Mmcp.market

Palmyr MCP server

by palmyr.ai·ai.palmyr/palmyr·v1.0.0

Agent infra: email, phone, social, domains, VPS, wallets. Paid per-action via x402, no API key.

B80/100grade B
What users say
No reviews yet
Be the first
Safety scan
B80/100

full report

Adoption
Growing

6 stars

Reviews

Write one

Nobody has reviewed Palmyr yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Palmyr tools (33, 12 write)

write = sends, deletes, buys or posts
  • card_buywrite actionFree

    Buy a USA prepaid Visa card loaded with EXACTLY the requested balance ($5–$1000). Dynamic x402 price = amount + fee (3% min 0.50 USDC) — the 402 instructions carry the exact total. Returns 202 with an operation_id: poll card_status until ready (~10s), then fetch the number with card_get. US merchants only; non-reloadable (spend across transactions until depleted); max 6 cards per agent per rolling 24h (issuer limit).

  • card_getFree

    Retrieve a prepaid card you own: full card number, CVV, expiry, live balance. Owner-verified (0.01 USDC ownership proof; the paying wallet must be the card's buyer).

  • card_listFree

    List cards owned by the paying wallet: status, last4, balance (never full numbers — those are per-card via card_get). 0.01 USDC ownership proof.

  • card_statusFree

    Poll a card purchase started by card_buy (free). done=true when status is 'ready' (fetch details with card_get) or 'failed' (payment auto-refunded — see refund_status).

  • compute_deploywrite actionFree

    Deploy a cloud VPS keyed to your wallet (optionally auto-installs OpenClaw/skills). Priced per server type — the exact quote is returned in the 402 challenge, paid per-action via x402.

  • domain_checkFree

    Check domain availability and per-TLD pricing. Pass a full domain (example.com) or a bare name to scan popular TLDs. Free — no payment required.

  • domain_registerFree

    Register a domain to your wallet. Priced per TLD — the exact quote is returned in the 402 challenge, paid per-action via x402.

  • email_create_inboxwrite actionFree

    Provision an email inbox at {name}@palmyr.ai (or a custom domain you own), keyed to your wallet. Costs 2.00 USDC, paid per-action via x402.

  • email_create_tempwrite actionFree

    Provision a cheap, disposable, receive-only email inbox — ideal for receiving a one-off verification or order-confirmation email during a checkout/signup flow. The address (a natural-looking handle on a dedicated inbox domain) is returned in the response. Auto-expires (default 24h). Reads return plaintext to the owning wallet (no E2E key to manage). Costs 0.50 USDC, paid per-action via x402.

  • email_extend_tempwrite actionFree

    Rent another 7 days on a live disposable temp inbox — each call pushes expires_at exactly 7 days further (fixed, stackable, no cap). Owner-only; expired temp inboxes cannot be revived (buy a new one via email_create_temp). Costs 0.50 USDC, paid per-action via x402.

  • email_read_messageswrite actionFree

    Read decrypted messages from an inbox you own (payment wallet must match the inbox). Costs 0.02 USDC, paid per-action via x402.

  • email_sendwrite actionFree

    Send an email from an inbox you own. Costs 0.08 USDC, paid per-action via x402.

  • i402_planFree

    State an intent, get a priced execution plan. The i402 orchestrator turns a natural-language outcome into an ordered list of x402 calls your agent signs and runs. Costs 0.10 USDC per plan, paid per-action via x402.

  • palmyr_capabilitiesFree

    List the i402 capabilities Palmyr can plan and execute (the intent-resolver catalog). Free — no payment required.

  • palmyr_pricingFree

    List every paid Palmyr capability and its live x402 price (USDC on Solana/Base). Free — no payment required.

  • phone_buy_numberwrite actionFree

    Provision a real phone number (SMS + voice) for your agent. Costs 3.00 USDC, paid per-action via x402.

  • phone_extend_tempFree

    Rent another 30 minutes on a live disposable temp number — each call pushes expires_at 30 min further (stackable up to 24h total lease). Owner-only; expired temp leases cannot be revived (lease a fresh one via phone_temp_number). Costs 0.20 USDC, paid per-action via x402.

  • phone_read_messagesFree

    Read SMS messages received on a phone number you own. Costs 0.02 USDC, paid per-action via x402.

  • phone_send_smswrite actionFree

    Send an SMS from a phone number you own. Costs 0.05 USDC, paid per-action via x402.

  • phone_temp_numberFree

    Lease a cheap, instant, receive-only US phone number from a pool to receive one SMS verification code — the phone analogue of a disposable temp email inbox. $0.20 for 30 min (ttl_seconds, clamped 300–1800), returned to the pool at expiry; call wait_for_otp to catch the code. Good for one-time SMS verification and phone-gated signups. Works with major sites like Google, X, and Discord; some (Telegram, WhatsApp, OpenAI) may reject it as a VoIP number — for strict sites, buy a dedicated number with phone_buy_number. Pool numbers are recycled after the lease, so use them for one-time codes only, not long-term 2FA. Costs 0.20 USDC, paid per-action via x402.

  • tiktok_accountsFree

    List the TikTok accounts the paying wallet owns, with session health (status, profile_present, hours_since_success, last_error_code) — i.e. which of your accounts are still logged in. Costs 0.001 USDC, paid per-action via x402.

  • tiktok_analyticsFree

    Scrape per-post analytics (views, likes, comments, shares) for a TikTok account you control, and record a sample so tiktok_series can answer 'is it still growing'. Async: returns an operation to poll with tiktok_operation_status. Costs 0.005 USDC, paid per-action via x402.

  • tiktok_cancel_scheduledwrite actionFree

    Cancel a post queued with tiktok_post(schedule_at). TikTok has no 'unschedule', so this deletes the held video — the cancellation is recorded only once that succeeded. Async: returns an operation to poll with tiktok_operation_status. Costs 0.001 USDC, paid per-action via x402.

  • tiktok_connectFree

    Attach a TikTok account by logging in ON THE SERVER, into that account's own persistent browser profile: returns a connect_url to hand a human, who scans the QR in the TikTok app. The recommended path — the browser that authenticates is the browser that later acts, and every other TikTok tool then works with `cookies` omitted (no jar to move). The paying wallet becomes the account's owner. Async: poll tiktok_connect_status with the returned token. Costs 0.01 USDC, paid per-action via x402.

  • tiktok_connect_statusFree

    Poll a server-side login started by tiktok_connect (free). done=true when state is 'completed' (the account is live and usable with cookies omitted) or 'failed'.

  • tiktok_hooksFree

    Which caption openings actually earn views. Pass account_id or tag to measure YOUR accounts against their own median (0.001 USDC). Pass niche to report what is working in that niche across TikTok, needing no posting history — the answer for a brand-new account (0.05 USDC; tiktok_niches lists them, free). The two are never blended. Pass caption to classify a draft before posting. Paid per-action via x402 — the 402 challenge carries the exact price for the arguments you sent.

  • tiktok_nichesFree

    List the niches tiktok_hooks can report on, with how fresh each corpus is. Free — an agent should not pay to learn what it may ask for.

  • tiktok_operation_statusFree

    Poll an async TikTok operation started by tiktok_post / tiktok_analytics / tiktok_cancel_scheduled (free). done=true when status is 'posted' / 'done' (carries video_url or the op's result) or 'failed' (payment auto-refunded — see refund_status).

  • tiktok_postwrite actionFree

    Post a video to a TikTok account you control (from video_base64 or video_url), immediately or scheduled. Async: returns an operation to poll with tiktok_operation_status. Costs 0.01 USDC, paid per-action via x402.

  • tiktok_scheduledFree

    List the posts you have queued with tiktok_post(schedule_at), and whether each is still pending, due, or confirmed published. Palmyr's own record — TikTok exposes no way to read pending posts back, so edits made directly in TikTok Studio are invisible to it. Costs 0.001 USDC, paid per-action via x402.

  • tiktok_seriesFree

    Read the stored per-post history for an account you own: the full time series for one video (video_id), per-video growth over a window (hours), or the latest sample per video (neither). Samples come from tiktok_analytics runs, so history exists only for what you have scraped. Costs 0.001 USDC, paid per-action via x402.

  • twitter_postwrite actionFree

    Post a tweet from an X account you control (via injected session cookies). Costs 0.001 USDC, paid per-action via x402.

  • wait_for_otpFree

    Wait for an SMS verification code / OTP to arrive on a Palmyr phone number you own, and return the parsed code. Blocks up to timeout_s (default 60, max 90) checking every ~2s — one call replaces hand-rolled polling of phone_read_messages during account signups and 2FA flows. Messages that arrived up to lookback_s seconds (default 10) BEFORE the call also match, so a code that landed early is not missed — pass lookback_s=0 when reusing a number across signups so a stale code can't be re-served. Default extraction handles standalone 4-8 digit codes, 'code is/code:' tokens, and Google-style G-XXXXXX; pass pattern to override (max 256 chars; a pattern that blows its per-match budget is dropped mid-wait and pattern_timeout: true is reported). Returns { found: true, code, message_text } on a hit or { found: false, waited_s } on timeout (not an error — just call again). Costs 0.02 USDC, paid per-action via x402.

Public scan report

scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it

1 high
  • –Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 1516ms20/20
  • Tool poisoning33 tool descriptions checked15/15
  • Auth qualityopen endpoint exposes 12 write-action tools with no auth3/15
  • Maintenancelast push 13 days ago15/15
  • Maintainer identitynamespace and repository owner differ; GitHub account older than a year; website matches verified namespace7/10

Findings (1)

  • highWrite-action tools reachable without authenticationauth.open-write
Overall 80/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

What the publisher says

From the Palmyr repository's README, as published. We do not edit it. Read it on GitHub

Palmyr

Everything your AI agent needs — one CLI.

Phone, email, compute, domains, wallets, X accounts, and more. Pay with USDC. Your wallet is your identity.

Quick Start • Services • Dashboard • Skill File • Docs

Stop asking your human for a credit card.

Quick Start

CLI

npm i -g @palmyr/cli
palmyr wallet create                      # local HD wallet, both Solana + Base, ready to pay

palmyr phone search --country US
palmyr email create --name my-agent --wallet SOL_PUBKEY
palmyr compute deploy --type cx23 --json  # auto-key, auto-wait, verified ssh — JSON out
palmyr compute ssh my-vps                 # drop into the new box
palmyr domain buy --name myagent.dev
palmyr twitter buy                        # $5 USDC → ready X account from the pool
palmyr twitter post @handle --body "gm"   # post immediately, no setup

Agents: pipe stdout into jq, branch on $? against the exit code table. Force JSON on a TTY with --json or PALMYR_JSON=1.

Or run without installing: npx @palmyr/cli phone search --country US

Skill File

Add to your OpenClaw / Claude Code agent: palmyr.ai/skill.md

Dashboard

Visual node-based agent deployment: palmyr.ai/dashboard.html

Services

How It Works

Agent calls API → gets 402 → pays USDC (Solana or Base) → service provisioned

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Install directly

claude mcp add --transport http palmyr https://palmyr.ai/mcp
Add to Cursor

Palmyr: common questions

Is Palmyr MCP server safe?
Mostly: it is graded B (80/100). Read the Palmyr safety report
How do I install Palmyr?
It runs remotely at palmyr.ai. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Palmyr need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Palmyr maintained?
The last commit was 15 days ago (2026-09-13). The latest release is v1.0.0.
Is Palmyr up?
100% of our last 28 checks got an answer. We check remote servers about four times a day.
What can I use instead of Palmyr?
Servers from other publishers that do the same job: MCP server, Blackwall MCP server and e2a — email for AI agents MCP server. Compare all Palmyr alternatives.

Alternatives to Palmyr

Same job from other publishers: the closest match first, then the best rated.

All Palmyr alternatives →
  • MCP
    Email infrastructure for AI agents: send, read replies as threads, campaigns, per-key limits.
    B
  • Blackwall
    API-key pre-action risk gate: any irreversible agent action (money, SQL, delete, email).
    B
  • e2a — email for AI agents
    Authenticated email gateway for AI agents — per-agent inboxes, HITL approval, SPF/DKIM verified.
    A
  • Impreza Host
    No-KYC offshore hosting an AI agent runs end-to-end: no-email signup, crypto, VPS, deploy, Tor.
    B
  • MCP
    20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
    A

More from palmyr.ai →