
Security News
White House Authorizes Private Companies to Conduct Offensive Cyber Operations
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.
@marupelkar/vaaya-mcp
Advanced tools
Stdio MCP server for [Vaaya](https://vaaya.ai), the agent payment system. Lets an MCP client (Codex CLI, opencode, or any other stdio MCP host) call paid APIs through Vaaya's proxy endpoints on the user's behalf — the agent never sees upstream URLs or API
Stdio MCP server for Vaaya, the agent payment system. Lets an MCP client (Codex CLI, opencode, or any other stdio MCP host) call paid APIs through Vaaya's proxy endpoints on the user's behalf — the agent never sees upstream URLs or API keys.
// mcp.json
{ "mcpServers": { "vaaya": { "command": "npx", "args": ["-y", "@marupelkar/vaaya-mcp"] } } }
On the first tool call the shim opens a browser tab pointed at Vaaya's
OAuth authorize endpoint. After you approve, a refresh token is written to
${env-paths.config}/vaaya/credentials with 0o600 mode and reused across
sessions.
| Env var | Default | Purpose |
|---|---|---|
VAAYA_BACKEND_URL | https://vaaya.ai | Backend origin (override for self-hosting / preview deploys). |
VAAYA_DEBUG | unset | Set to 1 to print the OAuth authorize URL to stderr. |
VAAYA_NON_INTERACTIVE | unset | Set to 1 to suppress the automatic browser open (you still get the URL on stderr). |
vaaya-mcp logout # forget local credentials
vaaya-mcp reauthorize # re-run the OAuth flow (e.g. to add scopes)
consult(message) — ask which registered service+action fits the task.use(service, action, params, max_cost_cents) — call a registered Vaaya service; bills the user's wallet on success.logout — same as the CLI command.reauthorize — same as the CLI command.The tool list is proxied from the backend, so new server-side tools appear without a shim upgrade.
Most vendors are pay-per-call on x402 (USDC on Base) or MPP (Stripe SPT
or Tempo chain) — the payment IS the auth. fal is on the REST rail
(Vaaya holds the key). Either way you supply no per-vendor API keys. Highlights:
fal / generate (REST — Nano Banana Pro 2, GPT Image 2, Seedream v4.5, Kling v3, Seedance 2.0)exa / search · contents, parallel / search · extract · taskfirecrawl / scrape · crawl · map · search · extract (MPP / Tempo)modal / sandbox-{create,status,terminate} (MPP / Tempo)browserbase / create_session · …agentmailThe shim ships the full agent skill alongside the binary — your client will
auto-load skills/vaaya/SKILL.md + the category files (compute.md,
web-search.md, web-scraping.md, etc.) which document params, prices, and
gotchas per action.
When Claude Code is detected, the installer also wires two always-on triggers
(both idempotent, both respect --dry-run):
~/.claude/CLAUDE.md (<!-- vaaya:begin -->
… <!-- vaaya:end --> — content outside the markers is never touched), andUserPromptSubmit hook in ~/.claude/settings.json that injects a
one-line reminder that Vaaya exists for any capability gap.Visit /connected-apps
on Vaaya, find the connection, and click Disconnect. The next time
the agent makes a request, the shim re-enters the OAuth flow.
FAQs
Stdio MCP server for [Vaaya](https://vaaya.ai), the agent payment system. Lets an MCP client (Codex CLI, opencode, or any other stdio MCP host) call paid APIs through Vaaya's proxy endpoints on the user's behalf — the agent never sees upstream URLs or API
The npm package @marupelkar/vaaya-mcp receives a total of 30 weekly downloads. As such, @marupelkar/vaaya-mcp popularity was classified as not popular.
We found that @marupelkar/vaaya-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.