
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@arispay/payagent-mcp
Advanced tools
MCP server that gives AI agents a wallet: pay x402 APIs (USD + EUR), check balances, self-onboard with one tool call. Use with Claude, Cursor, or any MCP client — delegated custody, no private keys on the agent.
MCP server for ArisPay-delegated x402 USDC payments. Lets AI agents call paid APIs and settle HTTP 402 challenges with USDC on Base — no private keys ever live in this process.
Works with Claude Desktop, Cursor, Windsurf, or any MCP client. A thin wrapper around the payagent SDK.
ARISPAY_AGENT_KEY (returned exactly once — store it securely)Edit ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"arispay": {
"command": "npx",
"args": ["-y", "@arispay/payagent-mcp"],
"env": {
"ARISPAY_AGENT_KEY": "ap_live_...",
"PAYAGENT_WALLET": "0x..."
}
}
}
}
Edit .cursor/mcp.json in your project:
{
"mcpServers": {
"arispay": {
"command": "npx",
"args": ["-y", "@arispay/payagent-mcp"],
"env": {
"ARISPAY_AGENT_KEY": "ap_live_...",
"PAYAGENT_WALLET": "0x..."
}
}
}
}
Edit ~/.codeium/windsurf/mcp_config.json with the same pattern.
| Variable | Required | Default | Description |
|---|---|---|---|
ARISPAY_AGENT_KEY | Yes | — | Agent-scoped API key from payagent.arispay.app |
ARISPAY_URL | No | https://api.arispay.app | ArisPay API base URL |
PAYAGENT_WALLET | No | — | Wallet address (for check_wallet tool output) |
pay_apiMake an HTTP request to a paid API. Automatically handles HTTP 402 payment challenges via ArisPay-delegated signing.
Parameters:
url (string, required) — The API endpoint URLmethod (string, default: "GET") — HTTP methodheaders (object, optional) — Additional HTTP headersbody (string, optional) — Request bodySpend caps (maxPerTx, maxDaily, maxMonthly, allowedDomains) are set on the agent at provisioning time and enforced server-side by ArisPay. There is no client-side budget parameter — attempts that exceed the delegation return a PaymentRejectedError.
Example prompt: "Use pay_api to fetch https://api.example.com/premium-data"
check_walletReport the configured agent, and — if PAYAGENT_WALLET is set — the on-chain USDC balance on Base.
Parameters: None
Example prompt: "Check my agent wallet"
Full delegation limits and spend history live at payagent.arispay.app.
pay_api with a URL.payagent asks ArisPay to sign via CDP.payagent retries with the signed X-PAYMENT header; the seller's facilitator settles on-chain.No private key lives in this process. The signing key is held by Coinbase CDP; ArisPay enforces limits before signing. If a payment breaches the delegation, it's rejected before any on-chain action.
npm install @arispay/payagent-mcp
Or invoke directly via npx @arispay/payagent-mcp from an MCP client config — no pre-install required.
MIT
FAQs
MCP server that gives AI agents a wallet: pay x402 APIs (USD + EUR), check balances, self-onboard with one tool call. Use with Claude, Cursor, or any MCP client — delegated custody, no private keys on the agent.
The npm package @arispay/payagent-mcp receives a total of 310 weekly downloads. As such, @arispay/payagent-mcp popularity was classified as not popular.
We found that @arispay/payagent-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.