{"name":"io.github.nirholas/x402-bridge","slug":"nirholas-x402-bridge","title":"x402 Universal Payer","description":"Pay any x402 endpoint on the open web: auto-paying bridge with Bazaar discovery and spend caps.","url":"https://mcp.market/server/nirholas-x402-bridge","rating":null,"grade":"B","score":83,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":48,"stars":206,"forks":49,"downloads_week":34,"last_push_at":"2026-09-22T07:42:31.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/nirholas/three.ws","website":"https://three.ws","version":"1.0.2","remotes":[],"packages":[{"registryType":"npm","identifier":"@three-ws/mcp-bridge","version":"1.0.2","runtimeHint":"npx","transport":{"type":"stdio"},"environmentVariables":[{"description":"0x-prefixed 32-byte hex private key that funds USDC payments on EVM chains (Base, Arbitrum, …). At least one of the EVM/SVM keys is required. Treat like cash — use a dedicated low-balance wallet.","format":"string","isSecret":true,"name":"MCP_BRIDGE_EVM_PRIVATE_KEY"},{"description":"Solana secret key that funds USDC payments: base58 64-byte secret key (Phantom / solana-keygen format) or a JSON array of 64 integers. At least one of the EVM/SVM keys is required. Treat like cash.","format":"string","isSecret":true,"name":"MCP_BRIDGE_SVM_PRIVATE_KEY"},{"description":"Per-call spending cap in atomic units (USDC has 6 decimals). Payments above this abort with a clear reason.","format":"number","default":"100000","name":"MCP_BRIDGE_MAX_PRICE_PER_CALL_ATOMIC"},{"description":"Cumulative session spending ceiling in atomic units. Once total spend would exceed it, further payments abort until restart.","format":"number","default":"1000000","name":"MCP_BRIDGE_MAX_TOTAL_ATOMIC"},{"description":"Comma-separated payee allowlist. When set, any payment whose payTo address is not listed is refused.","format":"string","name":"MCP_BRIDGE_ALLOWED_PAYTO"},{"description":"Comma-separated hostname allowlist for outbound paid requests. When set, any other host is refused before a request is signed.","format":"string","name":"MCP_BRIDGE_ALLOWED_HOSTS"},{"description":"Set to 1 to allow http:// targets (local development only). https is enforced otherwise.","format":"boolean","default":"0","name":"MCP_BRIDGE_ALLOW_HTTP"},{"description":"Max number of x402 Bazaar resources to register as dynamic tools at startup. Set 0 to disable discovery.","format":"number","default":"20","name":"MCP_BRIDGE_DISCOVER_LIMIT"},{"description":"x402 Bazaar discovery endpoint. Override to point at a self-hosted or alternative bazaar.","format":"string","default":"https://api.cdp.coinbase.com/platform/v2/x402/discovery/resources","name":"MCP_BRIDGE_BAZAAR_URL"},{"description":"How many request-amounts to deposit at once when opening an EVM batch-settlement channel.","format":"number","default":"5","name":"MCP_BRIDGE_BATCH_DEPOSIT_MULTIPLIER"},{"description":"Hard cap in atomic units on a single batch-settlement channel deposit or top-up.","format":"number","default":"5000000","name":"MCP_BRIDGE_MAX_DEPOSIT_ATOMIC"},{"description":"Directory for persisted batch-settlement channel state (survives client restarts).","format":"string","default":"~/.x402-mcp-bridge/channels","name":"X402_MCP_BRIDGE_CHANNELS_DIR"},{"description":"Per-chain RPC override, one variable per chain id (RPC_URL_<chainId>, e.g. RPC_URL_8453 for Base). Defaults to viem's public RPC for that chain.","format":"string","name":"RPC_URL_8453"}]}],"tools":[{"name":"call_paid_endpoint","description":"Calls any HTTP URL that returns 402 with x402 payment requirements, automatically signing and paying.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_bazaar_tools","description":"Returns the cached list of x402 Bazaar resources registered as MCP tools on this bridge. Free: reads the in-process cache only, no network and no payment.","write_action":false,"price_micros":0,"input_schema":null},{"name":"refresh_bazaar","description":"Re-queries the x402 Bazaar discovery endpoint and re-registers dynamic tools. Use when new paid services have been added since the bridge started. Free (no payment), but mutates the bridge tool list and results vary with the live Bazaar.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":83,"grade":"B","scanned_at":"2026-09-22T17:07:39.683Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-22T17:07:39.602Z","components":{"code":{"score":25,"max":25,"notes":["9 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 0 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"@three-ws/mcp-bridge","version":"1.0.2","found":true,"license":"SEE LICENSE IN LICENSE","hasInstallScripts":false,"dependencyCount":10,"publishedAt":"2026-08-19T03:41:49.411Z","repositoryUrl":"git+https://github.com/nirholas/three.ws.git","weeklyDownloads":34}],"repo":{"found":true,"owner":"nirholas","repo":"three.ws","archived":false,"pushedAt":"2026-09-22T07:42:31Z","stars":206,"forks":49,"openIssues":12,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/22895867?v=4","ownerCreatedAt":"2016-10-17T19:21:57Z","license":"Apache-2.0"},"icon":{"url":"https://three.ws/three-ws-mcp-icon.svg","source":"registry"},"presence":{"stars":206,"forks":49,"downloadsWeek":34,"license":"Apache-2.0","lastPushAt":"2026-09-22T07:42:31.000Z","score":48}}}},"grade_history":[],"reviews":[]}