Zen7 Payment AgentCAUTION
Zen7 Payment Agent is the first implementation project of DePA (Decentralized Payment Agent), pioneers next-generation intelligent payment infrastructure.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE) [](https://python.org) [](https://github.com/astral-sh/uv) 中文版本
Real-time progress updates can be viewed on page Real-time progress For support on the x402 protocol, please click here
Zen7 Payment Agent is the first practical implementation of DePA (Decentralized Payment Agent), pioneering the next generation of intelligent payment infrastructure. It not only fully implements the core functionalities of DePA but also successfully deploys innovative application cases in the agentic commerce domain.
As the first practical project in the DePA ecosystem, Zen7 implements several key features: automated encrypted payments between agents, a "permissionless authorization" mechanism, and LLM-driven intent recognition and interaction.
Zen7 Payment Agent adopts a multi-agent collaborative architecture, supporting both A2A and MCP protocols, as well as custodial and non-custodial payment models. It provides a comprehensive payment solution for AI Agents and native Dapp applications with multi-chain, multi-currency, multi-wallet support, high-frequency transactions, gasless operations, and passwordless authentication.
Navigating the Repository
This repository contains the complete implementation of Zen7 Payment Agent, showcasing the core components and architectural design based on the Zen7 Payment Agent (Decentralized Payment Agent) protocol.
Core Directory Structure
The core implementation of the project is located in the following key directories:
**[host_agent](ht
8902686008f7OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add zen7-payment-agent --env ACTIVE_TOKEN=${ACTIVE_TOKEN} --env FEE_PAYER_KEY=${FEE_PAYER_KEY} --env PAYER_PRIVATE_KEY=${PAYER_PRIVATE_KEY} --env PRIVATE_KEY=${PRIVATE_KEY} -- uvx zen7-payment-agent{
"mcpServers": {
"zen7-payment-agent": {
"command": "uvx",
"args": [
"zen7-payment-agent"
],
"env": {
"ACTIVE_TOKEN": "${ACTIVE_TOKEN}",
"FEE_PAYER_KEY": "${FEE_PAYER_KEY}",
"PAYER_PRIVATE_KEY": "${PAYER_PRIVATE_KEY}",
"PRIVATE_KEY": "${PRIVATE_KEY}"
}
}
}
}Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
proceed_payment_or_settlement_or_order_or_allowance_details | write |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (15)
logger.info(f">>> {token} Contract Address: {TOKEN_ADDRESS}")logger.info(f">>> {token} Mint Address (Token Contract): {token_config['mint_address']}")logger.info(f">>> Payer {token} Balance: {token_balance_display} {token}")logger.warning(f"Warning: Payer's {token} Token Account does not exist")logger.warning(f"Warning: Failed to query {token} balance: {e}")bytes.fromhex(r[2:]) if r.startswith('0x') else bytes.fromhex(r), # Remove 0x prefixbytes.fromhex(s[2:]) if s.startswith('0x') else bytes.fromhex(s) # Remove 0x prefixbytes.fromhex(r[2:]) if r.startswith('0x') else bytes.fromhex(r),bytes.fromhex(s[2:]) if s.startswith('0x') else bytes.fromhex(s)key_bytes = bytes.fromhex(key_hex)
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
8902686008f7full audit observations/trust-audit/mcp-server/zen7-labs__zen7-payment-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 8902686008f7 | CAUTION | B | 86 | first audit |
Questions
What is the Zen7 Payment Agent MCP server?
Zen7 Payment Agent is the first implementation project of DePA (Decentralized Payment Agent), pioneers next-generation intelligent payment infrastructure.
What tools does Zen7 Payment Agent expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Zen7 Payment Agent safe to connect to an agent?
With care. The audit graded it B (86/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Zen7 Payment Agent need?
It reads ACTIVE_TOKEN, FEE_PAYER_KEY, PAYER_PRIVATE_KEY, PRIVATE_KEY, SOLANA_PAYER_PRIVATE_KEY and SPENDER_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Zen7 Payment Agent run?
It speaks sse, so it runs as a service you connect to over the network. It is published on PyPI as zen7-payment-agent.
How current is this page?
The grade is for one exact copy of the source (8902686008f7), read on 2026-10-06. The repository is watched and re-audited when it changes.