Per-call paid skills for AI agents, run server-side: inputs in, outputs back. The body never ships.
Thin MCP stdio client for Sealed — the skill marketplace where your skill runs sealed.
This package is a pure proxy. It connects your MCP-capable agent to a remote Sealed server and exposes two tools:
| Tool | What it does | Annotations |
|---|---|---|
list_skills | Lists the public skill catalog (name, description, input schema, price per call) | readOnlyHint: true |
run_skill | Runs a skill server-side and returns only its output + price/mode meta. Each call spends wallet balance at the listed per-call price. | readOnlyHint: false, destructiveHint: false |
Skill bodies never reach this process. Skills execute on Sealed's infrastructure; this client only carries your inputs up and the output back. There is no local execution mode — SEALED_API_URL is required.
Zero runtime dependencies. Plain Node 18+ (uses the global fetch).
npm naming: this package targets the unscoped name
sealed-mcpand carriesmcpName: io.github.edwardyen724-g/sealedfor the official MCP registry. If that npm name is unavailable at publish time, the fallbacks are the scoped names@sealed/mcpor@sealedrun/mcp— updatepackage.json, registry drafts, and install snippets together.
claude mcp add sealed --env SEALED_API_URL=https://sealed.run --env SEALED_API_KEY=sealed_sk_… -- npx -y sealed-mcp
Add to ~/.cursor/mcp.json (Cursor) or ~/.codeium/windsurf/mcp_config.json (Windsurf):
{
"mcpServers": {
"sealed": {
"command": "npx",
"args": ["-y", "sealed-mcp"],
"env": {
"SEALED_API_URL": "https://sealed.run",
"SEALED_API_KEY": "sealed_sk_…"
}
}
}
}
Spawn the binary and speak newline-delimited JSON-RPC 2.0 over stdin/stdout (initialize, tools/list, tools/call):
SEALED_API_URL=https://sealed.run SEALED_API_KEY=sealed_sk_… npx -y sealed-mcp
| Variable | Required | Purpose |
|---|---|---|
SEALED_API_URL | Yes | Base URL of the Sealed API (e.g. https://sealed.run). The client exits with an error if unset. |
SEALED_API_KEY | No | Your Sealed API key (sealed_sk_…), sent as the bearer token. Without it, calls run unauthenticated and most servers will reject paid runs. |
Fixed, non-leaking error strings: unauthorized (bad/missing key), insufficient funds (top up your wallet), output blocked by leak gate, unknown skill: <id>, cannot reach the Sealed API. Server error bodies are never echoed.
/signup endpoint (production emails you a single-use sign-in link that shows the key once)Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y sealed-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-edwardyen724-g-sealed": {
"command": "npx",
"args": [
"-y",
"sealed-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencesealed-mcpnpmSealed works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.