Sign in
mcp server · quackai-org.github.io

q402-mcp

Q402 - gasless payments, yield, escrow, bridge & NAV triggers on 12 EVM chains. Sandbox-default.

What it says

The record the registry holds

How you get it

There is no address to call. This one is a package you install and run yourself, wherever your assistant runs.

@quackai/q402-mcp · npm · 0.11.23
the record Copied from the official MCP registry, exactly as it holds it.
{
  "server": {
    "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
    "name": "io.github.quackai-org/q402-mcp",
    "description": "Q402 - gasless payments, yield, escrow, bridge & NAV triggers on 12 EVM chains. Sandbox-default.",
    "repository": {
      "url": "https://github.com/quackai-org/q402-mcp",
      "source": "github"
    },
    "version": "0.11.23",
    "packages": [
      {
        "registryType": "npm",
        "identifier": "@quackai/q402-mcp",
        "version": "0.11.23",
        "transport": {
          "type": "stdio"
        },
        "environmentVariables": [
          {
            "description": "Recommended path: skip this UI and run `q402_doctor` after install - it stores secrets in ~/.q402/mcp.env, which the server auto-loads. Fill this field directly ONLY if your MCP client manages secrets for you. Value is a Free Trial API key from https://q402.quackai.ai/event - BNB Chain (permanent) + Base (permanent) + Mantle limited-time (2026-08-21~08-28 UTC+9), 500 sponsored TXs, gas covered by Q402. Avalanche trial has ended. BNB and Base payments auto-route to this key when set (same rule for q402_pay and q402_batch_pay up to 5 recipients).",
            "format": "string",
            "isSecret": true,
            "name": "Q402_TRIAL_API_KEY"
          },
          {
            "description": "Recommended path: skip this UI and run `q402_doctor` after install - it stores secrets in ~/.q402/mcp.env, which the server auto-loads. Fill this field directly ONLY if your MCP client manages secrets for you. Value is a Paid Multichain API key from https://q402.quackai.ai/payment - full 12-chain support with per-chain Gas Tank. Auto-routed for non-BNB payments and whenever keyScope='multichain' is chosen.",
            "format": "string",
            "isSecret": true,
            "name": "Q402_MULTICHAIN_API_KEY"
          },
          {
            "description": "Mode A - real EOA signing. Hex-encoded EVM private key (0x + 64 hex chars) of YOUR MetaMask wallet, used to sign payment authorizations LOCALLY on your machine. After your first payment that wallet shows as 'Smart account' in MetaMask (EIP-7702 delegation, reversible via q402_clear_delegation). Use a fresh wallet, not your main one. Skip this and pick Mode B (Q402_AGENTIC_PRIVATE_KEY) or Mode C (server-managed Agent Wallet) if you'd rather keep your MetaMask untouched. Recommended path: run q402_doctor after install - it stores secrets in ~/.q402/mcp.env, which the server auto-loads.",
            "format": "string",
            "isSecret": true,
            "name": "Q402_PRIVATE_KEY"
          },
          {
            "description": "Mode B - local Agent Wallet signing. Hex-encoded EVM private key (0x + 64 hex chars) exported from your Agent Wallet at https://q402.quackai.ai/dashboard -> Agent tab -> Export. Signs LOCALLY just like Mode A, but the signer is your dedicated Agent Wallet - your MetaMask EOA is never touched. Pick this for AI-agent automation when you want a dedicated purse with per-tx + daily caps you set on the dashboard.",
            "format": "string",
            "isSecret": true,
            "name": "Q402_AGENTIC_PRIVATE_KEY"
          },
          {
            "description": "Live-mode switch. 0 = sandbox (test mode, no funds move - every q402_pay returns a fake hash). 1 = real on-chain payments. Default 1 since v0.5.11: safe because mode only flips to live when a live API key (q402_live_*) is set AND one of (a) a valid 32-byte private key for local signing modes, OR (b) walletMode=\"agentic-server\" with Q402_MULTICHAIN_API_KEY for the server-managed Agent Wallet path. Without either combination, the server stays in sandbox regardless of this flag.",
            "format": "string",
            "default": "1",
            "name": "Q402_ENABLE_REAL_PAYMENTS"
          },
          {
            "description": "Per-call USD-equivalent cap for USDC/USDT/RLUSD. Any such q402_pay request with amount above this is rejected before signing. Q (QuackAI) is exempt by design (your own token; recipient allowlist + confirmation still apply). Lower this for a tighter agent blast-radius; raise for treasury-grade transfers.",
            "format": "string",
            "default": "200",
            "name": "Q402_MAX_AMOUNT_PER_CALL"
          },
          {
            "description": "Optional comma-separated lowercase EVM addresses. When set, q402_pay rejects any recipient not on this allowlist.",
            "format": "string",
            "name": "Q402_ALLOWED_RECIPIENTS"
          },
          {
            "description": "Override for the Q402 relay endpoint. Defaults to https://q402.quackai.ai/api. Set explicitly when running against a self-hosted Q402 deployment or a non-canonical environment.",
            "format": "string",
            "default": "https://q402.quackai.ai/api",
            "name": "Q402_RELAY_BASE_URL"
          },
          {
            "description": "Server-managed Agent Wallet picker (walletMode='agentic-server' only). Lowercased agent wallet address (the hex 0x... shown on the Agent tab of your dashboard) selecting which of your Agent Wallets to spend from when you hold more than one (max 10 per owner). Omit to use the default wallet. Ignored for the local-signing modes that carry their own private key.",
            "format": "string",
            "name": "Q402_AGENT_WALLET_ADDRESS"
          },
          {
            "description": "DEPRECATED legacy single-key env from pre-v0.5.0 installs. The server still reads it as a silent fallback so existing setups keep working, but new users should pick a scoped variant instead. Q402_TRIAL_API_KEY (Free Trial, BNB Chain + Base) and Q402_MULTICHAIN_API_KEY (full 12-chain surface) are designed to coexist - BNB and Base payments auto-route to the trial key, other chains use multichain. Only set Q402_API_KEY if you are migrating an existing pre-v0.5.0 install; do NOT set it alongside the scoped variants on a fresh install.",
            "format": "string",
            "isSecret": true,
            "name": "Q402_API_KEY"
          },
          {
            "description": "DEPRECATED soft-migration alias for Q402_AGENT_WALLET_ADDRESS (one release of overlap from v0.6.0). The server still accepts it but logs a deprecation notice. New installs should set Q402_AGENT_WALLET_ADDRESS directly.",
            "format": "string",
            "name": "Q402_WALLET_ID"
          },
          {
            "description": "Optional Base Builder Code for onchain attribution (ERC-8021 / Base Builder Codes). When set, every q402_x402_fetch payment includes your code as the client/intermediary in the x402 payment extension so payments are attributed onchain. Format: 1-32 lowercase letters, numbers, or underscores. Leave unset to disable attribution.",
            "format": "string",
            "name": "Q402_BUILDER_CODE"
          }
        ]
      }
    ]
  },
  "_meta": {
    "io.modelcontextprotocol.registry/official": {
      "status": "active",
      "statusChangedAt": "2026-08-19T03:30:51.946532Z",
      "publishedAt": "2026-08-19T03:30:51.946532Z",
      "updatedAt": "2026-08-19T03:30:51.946532Z",
      "isLatest": true
    }
  }
}
Make it installable

Draft an Agent Plugin from this

An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.

Make it installable

Draft an Agent Plugin from q402-mcp

Paste it into your assistant. It asks for the manifest, the server wiring and the skills, and for an honest account of what this record does not say. Read that second file first.

176 lines · the record is inside it, so nothing else is needed
Draft an Agent Plugin (agent-plugins.org, specification 1.1.0) that wraps the
MCP server described below, so that somebody could install one thing and have
an assistant that knows when and how to use it.

An Agent Plugin is one installable unit: a `plugin.json` manifest, an
`mcp.json` that wires up the servers it needs, and a `skills/` directory
where each skill is a folder holding a `SKILL.md`. Hand back every file in
full, each under its own path, ready to save.

1. Write `plugin.json` with `$schema` exactly `https://agent-plugins.org/schemas/1.1.0/plugin.schema.json`. The name is
   1 to 64 characters of a-z, 0-9, `-` and `.`, alphanumeric at both ends, with
   no `--` and no `..` in it.

2. Write `mcp.json` wiring THIS server exactly as its record declares it. A
   remote keeps the URL and the transport type as written. A package keeps the
   registry, the identifier and the version as written. Do not invent a command,
   a port, a flag or an argument that is not in the record.

3. Every secret stays an input. No key, token, password or connection string
   belongs in either file. Declare what has to be supplied, name it, and say what
   it is for.

4. Do not invent tools. The record lists the tools it lists, and if it lists
   none then the honest plugin says the tool list was not published rather than
   guessing one from the description.

5. Skills are jobs, not tools. Write one skill per thing somebody would actually
   ask for, and inside each one say when to reach for this server, what a good
   result looks like, and what to do when it comes back empty. A skill per tool
   is a manual page with a different filename.

6. Say where it stops. Name what this plugin will not do — what it has no tool
   for, what needs a person, and what it must not be pointed at. A plugin with no
   stated edge reads as one with no edge.

7. Keep the author's own words for the description. If you would rather say it
   differently, say yours somewhere else and leave theirs where it is.

8. Record which version of the server you wrapped, and where the record came
   from, at the top of `plugin.json`'s description or in the readme. A plugin
   nobody can trace back to a version is one nobody can update.

Produce a second file alongside them, `LIMITS.md`, and treat it as the more
important of the two. The plugin is for whoever installs it. This is for
whoever has to decide whether installing it is a good idea, and that is
usually a different person who will never read the manifest.

It has three parts.

**What this is built from.** One paragraph: whose server it is, what the
record says it does, which version, and the fact that the record is all you
had. Say plainly that nobody ran it.

**What the record does not say.** One entry per gap. Whether the tool list was
published. What the server does with what it reads. What it costs. Whether it
writes anything anywhere. What credentials it will ask for and what those
credentials can reach. An unanswered question stays an unanswered question:
do not fill one in from the description or from what similar servers usually do.

**What a person has to check before trusting it.** The specific things
somebody should verify for themselves, in the order that would stop them
soonest if the answer is bad.

Write it in plain English, and do not soften it. A plugin drafted from a
directory record is a starting point to argue with, not something to install
into anything that matters.

The server record follows, exactly as the public index holds it. It is
everything I have: nobody has run this server, called a tool on it, or checked
that the address answers.

```json
{
  "server": {
    "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
    "name": "io.github.quackai-org/q402-mcp",
    "description": "Q402 - gasless payments, yield, escrow, bridge & NAV triggers on 12 EVM chains. Sandbox-default.",
    "repository": {
      "url": "https://github.com/quackai-org/q402-mcp",
      "source": "github"
    },
    "version": "0.11.23",
    "packages": [
      {
        "registryType": "npm",
        "identifier": "@quackai/q402-mcp",
        "version": "0.11.23",
        "transport": {
          "type": "stdio"
        },
        "environmentVariables": [
          {
            "description": "Recommended path: skip this UI and run `q402_doctor` after install - it stores secrets in ~/.q402/mcp.env, which the server auto-loads. Fill this field directly ONLY if your MCP client manages secrets for you. Value is a Free Trial API key from https://q402.quackai.ai/event - BNB Chain (permanent) + Base (permanent) + Mantle limited-time (2026-08-21~08-28 UTC+9), 500 sponsored TXs, gas covered by Q402. Avalanche trial has ended. BNB and Base payments auto-route to this key when set (same rule for q402_pay and q402_batch_pay up to 5 recipients).",
            "format": "string",
            "isSecret": true,
            "name": "Q402_TRIAL_API_KEY"
          },
          {
            "description": "Recommended path: skip this UI and run `q402_doctor` after install - it stores secrets in ~/.q402/mcp.env, which the server auto-loads. Fill this field directly ONLY if your MCP client manages secrets for you. Value is a Paid Multichain API key from https://q402.quackai.ai/payment - full 12-chain support with per-chain Gas Tank. Auto-routed for non-BNB payments and whenever keyScope='multichain' is chosen.",
            "format": "string",
            "isSecret": true,
            "name": "Q402_MULTICHAIN_API_KEY"
          },
          {
            "description": "Mode A - real EOA signing. Hex-encoded EVM private key (0x + 64 hex chars) of YOUR MetaMask wallet, used to sign payment authorizations LOCALLY on your machine. After your first payment that wallet shows as 'Smart account' in MetaMask (EIP-7702 delegation, reversible via q402_clear_delegation). Use a fresh wallet, not your main one. Skip this and pick Mode B (Q402_AGENTIC_PRIVATE_KEY) or Mode C (server-managed Agent Wallet) if you'd rather keep your MetaMask untouched. Recommended path: run q402_doctor after install - it stores secrets in ~/.q402/mcp.env, which the server auto-loads.",
            "format": "string",
            "isSecret": true,
            "name": "Q402_PRIVATE_KEY"
          },
          {
            "description": "Mode B - local Agent Wallet signing. Hex-encoded EVM private key (0x + 64 hex chars) exported from your Agent Wallet at https://q402.quackai.ai/dashboard -> Agent tab -> Export. Signs LOCALLY just like Mode A, but the signer is your dedicated Agent Wallet - your MetaMask EOA is never touched. Pick this for AI-agent automation when you want a dedicated purse with per-tx + daily caps you set on the dashboard.",
            "format": "string",
            "isSecret": true,
            "name": "Q402_AGENTIC_PRIVATE_KEY"
          },
          {
            "description": "Live-mode switch. 0 = sandbox (test mode, no funds move - every q402_pay returns a fake hash). 1 = real on-chain payments. Default 1 since v0.5.11: safe because mode only flips to live when a live API key (q402_live_*) is set AND one of (a) a valid 32-byte private key for local signing modes, OR (b) walletMode=\"agentic-server\" with Q402_MULTICHAIN_API_KEY for the server-managed Agent Wallet path. Without either combination, the server stays in sandbox regardless of this flag.",
            "format": "string",
            "default": "1",
            "name": "Q402_ENABLE_REAL_PAYMENTS"
          },
          {
            "description": "Per-call USD-equivalent cap for USDC/USDT/RLUSD. Any such q402_pay request with amount above this is rejected before signing. Q (QuackAI) is exempt by design (your own token; recipient allowlist + confirmation still apply). Lower this for a tighter agent blast-radius; raise for treasury-grade transfers.",
            "format": "string",
            "default": "200",
            "name": "Q402_MAX_AMOUNT_PER_CALL"
          },
          {
            "description": "Optional comma-separated lowercase EVM addresses. When set, q402_pay rejects any recipient not on this allowlist.",
            "format": "string",
            "name": "Q402_ALLOWED_RECIPIENTS"
          },
          {
            "description": "Override for the Q402 relay endpoint. Defaults to https://q402.quackai.ai/api. Set explicitly when running against a self-hosted Q402 deployment or a non-canonical environment.",
            "format": "string",
            "default": "https://q402.quackai.ai/api",
            "name": "Q402_RELAY_BASE_URL"
          },
          {
            "description": "Server-managed Agent Wallet picker (walletMode='agentic-server' only). Lowercased agent wallet address (the hex 0x... shown on the Agent tab of your dashboard) selecting which of your Agent Wallets to spend from when you hold more than one (max 10 per owner). Omit to use the default wallet. Ignored for the local-signing modes that carry their own private key.",
            "format": "string",
            "name": "Q402_AGENT_WALLET_ADDRESS"
          },
          {
            "description": "DEPRECATED legacy single-key env from pre-v0.5.0 installs. The server still reads it as a silent fallback so existing setups keep working, but new users should pick a scoped variant instead. Q402_TRIAL_API_KEY (Free Trial, BNB Chain + Base) and Q402_MULTICHAIN_API_KEY (full 12-chain surface) are designed to coexist - BNB and Base payments auto-route to the trial key, other chains use multichain. Only set Q402_API_KEY if you are migrating an existing pre-v0.5.0 install; do NOT set it alongside the scoped variants on a fresh install.",
            "format": "string",
            "isSecret": true,
            "name": "Q402_API_KEY"
          },
          {
            "description": "DEPRECATED soft-migration alias for Q402_AGENT_WALLET_ADDRESS (one release of overlap from v0.6.0). The server still accepts it but logs a deprecation notice. New installs should set Q402_AGENT_WALLET_ADDRESS directly.",
            "format": "string",
            "name": "Q402_WALLET_ID"
          },
          {
            "description": "Optional Base Builder Code for onchain attribution (ERC-8021 / Base Builder Codes). When set, every q402_x402_fetch payment includes your code as the client/intermediary in the x402 payment extension so payments are attributed onchain. Format: 1-32 lowercase letters, numbers, or underscores. Leave unset to disable attribution.",
            "format": "string",
            "name": "Q402_BUILDER_CODE"
          }
        ]
      }
    ]
  },
  "_meta": {
    "io.modelcontextprotocol.registry/official": {
      "status": "active",
      "statusChangedAt": "2026-08-19T03:30:51.946532Z",
      "publishedAt": "2026-08-19T03:30:51.946532Z",
      "updatedAt": "2026-08-19T03:30:51.946532Z",
      "isLatest": true
    }
  }
}
```

The server is listed as "q402-mcp".
What this is

MCP server

application/mcp-server-record+jsonlocal · you run it yourselfversion 0.11.23last seen 2026-08-23

These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.

Where it lives

The publisher's own address

https://github.com/quackai-org/q402-mcp

The address the publisher put in their registry record, printed as they wrote it. Nobody here has opened it.