Skip to main content
ClaudeWave

Payment firewall for AI agents: a signed, independently-verifiable verdict on every money-moving action. Non-custodial, local-first. npx @fidacy/mcp

MCP ServersRegistry oficial1 estrellas0 forksTypeScriptApache-2.0Actualizado 11d ago
Install in Claude Code / Claude Desktop
Method: NPX · @fidacy/mcp
Claude Code CLI
claude mcp add fidacy-mcp -- npx -y @fidacy/mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "fidacy-mcp": {
      "command": "npx",
      "args": ["-y", "@fidacy/mcp"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Casos de uso

Resumen de MCP Servers

# @fidacy/mcp

![Fidacy blocks a BEC lookalike-payee payment, then allows the legit one with a signed Ed25519 grant](assets/fidacy-firewall-demo.svg)

The action firewall for AI agents. A drop-in MCP server that gates payment
actions against a cryptographically signed mandate **before** money can move.
Non-custodial: Fidacy authorizes and proves, it never holds funds.

Install once, works in any MCP-compatible agent: Claude Code, Claude Desktop,
Hermes, OpenClaw, and anything else that speaks MCP.

[![npm](https://img.shields.io/npm/v/@fidacy/mcp)](https://www.npmjs.com/package/@fidacy/mcp)
[![license](https://img.shields.io/npm/l/@fidacy/mcp)](https://www.npmjs.com/package/@fidacy/mcp)
**Works with:** Claude Code · Claude Desktop · OpenClaw · Hermes · Brex CrabTrap

> **Your agent could be paying scammers right now.** Prompt-injected into the wrong
> payee, an inflated amount, or the same invoice twice — and your logs aren't
> evidence. Fidacy blocks it *before* money moves, and hands back a signed verdict
> **anyone can verify** against public keys. You don't trust us — you check the signature.

## Quick start (free, local-first, no account)

```json
{
  "mcpServers": {
    "fidacy": { "command": "npx", "args": ["-y", "@fidacy/mcp"] }
  }
}
```

Runs on your machine, offline, deny-by-default. Add trusted payees + caps in
`~/.fidacy/config.json`. Verify any verdict yourself against the public keys at
[`/.well-known/jwks.json`](https://api.fidacy.com/.well-known/jwks.json).

## Why

An agent can hallucinate or be prompt-injected into a payment: wrong payee,
wrong amount, fabricated invoice. Prompt-level guardrails are probabilistic and
bypassable. `@fidacy/mcp` is a deterministic gate between the agent's intent and
the executor: the action is dead on arrival unless it validates against a signed
mandate, and every decision lands in an immutable hash-chained audit trail.

## Enforcement model

1. Register `@fidacy/mcp` as the agent's **only** payment-capable tool. Do not
   give the agent a raw payment tool. Tool inventory is the runtime firewall.
2. The agent calls `request_payment`. Fidacy checks it against the mandate
   (payee allowlist, per-tx cap, total cap, currency, time window, revocation).
3. ALLOW returns a short-lived Ed25519 **grant**. DENY returns no grant and the
   violated rule. The downstream executor MUST require the grant, so a denied
   action cannot proceed.
4. Every decision is appended to a hash-chained log. `get_audit_proof` returns
   the portable, verifiable proof.

## One install, two backends

`@fidacy/mcp` ships two complementary capabilities in a single install:

- **Verdict layer (advisory)**: `assess_action` calls the live Fidacy engine and
  returns a **signed trust verdict**. It moves no money; it returns a judgment
  whose proof (`riskPayloadJws` + `signingKeyId`) is verifiable by anyone via
  `@fidacy/verify` against the engine JWKS at `/.well-known/jwks.json`.
- **Payment firewall (enforcement)**: `request_payment` / `verify_mandate` /
  `get_audit_proof` gate and prove a payment against a signed mandate through the
  core, returning short-lived Ed25519 grants.

Mental model: `assess_action` -> **engine** (signed verdict);
`request_payment` and friends -> **core** (payment firewall).

## Tools

| Tool | Backend | Purpose |
|---|---|---|
| `assess_action` | engine | Signed Fidacy trust verdict for a proposed action. Advisory. |
| `request_payment` | core | Authorize a payment action. ALLOW + grant, or DENY + rule. |
| `verify_mandate` | core | Read the mandate envelope + Fidacy public key. |
| `get_audit_proof` | core | Hash-chained proof for a decision id. |

### `assess_action`

Returns a signed Fidacy trust verdict from the live engine for a proposed
action. The signed proof is `riskPayloadJws` + `signingKeyId`, verifiable by
anyone via `@fidacy/verify` against `{engineUrl}/.well-known/jwks.json`.

Inputs:

- `kind` (optional, default `ap2_payment`): one of `ap2_payment`,
  `message_send`, `voice_call`, `custom`, `claim_document`.
- `mandate` (required): the action/mandate object for that `kind`.
- `mandateType`, `spendingMandate`, `idempotencyKey`, `a2a.task_id` (optional).

Environment:

| Var | Default | Purpose |
|---|---|---|
| `FIDACY_ENGINE_URL` | `https://api.fidacy.com` | Base URL of the Fidacy engine. |
| `FIDACY_ENGINE_API_KEY` | (none) | An `fky_live_` / `fky_test_` key with scope `assess:write`. |

The server boots without `FIDACY_ENGINE_API_KEY`; the tool is always registered.
Only **calling** `assess_action` without the key returns a helpful error telling
you to set it. The key is never logged, echoed, or attached to any error.

## Install

```bash
npm install -g @fidacy/mcp   # or run via npx, no install
```

### Claude Code

```bash
claude mcp add fidacy -- npx -y @fidacy/mcp
```

### Claude Desktop (`claude_desktop_config.json`)

```json
{
  "mcpServers": {
    "fidacy": { "command": "npx", "args": ["-y", "@fidacy/mcp"] }
  }
}
```

### Hermes (`config.yaml`)

```yaml
mcp_servers:
  fidacy:
    command: npx
    args: ["-y", "@fidacy/mcp"]
```

### OpenClaw

Add the same server via the Tools panel, or the `mcpServers` block in your
agent config. Any MCP-compatible host uses the same command.

## Wiring the real core (production)

The MCP layer talks to your core through one interface (`FidacyCore`). Your
repository stays private. Set `FIDACY_MODE=http` and implement three endpoints:

- `POST /v1/mandate/get` -> `Mandate`
- `POST /v1/decide` -> `Decision` (runs your Ed25519/AP2 verification + audit append)
- `POST /v1/audit/proof` -> `AuditProof`

No change to the MCP layer is needed.

## Dev

```bash
npm install
npm run build
npm start      # stdio server, in-memory demo mandate
```
ai-agentsbitcoined25519firewallmcpmcp-servermodel-context-protocolpaymentsprompt-injectionsecurity

Lo que la gente pregunta sobre fidacy-mcp

¿Qué es lucaslubi/fidacy-mcp?

+

lucaslubi/fidacy-mcp es mcp servers para el ecosistema de Claude AI. Payment firewall for AI agents: a signed, independently-verifiable verdict on every money-moving action. Non-custodial, local-first. npx @fidacy/mcp Tiene 1 estrellas en GitHub y se actualizó por última vez 11d ago.

¿Cómo se instala fidacy-mcp?

+

Puedes instalar fidacy-mcp clonando el repositorio (https://github.com/lucaslubi/fidacy-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar lucaslubi/fidacy-mcp?

+

lucaslubi/fidacy-mcp aún no ha sido auditado por nuestro agente de seguridad. Revisa el repositorio original en GitHub antes de usarlo en producción.

¿Quién mantiene lucaslubi/fidacy-mcp?

+

lucaslubi/fidacy-mcp es mantenido por lucaslubi. La última actividad registrada en GitHub es de 11d ago, con 0 issues abiertos.

¿Hay alternativas a fidacy-mcp?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega fidacy-mcp en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: lucaslubi/fidacy-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/lucaslubi-fidacy-mcp)](https://claudewave.com/repo/lucaslubi-fidacy-mcp)
<a href="https://claudewave.com/repo/lucaslubi-fidacy-mcp"><img src="https://claudewave.com/api/badge/lucaslubi-fidacy-mcp" alt="Featured on ClaudeWave: lucaslubi/fidacy-mcp" width="320" height="64" /></a>

Más MCP Servers

Alternativas a fidacy-mcp