74
grade C
10 days ago
glama

402-mcp

L402 + x402 client MCP. AI agents discover, pay for, and consume any payment-gated API autonomously. Supports Lightning (NWC), Cashu ecash, stablecoins, and human-in-the-loop payments.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
10 tools verified — handlers match their declared behaviour
5 read-only tools verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOW_INSECURE_TLS
configBIND_ADDRESS
configCASHU_TOKENSPath to Cashu token store file
configCORS_ORIGIN
configCREDENTIAL_STORE~/.402-mcp/credentials.json Persistent macaroon/credential storage
configFETCH_MAX_RESPONSE_BYTES
configFETCH_MAX_RETRIES
configFETCH_TIMEOUT_MS
configHNS_GATEWAY_URLHTTP gateway for Handshake (.hns) domains (e.g. https://hns.to)
configHUMAN_PAY_POLL_S
configHUMAN_PAY_TIMEOUT_S
configMAX_AUTO_PAY_SATS1000 Safety cap; payments above this require human confirmation
configMAX_SPEND_PER_MINUTE_SATS
configNWC_URINostr Wallet Connect URI for autonomous Lightning payments
configPORT3402 HTTP server port (when TRANSPORT=http)
configSOCKS_PROXYGeneric SOCKS5 proxy for all requests when set
configSSRF_ALLOW_PRIVATE
configTOR_PROXYSOCKS5 proxy for .onion addresses (e.g. socks5h://127.0.0.1:9050)
configTRANSPORTstdio Transport mode: stdio or http
configTRANSPORT_PREFERENCEonion,hns,https,http Preferred transport order for multi-URL services (comma-separated)
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/forgesworn-402-mcp-wlfpmx)](https://m8ven.ai/mcp/forgesworn-402-mcp-wlfpmx)
commit: bf8560941c73abc46fd0909f8db9dc9ddd37ffa7
code hash: c86a360140b0d4be5293bcfd611c646bd2dc857c18e03f08aaf9734567299a27
verified: 4/11/2026, 2:15:26 PM
view raw JSON →