x402check runs on your own machine — the client starts it, so there is no endpoint to ping. 97 installs a week from npm. Last commit 7 Oct 2026.
Risk-check counterparties before an AI agent pays; pay x402 resources only after a verified allow
We read the source, 3 d ago · rules ccca72095570
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
subprocess.run(["ffmpeg", "-y", "-framerate", str(FPS), "-i",
img.save(os.path.join(OUT, f"{name}-{idx}-{i:04d}.png"))
export const ICON_PNG_B64 = "iVBORw0KGgoAAAANSUhEUgAAAQAAAAEACAYAAABccqhmAAAYv0lEQVR42u3deXhTVf4G8Pd7k6ZtWgpdUgptwREsICKLuMCoIMrmyoCUgiggLqAzLuMCKsyAM47bjNsAggsIsoOIigOKyo5IlfWnQgdUaAttU1pom9I2zT2/P1R0ZGubkyZp3s/z8DzaNifnnnPPe8+5ublXEITi4uJiDCO8tViNVlBoDUgrAc5RIo0BFQ0gGpAoAWJB5CU…
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add x402check -- npx -y @x402check/mcp
{
"mcpServers": {
"x402check": {
"args": [
"-y",
"@x402check/mcp"
],
"command": "npx"
}
}
}
[mcp_servers.x402check]
command = "npx"
args = ["-y", "@x402check/mcp"]
{
"mcpServers": {
"x402check": {
"args": [
"-y",
"@x402check/mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"x402check": {
"args": [
"-y",
"@x402check/mcp"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
X402CHECK_CREDIT_TOKEN (Prepaid credit token (x402c_…, from POST https://x402check.xyz/v1/credits): $0.001 a check), X402CHECK_PAYER_KEY (Private key of a dedicated low-balance wallet: pays the x402 resources x402check_pay clears, and per-call checks without credits), X402CHECK_BUDGET_USD (Spend cap for this server process: the payer's spend (checks and resources), and separately what checks spend from prepaid credits), X402CHECK_PINNED_KEYS (Comma-separated RFC 7638 thumbprints of the attestation keys accepted (default: x402check's own keys, for its own issuer)), X402CHECK_MAX_PAYMENT_USD (The most a single payment may cost (a check or a resource)).
The author declared them in the registry entry; get the values from the project itself.
Check an x402 endpoint before your agent pays: pay, skip or recheck. Plus a verified x402 catalog.
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.
Screen the counterparty of an x402 payment before an agent pays it. Runs offline by default.
Verified directory for machine payments (x402 & MPP): check services and wallets before agents pay.
Pay-per-call x402 checks before an agent moves money: token safety, wallet risk, identifiers.
Check stablecoin and x402 payments before an AI agent pays: approve, hold or reject.
Check a Base counterparty before you pay it: EAS attestations and on-chain risk reports.
Checks a counterparty before an AI agent pays: what the evidence supports, and for how much.
Answers built from our own checks of this server.