Runtime security for AI agent commerce. CLI + MCP server blocks hallucinated purchases.
npx -y pop-pay{
"POP_CDP_URL": "http://localhost:9222",
"POP_ALLOWED_CATEGORIES": "[\"aws\",\"cloudflare\"]",
"POP_MAX_PER_TX": "100.0",
"POP_MAX_DAILY": "500.0",
"POP_GUARDRAIL_ENGINE": "keyword"
}Add this server entry to the mcpServers object in your Claude Desktop config, then restart the app.
{
"mcpServers": {
"io-github-100xpercent-pop-pay": {
"command": "npx",
"args": [
"-y",
"pop-pay"
],
"env": {
"POP_CDP_URL": "http://localhost:9222",
"POP_ALLOWED_CATEGORIES": "[\"aws\",\"cloudflare\"]",
"POP_MAX_PER_TX": "100.0",
"POP_MAX_DAILY": "500.0",
"POP_GUARDRAIL_ENGINE": "keyword"
}
}
}
}~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.jsonNo remote HTTP endpoint is advertised. Use the package or stdio setup shown in Install.
pop-pay is an MCP server for Runtime security for AI agent commerce. CLI + MCP server blocks hallucinated purchases.. It supports STDIO transport.
Use the generated config in Install. This server runs with npx -y pop-pay; add any required environment variables before starting your client.
Choose the Claude Desktop tab in Install and copy the config for npx -y pop-pay. Add required environment variables before starting Claude Desktop.
Choose the Claude Code tab in Install and copy the config for npx -y pop-pay. Add required environment variables before starting Claude Code.
Choose the Codex tab in Install and copy the config for npx -y pop-pay. Add required environment variables before starting Codex.
Choose the Cursor or VS Code tab in Install and copy the config for npx -y pop-pay. Add required environment variables before starting Cursor or VS Code.
pop-pay uses STDIO transport. Use the package or command config in Install.
pop-pay inventory is listed when the MCP endpoint exposes tools, resources, or prompts. Some servers require auth first.
pop-pay does not advertise a verified auth requirement. If discovery fails, it may still need provider login, an API key, a bearer token, or a session header.
| Package | Registry | Version | Inputs |
|---|---|---|---|
pop-paystdio | npm | 0.5.7 | Env: POP_CDP_URL Env: POP_ALLOWED_CATEGORIES Env: POP_MAX_PER_TX Env: POP_MAX_DAILY Env: POP_GUARDRAIL_ENGINE |