receiptrail

MCP serverCommerce & finance

Lets your agent verify that an x402 payment actually settled by checking its transaction receipt.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the issue receipt tool from receiptrail

About this server

Read-only on-chain receipt check for x402 payments; confirm settlement before trusting a tx.

Install receiptrail

The server’s own address, for the clients that take one directly. Or connect ahel onceand every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.

  • Claude Code

    claude mcp add --transport http --scope user receiptrail 'https://agenttoll-receipts.app.workbuddy.host/mcp'

    Run it once in your project, then open /mcp to approve any sign-in the server asks for.

  • Claude Desktop

    https://agenttoll-receipts.app.workbuddy.host/mcp

    Add a custom connector in Settings, paste this address, and approve the sign-in.

  • Cursor

    cursor://anysphere.cursor-deeplink/mcp/install?name=receiptrail&config=eyJ1cmwiOiJodHRwczovL2FnZW50dG9sbC1yZWNlaXB0cy5hcHAud29ya2J1ZGR5Lmhvc3QvbWNwIn0=

    Open the link and Cursor adds the server at that address.

  • ChatGPT

    https://agenttoll-receipts.app.workbuddy.host/mcp

    In Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.

  • Codex

    codex mcp add receiptrail --url 'https://agenttoll-receipts.app.workbuddy.host/mcp'

    Run it once, then sign in with codex mcp login receiptrail if the server asks for an account.

From the project's README

As published by xka0085-byte/agenttoll in README.md.

⚠️ Official project notice / 身份声明: This is the official ReceiptRail repository, maintained by GitHub org xka0085-byte and npm account eidonze. We are NOT affiliated with agenttoll.dev, npm/agent-toll, agenttoll-mcp (Base), @agenttoll/sdk, 402.ad/AgentToll, or the "Receiptrail" accounting SaaS. Verify you are talking to this project by checking: MCP endpoint https://agenttoll-receipts.app.workbuddy.host/mcp · Official MCP Registry id io.github.xka0085-byte/receiptrail · npm package receiptrail-mcp (published by eidonze).

🔎 Early access (2 slots): I'll manually inspect your x402 endpoint's payment-to-delivery path and send you a conformance report within 24h — $9/$19. Details: https://x402-endpoint-inspection.app.workbuddy.host/

ReceiptRail is an on-chain delivery-receipt service for x402 AI-agent payments on Solana: after a settlement, sellers anchor a SHA-256 digest of the delivered content plus the settlement reference into a public PDA. Anyone — the buyer agent, an auditor, a regulator — can independently verify what was delivered, without trusting the vendor, the buyer, or any API we operate.

⚡ Live service (use it now)

SurfaceEntry
MCP endpoint (streamable-http)https://agenttoll-receipts.app.workbuddy.host/mcp
Official MCP Registryio.github.xka0085-byte/receiptrail
npm (stdio MCP bridge)npx -y receiptrail-mcp
Agent Card / SKILL.md / llms.txt/.well-known/agent-card.json · /SKILL.md · /llms.txt
Pricing (0.001 USDC/receipt via x402)https://agenttoll-receipts.app.workbuddy.host/
Toolsissue_receipt · verify_receipt · get_receipt · verify_x402_receipt

🆕 verify_x402_receipt — official x402 receipt-format verification (v0.3)

The x402 Foundation now ships a standard Signed Offers & Receipts extension (docs.x402.org/extensions/offer-receipt, npm @x402/extensions): servers sign an offer on every 402 and a receipt on every 200 — portable proof-of-interaction artifacts for reputation, auditing and disputes.

ReceiptRail is a Solana-side verification node for that format: our MCP tool verify_x402_receipt validates any official-format receipt artifact (JWS with EdDSA/Ed25519 — Solana-native — or ES256/P-256), resolves the signer key automatically from did:key / did:web / did:jwk, enforces freshness and payload assertions, and anchors verification results on-chain. Cross-verified against the official @x402/extensions verifier (same verdicts on valid and tampered artifacts — see receipts-service/test/cross-verify.mjs).

Keywords for agent discovery: x402 receipt, x402 offer-receipt, signed receipt verification, x402 dispute, delivery receipt, proof of delivery, proof of payment, Solana, USDC, MCP, AI-agent payments, verifiable settlement, agent reputation, on-chain audit.

Agent / Chain Evidence Tools — the suite

ReceiptRail is the flagship of a six-tool evidence suite (all read-only, no keys, JSON output):

ToolWhat it checks / provesTry
ReceiptRailon-chain x402 delivery receipts (Solana)live MCP endpoint
mcpdoctorx402 payment endpoint & MCP server preflightnpx @eidonze/mcpdoctor
oauthdoctorMCP OAuth discovery diagnosticsnpx oauthdoctor
x402-reconcilex402 402-challenge inspectornpx x402-reconcile
wallet-evidenceSolana transaction evidence reportsnpx wallet-evidence
crosschain-incidentcross-chain message incident normalizationnpx crosschain-incident

Live tools page: https://x402-endpoint-inspection.app.workbuddy.host/tools.html


AgentToll is the delivery-receipt protocol behind ReceiptRail. A vendor pins the SHA-256 digest of a report's exact bytes into a public PDA account on-chain. Anyone can independently recompute the digest from the delivered file and compare it against the chain, without trusting anyone.

"Don't trust what we say. Run the command." Every capability claim in this README maps to a command in this repo and, where possible, a Solscan link on devnet.

Status: W1–W3 complete, independently audited (reports in audit/). Deployed on Solana devnet.

Honesty note: the demo uses test-USDC, a self-issued devnet mint with no real-world value. It is not real USDC. We say so everywhere, including in code output.

Why this exists

Machine-to-machine payments (the x402 pattern) are becoming real: agents pay per API call. But after an agent pays, it holds no trustworthy proof of what it received. Receipts, invoices, or hashes served by the vendor itself are indistinguishable from fabricated ones. AgentToll moves that proof to a neutral public ledger: the digest is written once, is tamper-evident (same id + different digest is rejected on-chain), and is verifiable offline forever.

Verify an existing receipt right now (no vendor involved)

cd verifier && npm install && cd ..
node verifier/verify.mjs \
  --url https://api.devnet.solana.com \
  --vendor B7wGaKwEGAmNP7PEhqwFrvfCQPH4zwiE7FZNLoeB4naD \
  --report-id x402-demo-001 \
  --file demo/report-402.json

Expected: JSON with "verdict": "PASS" and all five checks true (C1 ownership, C2 PDA derivation, C3 schema, C4 content binding, C5 freshness). Exit code 0. Then tamper with the file (add one byte) and rerun — C4 fails, exit code 1. That mismatch is the product.

Architecture

sequenceDiagram
    participant B as Buyer agent
    participant V as Vendor HTTP service
    participant S as Solana devnet
    participant C as Offline verifier
    B->>V: GET /report/x402-demo-001
    V-->>B: HTTP 402 + payment challenge
    B->>S: SPL transferChecked (test-USDC)
    B->>V: POST + X-Payment-Signature
    V->>S: getParsedTransaction, verify payment
    V->>S: create_receipt(report_id, SHA-256)
    V-->>B: report bytes + receipt metadata
    B->>C: Spawn verifier with local report
    C->>S: Read receipt PDA via public RPC
    C-->>B: C1-C5 PASS/FAIL JSON

The on-chain program enforces the anti-tamper rule at the ledger level: a PDA seeded by (vendor, report_id) can be created once; re-creating with the same digest is idempotent, with a different digest fails with DigestConflict. Overwrites are impossible, not just discouraged.

Run the full x402 demo

Requires Node.js 22+, a devnet-funded vendor keypair, and the deployed program above.

# 0. install the single JS dependency set
cd verifier && npm install && cd ..

# 1. configure (bash example)
export AGENTTOLL_RPC_URL='https://api.devnet.solana.com'
export AGENTTOLL_KEYPAIR='/absolute/path/to/vendor-keypair.json'

# 2. create test-USDC mint, fund buyer (idempotent)
node demo/setup.mjs

# 3. start vendor (localhost:8787)
node demo/vendor.mjs

# 4. unpaid request must be refused
curl -i http://127.0.0.1:8787/report/x402-demo-001        # → HTTP 402

# 5. run the buyer agent: pay → receive report+receipt → verify 5/5
node demo/buyer-agent.mjs

# 6. forged payment signatures must be rejected
curl -i -X POST -H 'X-Payment-Signature: not-a-real-signature' \
  http://127.0.0.1:8787/report/x402-demo-001              # → HTTP 402, no report

demo/buyer-agent.mjs prints {payment_sig, receipt_tx, pda, verifier_verdict, checks} and exits 0 only if the spawned offline verifier passes all five checks.

On-chain program (W1)

Anchor 1.2.0, two instructions:

  • create_receipt(report_id, digest) — first call creates the PDA; same id + same digest is idempotent; same id + different digest → DigestConflict
  • verify_receipt(report_id, digest) — permissionless; emits a ReceiptVerified event

Build and test locally:

./build.sh        # = anchor build --arch v0
cargo test --all  # 8 litesvm tests, incl. DigestConflict & idempotency

Audits

Every milestone was reviewed by an independent auditor that did not write the business code. Reports with command outputs and on-chain evidence:

Scope & limitations (read before trusting anything)

  • test-USDC is self-issued on devnet; it stands in for a real stablecoin. No real value.
  • The demo serves one report id on localhost; it is a protocol demo, not a hosted service.
  • The on-chain receipt binds report_id + digest; the payment signature is linked via the demo flow, not stored on-chain (the frozen W1 schema has no such field). See W3 audit §findings.
  • A professional third-party security audit is on the roadmap and has not happened yet.

Disclosed prior work

This project was built for the Colosseum CWF hackathon. Per the rules, we disclose pre-existing development: t3n-recon-agent and z-tenant-recon — a TEE-based prototype implementing the same anti-tamper digest logic (same-id-different-digest rejection, independent verifier), from which the on-chain design was ported. All AgentToll commits, tests, and deployments happened during the competition window (first commit: 2026-09-14).

中文说明见 README.zh-CN.md。

Suite hub

Part of the Agent / Chain Evidence Tools suite — read-only, no-keys, no-payments diagnostics for AI agents on Web3.

Tools it offers (3)

What this server listed when ahel dialed its public endpoint in Sep 2026, with no key and no account of yours. The names are the server’s own.

  • issue_receipt
  • verify_receipt
  • get_receipt

Signals

Last commit
Sep 2026
Advanced
Delivery
receiptrail MCP server → your ahel connector (mcp.ahel.ai) → your AI.
Item type
mcp-server
Key
io-github-xka0085-byte-receiptrail
Source
github.com/xka0085-byte/agenttoll
Hosted endpoint
https://agenttoll-receipts.app.workbuddy.host/mcp