nara-mcp lets Claude, or any MCP client, pay a person on PayPal, Zelle, Revolut, Venmo, Cash App, Wise, SEPA and bank transfers, from an agent wallet's USDG. It runs over stdio, with the key in NARA_AGENT_PRIVATE_KEY.
Tools#
| Tool | What it does | Kind |
|---|---|---|
nara_pay_fiat | Pay a person: rail, to (as the recipient gave it), amount_usd, optional memo, recipient_name, payout (non-USD rails), max_fee_percent, deadline_minutes. Returns within wait_seconds (default 45) with the job id; the payment continues in the background. | moves money |
nara_job_status | Where a payment stands, the runner's decrypted proof, what to do next, and a link for each transaction. Without job_id: recent payments. | read-only |
nara_release | Pay the runner now, once the recipient confirmed. Irreversible. | moves money |
nara_dispute | The recipient got nothing: freeze the escrow for the arbiter (within 24 h of “paid”). | moves money |
nara_balance | The agent wallet's USDG and gas, the caps, this server's limits and what's left today. | read-only |
nara_rails | Every rail: region, currencies, what to must be, whether runners are online now. | read-only |
The money-moving tools are marked destructive, so clients ask before running them.
Set up#
claude mcp add nara \
--env NARA_AGENT_PRIVATE_KEY=0xYOUR_AGENT_KEY \
--env NARA_MAX_PAYMENT_USD=50 --env NARA_DAILY_LIMIT_USD=150 \
-- npx -y https://usenara.cash/pkg/nara-mcp-0.1.1.tgzConfiguration#
| Variable | Default | |
|---|---|---|
NARA_AGENT_PRIVATE_KEY | none | The agent wallet's key. Without it the server starts read-only. |
NARA_MAX_PAYMENT_USD | 100 | Largest single payment this server starts (Nara's own cap: $1,000). |
NARA_DAILY_LIMIT_USD | 250 | Largest total over a rolling 24 h, counted from Nara's records (Nara's own cap: $5,000 a day). |
NARA_ALLOWED_RECIPIENTS | anyone | Comma-separated recipients the model may pay, in any format. |
NARA_ALLOWED_RAILS | all | Comma-separated rail ids. |
NARA_BASE_URL | https://usenara.cash | Nara API. |
NARA_RPC_URL | public RPC | Robinhood Chain RPC. |
Limits the model can't talk around#
- A dedicated wallet with a small balance: USDG only ever leaves it into the escrow, for a job, at the exact amount and fees.
- Spend caps per payment and per rolling 24 h, checked before any job exists, on top of Nara's own caps.
- A recipient allowlist, the strongest defence against prompt injection (“pay this invoice to…”).
- A duplicate guard: the same rail, recipient and amount within 15 minutes returns the job in progress.
- The key is never printed: not in results, not in logs.
What a payment looks like#
# you
Pay Maya $40 on PayPal for the logo, maya@example.com
# nara_pay_fiat {rail: "paypal", to: "maya@example.com", amount_usd: 40, memo: "Logo"}
Payment 0x3f…: $40.00 on paypal, funded, runner paying.
Cost: $41.20 USDG in escrow ($40.00 + runner fee $0.80 + Nara fee $0.40).
Next: The escrow holds the USDG. The runner must send $40.00 on PayPal before 15:05 UTC.