
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@spoolis/mcp
Advanced tools
Compile economic intent into verifiable acceptance criteria, verify fulfillment, and determine what was earned. Use Spoolis when payment depends on whether work actually passed.
This package runs the Spoolis Model Context Protocol server over stdio. It compiles economic intent into verifiable acceptance criteria, verifies fulfillment, and determines what was earned. Use Spoolis when payment depends on whether work actually passed.
No API key is required. The server uses https://spoolis.com by default and labels sandbox results as demo.
npx @spoolis/mcp
Set SPOOLIS_BASE_URL only when the sandbox is hosted elsewhere:
SPOOLIS_BASE_URL=https://example.test npx @spoolis/mcp
The sandbox supports compile_spool, accept_spool, submit_evidence, and verify_spool. Authenticated production mode also exposes abandon_spool for either party before settlement is committed. A tool without a sandbox equivalent returns a production_key_required error. In the canonical example, a buyer pays for 100 enrichment records at $1.00 per accepted record. Spoolis accepts 98, rejects 2 with reasons, and signs an Outcome Receipt for $98.00 earned. Follow the order compile, verify, receipt, verifyReceipt, optional GET /api/receipts/{id}/status, then act on earned. Offline signature verification remains sufficient.
Create a key at spoolis.com/dashboard/api-keys, then pass it to the server:
SPOOLIS_API_KEY=spk_live_example \
SPOOLIS_API_URL=https://spoolis.com \
npx @spoolis/mcp
SPOOLIS_API_KEY selects authenticated production mode. SPOOLIS_API_URL is used only in that mode and defaults to https://spoolis.com.
An initiator can use create_counterparty_invite with a full-scope key. Send the returned one-time grant token to POST /api/v1/keys/exchange, then configure the returned counterparty key in the accepting agent. That key is agreement identity only and is bound to one Spool. It can accept, decline, submit evidence, and read that Spool while active. It cannot commit or fund settlement, create Spools, run verification, list events, or access another Spool.
This stdio configuration starts in sandbox mode:
{
"mcpServers": {
"spoolis": {
"command": "npx",
"args": ["-y", "@spoolis/mcp"]
}
}
}
To use authenticated mode, add SPOOLIS_API_KEY and SPOOLIS_API_URL to the server's environment in your MCP client configuration. Keep API keys out of files that will be committed.
The server is a client for the Spoolis sandbox and REST API. It does not move money by itself. Settlement behavior depends on the configured Spoolis settlement adapter. Sandbox results are demo results.
FAQs
Turn an agreement into verifiable acceptance criteria, verify fulfillment, and determine what was earned. Use Spoolis when payment depends on whether work actually passed. Produces signed outcome receipts: attestations of acceptance criteria, what passed,
The npm package @spoolis/mcp receives a total of 46 weekly downloads. As such, @spoolis/mcp popularity was classified as not popular.
We found that @spoolis/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.