
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
402coffee-mcp
Advanced tools
MCP server for 402.coffee — the trust layer for agent payments (x402 on Base). Free tools: verify any agent's credential (with offline Ed25519 signature check), browse the conformance menu, read the arbiter policy. Paid tools (x402 USDC, non-custodial loc
MCP server for 402.coffee — the trust layer for agent payments (x402 · Base · USDC).
Give any MCP client (Claude Desktop, Claude Code, Cursor, …) the tools to check an agent before trusting it with money, and to pay for the decision-grade products directly over x402.
| Tool | Cost | What |
|---|---|---|
verify_agent | free | Current certs + free on-chain USDC activity summary for any wallet |
check_credential | free | Portable credential + local Ed25519 signature verification |
list_tests | free | The machine-readable menu (tests, prices, products) |
arbiter_policy | free | The published arbiter policy |
escrow_info | free | The full-escrow product (1% on release) |
behavioural_test_info | free | How to run the adversarial scam/recipient tests safely |
score_wallet | $0.10 | Deterministic 0–100 risk score, tier A–F, itemized evidence |
score_batch | $0.50 | Up to 25 wallets per payment |
certify | $0.25/$0.75 | Certify this wallet's x402 client → public cert + README badge |
arbiter_verify | $0.25/$0.60 | Signed release/refund/escalate delivery verdict any escrow can execute |
{
"mcpServers": {
"402coffee": {
"command": "npx",
"args": ["-y", "402coffee-mcp"],
"env": { "PAYER_PRIVATE_KEY": "0x…" }
}
}
}
PAYER_PRIVATE_KEY is optional — free tools work without it. To enable the paid tools, use a throwaway wallet holding a little USDC on Base (gasless EIP-3009 — no ETH needed). Signing is local and non-custodial; the key never leaves the process, and the server only ever pays api.402.coffee.
behavioural_test_info explains the correct flow./.well-known/jwks.json) before being returned.MIT · docs · integrations · examples
FAQs
MCP server for 402.coffee — the trust layer for agent payments (x402 on Base). Free tools: verify any agent's credential (with offline Ed25519 signature check), browse the conformance menu, read the arbiter policy. Paid tools (x402 USDC, non-custodial loc
The npm package 402coffee-mcp receives a total of 63 weekly downloads. As such, 402coffee-mcp popularity was classified as not popular.
We found that 402coffee-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.