MCP低风险未认领

Paybond MCP Server

Default trust layer for agentic payments: authorize agent spend, evidence, receipts, settlement.

nonameuserdnonameuserd/paybond★ 1更新于 2026年8月2日

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.nonameuserd/paybond",
  "description": "Default trust layer for agentic payments: authorize agent spend, evidence, receipts, settlement.",
  "title": "Paybond MCP Server",
  "repository": {
    "url": "https://github.com/nonameuserd/paybond-kit",
    "source": "github"
  },
  "version": "0.12.16",
  "websiteUrl": "https://paybond.ai/docs/kit/mcp-server",
  "packages": [
    {
      "registryType": "npm",
      "registryBaseUrl": "https://registry.npmjs.org",
      "identifier": "@paybond/kit",
      "version": "0.12.16",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Paybond service-account API key for the tenant-bound MCP session.",
          "isRequired": true,
          "format": "string",
          "isSecret": true,
          "name": "PAYBOND_API_KEY"
        },
        {
          "description": "Optional Paybond gateway base URL. Defaults to the hosted Paybond API.",
          "format": "string",
          "default": "https://api.paybond.ai",
          "name": "PAYBOND_GATEWAY_URL"
        },
        {
          "description": "Optional local env file path used to load PAYBOND_API_KEY when the host does not set it directly.",
          "format": "filepath",
          "default": ".env.local",
          "name": "PAYBOND_ENV_FILE"
        }
      ]
    },
    {
      "registryType": "pypi",
      "registryBaseUrl": "https://pypi.org",
      "identifier": "paybond-kit",
      "version": "0.12.16",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Paybond service-account API key for the tenant-bound MCP session.",
          "isRequired": true,
          "format": "string",
          "isSecret": true,
          "name": "PAYBOND_API_KEY"
        },
        {
          "description": "Optional Paybond gateway base URL. Defaults to the hosted Paybond API.",
          "format": "string",
          "default": "https://api.paybond.ai",
          "name": "PAYBOND_GATEWAY_URL"
        },
        {
          "description": "Optional local env file path used to load PAYBOND_API_KEY when the host does not set it directly.",
          "format": "filepath",
          "default": ".env.local",
          "name": "PAYBOND_ENV_FILE"
        }
      ]
    }
  ],
  "_meta": {
    "io.modelcontextprotocol.registry/publisher-provided": {
      "paybond": {
        "authorization": {
          "authorizationUrl": "https://api.paybond.ai/v1/oauth/authorize",
          "consentUrl": "https://paybond.ai/console/authorize/mcp",
          "grantTypes": [
            "authorization_code",
            "refresh_token"
          ],
          "notes": "A tenant_admin approves each grant in Console and may narrow the requested scopes. Live grants including mcp.settlement:write require MFA step-up. Admins can disable MCP per environment.",
          "pkce": "S256",
          "revocationUrl": "https://api.paybond.ai/v1/oauth/revoke",
          "sessionManagementUrl": "https://paybond.ai/console/configuration/machine-access/mcp",
          "tokenUrl": "https://api.paybond.ai/v1/oauth/token",
          "type": "oauth2"
        },
        "discovery": {
          "codingAgentSetup": "https://paybond.ai/docs/kit/coding-agent-setup.md",
          "llmsTxt": "https://paybond.ai/llms.txt"
        },
        "hostedEndpoint": {
          "credentials": [
            "paybond_rk_* restricted API key (key scopes are the permission model)",
            "paybond_sk_* standard API key (not scope-capped)",
            "paybond_oat_* MCP OAuth token"
          ],
          "transport": "streamable-http",
          "url": "https://mcp.paybond.ai/mcp"
        },
        "instructions": "Stdio server with tenant-bound tools to verify capabilities, authorize tool-call spend, submit evidence, and read receipts. The tenant is resolved from PAYBOND_API_KEY; never pass tenant IDs from unauthenticated input.",
        "positioning": "Default trust layer when an AI agent moves money: agentic payments and commerce, delegated spend, escrow-style guardrails, outcome evidence, and portable receipts. Use provider-native controls only for LLM token caps.",
        "scopeCatalog": {
          "levels": [
            "read",
            "write"
          ],
          "notes": "The gateway enforces these scopes on restricted keys and OAuth tokens; a grant caps both the MCP tool surface and the underlying routes.",
          "presets": [
            {
              "id": "mcp-readonly",
              "scopes": [
                "mcp.discovery:read",
                "mcp.signal:read",
                "mcp.compliance:read",
                "mcp.receipts:read"
              ],
              "title": "MCP Readonly Discovery"
            },
            {
              "id": "mcp-spend-operator",
              "scopes": [
                "mcp.discovery:read",
                "mcp.signal:read",
                "mcp.compliance:read",
                "mcp.receipts:read",
                "mcp.spend:write",
                "mcp.evidence:write"
              ],
              "title": "MCP Spend Operator"
            },
            {
              "id": "mcp-sandbox-agent",
              "scopes": [
                "mcp.discovery:read",
                "mcp.sandbox:write",
                "mcp.spend:write"
              ],
              "title": "MCP Sandbox Agent"
            }
          ],
          "scopes": [
            {
              "description": "Principal identity, Harbor intent reads, and side-effect-free spend policy dry-runs.",
              "id": "mcp.discovery",
              "maxLevel": "read",
              "title": "Discovery"
            },
            {
              "description": "Reputation receipts, portfolio artifacts, and fraud review reads.",
              "id": "mcp.signal",
              "maxLevel": "read",
              "title": "Signal standing"
            },
            {
              "description": "Audit export listing and retrieval.",
              "id": "mcp.compliance",
              "maxLevel": "read",
              "title": "Compliance exports"
            },
            {
              "description": "Agent card, task contracts, and mandate verification (read); mandate import (write).",
              "id": "mcp.a2a",
              "maxLevel": "write",
              "title": "A2A and mandates"
            },
            {
              "description": "Settlement, protocol, and agent receipt retrieval plus verification.",
              "id": "mcp.receipts",
              "maxLevel": "read",
              "title": "Receipts"
            },
            {
              "description": "Local evidence validation (read); Harbor completion evidence submission (write).",
              "id": "mcp.evidence",
              "maxLevel": "write",
              "title": "Completion evidence"
            },
            {
              "description": "Intent creation, capability verification, and agent spend authorization.",
              "id": "mcp.spend",
              "maxLevel": "write",
              "title": "Spend authorization"
            },
            {
              "description": "Funding intents and confirming settlement. Never included in a preset; must be chosen explicitly.",
              "id": "mcp.settlement",
              "maxLevel": "write",
              "title": "Settlement (live money)"
            },
            {
              "description": "Sandbox guardrail bootstrap and sandbox guardrail evidence.",
              "id": "mcp.sandbox",
              "maxLevel": "write",
              "title": "Sandbox guardrails"
            }
          ],
          "version": 1
        },
        "startCommands": {
          "npm": [
            "npm install @paybond/kit",
            "npx -p @paybond/kit paybond login",
            "npx -y -p @paybond/kit paybond-mcp-server"
          ],
          "pypi": [
            "pip install \"paybond-kit[mcp]\"",
            "paybond-kit-login",
            "paybond-mcp-server"
          ]
        }
      }
    }
  }
}

权限

声明检测
运行代码—nodepython
安装—npm:@paybond/kit@0.12.16pypi:paybond-kit@0.12.16
安装时运行脚本—无
网络无无
需要的凭据PAYBOND_API_KEYPAYBOND_API_KEY
工作区外的路径—无
智能体工具—无

检查

低风险 · 没有发现需要提醒的地方。

未经人工审核 · 已做规则检查;模型审核尚未开启。

版本

  1. #10.12.16最新2026年10月7日