Back to Directory/Developer Tools

io.github.dingdawg/agent-spend-policy-mcp

Local agent spend-policy checks. No funds, keys, payment authority, or network access.

Developer ToolsTypeScriptv0.1.1

DingDawg Agent Spend Policy MCP

A small, local MCP server that deterministically evaluates whether a proposed agent spend action matches a supplied policy.

It returns one of ELIGIBLE, DENY, or STEP_UP, with a stable reason code. ELIGIBLE is local policy evidence only. It is not payment authorization.

Safety boundary

This package does not hold funds, private keys, payment credentials, customer data, or settlement authority. It does not sign, send, settle, custody, or record payments. It makes no network requests.

A production payment adapter needs separate, independently verified controls for authenticated policy/action provenance, canonical payload hashing, durable atomic budget reservation and replay protection, customer-controlled signing, rail validation, and settlement reconciliation.

Install

npx -y @dingdawg/agent-spend-policy-mcp

Configure it as a local stdio MCP server:

{
  "mcpServers": {
    "dingdawg-agent-spend-policy": {
      "command": "npx",
      "args": ["-y", "@dingdawg/agent-spend-policy-mcp"]
    }
  }
}

Tool

evaluate_spend_policy accepts an evaluation time, a policy, a proposed action, and the already-spent amount. All money is passed as integer micro-unit strings, never JavaScript floating-point numbers.

The caller supplies the clock and already-spent value; therefore this tool is safe for dry runs and local evidence, not a replacement for a trusted payment or accounting system.

Agent contract

The versioned machine-readable contract is capabilities.json. It describes the only tool this package exposes, its required inputs, its three possible outcomes, and its non-negotiable safety boundary.

  • Transport: local stdio MCP
  • Tool: evaluate_spend_policy
  • Required inputs: evaluationTime, policy, action, and alreadySpentMicros
  • Outputs: ELIGIBLE, DENY, or STEP_UP, each with a stable reason code
  • Side effects: none
  • Credentials, payment execution, custody, signing, settlement, and network access: not supported

The manifest is package-source evidence for this release, not a promise of a hosted agent-discovery endpoint. ELIGIBLE remains local policy evidence only, not payment authorization.

Development

npm install
npm test
npm run pack:check

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @dingdawg/agent-spend-policy-mcp

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-dingdawg-agent-spend-policy-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@dingdawg/agent-spend-policy-mcp"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@dingdawg/agent-spend-policy-mcpnpm

Compatible MCP Clients

io.github.dingdawg/agent-spend-policy-mcp works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More