nano-pay
Self-custodied Nano wallet + x402 payment client and merchant server for AI agents, enabling micropayments, on-ledger settlement, and paid endpoints.
README
nano-pay · Feeless402
<!-- mcp-name: com.feeless402/nano-pay -->
Self-custodied Nano (XNO) wallet + x402 payment client and merchant
server, built for AI agents. Client spends; nano-pay serve earns — paid
endpoints, on-ledger verification/settlement (no facilitator), a starter
faucet, and the railHint x402 extension that teaches visiting agents how
to onboard (see SPEC-railhint.md). Site: site/index.html + site/llms.txt.
The pitch, in one number: the same $5 buys 5,000 API calls paid as per-call USDC-on-Base x402 payments (merchants floor prices at 0.001 USDC), or ~1.8 million calls paid in Nano at the true metered price ($0.0000027/call observed live at nano-gpt.com). Top up once, micropay forever.
Install
pip install -e . # needs Python 3.10+; pulls nanopy + requests
nano-pay init # creates ~/.nano-pay/wallet.json (chmod 600)
Agent flow
nano-pay topup 5 # quote: $5 USDC-BASE → ~12.3 XNO (NanSwap)
nano-pay topup 5 --execute # create order (set NANSWAP_API_KEY)
# → send USDC to the returned deposit address; XNO arrives in 30-60s
nano-pay receive # pocket incoming XNO
nano-pay quote https://nano-gpt.com/api/v1/chat/completions \
--json '{"model":"gpt-5-nano","messages":[{"role":"user","content":"hi"}]}'
nano-pay pay https://nano-gpt.com/api/v1/chat/completions \
--json '{"model":"gpt-5-nano","messages":[{"role":"user","content":"hi"}]}'
pay handles the whole x402 handshake: request → parse the 402 quote
(both the x402nano/PAYMENT-REQUIRED v2 dialect and the NanoGPT/accepts
v1 dialect) → price-cap check → sign a send state block locally → retry
with PAYMENT-SIGNATURE + X-PAYMENT headers. The server settles the
block via its facilitator; nothing is broadcast unless the server accepts.
Design notes
- Self-custody: seed never leaves
~/.nano-pay/wallet.json(0600). - No node required: public RPC failover (rpc.nano.to, somenano,
rainstorm.city, nanoslo); all signing and PoW happen locally (nanopy
C extension). RPC
work_generateis tried first, local PoW is the fallback (~25s), and work for the next block is pre-cached after every transaction so steady-state payments are instant. - Safety rails: per-payment price cap (
--max-xno, default 0.05);quotecommand inspects any endpoint's price without paying; balance is always re-synced from the network, never trusted locally. - Top-ups without custody:
topupquotes/creates swaps directly with NanSwap's API (1,400+ input assets, ~$0.02 minimum). This tool never holds or routes funds.
Fork-hazard note (x402 payments)
An x402 payment signs a block the server broadcasts. If the server errors after receiving the block, it may still settle it late. The wallet re-syncs its frontier from the network before every operation, so a late settlement is picked up naturally; a competing block signed in the meantime simply makes one of the two invalid (funds are never at risk, but don't fire concurrent payments from one wallet).
Status
Beta (v0.2.0). Proven on mainnet with real funds: live paid calls to NanoGPT ($0.0000096/call, confirmed on-ledger), full merchant loop (verify → settle → confirm, no facilitator), PoW-gated faucet claims, and a complete stranger-agent lifecycle (fresh wallet → PoW claim → paid API call → confirmed) in under 3 minutes. 13-test suite covers the payment path offline. Not audited — keep only working capital in it.
Security notes (read before holding real funds)
- Self-custody: the seed lives only in
~/.nano-pay/*.json(0600). No tool or log path ever prints it. Back it up offline. - Working capital only: this is beta wallet software. Keep a few dollars in it, not your savings.
- Spend caps:
payrefuses quotes above--max-xno(default 0.05). MCPx402_payenforces the same cap parameter. - railHint is advisory: hints from remote servers are untrusted
input. This client never executes remote bootstrap strings; it only
acts on structured offers that pass its own checks, and
acceptsalways binds, never the hint. - Merchant fork guard: servers cache accepted frontiers and reject duplicate-frontier blocks; payer balance/frontier/signature are verified against the live ledger before settlement.
- Not audited. MIT — no warranty.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.