Give your AI agent a
Canton wallet

Canton payments, inside your AI app.

An MCP server that gives an AI agent a Canton wallet to pay for the x402-gated APIs it calls. Run @ftptech/canton-x402-mcp locally with npx and the key stays on your machine. Or connect the hosted server by URL from Claude, ChatGPT, or Perplexity, where FTP Tech holds the key. Both limit what the agent can spend.

What it provides

The same seven wallet tools run in two places: a local server you start with npx, and a hosted server you connect by URL. Both limit what the agent can spend and settle on Canton MainNet.

Local or hosted

Run the server with npx in Claude Code, Claude Desktop, or any host that can start a local process. Assistants that connect only by URL, such as claude.ai, ChatGPT, and Perplexity, use the hosted server.

Two custody models

On the local server, the Ed25519 key is generated and held on the machine that runs it. On the hosted server, FTP Tech holds the key, encrypted at rest.

Capped spending

Locally, the owner sets a per-transaction cap, a daily cap, and a domain allowlist at startup. The hosted server limits every user to 5 CC per payment and 20 CC per day. The agent cannot change either.

Pays x402 APIs

A new wallet is sent a small Canton Coin starter grant. The agent pays x402-gated endpoints, and each payment settles on-ledger on Canton MainNet.

How it works

Connect the server once. The first tool call creates the wallet, the agent pays an x402-gated URL, and the on-ledger updateId proves it settled.

Connect

Locally, the owner adds the server with one command that also sets the spend policy. For the hosted server, the user adds the URL as a connector and signs in with a passkey.

Fund

The first tool call creates the wallet. The relay sends a new wallet a small starter grant, 0.2 CC on MainNet, accepted within about a minute. For more, or if no grant arrives, request_funding writes a message asking the owner to send Canton Coin.

Pay

The agent calls pay on an x402-gated URL. The server signs the transfer with the wallet key; the signed payload travels in the payment header and the merchant's facilitator relays it on-ledger.

Verify

The tool returns the response and the on-ledger updateId. The wallet balance is the proof a payment landed.

The first payment takes about 60 to 90 seconds while Canton creates the payment counter. That is warm-up, not a failure; later payments are quick. A 200 response is never the proof a payment landed, the on-ledger balance is.

The building blocks

The local server is a process your host runs, with a key it holds on disk. The hosted server runs the same tools for assistants that connect by URL. Both submit through a facilitator relay that pays gas without custody.

Local MCP server

Runs over local stdio and exposes the wallet as tools. The Ed25519 key is generated on first use, held in the server's home directory, and never returned by any tool or sent to the relay.

@ftptech/canton-x402-mcp

Hosted MCP server

The same tools over HTTPS, for assistants that connect by URL. Each user signs in with a passkey and gets one wallet. FTP Tech holds the wallet key, encrypted at rest.

pay.ftptech.xyz/mcp

Facilitator relay

Onboards each wallet's party, submits the signed transactions, and pays gas. It cannot move the funds.

facilitator.ftptech.xyz

Run it locally

Add the server to any host that can start a local process, such as Claude Code or Claude Desktop. The owner sets it up once, and the key stays on that machine.

Hosts that attach MCP servers only by URL, such as ChatGPT, Perplexity, and claude.ai, cannot start a local process. Use the hosted server for those.

claude mcp add canton-x402 -- npx -y @ftptech/canton-x402-mcp \
  --relay-url https://facilitator.ftptech.xyz \
  --allow-domains api.cantrustai.xyz \
  --daily-cap 5 --max-per-tx 1

Replace the caps with your limits, then restart the client. For Claude Desktop, the JSON goes in claude_desktop_config.json; other hosts that read an mcpServers config take the same block. Flags: --relay-url is required, --allow-domains is the pay allowlist (comma-separated; empty denies every pay, * allows any), and --daily-cap and --max-per-tx are the spend limits in CC. Add --home <dir> to keep the wallet in its own directory (default ~/.canton-agent). After it connects, have the agent call get_address, then get_balance to see the starter grant arrive.

MCP toolsLocal and hosted
  • get_addressReturns the wallet's Canton party id. Creates the wallet on first use.read
  • get_balanceReturns the on-ledger Canton Coin balance and says when an incoming transfer is waiting to be claimed.read
  • request_fundingReturns the party id and a paste-ready message asking the owner to send Canton Coin. Moves nothing.read
  • claimAccepts pending incoming transfers, Canton Coin and USDCx alike. Run after the owner sends funds.funds in
  • payPays an HTTP 402 / x402-gated URL and returns the response. Calls the URL exactly once.money out
  • withdrawSends Canton Coin to another Canton party.money out
  • swapSwaps Canton Coin for a registry token such as USDCx, or back, on Cantex Connect or the Tradecraft AMM.money out

@ftptech/canton-x402-mcp 2.2.0 (Apache-2.0). Requires Node 18 or newer with npx. The hosted server exposes the same seven tools. The key is never returned by any tool; back up a local wallet with the canton-agent-wallet CLI against the same home directory.

Spend policy

On the local server, the owner sets the spend policy at startup. The agent cannot change it.

--daily-cap <CC>

Cap on outbound spend across pay and withdraw over a rolling 24-hour window. No built-in default; unset means uncapped, and the connect snippet sets 5. Set 0 to freeze.

--max-per-tx <CC>

Per-transaction cap. No built-in default; the connect snippet sets 1. Enforced before signing on both withdraw and pay: on pay the cap is handed to the signer, which refuses an over-quote before anything reaches the relay.

--allow-domains <csv>

The hosts pay may target. Empty denies every pay; withdraw is not domain-gated. Use * to allow any host.

--no-funded-ceiling

By default, total outbound spend can never exceed what the wallet has received, including the starter grant. This flag turns that guard off.

Every cap is checked before a transaction is signed, and a refusal sends nothing to the relay. The per-transaction cap reaches pay as well: the price is only known mid-request, so the cap is handed to the paying fetch and the signer refuses a quote above it. A payment is additionally bounded by the daily cap, the funded ceiling, the domain allowlist, and balance accounting. The hosted server applies one policy to every user: 5 CC per payment and 20 CC per day.

Connect by URL

For assistants that connect to MCP servers by URL and cannot start a local process. Add the address as a custom connector and sign in once with a passkey. The hosted server is custodial: FTP Tech holds the wallet key.

Hosted MCP server
https://pay.ftptech.xyz/mcp

Canton MainNet. The same seven tools as the local server: get_address, get_balance, request_funding, claim, pay, withdraw, swap.

Claude

On claude.ai or in Claude Desktop, add a custom connector and paste the URL.

ChatGPT

Turn on developer mode, then add the URL as a connector. Developer mode is available on paid plans.

Perplexity

Add a custom connector and paste the URL.

Hosted serverpay.ftptech.xyz/mcp
  • Sign-inA passkey, created the first time you connect. Your wallet belongs to that account.
  • Recovery codeShown once, when you sign up. Save it. If you lose the passkey, the code signs you in to the same wallet and lets you set up a new passkey, which issues a new code and retires the old one.
  • WalletCreated on your first tool call and sent the same starter grant. To add more, send Canton Coin to the address from get_address, then have the assistant call claim.
  • Account pagepay.ftptech.xyz/account, signed in with your passkey. It shows the address, balance and history, and lets you set lower limits, disconnect assistants, manage passkeys, issue a new recovery code, export the wallet key or close the account.
  • WithdrawalsOnly to addresses you confirmed on your account page with your passkey. An assistant cannot send the wallet anywhere else. Paying for APIs is not affected.
  • Spend limitsAt most 5 CC per payment and 20 CC per day. You can set lower limits for your wallet on the account page.
  • NetworkCanton MainNet.

The hosted server is custodial

FTP Tech holds your wallet key, encrypted at rest with AES-256-GCM. It is decrypted only in memory while a call runs. You can export the key from your account page at any time, or run the local server with npx and hold it yourself.

Run it locally

Who it is for

The same server serves the builder shipping one agent, the long-running service that pays as it goes, and the institution that needs self-custody and on-ledger settlement.

AI-agent builders

Give a desktop or IDE agent its own Canton wallet so it can pay for the tools it calls, bounded by a policy you set at startup.

Autonomous services

A long-running agent starts from the starter grant or its owner's funding and settles payments with no human in the loop, capped by the daily limit, the allowlist, and the funded ceiling.

Institutions

Deploy agent payments with self-custody on the local server, on-ledger settlement on Canton MainNet, and a relay that controls no funds.

Giving your agents a wallet inside your app

FTP Tech LLC publishes the MCP server, operates the hosted server, and runs the facilitator relay both settle through. Reach out to discuss an integration.

Talk to us

On the local server, the Ed25519 key is generated and held on your machine and is never sent to the agent or to the relay. On the hosted server, FTP Tech holds the key, encrypted at rest.

The facilitator relay at facilitator.ftptech.xyz onboards the party, submits the signed transactions, and pays gas. It cannot move the funds. Settlement is verifiable on the ledger: every paid request resolves to an updateId on Canton MainNet.

Let’s build something
that stays online

Launching a network, need a battle-tested validator, or want a community that actually shows up? Talk to us.