ReceiptRail
Read-only on-chain receipt check for x402 payments; confirm settlement before trusting a tx.
我該用這個嗎
品質與安全性
發現項目(2)
- HIGH
- MEDIUM在 verify_x402_receipt 中
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"receiptrail": {
"url": "https://agenttoll-receipts.app.workbuddy.host/mcp"
}
}
}遠端端點
https://agenttoll-receipts.app.workbuddy.host/mcpstreamable-http它能做什麼
工具清單
工具(4)
⚪issue_receipt(x402_payment_ref, deliverable_digest, x402_payment_signature, buyer, seller)
Anchor a SHA-256 digest of delivered content plus the x402 settlement reference on Solana. Returns a permanent, publicly verifiable receipt (poll until outcome === "settled"). Costs 0.001 USDC via x402; if x402_payment_signature is omitted, returns the payment challenge instead (pay 0.001 USDC to the service address, then call again with the payment tx signature).
輸入結構描述
{
"type": "object",
"properties": {
"x402_payment_ref": {
"type": "string",
"description": "Unique reference for this transaction (1-128 chars)"
},
"deliverable_digest": {
"type": "string",
"description": "SHA-256 hex digest (64 chars) of the delivered content"
},
"x402_payment_signature": {
"type": "string",
"description": "Solana tx signature of the 0.001 USDC payment to the service address. Omit to receive the payment challenge."
},
"buyer": {
"type": "string",
"description": "Optional buyer identifier (wallet address)"
},
"seller": {
"type": "string",
"description": "Optional seller identifier"
}
},
"required": [
"x402_payment_ref",
"deliverable_digest"
]
}🟢verify_receipt(receipt_id, payment_ref)
Verify an AgentToll receipt against live Solana state: PDA owner must be the AgentToll program and the stored digest must match the receipt. Look up by receipt_id, or by x402_payment_ref (always works — the receipt lives on-chain). Read-only, no cost.
輸入結構描述
{
"type": "object",
"properties": {
"receipt_id": {
"type": "string",
"description": "Receipt id, e.g. r_abcdef1234567890"
},
"payment_ref": {
"type": "string",
"description": "x402_payment_ref of the transaction (use this if receipt_id unknown; resolved on-chain)"
}
}
}🟢get_receipt(receipt_id, payment_ref)
Fetch full receipt details: digests, checks, outcome, amount, buyer, seller, timestamp, PDA. Look up by receipt_id, or by x402_payment_ref (always works — the receipt lives on-chain). Read-only, no cost.
輸入結構描述
{
"type": "object",
"properties": {
"receipt_id": {
"type": "string",
"description": "Receipt id, e.g. r_abcdef1234567890"
},
"payment_ref": {
"type": "string",
"description": "x402_payment_ref of the transaction (use this if receipt_id unknown; resolved on-chain)"
}
}
}🟢verify_x402_receipt(receipt, public_key_jwk, max_age_seconds, expect)
Verify a signed receipt in the official x402 offer-receipt extension format (docs.x402.org/extensions/offer-receipt, npm @x402/extensions). Accepts {format:"jws", signature} artifacts (JWS with EdDSA/Ed25519 or ES256/P-256), checks structure, required payload fields (version/network/resourceUrl/payer/issuedAt), cryptographic signature, optional freshness window, and optional expected values. Public key resolves automatically from did:key/did:web/did:jwk kid, or pass public_key_jwk directly. Read-only, no cost.
輸入結構描述
{
"type": "object",
"properties": {
"receipt": {
"type": "object",
"description": "Signed receipt artifact, e.g. {\"format\":\"jws\",\"signature\":\"<JWS compact serialization>\"}",
"required": [
"format",
"signature"
],
"properties": {
"format": {
"type": "string",
"enum": [
"jws"
]
},
"signature": {
"type": "string",
"description": "JWS compact serialization (header.payload.signature)"
}
}
},
"public_key_jwk": {
"type": "object",
"description": "Optional JWK to verify with. Omit to resolve from the kid (did:key:z... Ed25519, did:web, did:jwk)."
},
"max_age_seconds": {
"type": "number",
"description": "Freshness window for issuedAt (default 3600; pass 0 to skip the freshness gate)."
},
"expect": {
"type": "object",
"description": "Optional assertions: {resourceUrl?, payer?, network?} — verification fails if the payload contradicts them.",
"properties": {
"resourceUrl": {
"type": "string"
},
"payer": {
"type": "string"
},
"network": {
"type": "string"
}
}
}
},
"required": [
"receipt"
]
}社群
證據