Skip to main content
ClaudeWave

Shinjuku Shielded MCP: the private x402 facilitator, inside your agent. Shield, pay, and unshield USDC on Solana. Self-custody, Tor built in.

MCP ServersOfficial Registry2 stars0 forksUpdated today
ClaudeWave Trust Score
62/100
· OK
Passed
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !No standard license detected
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 10/9/2026
Install in Claude Code / Claude Desktop
Method: NPX · shinjuku-shielded
Claude Code CLI
claude mcp add shinjuku-mcp -- npx -y shinjuku-shielded
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "shinjuku-mcp": {
      "command": "npx",
      "args": ["-y", "shinjuku-shielded"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Use cases

MCP Servers overview

<p align="center"><img src="assets/banner.png" alt="Shinjuku Shielded MCP: the private x402 facilitator, inside your agent" width="100%"></p>

<p align="center">
<img alt="Solana mainnet" src="https://img.shields.io/badge/Solana-mainnet-D22B23?style=flat-square&labelColor=0C0707">
<img alt="x402 facilitator" src="https://img.shields.io/badge/x402-private%20facilitator-D22B23?style=flat-square&labelColor=0C0707">
<img alt="MCP" src="https://img.shields.io/badge/MCP-stdio-DEB868?style=flat-square&labelColor=0C0707">
<img alt="Self-custody" src="https://img.shields.io/badge/keys-self--custody-DEB868?style=flat-square&labelColor=0C0707">
<img alt="Tor" src="https://img.shields.io/badge/Tor-built%20in-ECE6DA?style=flat-square&labelColor=0C0707">
</p>

# Shinjuku Shielded MCP

The private x402 facilitator, inside your agent.

Shinjuku Shielded settles x402 payments from a shielded USDC balance on
Solana: on chain, a shielded payment does not show who paid. This MCP server
is how your agent uses it. It runs on your machine, under caps that only you
set.

- **Self-custody.** The server runs on your machine. Your keys never leave
  it. We never run it, and we never hold your money.
- **Shielded payments.** Your agent pays from a shielded balance. Add `--tor`
  and no server sees your IP.
- **One command to set up.** `npx -y shinjuku-shielded mcp` offers the
  setup on a machine with no wallet. It makes the wallet, a private
  passphrase file, and the checked proof tools.
- **Caps that only you set.** Setup records them (default: 0.05 USDC per
  payment, 1 USDC per session). A tool call can only lower them, never raise
  them.
- **Find sellers.** `x402_discover` searches public x402 listings
  (Coinbase x402 Bazaar, PayAI, Dexter, and others) on your machine.
- **Look before you pay.** `x402_preview` shows the price and whether your
  caps allow it. It pays nothing.
- **No SOL.** `wallet_shield` needs only USDC. Our facilitator's relayer
  pays the network fee.
- **Never twice.** A retry with the same `request_id` resumes the same
  payment, deposit, or unshield. It never starts a second one.
- **No RPC, no account, no API key.** Reads go through our relay by default.
  Your own RPC always wins if you give one.

Every Shinjuku Shielded service joins this MCP as it ships.

The server is the `mcp` command of `shinjuku-wallet`, one file. This
repository holds the setup guide and [examples](examples/). The wallet file, its SHA-256, and its
release history are in
[ShinjukuStaition/shinjuku-shielded](https://github.com/ShinjukuStaition/shinjuku-shielded).

## Talk to it in plain words

Ask your agent the way you would ask a person:

| You say | Your agent calls |
|---|---|
| "what is my balance" | `wallet_balance` |
| "shield 5 USDC" | `wallet_shield` |
| "find a seller of satellite images" | `x402_discover` |
| "pay this URL" | `x402_preview`, then `x402_pay` |
| "send 2 USDC privately to <address>" | `wallet_unshield` |

Each answer tells the agent the exact next call. The wallet reads the chain
and writes an encrypted backup by itself, so you never run a command for
upkeep.

## Tools

### SETUP

On a machine with no wallet, the server starts in setup mode.

| Tool | What it does |
|---|---|
| `shinjuku_setup` | Asks you to confirm in your MCP client that it may create a Shinjuku Shielded wallet on this machine, and shows the caps. Then it runs the setup and switches the same server to the wallet tools. It never asks for a secret. A client that cannot ask is told to run `npx -y shinjuku-shielded setup` in a terminal. |
| `wallet_status` | Says whether the wallet is set up, and what to do next. |

In setup mode, every money tool answers `wallet_not_set_up` and does
nothing.

### SHIELD

| Tool | What it does |
|---|---|
| `wallet_shield` | Moves USDC from the wallet's own Solana key into your shielded balance. It is on with `--proof-tools`. `--no-shield` turns it off. Funding takes minutes: the first call starts it and returns a stage. Call again with the same `request_id` to see the stage. It never starts a second deposit. When the deposit lands, the wallet reads it from the chain and writes an encrypted backup. The wallet's own key needs the USDC and no SOL: our facilitator's relayer pays the network fee, and you pay the shield cost. |

### PAY

| Tool | What it does |
|---|---|
| `x402_discover` | Searches public x402 listings (Coinbase x402 Bazaar, PayAI, Dexter, and others) on your machine and returns the sellers that match. Pays nothing. The first call takes about 15 s. |
| `x402_preview` | One unpaid request. Returns the seller's price, the scheme, and whether your caps allow it. Pays nothing. A seller that lists several networks is priced from its Solana offer. |
| `x402_pay` | Pays the URL (if it asks for payment) and returns the answer. A URL that does not answer 402 is fetched once and nothing is paid. An image answer (image bytes, or JSON `image_base64`) comes back as an MCP image block, and the file is saved. A payment that landed, from a seller that gives no answer, closes as paid. Alias: `fetch_paid`. |

### UNSHIELD

| Tool | What it does |
|---|---|
| `wallet_unshield` | Sends shielded USDC to a public Solana address. It is on with `--exit-proof-tools` and `--profile`. Our facilitator pays every network fee. The same `request_id` never unshields twice. An address that you named with `--unshield-to` is sent at once. Any other address is sent only after you confirm it in your MCP client: "Send X USDC from your shielded balance to <address>?". A decline, or no answer in 5 minutes, sends nothing. A client that cannot ask is refused, so a prompt injection cannot pick an address by itself. The wallet's own key is refused: it made the deposits, so an exit there would link them. |

### ACCOUNT

| Tool | What it does |
|---|---|
| `wallet_balance` | SHIELDED (what your agent can pay with) and UNSHIELDED (plain USDC on the wallet's own Solana key), each on its own line, plus pockets, unfinished payments, and what this session may still pay. A stale balance is read from the chain first. UNSHIELDED is one network read; if it fails, that line is empty and says why. |
| `wallet_receipts` | Your most recent paid receipts: host (never the full URL), amount, transaction, time. |

Also: `wallet_cancel` closes one unfinished payment, so its reserved balance
comes back.

`wallet_shield` and `wallet_unshield` always appear in the tool list. When
one is off, it answers `"error": "mcp_tool_disabled"` and tells the agent
what to ask you.

What it pays: x402 scheme `shielded-exact` from your shielded balance, and
standard Solana `exact` from a ready pocket. A ready pocket pays any Solana
x402 `exact` seller, whichever facilitator settles it. Pockets are automatic:
when a standard `exact` seller needs one, `x402_pay` fills a 1 USDC pocket
from your shielded balance. `--ready-pockets` sets how many stay ready, and
`--no-auto-pockets` turns this off. A seller receipt that names another
payer is checked on chain. For sellers that
offer only `confidential` (hidden amounts), use `shinjuku-wallet laneb pay-url`.

## Privacy modes

| | Default | `--tor` |
|---|---|---|
| On chain | A shielded payment does not show who paid. | The same. |
| Your IP | Payments go to `pay.shinjukustaition.com`, with no CDN in the path. Our server sees your IP. It keeps no access logs. | Hidden from everyone, us included. |
| The seller | Sees your IP. | Does not see your IP. |
| Speed | Faster. | About 1-2 s slower per request. |
| Needs | Nothing extra. | Tor with `HTTPTunnelPort 127.0.0.1:9080 IsolateDestAddr` in `torrc`. |

## Setup

You need Node.js 22 or later, on Linux, or on Windows with WSL. macOS is not
supported: the provers are Linux programs. The current wallet release is
`d2a7291f` (npm `shinjuku-shielded@0.3.2`).

Update from 0.2.0. The pool program was upgraded on 2026-10-08. Setup from
npm 0.2.0 pins the program from before the upgrade, so it now refuses
production. 0.3.2 pins the new program.

### 1. Add the server to your agent

Claude Code:

```sh
claude mcp add --scope user shinjuku-shielded -- npx -y shinjuku-shielded mcp
```

Claude Desktop (`claude_desktop_config.json`), Cursor (`~/.cursor/mcp.json`),
and other JSON-config hosts:

```json
{
  "mcpServers": {
    "shinjuku-shielded": {
      "command": "npx",
      "args": ["-y", "shinjuku-shielded", "mcp"]
    }
  }
}
```

### 2. Start it and accept the setup

The first time, the server has no wallet, so it starts in setup mode. Ask
your agent "what is my balance". Your MCP client asks you to confirm: create
a Shinjuku Shielded wallet on this machine. Accept, and the setup runs (about
25 s in our test, with the proof-tool download of about 150 MB). Then the
same server switches to the wallet tools. You do not restart it.

In a terminal, `npx -y shinjuku-shielded mcp` asks
"Set up Shinjuku Shielded now? (y/n)". Or run the setup by itself:

```sh
npx -y shinjuku-shielded setup
```

It asks for the caps (Enter keeps the default) and Tor. `--yes` asks
nothing. `--add-to claude-code` (or `claude-desktop`, `cursor`) also adds
the server to that host's config.

Setup writes to `~/.carbon-shielded-wallet` (or `SHIELDED_WALLET_HOME`):

- The wallet, and a recovery file with the seed and the key. Copy the
  recovery file to two offline places, then delete it from this machine.
- `passphrase.txt`: a new random passphrase, readable by you alone. It is
  never printed, and no tool takes or returns it.
- The proof tools. Setup checks every file against the set that this wallet
  release pins.
- `config.json`: the caps, the paths, and Tor. With it, `mcp` needs no
  flags. A flag on the command line still wins.

Default caps: 0.05 USDC per payment, 1 USDC per session, and 20 USDC for the
life of the wallet (`--max-payment`, `--max-session`, `--max-total`, in
atomic USDC: `50000` = 0.05 USDC). `--prefer-tor` records Tor (see Privacy
modes).

You can run `setup` again at any time. It never changes an exi
ai-agentsmcpmodel-context-protocolprivacysolanax402

What people ask about shinjuku-mcp

What is ShinjukuStaition/shinjuku-mcp?

+

ShinjukuStaition/shinjuku-mcp is mcp servers for the Claude AI ecosystem. Shinjuku Shielded MCP: the private x402 facilitator, inside your agent. Shield, pay, and unshield USDC on Solana. Self-custody, Tor built in. It has 2 GitHub stars and its last recorded update is dated 2026-10-08.

How do I install shinjuku-mcp?

+

You can install shinjuku-mcp by cloning the repository (https://github.com/ShinjukuStaition/shinjuku-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is ShinjukuStaition/shinjuku-mcp safe to use?

+

Our security agent has analyzed ShinjukuStaition/shinjuku-mcp and assigned a Trust Score of 62/100 (tier: OK). See the full breakdown of passed checks and flags on this page.

Who maintains ShinjukuStaition/shinjuku-mcp?

+

ShinjukuStaition/shinjuku-mcp is maintained by ShinjukuStaition. The last recorded GitHub activity is dated 2026-10-08, with 0 open issues.

Are there alternatives to shinjuku-mcp?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy shinjuku-mcp to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: ShinjukuStaition/shinjuku-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/shinjukustaition-shinjuku-mcp)](https://claudewave.com/repo/shinjukustaition-shinjuku-mcp)
<a href="https://claudewave.com/repo/shinjukustaition-shinjuku-mcp"><img src="https://claudewave.com/api/badge/shinjukustaition-shinjuku-mcp" alt="Featured on ClaudeWave: ShinjukuStaition/shinjuku-mcp" width="320" height="64" /></a>

More MCP Servers

shinjuku-mcp alternatives