
},
"args": [
"-y",
"@wzrd_sol/eliza-plugin"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
TWZRD
Spend control and counterparty trust for agents paying over x402 on Solana (and Base).
Vet the seller before USDC leaves the wallet, cap and ledger every spend, and bind each settled payment to the exact offer it paid for (bind-v1 — verifiable from public chain data). Free preflight → optional paid V6 receipt. Not a wallet. Not a payment network.
Canonical skill (always refresh) • https://intel.twzrd.xyz/skill.md (twzrd-trust 1.13.16) · ClawHub twzrd-trust
Spend-control SDK (npm) • twzrd-x402-gate@0.9.3 + seat x402-solana@3.0.0
Live MCP • https://intel.twzrd.xyz/mcp (streamable HTTP — 24 tools)
Agent contract • https://intel.twzrd.xyz/llms.txt · https://intel.twzrd.xyz/.well-known/agent.json
60-second deterministic free demo
Run this one-line command with no wallet, no API key, and no configuration:
curl -fsS https://intel.twzrd.xyz/v1/intel/demo-gate | jq '{verdict: (.steps[] | select(.name == "block_path") | .verdict), approved: (.steps[] | select(.name == "block_path") | .approved), signerInvocations: (.steps[] | select(.name == "block_path") | .signer_invocations), mode, ok}'
Without jq, run: curl -fsS https://intel.twzrd.xyz/v1/intel/demo-gate
Expected output:
{
"verdict": "block",
"approved": false,
"signerInvocations": 0,
"mode": "no_spend",
"ok": true
}
Blocks happen before your signer is invoked (signerInvocations: 0) — zero USDC at risk.
Quickstart
1. Install
npm install twzrd-x402-gate@0.9.3 x402-solana@3.0.0
2. Wrap paid fetches with spend controls
import { twzrd } from "twzrd-x402-gate";
const result = await twzrd.safeFetch("https://merchant.example/paid-endpoint", {
maxSpend: "0.10", // per-call cap AND cumulative budget in USD
allowNetworks: ["solana"], // allowed settlement networks
requireOfferBinding: true, // demand an on-chain verifiable bind-v1 receipt
pay: async ({ url, paymentRequired, selected }) => {
// Your existing x402 client signs here — e.g. @x402/fetch + your signer
return await myWallet.payX402(url, paymentRequired, selected);
},
});
// On block: result.verdict === "block", result.signerInvocations === 0
3. Or hook an existing client
import { createX402Client } from "x402-solana";
import { createTwzrdBeforePaymentHook } from "twzrd-x402-gate";
const client = createX402Client({
wallet,
network: "solana",
beforePayment: createTwzrdBeforePaymentHook({ refuseWashFlagged: true }),
});
Default Protection Sequence
- Discover —
GET /v1/intel/resources(resource catalog) - Merchant card —
GET /v1/intel/merchant_card/{pay_to}(refuse ifwash_flagged: true) - Preflight —
POST /v1/intel/preflight→ ReadinessCard (allow / warn / block) - Optional V6 Receipt —
GET /v1/intel/trust/{pay_to}($0.05 USDC paid receipt) - Pay — sign only when preflight & spend policy allow
# Free preflight (no signup, no wallet)
curl -s -X POST https://intel.twzrd.xyz/v1/intel/preflight \
-H 'content-type: application/json' \
-d '{"seller_wallet":"46vMcwuC4sK11sB3gkLhyA7J7GEwfkhn5rFyDtihBwqe","price_usdc":0.01,"agent_intent":"preflight"}'
Packages & References
| Package | Pin | Description |
|---|---|---|
twzrd-x402-gate | @0.9.3 | Spend-control SDK (twzrd.safeFetch) + pre-sign gate hooks |
x402-solana | @3.0.0 | Compatible Solana client seat for the pre-payment gate |
twzrd-receipt-verifier | @^1.3.0 | Standalone offline verifier for Ed25519 V6 receipts |
twzrd-mcp-server | @0.5.2 | Local spend-capped auto-pay client (6 tools) |
- Step-by-step Guide: QUICKSTART.md
- Concepts & Architecture: docs/taxonomy.md
- V6 Receipt Specification: docs/receipt-v6-spec.md
- Receipt Verification & Ground Truth: REVIEW.md
- Security Policy: SECURITY.md · docs/security-assurance.md
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
