Skip to main content

M2M Sentinel SDK & MCP Server

Official multi-language client library, Model Context Protocol (MCP) server, and Coinbase AgentKit ActionProvider for M2M Sentinel — deterministic EVM bytecode capability observations and common-proxy resolution for autonomous applications operating on Base. Callers own transaction policy.

npm version PyPI version License: MIT Smithery


⚡ 1. Model Context Protocol (MCP) Server

Connect M2M Sentinel directly to Claude Desktop, Cursor, Windsurf, or any MCP-compliant LLM agent.

Option A: 1-Click via Smithery

npx -y @smithery/cli mcp add M2M-Sentinel/m2m-sentinel-sdk --client claude

Option B: Local Stdio (claude_desktop_config.json)

{
  "mcpServers": {
    "m2m-sentinel": {
      "command": "npx",
      "args": ["-y", "m2m-sentinel-sdk"],
      "env": {
        "M2M_SENTINEL_API_KEY": ""
      }
    }
  }
}

Option C: Remote Streamable HTTP

  • Current MCP endpoint: https://api.m2msentinel.com/mcp
  • Legacy HTTP+SSE compatibility: https://api.m2msentinel.com/sse with messages at https://api.m2msentinel.com/messages

🤖 2. Coinbase AgentKit Integration

import { AgentKit } from "@coinbase/agentkit";
import { m2mSentinelActionProvider } from "m2m-sentinel-sdk";

const agentKit = await AgentKit.from({
  walletProvider,
  actionProviders: [
    m2mSentinelActionProvider({
      apiKey: process.env.M2M_SENTINEL_API_KEY
    })
  ]
});

📦 3. JavaScript / TypeScript Client

npm install m2m-sentinel-sdk
const { M2MSentinelClient } = require('m2m-sentinel-sdk');

const client = new M2MSentinelClient();

async function main() {
  const audit = await client.auditContract('0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913');
  console.log('Proxy Detected:', audit.audit.proxyResolution.isProxy);
  console.log('Proxy Target:', audit.audit.proxyResolution.targetAddress);
  console.log('Capabilities:', audit.audit.verdict.executableCapabilities);
  console.log('Evidence:', audit.audit.dissection.capabilities);
}

main().catch(console.error);

🛡️ Base Account wallet_sendCalls Guard

The public SDK includes guardWalletSendCalls, a customer-side execution-identity boundary for Base Account / EIP-5792 batches. It preflights the anchor call and evaluates its caller policy before scheduling any remaining call, then pins remaining calls to the first trusted block identity in waves of at most four. Each settled wave is validated and policy-checked in ascending request-index order before a later wave starts; a failure or rejection stops later scheduling. The original detached request is forwarded only after all checks pass. It does not sign, broadcast, custody funds, infer inner UserOperation semantics, or make a safety claim. See examples/base_account_paymaster_guard.js for a no-network fixture.


🐍 4. Python Client

pip install m2m-sentinel
from m2m_sentinel import M2MSentinelClient

client = M2MSentinelClient()
audit = client.audit_contract("0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913")
print("Proxy detected:", audit["audit"]["proxyResolution"]["isProxy"])
print("Proxy target:", audit["audit"]["proxyResolution"].get("targetAddress"))
print("Capabilities:", audit["audit"]["verdict"]["executableCapabilities"])
print("Evidence:", audit["audit"]["dissection"]["capabilities"])

Transaction-specific preflight example

The public repository includes a standalone, mock-only transaction boundary example at examples/transaction_preflight.js. From this repository root, run:

node examples/transaction_preflight.js

It observes one caller-supplied Base transaction, passes the observation to a caller-owned policy, and reaches only a mock signing/send callback. It refuses to continue on unverified evidence, unresolved execution, an observation mismatch, or a missing Diamond selector mapping. It never signs or sends a transaction; optional live mode uses only a caller-supplied API-key header and remains the caller's responsibility.


💳 5. Autonomous x402 Micropayments (Headless M2M)

import { x402SignerClient } from "m2m-sentinel-sdk";

const client = new x402SignerClient({
  walletSigner: myAgentWallet,
  baseUrl: "https://api.m2msentinel.com"
});

const result = await client.request("/v1/audit/0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913");

📜 License

MIT License. Copyright (c) 2026 M2M Sentinel.

Metadata

Release files for m2m-sentinel 1.2.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for m2m-sentinel 1.2.7
File Size Uploaded
m2m_sentinel-1.2.7.tar.gz 13.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for m2m-sentinel 1.2.7
File Interpreter ABI Platform
m2m_sentinel-1.2.7-py3-none-any.whl Python 3 none any Details

Total release size: 27.8 kB

Release files / m2m_sentinel-1.2.7.tar.gz

Download URL m2m_sentinel-1.2.7.tar.gz
Size 13.9 kB
Tags Source
SHA-256 checksum
How to use checksums
cc7ca9e5a7ed4df8bddffafdff9aec10aeb1ff40d5ef3a15b492bb2ae85bc039
BLAKE2b-256 checksum
How to use checksums
d1e06e422b0a09f43c1e587d49ea7e85b72673d1d6ba1d4b0b6570205c032730
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.

Transparency log

Release files / m2m_sentinel-1.2.7-py3-none-any.whl

Download URL m2m_sentinel-1.2.7-py3-none-any.whl
Size 13.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
eb48c3deea6ddfee724bde77423c00ed5551b5f2a7b1a1f28e8dbf8f94fff381
BLAKE2b-256 checksum
How to use checksums
1bf1b68cb940dd000924e42eff542ed20fac7f176f54f3ddde112b9d9473f294
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.2.7 This release

2 release files

1.2.5

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.2

2 release files

1.1.0

2 release files

1.0.4

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page