agentscore-pay --mcp exposes the AgentScore CLI as an MCP server over stdio. AI agents and coding assistants can register the binary once and call every wallet, payment, and identity command as a tool; wallet management, x402/MPP payments, on-the-fly assessments, verification sessions, operator credentials, and wallet attribution all in one server.
Install
AGENTSCORE_API_KEY for identity tools (assess, sessions, credentials, and associate-wallet) available on every tier and metered by quota (paid tiers raise the limits). Wallet and payment tools are local and need no key.
Register with your agent
Manual config: Claude Desktop
Add to~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
Manual config: Cursor
Add to.cursor/mcp.json (project) or ~/.cursor/mcp.json (global) with the same shape.
Available tools
Every command fromagentscore-pay --help is exposed as a tool. The most agent-relevant ones:
Wallet + payment
Identity (any tier: set AGENTSCORE_API_KEY)
Run
agentscore-pay --llms for the full machine-readable manifest (or --llms --format json for JSON Schema).
Denial-code handling
assess, sessions, credentials and associate-wallet turn the API’s typed errors into structured CliError codes with hint lines, so agents act from the response without parsing raw 4xx/5xx shapes: config_error (an API-key problem, or an operator token that expired or is not recognized; extra carries verify_url / session_id / poll_secret when the API minted a recovery session), insufficient_balance (the endpoint is not enabled for the account), quota_exceeded (account cap reached; retrying will not help), and network_error (rate limit, timeout or transient failure; retry with backoff). A compliance deny is not an error: it comes back as decision: "deny" with decision_reasons.
A merchant’s own denial codes (missing_identity, identity_verification_required, wallet_not_trusted, …) reach the agent through pay, in the merchant’s 403 body and its agent_instructions.
Use cases
Agent-to-agent trust; runassess on another agent’s wallet before initiating a transaction.
Gateway pre-screening; an agent acting as a gateway screens incoming requests with assess.
Autonomous payment; discover a 402-gated endpoint, probe it with agentscore-pay check, dry-run with agentscore-pay pay --dry-run, then settle the payment via agentscore-pay pay. All without leaving the MCP loop.
Identity bootstrap; an agent encounters an AgentScore-gated merchant for the first time, receives a missing_identity denial, calls sessions_create → polls sessions_get → uses the returned operator_token to retry the original request.
Environment variables
Running locally
{"jsonrpc":"2.0","id":1,"method":"tools/list"} to it to enumerate tools.