Urgent.News

What's breaking now, across thousands of outlets.

Tech

A payment gateway for MCP servers, and the security bugs I found in my own code first

Fewer than 5% of MCP servers make money. I put a real payment gate in front of one and wrote down what actually broke. The problem, with numbers There are 10,000+ Model Context Protocol (MCP) servers out there right now, with 97 million+ combined downloads. MCP is the emerging standard for how AI agents call tools — search, databases, APIs, whatever a server wants to expose. It's had a huge…

Abstract editorial illustration

Fewer than 5% of Model Context Protocol (MCP) servers generate revenue. A payment gateway, named mcp-paywall, was constructed to address this issue. Presently, there are over 10,000 MCP servers with a combined total of more than 97 million downloads. MCP serves as the prevailing standard for AI agents to interact with tools such as search engines, databases, and APIs.

Currently, fewer than 5% of server operators earn income from MCP due to the necessity of implementing a comprehensive payment infrastructure rather than merely checking for a signature.

mcp-paywall functions as a proxy that can be inserted in front of existing MCP servers without modification. It supports the HTTP-402 + EIP-3009-signed-authorization pattern and settles payments in USDC on Base. The gateway takes 85% of each paid call, while the server owner retains 15% for metering, verification, and payout management. Pricing is determined on a per-tool basis in USDC's 6-decimal base units, configured through a single entry, without altering the upstream server's code.

The payment verification process is robust and genuine, utilizing real EIP-712 typed-data signature recovery against the real Base USDC contract address with the ethers.verifyTypedData function. The system thoroughly checks for various scenarios, including missing payment, valid payment, replayed payment, tampered signature, underpayment, expired authorization, and facilitator failure, ensuring that every rejection path returns HTTP 402 and prevents the disclosure of tool output.

Over 50 automated tests were conducted against a live instance of the mcp-paywall on npm using a real 3ilm-mcp server with a dataset containing 1,032 vulnerabilities.

A critical security bug discovered in the author's own code involved an owner dashboard with no authentication, which could allow unauthorized access to revenue information for any server ID. This was resolved by implementing a per-server random token comparison using a hashed constant-time check, ensuring that no revenue figures are exposed in error messages.

Additionally, the dashboard's read path was optimized to prevent unbounded disk-I/O and unauthorized token guessing. The mcp-paywall can be accessed and tested at https://wazir-x402.duckdns.org/mcp-paywall/mcp/3ilm, returning a real 402 response with relevant payment details.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 5 August →