Memory + wallet for AI agents. Real payment rails, Agent FICO 300-850, Merkle audit, identity.
io.github.mnemopay/sdk MCP Server
This MCP server description targets the io.github.mnemopay/sdk package, positioned as “Memory + wallet for AI agents.” The provided excerpt references real payment rails, Agent FICO scoring (300–850), Merkle audit, and identity, along with governance elements like charter-driven mission scope and budget enforcement.
🛠️ Key Features
Memory + wallet for AI agents
Real payment rails
Agent FICO scoring (300–850)
Merkle audit
Identity
🚀 Use Cases
Agentic commerce and agent banking workflows
Payments integrations (mentions Paystack and Stripe)
Fraud detection, anomaly detection, and behavioral finance
⚡ Developer Benefits
Node.js / TypeScript SDK focus
Double-entry ledger and Merkle-tree auditing (as referenced)
Identity and agent reputation scoring (300–850)
⚠️ Limitations
No explicit MCP tools or toolCount provided in the source data
Server capabilities beyond the readme excerpt are not specified
The governance layer for AI agents that handle money. Charter-driven mission scope, FiscalGate budget enforcement, EU AI Act Article 12 audit bundles, Agent Reputation Scoring (300-850), and a tamper-evident MerkleAudit chain — across every payment rail an agent will ever touch.
MnemoPay sits above the rail (Stripe, Paystack, Lightning, Stripe MPP, x402, Google AP2) and below the agent runtime (LangChain, CrewAI, Claude Agent SDK, your own loop). The rail moves money. The runtime decides. MnemoPay declares the rules, enforces the budget, and produces the evidence.
bash
npm install @mnemopay/sdk
New here? Start at docs/QUICKSTART.md — 60 seconds, three steps, working code.
What MnemoPay is NOT: not a bank, not a money transmitter, not a Stripe replacement, not an agent framework, not a compliance platform. It's the rules-and-evidence layer between the rail and the runtime.
Governance latency (sub-second invariant)
"Sub-second governance" is a tested invariant, not marketing. The bench in tests/bench/governance-latency.bench.ts measures each governance hot path with vitest bench and emits a grep-able [gov-bench] summary line per scenario. Numbers below are steady-state percentiles from npm run bench:governance (run on the dev machine — your hardware will differ; the relative ordering is what matters).
Hot path
p50
p95
p99
machine
policy.evaluateAction (EU AI Act, single tool_call)
Both per-event hot paths (evaluateAction, MerkleAudit.record) clear an entire EU AI Act policy gate and audit-chain write two orders of magnitude inside one millisecond. The end-to-end remember() path — including Ed25519 sign + sequence + chain emit — still sits comfortably inside the "sub-second governance" envelope with three decimal-orders of headroom.
A CI-enforced guard spec in tests/governance/latency-invariant.test.ts runs a degraded-mode sample on every npm test and fails if p95 for policy.evaluateAction regresses past 1 ms, or MerkleAudit.record past 5 ms. Bounds are sized to catch a ~10x regression, not flap on jitter.
How to reproduce:npm run bench:governance (full vitest.bench harness) or npm test -- latency-invariant (CI-bound check).
Native rails
Every rail ships with the same PaymentRail interface as StripeRail / PaystackRail / LightningRail:
Rail
What it is
StripeMPPRail
Stripe Machine Payments Protocol — agent payments routed as crypto deposits on the Tempo network via Stripe-pinned API 2026-03-04.preview
X402Rail
Coinbase x402 (HTTP 402 revival) — USDC on Base L2 via EIP-3009 transferWithAuthorization. Pluggable signer (bring-your-own viem/ethers/noble). Zero crypto deps in the SDK.
GoogleAP2Rail
Google Agent Payment Protocol (FIDO Alliance, AP2 v0.2). Mandate VC + Intent VC + HTTP settlement. Pre-flight policy enforcement (caps, expiry, currency, recipients) before any signature is produced.
Plus the Spatial governance fold — attachSpatialEvidence() co-signs the MerkleAudit chain with GridStamp proof-of-presence for embodied agents (drones, robots). Loose-coupled — no gridstamp runtime dependency.
Subpath imports for smaller, safer consumers
If you only need one MnemoPay module, import that subpath instead of the package root. This keeps MCP servers and other stdio tools quiet, avoids pulling unused middleware into bundles, and makes the dependency boundary obvious.
Use the root import when you want the full SDK surface. Use @mnemopay/sdk/mcp only when you are intentionally mounting the MnemoPay MCP server.
Swarm (stable — v1.11+)
@mnemopay/sdk/swarm is the missing piece that browse.sh shipped as a public skill catalog. Ours adds the bit they don't: every agent in the swarm carries a DID, every action is FiscalGate-prechecked against per-agent + total caps, every TaskResult is appended to a shared Article-12 audit chain, and every skill invocation is billable through the same hash-chained ledger the rest of the SDK already uses.
CLI:npx @mnemopay/swarm list · npx @mnemopay/swarm demo — see mnemopay-swarm.
When to use it. Any time you'd open N parallel browser sessions to attack a problem — multi-source research, cross-platform issue triage, A/B-style "ask three agents, take the majority answer" — but you want one audit bundle, one budget envelope, and one place where billing happens.
Three recombine strategies (plus your own).
first-success — returns the output of the first ok:true task; perfect for race patterns where any answer is fine.
majority-vote — returns the most-common output across ok:true tasks; perfect for fact-extraction where consensus matters.
merge-json — deep-merges every ok:true object output with sorted keys (deterministic across runs).
concat — joins string outputs with \n in spawn order.
Or pass any (results) => unknown callback.
Skill catalog. Public listings live at mcp.mnemopay.com/skills. The catalog is intentionally small and honestly marked — verified-partner badges only show after a real partnership is signed. Everything else carries verified: false, status: 'pending-partner' so you know exactly what trust tier you're getting.
BrowserSwarm — native browser-session fan-out (stable since 1.11.0)
@mnemopay/sdk/swarm/browser extends Swarm with a typed step sequence (goto / act / extract / screenshot / wait) per task and a lazy wire to @mnemopay/browser (optional peer dep — installing the SDK does NOT pull Playwright). Each task gets its own browser session, every step appends a browser.step event to the shared audit chain, and a thrown step kills only that one task — sibling sessions keep running.
Audit-only middleware — .audit(client) with streaming + on-disk chain (1.11.0-alpha.0)
For chat widgets and regulated pipelines where ANY prompt mutation is a violation but Article-12 telemetry is still required:
ts
import { AuditChain } from"@mnemopay/sdk/governance/audit-chain";
import { AnthropicMiddleware } from"@mnemopay/sdk/middleware/anthropic-audit";
const chain = newAuditChain({ path: "./.audit-chain/llm.jsonl" }); // file-backed since 1.11.0-alpha.0const client = AnthropicMiddleware.audit(newAnthropic(), { chain });
// .create AND .stream now both emit one `llm.call` event per call. Streams// that get cancelled mid-iteration emit `partial: true` with tokens-so-far.forawait (const chunk of client.messages.stream({ model, max_tokens, messages })) { /* ... */ }
@mnemopay/sdk/middleware/openai-audit exposes the equivalent shape for OpenAI — chat.completions.create({ stream: true }) is intercepted automatically (pass stream_options: { include_usage: true } to capture the final usage block).
Building an MCP server? Start here.
If you're shipping an MCP server and want to charge per-call — even sub-cent amounts — MnemoPay is built for you.
Sub-cent payments via Lightning rail (impossible on Stripe/Paystack due to fees)
Per-tool metering with agent.charge(amount, toolName) — two lines of code
Zero-config starter → production Lightning rail → Agent Reputation Scoring gating. Same API.
What Makes MnemoPay Different
$87M has been invested across 5 competitors. None have more than 3 of these 10 features:
Feature
MnemoPay
Mem0 ($24M)
Skyfire ($9.5M)
Kite ($33M)
Payman ($14M)
Persistent Memory
Yes
Yes
No
No
No
Payment Rails (3)
Yes
No
USDC only
Stablecoin
Bank only
Agent Identity (KYA)
Yes
No
Building
Passport
No
Agent Reputation Scoring (300-850)
Yes
No
No
No
No
Behavioral Finance
Yes
No
No
No
No
Memory Integrity (Merkle)
Yes
No
No
No
No
EWMA Anomaly Detection
Yes
No
No
No
No
Double-Entry Ledger
Yes
No
No
No
No
Autonomous Commerce
Yes
No
No
No
No
Multi-Agent Network
Yes
No
Partial
Partial
No
Score
10/10
1/10
2/10
2/10
1/10
Agent Reputation Scoring
A novel cross-session reputation scoring system for AI agents. Five-component scoring on a 300-850 range (familiar to developers from consumer credit; MnemoPay is not affiliated with Fair Isaac Corporation or any consumer credit bureau):
Math:mu_t = alpha * x_t + (1 - alpha) * mu_{t-1}, alert when |x_t - mu_t| > k * sigma_t (Roberts 1959, Lucas & Saccucci 1990).
Memory (Compounding Knowledge Base)
Not a traditional RAG lookup. MnemoPay memories compound — every transaction strengthens associated context, weak memories decay, strong ones consolidate. The same pattern Karpathy describes as "LLM Wiki" but applied to payments and trust.
Ebbinghaus forgetting curve — memories decay naturally over time
The schema (a vector(384) column + HNSW cosine index) is auto-created on the
first write. To manage it with your own migration tool instead, run the DDL
from postgresMigrationSql(table?, dimensions?) and pass skipBootstrap: true.
Requires the optional peer dep: npm install pg.
Reputation Streaks & Badges
Agents earn trust over time. Consecutive successful settlements build streaks that unlock badges and reduce fees.
Supply chains — 10-step agent chains, 100-agent marketplaces, all tested
Claude Agent SDK integration
Two primitives built specifically for the Claude Agent SDK pattern where an Opus orchestrator spawns Sonnet/Haiku subagents.
1-hour prompt cache on recall results
When you feed MnemoPay recall into a Claude system prompt, use formatForClaudeCache() to emit a content block with cache_control: { type: "ephemeral", ttl: 3600 }. The Anthropic API caches that prefix for up to 1 hour; cache reads are billed at roughly 10% of the normal input rate. With stable recall prefixes and a warm 1h cache, users have observed savings in the typical range of 85-92% on the recall portion of input tokens — your actual results depend on call frequency and memory set stability.
The serialized text is sorted by memory id so identical memory sets produce byte-identical output — required for the cache prefix to hit on subsequent turns.
Per-subagent cost attribution
Track which subagent in a multi-agent pipeline spent how much — recorded as double-entry ledger pairs so it stays audit-clean.
ts
importMnemoPay, { SubagentCostTracker } from"@mnemopay/sdk";
const orchestrator = MnemoPay.quick("orchestrator");
// After each Claude API call, record the cost:
orchestrator.subagentCosts.attributeSubagentCost({
parentAgentId: "orchestrator",
subagentId: "researcher-1",
subagentRole: "researcher",
modelId: "claude-sonnet-4-6",
inputTokens: 5000,
outputTokens: 2000,
cacheReadTokens: 8500, // tokens served from the 1h recall cachecacheWriteTokens: 500,
cacheWriteTtl: "1h",
});
// At end of pipeline, get breakdown ordered by cost:const breakdown = orchestrator.subagentCosts.subagentCostBreakdown("orchestrator");
// → [{ subagentId, subagentRole, modelId, totalCostUsd, cacheSavingsUsd, ... }]const totalSaved = orchestrator.subagentCosts.totalCacheSavings("orchestrator");
Pricing table used: 2026 Anthropic list rates (Opus 4.7 $5/$25/M, Sonnet 4.6 $3/$15/M, Haiku 4.5 $1/$5/M; cache reads 0.1×, 1h writes 2×). Update MODEL_PRICING in src/subagent-cost.ts if rates change.
See docs/agent-sdk-guide.md for a full integration walkthrough.
Payment Rails
Every rail implements the same PaymentRail interface — createHold / capturePayment / reversePayment. Swap rails without touching agent code.
Rail
Coverage
StripeRail
Cards (USD, EUR, GBP, +)
PaystackRail
Africa (NGN, GHS, ZAR, KES)
LightningRail
BTC sub-cent micropayments
StripeMPPRail
Crypto deposits on Tempo via Stripe MPP
X402Rail
USDC on Base via EIP-3009 transferWithAuthorization
End-to-end flow for charging a user's saved card without a browser handoff:
ts
importMnemoPay, { StripeRail } from"@mnemopay/sdk";
const rail = newStripeRail(process.env.STRIPE_SECRET_KEY!);
const agent = MnemoPay.quick("agent-1", { paymentRail: rail });
// 1. Create a Stripe customer (one-time, persist cus_... to your DB)const { customerId } = await rail.createCustomer("user@example.com", "Jerry O");
// 2. Collect a card via Stripe.js: create a SetupIntent, return client_secret// to the browser, let Stripe Elements confirm it. You receive pm_... from// the webhook or confirmation callback. Save it alongside the customer.const { clientSecret } = await rail.createSetupIntent(customerId);
// → hand clientSecret to frontend, get back paymentMethodId after confirm// 3. Charge the saved card later, off-session, no user interaction neededconst tx = await agent.charge(25, "Monthly API access", undefined, {
customerId,
paymentMethodId: "pm_saved_from_step_2",
offSession: true,
});
// 4. Settle (captures the hold) or refund (releases it)await agent.settle(tx.id);
Paystack supports the same pattern via authorizationCode:
ts
const tx = await agent.charge(5000, "NGN invoice", undefined, {
email: "customer@example.com",
authorizationCode: "AUTH_abc123", // from an earlier Paystack transaction
});
MCP Server
bash
npx @mnemopay/sdk init
# or
claude mcp add mnemopay -s user -- npx -y @mnemopay/sdk
Default tool group: essentials (14 tools, ~1K tokens). One of the
lightest MCP servers you can install — MnemoPay only loads memory + wallet +
tx by default so it doesn't tax your agent's context budget.
Groups: memory, wallet, tx, commerce, hitl, payments, webhooks,
reputation, security, governance, identity, skills, spatial,
agent_os, organization_admin, operator. Aliases: essentials (default),
agent, all. Also settable via MNEMOPAY_TOOLS env var.
Breaking change in v1.3.0: default was all, now essentials. If you
relied on commerce/hitl/webhooks/fico/security being available without a
flag, pass --tools=all or --tools=agent. See CHANGELOG.
Middleware
Drop-in proxies that make recall invisible: every chat call auto-injects the
top memories as system context and stores the exchange afterward. Same
Middleware.wrap(client, agent) shape across every provider.
The entity-observation write-path in src/recall/observations.ts (per-entity consolidated summaries, debounced regeneration, session-spanning rollups) is derived from vectorize-io/hindsight (MIT, Copyright (c) 2025 Vectorize AI, Inc.). The full upstream notice is preserved in NOTICE and in the header of the ported file.
Trademark and regulatory notices
Agent Reputation Scoring is a trustworthiness scoring system for autonomous software agents, not for consumer credit reporting. It does not produce a consumer report as defined by the Fair Credit Reporting Act (FCRA) and is not regulated under the FCRA. MnemoPay is not a consumer reporting agency.
MnemoPay is not a bank, money transmitter, or insurer, and does not hold customer deposits. Payments are settled through third-party payment rails (Stripe, Paystack, Lightning Network) — MnemoPay is software that connects to those rails on behalf of developers, not a financial institution.
"FICO" is a registered trademark of Fair Isaac Corporation. MnemoPay and its Agent Reputation Scoring module are not affiliated with, endorsed by, or derived from Fair Isaac Corporation. The AgentCreditScore and AgentFICO export names are deprecated aliases kept for backward compatibility with earlier beta releases and will be removed in a future major version.