This release is a pre-release and may not be stable for production use.
Add payments to any agent
EnvarPay gives an existing agent a budgeted payment wallet, a paid capability, or both. Your agent keeps its framework, model, tools and memory. Connect standard MCP tools; no Envar account is required. An optional Envar connection adds discovery, receiving settings and transaction observations.
中文 · Quickstart · Envar guide · Framework guides
Choose what to install
| You want to… | Use | What it provides |
|---|---|---|
| Give any MCP-capable agent payment tools | Python envarpay CLI/service |
Wallet signing, recipient/tool allowlists, budgets, durable state and recovery |
| Sell an existing MCP capability, whatever its language | Python envarpay payment gate |
Quote, collect and verify USDC before calling your private tool; no seller key needed |
| Call from a Python application | Python envarpay API |
WalletService / PaidServer; same policy and state as the CLI |
| Call from JavaScript/TypeScript or Bun | npm @envarai/envarpay |
Typed client to an authenticated wallet MCP service; no embedded signer or Python installer |
| Host language cannot embed either package | Separate MCP service | Run the Python service separately or build its Docker image; connect the agent's native MCP client |
| Use an agent that exposes only HTTP or a CLI | A small private adapter | Wrap one bounded operation as MCP; keep the runtime private behind the payment gate |
For current package versions and registry availability, see installation channels. The npm client is distributed separately. Standalone service images can be built from source.
An agent needs native MCP support or a callable API/CLI that can be adapted. A UI-only application needs its own integration. Protocol compatibility is not a claim that every possible agent/version has passed payment acceptance.
Install Python
Install uv, then:
uv tool install --python 3.13 --prerelease allow envarpay
envarpay --version
For a Python application's own environment, use python -m pip install --pre envarpay.
These are alpha releases. Pin the version you validated before upgrading an existing
wallet, and preserve its config, keys and ledger: upgrade guide.
Start receiving payment
Your agent must already expose a private MCP tool, such as ask_agent:
envarpay init --agent mcp --role seller --directory ./seller \
--pay-to YOUR_FULL_RECEIVING_ADDRESS \
--upstream http://127.0.0.1:8000/mcp --tool ask_agent --price 0.01
envarpay doctor --config ./seller/seller.toml
envarpay serve --config ./seller/seller.toml
The gate listens at http://127.0.0.1:4020/mcp. Expose the gate through your HTTPS
service and configure its allowed host; keep the raw upstream private. The seller
needs a receiving address, not its private key. Only after the exact payment is
confirmed does the private tool run. Seller recipes.
The generated config uses Base Sepolia test USDC. For real-money Base operation,
explicitly review the mainnet network/RPC, official USDC, receiving address, price
and supported facilitator. Initialization and doctor do not make a payment.
Configuration and network selection.
Give your agent a payment wallet
Obtain the seller's paid MCP URL, receiving address and exact tool name:
envarpay init --agent hermes --role buyer --directory ./buyer \
--peer-url https://seller.example/mcp --pay-to SELLER_FULL_RECEIVING_ADDRESS \
--tool ask_agent --max-per-call 0.01 --budget 0.05
envarpay keygen --output ./buyer/buyer.key
envarpay doctor --config ./buyer/buyer.toml
Fund the dedicated test wallet; review the network, recipient, allowed tool and
limits in buyer.toml, then explicitly enable payments_enabled. Merge the generated
host-config.json into the agent's existing config and reload it. For other MCP
clients, use the command/args in wallet-command.json. --agent selects instructions,
not a new agent or model. Framework-specific steps.
Your agent receives list_paid_tools, call_paid_tool, payment_status and
recover_payment. Give each purchase a stable request ID. On timeout, inspect or
recover that ID; do not create a second purchase. Budgets are cumulative, not daily.
Use --role both for both functions, with your address in --pay-to and the other
seller's in --peer-pay-to; buyer and seller retain separate config/state.
JavaScript/TypeScript and Bun
For JS/TS, use the separately distributed @envarai/envarpay wallet client; check its registry availability in the installation channels above.
Full npm guide includes authenticated wallet setup,
Envar discovery, a paid call, status and original-result recovery.
import { WalletClient } from '@envarai/envarpay';
const wallet = await WalletClient.connect({
url: 'https://YOUR_PRIVATE_WALLET/mcp',
token: process.env.ENVARPAY_WALLET_TOKEN!,
});
try {
const tools = await wallet.listPaidTools('seller');
console.log(tools.tools);
} finally { await wallet.close(); }
The npm client talks to the buyer's wallet, not directly to a seller. Signing, funding, allowlists and budgets stay in that separately operated wallet. An agent with native MCP support can connect directly and does not need this npm library.
Use it with Envar
Envar onboarding walks through registering an endpoint, ownership
proof, publishing a seller, receiving configuration, connecting a buyer and viewing
both sides of a transaction. [connection] enables catalog discovery and durable
reports; accept_receiving_updates optionally applies the seller's Envar prices.
Public discovery does not authorize a new receiving address or change wallet policy.
For asynchronous work with acceptance and refunds, use Python envarpay[task]
and its task wallet MCP tools. This is a separate experimental, Base Sepolia-only
flow; it is not the upfront call_paid_tool path. Task guide.
Evidence and operating limits
The six-framework testnet matrix records 28 paid deliveries in 30 attempts, including two failed settlements. Tests of installation, Node/Bun transport or CI are not additional payment evidence. Agent frameworks, HTTP connectors and task escrow have their own acceptance scope.
Payments default off. Keep wallet keys, policy and state in the wallet's permission boundary; an agent with unrestricted shell access under the same OS user is not isolated from them. Paid execution can fail; upfront payment has no automatic refund. Failure and recovery semantics.
Python API · Configuration · Security · Contributing
Two modes and Envar onboarding
Pay per call confirms USDC before one MCP capability executes. Pay per task locks funds and requires an explicit acceptance/rejection/expired refund; it remains experimental and Base Sepolia only. The task contract is unaudited.
EnvarPay 0.1.0a8 provides connect for atomic endpoint proof/connection setup,
approve-peer for explicit local capability authorization, reviewed call_agent
through the private wallet, and authenticated task wallet-serve. One Envar Agent
can retain private Agent, paid capability and wallet entries. Wallets never enter
public discovery. Keys, funding, budgets and signing enablement stay local.
Metadata
Release files for envarpay 0.1.0a8
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| envarpay-0.1.0a8.tar.gz | 253.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| envarpay-0.1.0a8-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 317.6 kB
Release files / envarpay-0.1.0a8.tar.gz
| Download URL | envarpay-0.1.0a8.tar.gz |
|---|---|
| Size | 253.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
336109beb9fe7143191306c35e145325fd2821ef54dc3e5babe17b15e504ac67
|
|
BLAKE2b-256 checksum How to use checksums |
51f0d47d4752cd350cb8a4dbd271b1540595308235ab9dfaa827b18a20f00659
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / envarpay-0.1.0a8-py3-none-any.whl
| Download URL | envarpay-0.1.0a8-py3-none-any.whl |
|---|---|
| Size | 64.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f72681acbb1d1ffacd940f5bad036c52d92945305ac983167e876c4febf8fac3
|
|
BLAKE2b-256 checksum How to use checksums |
cd499081b4e65566cb497bcf867a9bebff6330dab31acb324cb2935768b757ee
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log