63
/ 100
1 month ago
glama

Green Helix

AI agent commerce platform — 141 tools for payments, escrow, identity, marketplace, and Z3 formal verification

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 11 credentials: A2A_API_KEY, STRIPE_API_KEY, STRIPE_WEBHOOK_SECRET, WEBHOOK_ENCRYPTION_KEY, GITHUB_TOKEN, PG_PASSWORD, VERIFIER_SHARED_SECRET, VERIFIER_SIGNING_KEY, VERIFIER_PUBLIC_KEY, AUDITOR_PRIVATE_KEY, AUDITOR_PUBLIC_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretA2A_API_KEY
configA2A_BASE_URL
configA2A_DATA_DIR
configBILLING_DSN
configPAYWALL_DSN
configPAYMENTS_DSN
configMARKETPLACE_DSN
configTRUST_DSN
configIDENTITY_DSN
configEVENT_BUS_DSN
configWEBHOOK_DSN
configHOSTThe gateway starts on http://localhost:8000 by default. Override with and PORT env vars.
configPORTThe gateway starts on http://localhost:8000 by default. Override with HOST and env vars.
configMETRICS_ALLOWED_IPS
configCORS_ALLOWED_ORIGINS
configA2A_MAX_BATCH_SIZE
configA2A_CREDITS_PER_DOLLAR
configA2A_MIN_CREDITS
configA2A_MAX_CREDITS
configA2A_WEBHOOK_MAX_ATTEMPTS
configA2A_WEBHOOK_TIMEOUT
configA2A_MCP_TIMEOUT
configA2A_HEALTH_INTERVAL
configA2A_SCHEDULER_INTERVAL
configX402_ENABLED
configX402_MERCHANT_ADDRESS
configX402_FACILITATOR_URL
configX402_SUPPORTED_NETWORKS
configPG_MIN_POOL
configPG_MAX_POOL
configPG_STMT_CACHE
configCREDENTIALS_DIRECTORY
configA2A_ENV
configMESSAGING_DSN
configGATEKEEPER_DSN
configVERIFIER_AUTH_MODE
configDISPUTE_DSN
🔐 secretSTRIPE_API_KEY
configA2A_INSTALL_DIR
configA2A_TRUSTED_PROXIES
configFORCE_HTTPS
configA2A_LEGACY_EXECUTE
🔐 secretSTRIPE_WEBHOOK_SECRET
configA2A_DOMAIN
🔐 secretWEBHOOK_ENCRYPTION_KEY
🔐 secretGITHUB_TOKEN
configPG_HOST
configPG_PORT
configPG_DATABASE
configPG_USER
🔐 secretPG_PASSWORD
configPG_SSL
configPG_READ_ONLY
configVERIFIER_LAMBDA_FUNCTION
configVERIFIER_LAMBDA_REGION
configVERIFIER_FUNCTION_URL
🔐 secretVERIFIER_SHARED_SECRET
configVERIFIER_LAMBDA_FALLBACK_REGION
🔐 secretVERIFIER_SIGNING_KEY
🔐 secretVERIFIER_PUBLIC_KEY
🔐 secretAUDITOR_PRIVATE_KEY
🔐 secretAUDITOR_PUBLIC_KEY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/mirni-a2a-1ntk5k)](https://m8ven.ai/mcp/mirni-a2a-1ntk5k)
commit: ec0b30f5043ea1d8e2d32fd265ab6e54f443a1dd
code hash: b7338585d59d3e0f56130248144d8bbe1c0320a8fa1ccf619233c34667f48e8f
verified: 6/17/2026, 12:02:57 PM
view raw JSON →