
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
recapfy-mcp
Advanced tools
MCP server that exposes Recapfy's x402 endpoints (ask about a YouTube video, get its transcript) as tools. Each user runs it locally with their own Solana wallet and pays per call.
An MCP server that exposes Recapfy's paid endpoints as tools — ask anything about a YouTube video and fetch a video's full transcript — straight from an MCP-capable agent like Claude Desktop, Cursor, or Cline. It runs locally — there's no hosted Recapfy MCP endpoint; you launch your own copy.
Each call is paid in USDC on Solana (dynamic price, scales with
maxOutputTokens), settled automatically via the x402
protocol. You bring your own wallet; you pay only for what you call.
📦 npm: recapfy-mcp
solana-keygen).⚠️ The key signs real payments. Use a dedicated low-balance wallet, never share it, and never commit it.
No clone or build needed. Add this to your MCP client config (Claude Desktop:
claude_desktop_config.json) and restart the client:
{
"mcpServers": {
"recapfy": {
"command": "npx",
"args": ["-y", "recapfy-mcp@latest"],
"env": {
"SVM_PRIVATE_KEY": "<your base58 Solana secret key>"
}
}
}
}
Always use
recapfy-mcp@latest. A barenpx -y recapfy-mcpreuses whatever is in npx's cache and never re-checks the registry, so you can stay pinned to an old build (and miss new tools) indefinitely. The@latesttag forces npx to resolve the newest published version on every launch.
New versions (including new tools/endpoints) are picked up automatically when two things happen, because of two independent caches:
recapfy-mcp@latest (as above) makes npx fetch
the newest published version each launch. Without @latest, npx serves the
cached copy and you stay on an old build.So after a release: keep @latest and restart your client. If a brand-new
tool still doesn't show up, force a clean fetch:
npx clear-npx-cache # or: rm -rf "$(npm config get cache)/_npx"
then restart the client again.
| Variable | Required | Description |
|---|---|---|
SVM_PRIVATE_KEY | yes | Base58-encoded Solana secret key. Pays per call. Keep it funded. |
RECAPFY_API_BASE_URL | no | Override the API base URL (defaults to https://api.recapfy.ai). For local dev. |
RECAPFY_ALLOW_INSECURE_TLS | no | Set to 1 to accept self-signed TLS (local dev over https only). |
ask| Input | Type | Required | Description |
|---|---|---|---|
videoUrl | string | yes | Absolute http(s) URL of the YouTube video. |
prompt | string | yes | What to ask about the video. |
maxOutputTokens | integer | no | Max tokens in the answer (default 1024). Drives the dynamic price. |
Returns the agent's answer as text. Payment is settled before the answer returns.
The per-call price is dynamic: the API quotes the USDC amount in the 402
challenge based on maxOutputTokens, and your wallet pays whatever is quoted — so
keep maxOutputTokens sensible.
get_transcript| Input | Type | Required | Description |
|---|---|---|---|
videoUrl | string | yes | Absolute http(s) URL of the YouTube video. |
Returns the video's full transcript as timestamped segments, plus its title,
channelName, and durationSeconds. The text content is a readable, timestamped
transcript; the structured content carries the raw transcript array (each
segment is { timestampInSeconds, text }). The per-call price is flat USDC,
quoted in the 402 challenge and paid automatically.
Built on the official Coinbase x402 v2 client packages (@x402/fetch,
@x402/svm, @x402/core) plus @solana/kit for signing:
${RECAPFY_API_BASE_URL}
(/api/v1/agents/ask or /api/v1/agents/get-transcript).402 with requirements in the PAYMENT-REQUIRED header
(exact SVM scheme, USDC, dynamic amount, and a facilitator feePayer that
sponsors the network fee).PAYMENT-SIGNATURE header.PAYMENT-RESPONSE
settlement header.Inspect the tools without spending anything using the MCP Inspector (it only signs a payment when you actually invoke a tool, so any key is fine just to browse):
SVM_PRIVATE_KEY=<key> npx @modelcontextprotocol/inspector npx -y recapfy-mcp@latest
Open the printed URL → Tools → ask / get_transcript. Invoking a tool with a funded wallet performs a real paid call; verify the spend on a Solana explorer.
| Symptom | Cause / fix |
|---|---|
Missing required environment variable ... | SVM_PRIVATE_KEY not set. |
SVM_PRIVATE_KEY is not valid base58 | Needs base58 of the 64-byte secret key. |
400 ... maxOutputTokens must be greater than 0 | Pass a positive maxOutputTokens (the tool defaults to 1024). |
400 ... prompt | prompt is required and non-empty. |
| New tool/endpoint missing after an update | Pin recapfy-mcp@latest, restart the client, then clear the npx cache (see Updating). |
| 402 loop / "Failed to create payment payload" | Wallet has no USDC on mainnet, or wrong network. Fund it. |
| TLS error against a local API over https | Set RECAPFY_ALLOW_INSECURE_TLS=1 (localhost dev only). |
MIT
FAQs
MCP server that exposes Recapfy's x402 endpoints (ask about a YouTube video, get its transcript) as tools. Each user runs it locally with their own Solana wallet and pays per call.
The npm package recapfy-mcp receives a total of 39 weekly downloads. As such, recapfy-mcp popularity was classified as not popular.
We found that recapfy-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.