Shinjuku Shielded MCP: the private x402 facilitator, inside your agent. Shield, pay, and unshield USDC on Solana. Self-custody, Tor built in.
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
- !No standard license detected
- !Install pipes a remote script into a shell (curl | sh)
claude mcp add shinjuku-mcp -- npx -y shinjuku-shielded{
"mcpServers": {
"shinjuku-mcp": {
"command": "npx",
"args": ["-y", "shinjuku-shielded"]
}
}
}Resumen de MCP Servers
<p align="center"><img src="assets/banner.png" alt="Shinjuku Shielded MCP: the private x402 facilitator, inside your agent" width="100%"></p>
<p align="center">
<img alt="Solana mainnet" src="https://img.shields.io/badge/Solana-mainnet-D22B23?style=flat-square&labelColor=0C0707">
<img alt="x402 facilitator" src="https://img.shields.io/badge/x402-private%20facilitator-D22B23?style=flat-square&labelColor=0C0707">
<img alt="MCP" src="https://img.shields.io/badge/MCP-stdio-DEB868?style=flat-square&labelColor=0C0707">
<img alt="Self-custody" src="https://img.shields.io/badge/keys-self--custody-DEB868?style=flat-square&labelColor=0C0707">
<img alt="Tor" src="https://img.shields.io/badge/Tor-built%20in-ECE6DA?style=flat-square&labelColor=0C0707">
</p>
# Shinjuku Shielded MCP
The private x402 facilitator, inside your agent.
Shinjuku Shielded settles x402 payments from a shielded USDC balance on
Solana: on chain, a shielded payment does not show who paid. This MCP server
is how your agent uses it. It runs on your machine, under caps that only you
set.
- **Self-custody.** The server runs on your machine. Your keys never leave
it. We never run it, and we never hold your money.
- **Shielded payments.** Your agent pays from a shielded balance. Add `--tor`
and no server sees your IP.
- **One command to set up.** `npx -y shinjuku-shielded mcp` offers the
setup on a machine with no wallet. It makes the wallet, a private
passphrase file, and the checked proof tools.
- **Caps that only you set.** Setup records them (default: 0.05 USDC per
payment, 1 USDC per session). A tool call can only lower them, never raise
them.
- **Find sellers.** `x402_discover` searches public x402 listings
(Coinbase x402 Bazaar, PayAI, Dexter, and others) on your machine.
- **Look before you pay.** `x402_preview` shows the price and whether your
caps allow it. It pays nothing.
- **No SOL.** `wallet_shield` needs only USDC. Our facilitator's relayer
pays the network fee.
- **Never twice.** A retry with the same `request_id` resumes the same
payment, deposit, or unshield. It never starts a second one.
- **No RPC, no account, no API key.** Reads go through our relay by default.
Your own RPC always wins if you give one.
Every Shinjuku Shielded service joins this MCP as it ships.
The server is the `mcp` command of `shinjuku-wallet`, one file. This
repository holds the setup guide and [examples](examples/). The wallet file, its SHA-256, and its
release history are in
[ShinjukuStaition/shinjuku-shielded](https://github.com/ShinjukuStaition/shinjuku-shielded).
## Talk to it in plain words
Ask your agent the way you would ask a person:
| You say | Your agent calls |
|---|---|
| "what is my balance" | `wallet_balance` |
| "shield 5 USDC" | `wallet_shield` |
| "find a seller of satellite images" | `x402_discover` |
| "pay this URL" | `x402_preview`, then `x402_pay` |
| "send 2 USDC privately to <address>" | `wallet_unshield` |
Each answer tells the agent the exact next call. The wallet reads the chain
and writes an encrypted backup by itself, so you never run a command for
upkeep.
## Tools
### SETUP
On a machine with no wallet, the server starts in setup mode.
| Tool | What it does |
|---|---|
| `shinjuku_setup` | Asks you to confirm in your MCP client that it may create a Shinjuku Shielded wallet on this machine, and shows the caps. Then it runs the setup and switches the same server to the wallet tools. It never asks for a secret. A client that cannot ask is told to run `npx -y shinjuku-shielded setup` in a terminal. |
| `wallet_status` | Says whether the wallet is set up, and what to do next. |
In setup mode, every money tool answers `wallet_not_set_up` and does
nothing.
### SHIELD
| Tool | What it does |
|---|---|
| `wallet_shield` | Moves USDC from the wallet's own Solana key into your shielded balance. It is on with `--proof-tools`. `--no-shield` turns it off. Funding takes minutes: the first call starts it and returns a stage. Call again with the same `request_id` to see the stage. It never starts a second deposit. When the deposit lands, the wallet reads it from the chain and writes an encrypted backup. The wallet's own key needs the USDC and no SOL: our facilitator's relayer pays the network fee, and you pay the shield cost. |
### PAY
| Tool | What it does |
|---|---|
| `x402_discover` | Searches public x402 listings (Coinbase x402 Bazaar, PayAI, Dexter, and others) on your machine and returns the sellers that match. Pays nothing. The first call takes about 15 s. |
| `x402_preview` | One unpaid request. Returns the seller's price, the scheme, and whether your caps allow it. Pays nothing. A seller that lists several networks is priced from its Solana offer. |
| `x402_pay` | Pays the URL (if it asks for payment) and returns the answer. A URL that does not answer 402 is fetched once and nothing is paid. An image answer (image bytes, or JSON `image_base64`) comes back as an MCP image block, and the file is saved. A payment that landed, from a seller that gives no answer, closes as paid. Alias: `fetch_paid`. |
### UNSHIELD
| Tool | What it does |
|---|---|
| `wallet_unshield` | Sends shielded USDC to a public Solana address. It is on with `--exit-proof-tools` and `--profile`. Our facilitator pays every network fee. The same `request_id` never unshields twice. An address that you named with `--unshield-to` is sent at once. Any other address is sent only after you confirm it in your MCP client: "Send X USDC from your shielded balance to <address>?". A decline, or no answer in 5 minutes, sends nothing. A client that cannot ask is refused, so a prompt injection cannot pick an address by itself. The wallet's own key is refused: it made the deposits, so an exit there would link them. |
### ACCOUNT
| Tool | What it does |
|---|---|
| `wallet_balance` | SHIELDED (what your agent can pay with) and UNSHIELDED (plain USDC on the wallet's own Solana key), each on its own line, plus pockets, unfinished payments, and what this session may still pay. A stale balance is read from the chain first. UNSHIELDED is one network read; if it fails, that line is empty and says why. |
| `wallet_receipts` | Your most recent paid receipts: host (never the full URL), amount, transaction, time. |
Also: `wallet_cancel` closes one unfinished payment, so its reserved balance
comes back.
`wallet_shield` and `wallet_unshield` always appear in the tool list. When
one is off, it answers `"error": "mcp_tool_disabled"` and tells the agent
what to ask you.
What it pays: x402 scheme `shielded-exact` from your shielded balance, and
standard Solana `exact` from a ready pocket. A ready pocket pays any Solana
x402 `exact` seller, whichever facilitator settles it. Pockets are automatic:
when a standard `exact` seller needs one, `x402_pay` fills a 1 USDC pocket
from your shielded balance. `--ready-pockets` sets how many stay ready, and
`--no-auto-pockets` turns this off. A seller receipt that names another
payer is checked on chain. For sellers that
offer only `confidential` (hidden amounts), use `shinjuku-wallet laneb pay-url`.
## Privacy modes
| | Default | `--tor` |
|---|---|---|
| On chain | A shielded payment does not show who paid. | The same. |
| Your IP | Payments go to `pay.shinjukustaition.com`, with no CDN in the path. Our server sees your IP. It keeps no access logs. | Hidden from everyone, us included. |
| The seller | Sees your IP. | Does not see your IP. |
| Speed | Faster. | About 1-2 s slower per request. |
| Needs | Nothing extra. | Tor with `HTTPTunnelPort 127.0.0.1:9080 IsolateDestAddr` in `torrc`. |
## Setup
You need Node.js 22 or later, on Linux, or on Windows with WSL. macOS is not
supported: the provers are Linux programs. The current wallet release is
`d2a7291f` (npm `shinjuku-shielded@0.3.2`).
Update from 0.2.0. The pool program was upgraded on 2026-10-08. Setup from
npm 0.2.0 pins the program from before the upgrade, so it now refuses
production. 0.3.2 pins the new program.
### 1. Add the server to your agent
Claude Code:
```sh
claude mcp add --scope user shinjuku-shielded -- npx -y shinjuku-shielded mcp
```
Claude Desktop (`claude_desktop_config.json`), Cursor (`~/.cursor/mcp.json`),
and other JSON-config hosts:
```json
{
"mcpServers": {
"shinjuku-shielded": {
"command": "npx",
"args": ["-y", "shinjuku-shielded", "mcp"]
}
}
}
```
### 2. Start it and accept the setup
The first time, the server has no wallet, so it starts in setup mode. Ask
your agent "what is my balance". Your MCP client asks you to confirm: create
a Shinjuku Shielded wallet on this machine. Accept, and the setup runs (about
25 s in our test, with the proof-tool download of about 150 MB). Then the
same server switches to the wallet tools. You do not restart it.
In a terminal, `npx -y shinjuku-shielded mcp` asks
"Set up Shinjuku Shielded now? (y/n)". Or run the setup by itself:
```sh
npx -y shinjuku-shielded setup
```
It asks for the caps (Enter keeps the default) and Tor. `--yes` asks
nothing. `--add-to claude-code` (or `claude-desktop`, `cursor`) also adds
the server to that host's config.
Setup writes to `~/.carbon-shielded-wallet` (or `SHIELDED_WALLET_HOME`):
- The wallet, and a recovery file with the seed and the key. Copy the
recovery file to two offline places, then delete it from this machine.
- `passphrase.txt`: a new random passphrase, readable by you alone. It is
never printed, and no tool takes or returns it.
- The proof tools. Setup checks every file against the set that this wallet
release pins.
- `config.json`: the caps, the paths, and Tor. With it, `mcp` needs no
flags. A flag on the command line still wins.
Default caps: 0.05 USDC per payment, 1 USDC per session, and 20 USDC for the
life of the wallet (`--max-payment`, `--max-session`, `--max-total`, in
atomic USDC: `50000` = 0.05 USDC). `--prefer-tor` records Tor (see Privacy
modes).
You can run `setup` again at any time. It never changes an exiLo que la gente pregunta sobre shinjuku-mcp
¿Qué es ShinjukuStaition/shinjuku-mcp?
+
ShinjukuStaition/shinjuku-mcp es mcp servers para el ecosistema de Claude AI. Shinjuku Shielded MCP: the private x402 facilitator, inside your agent. Shield, pay, and unshield USDC on Solana. Self-custody, Tor built in. Tiene 2 estrellas en GitHub y su última actualización registrada es del 2026-10-08.
¿Cómo se instala shinjuku-mcp?
+
Puedes instalar shinjuku-mcp clonando el repositorio (https://github.com/ShinjukuStaition/shinjuku-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar ShinjukuStaition/shinjuku-mcp?
+
Nuestro agente de seguridad ha analizado ShinjukuStaition/shinjuku-mcp y le ha asignado un Trust Score de 62/100 (tier: OK). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene ShinjukuStaition/shinjuku-mcp?
+
ShinjukuStaition/shinjuku-mcp es mantenido por ShinjukuStaition. La última actividad registrada en GitHub es del 2026-10-08, con 0 issues abiertos.
¿Hay alternativas a shinjuku-mcp?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega shinjuku-mcp en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/shinjukustaition-shinjuku-mcp)<a href="https://claudewave.com/repo/shinjukustaition-shinjuku-mcp"><img src="https://claudewave.com/api/badge/shinjukustaition-shinjuku-mcp" alt="Featured on ClaudeWave: ShinjukuStaition/shinjuku-mcp" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.