Skip to main content
ClaudeWave

Payment firewall for AI agents: a signed, independently-verifiable verdict on every money-moving action. Non-custodial, local-first. npx @fidacy/mcp

MCP ServersOfficial Registry1 stars0 forksTypeScriptApache-2.0Updated 11d ago
Install in Claude Code / Claude Desktop
Method: NPX · @fidacy/mcp
Claude Code CLI
claude mcp add fidacy-mcp -- npx -y @fidacy/mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "fidacy-mcp": {
      "command": "npx",
      "args": ["-y", "@fidacy/mcp"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Use cases

MCP Servers overview

# @fidacy/mcp

![Fidacy blocks a BEC lookalike-payee payment, then allows the legit one with a signed Ed25519 grant](assets/fidacy-firewall-demo.svg)

The action firewall for AI agents. A drop-in MCP server that gates payment
actions against a cryptographically signed mandate **before** money can move.
Non-custodial: Fidacy authorizes and proves, it never holds funds.

Install once, works in any MCP-compatible agent: Claude Code, Claude Desktop,
Hermes, OpenClaw, and anything else that speaks MCP.

[![npm](https://img.shields.io/npm/v/@fidacy/mcp)](https://www.npmjs.com/package/@fidacy/mcp)
[![license](https://img.shields.io/npm/l/@fidacy/mcp)](https://www.npmjs.com/package/@fidacy/mcp)
**Works with:** Claude Code · Claude Desktop · OpenClaw · Hermes · Brex CrabTrap

> **Your agent could be paying scammers right now.** Prompt-injected into the wrong
> payee, an inflated amount, or the same invoice twice — and your logs aren't
> evidence. Fidacy blocks it *before* money moves, and hands back a signed verdict
> **anyone can verify** against public keys. You don't trust us — you check the signature.

## Quick start (free, local-first, no account)

```json
{
  "mcpServers": {
    "fidacy": { "command": "npx", "args": ["-y", "@fidacy/mcp"] }
  }
}
```

Runs on your machine, offline, deny-by-default. Add trusted payees + caps in
`~/.fidacy/config.json`. Verify any verdict yourself against the public keys at
[`/.well-known/jwks.json`](https://api.fidacy.com/.well-known/jwks.json).

## Why

An agent can hallucinate or be prompt-injected into a payment: wrong payee,
wrong amount, fabricated invoice. Prompt-level guardrails are probabilistic and
bypassable. `@fidacy/mcp` is a deterministic gate between the agent's intent and
the executor: the action is dead on arrival unless it validates against a signed
mandate, and every decision lands in an immutable hash-chained audit trail.

## Enforcement model

1. Register `@fidacy/mcp` as the agent's **only** payment-capable tool. Do not
   give the agent a raw payment tool. Tool inventory is the runtime firewall.
2. The agent calls `request_payment`. Fidacy checks it against the mandate
   (payee allowlist, per-tx cap, total cap, currency, time window, revocation).
3. ALLOW returns a short-lived Ed25519 **grant**. DENY returns no grant and the
   violated rule. The downstream executor MUST require the grant, so a denied
   action cannot proceed.
4. Every decision is appended to a hash-chained log. `get_audit_proof` returns
   the portable, verifiable proof.

## One install, two backends

`@fidacy/mcp` ships two complementary capabilities in a single install:

- **Verdict layer (advisory)**: `assess_action` calls the live Fidacy engine and
  returns a **signed trust verdict**. It moves no money; it returns a judgment
  whose proof (`riskPayloadJws` + `signingKeyId`) is verifiable by anyone via
  `@fidacy/verify` against the engine JWKS at `/.well-known/jwks.json`.
- **Payment firewall (enforcement)**: `request_payment` / `verify_mandate` /
  `get_audit_proof` gate and prove a payment against a signed mandate through the
  core, returning short-lived Ed25519 grants.

Mental model: `assess_action` -> **engine** (signed verdict);
`request_payment` and friends -> **core** (payment firewall).

## Tools

| Tool | Backend | Purpose |
|---|---|---|
| `assess_action` | engine | Signed Fidacy trust verdict for a proposed action. Advisory. |
| `request_payment` | core | Authorize a payment action. ALLOW + grant, or DENY + rule. |
| `verify_mandate` | core | Read the mandate envelope + Fidacy public key. |
| `get_audit_proof` | core | Hash-chained proof for a decision id. |

### `assess_action`

Returns a signed Fidacy trust verdict from the live engine for a proposed
action. The signed proof is `riskPayloadJws` + `signingKeyId`, verifiable by
anyone via `@fidacy/verify` against `{engineUrl}/.well-known/jwks.json`.

Inputs:

- `kind` (optional, default `ap2_payment`): one of `ap2_payment`,
  `message_send`, `voice_call`, `custom`, `claim_document`.
- `mandate` (required): the action/mandate object for that `kind`.
- `mandateType`, `spendingMandate`, `idempotencyKey`, `a2a.task_id` (optional).

Environment:

| Var | Default | Purpose |
|---|---|---|
| `FIDACY_ENGINE_URL` | `https://api.fidacy.com` | Base URL of the Fidacy engine. |
| `FIDACY_ENGINE_API_KEY` | (none) | An `fky_live_` / `fky_test_` key with scope `assess:write`. |

The server boots without `FIDACY_ENGINE_API_KEY`; the tool is always registered.
Only **calling** `assess_action` without the key returns a helpful error telling
you to set it. The key is never logged, echoed, or attached to any error.

## Install

```bash
npm install -g @fidacy/mcp   # or run via npx, no install
```

### Claude Code

```bash
claude mcp add fidacy -- npx -y @fidacy/mcp
```

### Claude Desktop (`claude_desktop_config.json`)

```json
{
  "mcpServers": {
    "fidacy": { "command": "npx", "args": ["-y", "@fidacy/mcp"] }
  }
}
```

### Hermes (`config.yaml`)

```yaml
mcp_servers:
  fidacy:
    command: npx
    args: ["-y", "@fidacy/mcp"]
```

### OpenClaw

Add the same server via the Tools panel, or the `mcpServers` block in your
agent config. Any MCP-compatible host uses the same command.

## Wiring the real core (production)

The MCP layer talks to your core through one interface (`FidacyCore`). Your
repository stays private. Set `FIDACY_MODE=http` and implement three endpoints:

- `POST /v1/mandate/get` -> `Mandate`
- `POST /v1/decide` -> `Decision` (runs your Ed25519/AP2 verification + audit append)
- `POST /v1/audit/proof` -> `AuditProof`

No change to the MCP layer is needed.

## Dev

```bash
npm install
npm run build
npm start      # stdio server, in-memory demo mandate
```
ai-agentsbitcoined25519firewallmcpmcp-servermodel-context-protocolpaymentsprompt-injectionsecurity

What people ask about fidacy-mcp

What is lucaslubi/fidacy-mcp?

+

lucaslubi/fidacy-mcp is mcp servers for the Claude AI ecosystem. Payment firewall for AI agents: a signed, independently-verifiable verdict on every money-moving action. Non-custodial, local-first. npx @fidacy/mcp It has 1 GitHub stars and was last updated 11d ago.

How do I install fidacy-mcp?

+

You can install fidacy-mcp by cloning the repository (https://github.com/lucaslubi/fidacy-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is lucaslubi/fidacy-mcp safe to use?

+

lucaslubi/fidacy-mcp has not been audited yet by our security agent. Review the original repository on GitHub before using it in production.

Who maintains lucaslubi/fidacy-mcp?

+

lucaslubi/fidacy-mcp is maintained by lucaslubi. The last recorded GitHub activity is from 11d ago, with 0 open issues.

Are there alternatives to fidacy-mcp?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy fidacy-mcp to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: lucaslubi/fidacy-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/lucaslubi-fidacy-mcp)](https://claudewave.com/repo/lucaslubi-fidacy-mcp)
<a href="https://claudewave.com/repo/lucaslubi-fidacy-mcp"><img src="https://claudewave.com/api/badge/lucaslubi-fidacy-mcp" alt="Featured on ClaudeWave: lucaslubi/fidacy-mcp" width="320" height="64" /></a>

More MCP Servers

fidacy-mcp alternatives