{
  "id": 163516,
  "title": "A payment gateway for MCP servers, and the security bugs I found in my own code first",
  "url": "https://urgent.news/2026/08/05/a-payment-gateway-for-mcp-servers-and-the-security-bugs-i-found-in-my",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-05T07:08:12.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/holistis/a-payment-gateway-for-mcp-servers-and-the-security-bugs-i-found-in-my-own-code-first-337"
  },
  "original_language": "en",
  "account": "Fewer than 5% of Model Context Protocol (MCP) servers generate revenue. A payment gateway, named mcp-paywall, was constructed to address this issue. Presently, there are over 10,000 MCP servers with a combined total of more than 97 million downloads. MCP serves as the prevailing standard for AI agents to interact with tools such as search engines, databases, and APIs. Currently, fewer than 5% of server operators earn income from MCP due to the necessity of implementing a comprehensive payment infrastructure rather than merely checking for a signature.\n\nmcp-paywall functions as a proxy that can be inserted in front of existing MCP servers without modification. It supports the HTTP-402 + EIP-3009-signed-authorization pattern and settles payments in USDC on Base. The gateway takes 85% of each paid call, while the server owner retains 15% for metering, verification, and payout management. Pricing is determined on a per-tool basis in USDC's 6-decimal base units, configured through a single entry, without altering the upstream server's code.\n\nThe payment verification process is robust and genuine, utilizing real EIP-712 typed-data signature recovery against the real Base USDC contract address with the ethers.verifyTypedData function. The system thoroughly checks for various scenarios, including missing payment, valid payment, replayed payment, tampered signature, underpayment, expired authorization, and facilitator failure, ensuring that every rejection path returns HTTP 402 and prevents the disclosure of tool output. Over 50 automated tests were conducted against a live instance of the mcp-paywall on npm using a real 3ilm-mcp server with a dataset containing 1,032 vulnerabilities.\n\nA critical security bug discovered in the author's own code involved an owner dashboard with no authentication, which could allow unauthorized access to revenue information for any server ID. This was resolved by implementing a per-server random token comparison using a hashed constant-time check, ensuring that no revenue figures are exposed in error messages. Additionally, the dashboard's read path was optimized to prevent unbounded disk-I/O and unauthorized token guessing. The mcp-paywall can be accessed and tested at https://wazir-x402.duckdns.org/mcp-paywall/mcp/3ilm, returning a real 402 response with relevant payment details.",
  "summary": "Fewer than 5% of MCP servers make money. I put a real payment gate in front of one and wrote down what actually broke. The problem, with numbers There are 10,000+ Model Context Protocol (MCP) servers out there right now, with 97 million+ combined downloads. MCP is the emerging standard for how AI agents call tools — search, databases, APIs, whatever a server wants to expose. It's had a huge…",
  "key_points": [
    "mcp-paywall payment gateway created for MCP servers with over 97 million downloads",
    "mcp-paywall takes 85% of each paid call, server owner retains 15%",
    "Critical security bug fixed: owner dashboard with no authentication exposing revenue info"
  ],
  "editors_take": null,
  "illustration": "https://urgent.news/ill/163516.png",
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}