# Payaion (npm · @payaion/mcp)

Agent file transfer. No API key to start; price downloads in USDC on Base.

- Trust score: 62/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-07

## Components

- npm · `@payaion/mcp`: 62/100 (this document), [markdown](https://verifymcp.io/servers/defdone-payaion/payaion-mcp.md), [page](https://verifymcp.io/servers/defdone-payaion/payaion-mcp)
- pypi · `payaion-mcp`: 56/100, [markdown](https://verifymcp.io/servers/defdone-payaion/payaion-mcp-2.md), [page](https://verifymcp.io/servers/defdone-payaion/payaion-mcp-2)

## Channel facts

- Registry: `npm`
- Package: `@payaion/mcp`
- Version: `1.0.5`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-07.

- **Supply Chain Security**: 100/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - No production dependencies, so there is no dependency health to assess.
- **Provenance & Transparency**: 19/100
  - Repository check failed: no source repository is declared.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 0 days ago).
  - Security-disclosure policy not yet verified: we couldn't inspect the source repository.
- **Schema Quality & AI Usability**: 65/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 1594 tokens (~177/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add defdone-payaion -- npx -y @payaion/mcp
```

### Codex

```bash
codex mcp add defdone-payaion -- npx -y @payaion/mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "defdone-payaion": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@payaion/mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add defdone-payaion --command npx --arg -y --arg @payaion/mcp
```

### Hermes

```yaml
mcp_servers:
  defdone-payaion:
    command: "npx"
    args: ["-y", "@payaion/mcp"]
```

### Other

```json
{
  "mcpServers": {
    "defdone-payaion": {
      "command": "npx",
      "args": [
        "-y",
        "@payaion/mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-07 (score 62, +28)

- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] MCP protocol: unverified → pass
- [functional] First check of Tool coverage: 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: good
- [functional] First check of Tool coverage: 100

### 2026-08-06 (score 34)

First indexed and scored.

## MCP tools (9)

### `upload_file` (~293 tokens)

Upload File

Low-level upload. Prefer the 'transfer' tool instead — it handles polling automatically. This tool returns immediately with PENDING_UPLOAD status; you must poll get_upload_status yourself. Max file size follows the account plan (Basic 500 MB / Pro 1 GB). Provide EITHER 'filePath' (local stdio only) OR 'content' (base64). Use only when you need explicit control over the upload lifecycle.No API key required — without one you upload as a guest (100 MB, 24-hour link); a key raises the limits and lets you sell.

Input parameters:

- `content` (string): Base64-encoded file content (standard or URL-safe base64)
- `fileName` (string): Original filename with extension (e.g. report.pdf). Required when using 'content', optional for 'filePath' (derived from path).
- `filePath` (string): Absolute path to a local file. Only works when this MCP server runs locally (stdio transport). Preferred over base64 — zero tokens wasted.
- `idempotencyKey` (string): Unique key for retry-safe uploads
- `mimeType` (string): MIME type override (auto-detected if omitted)
- `pricePerDownload` (number): Price per download in USD (e.g. 0.50 or 0.00005). When set, downloaders pay this amount in USDC. Omit for free downloads.

Output parameters:

- `downloadUrl` (string): Shareable download URL (works without auth, valid 24h)
- `expiresAt` (string): ISO 8601 expiration timestamp
- `status` (string): Upload status: PENDING_UPLOAD, UPLOADING, READY, or FAILED
- `uploadId` (string): Unique upload identifier (e.g. up_a1b2c3d4e5f6g7h8)

### `upload_from_url` (~206 tokens)

Upload from URL

Low-level upload from URL. Prefer the 'transfer' tool instead — it handles polling automatically. This tool returns immediately with PENDING_UPLOAD status; you must poll get_upload_status yourself. Max file size follows the account plan (Basic 500 MB / Pro 1 GB). Private/internal URLs are blocked. Use only when you need explicit control over the upload lifecycle.No API key required — without one you upload as a guest (100 MB, 24-hour link); a key raises the limits and lets you sell.

Input parameters:

- `fileName` (string): Optional filename override (derived from URL if omitted)
- `idempotencyKey` (string): Unique key for retry-safe uploads
- `pricePerDownload` (number): Price per download in USD (e.g. 0.50 or 0.00005). When set, downloaders pay this amount in USDC. Omit for free downloads.
- `url` (string, required): Public HTTPS URL of the file to upload

Output parameters:

- `downloadUrl` (string): Shareable download URL (works without auth, valid 24h)
- `expiresAt` (string): ISO 8601 expiration timestamp
- `status` (string): Upload status: PENDING_UPLOAD, UPLOADING, READY, or FAILED
- `uploadId` (string): Unique upload identifier (e.g. up_a1b2c3d4e5f6g7h8)

### `transfer` (~366 tokens)

Transfer File

One-shot file transfer with optional pricing and marketplace listing. Upload a file, set a per-download price, and list on the marketplace — all in a single call. Returns a shareable download URL. Supports free transfers, paid downloads, and marketplace listings. Provide EXACTLY ONE of: 'filePath' (local stdio — zero tokens), 'url' (remote fetch), or 'content' (base64 fallback).No API key required — without one you upload as a guest (100 MB, 24-hour link); a key raises the limits and lets you sell.

Input parameters:

- `content` (string): Base64-encoded file content (fallback when filePath and url are unavailable).
- `fileName` (string): Filename with extension. Required for 'content', optional for 'url'.
- `filePath` (string): Absolute path to a local file (stdio transport only — zero token cost).
- `idempotencyKey` (string): Unique key for retry-safe transfers.
- `listingCategory` (string): Marketplace category.
- `listingDescription` (string): What the buyer gets (40–500 chars). Required when listingTitle is set.
- `listingTags` (array): Discovery tags (max 8, alphanumeric + dash).
- `listingTitle` (string): Marketplace listing title (3–120 chars). When set, auto-lists the file on the marketplace once ready.
- `mimeType` (string): MIME type override (auto-detected if omitted).
- `pricePerDownload` (number): Price per download in USD (e.g. 0.50). Downloaders pay in USDC. Omit or 0 for free.
- `url` (string): Public HTTPS URL of the file to upload (server fetches it directly — no token cost).

Output parameters:

- `downloadUrl` (string): Shareable download URL (works without auth, valid 24h)
- `expiresAt` (string): ISO 8601 expiration timestamp
- `ready` (boolean): True when the file is downloadable right now
- `status` (string): Final status: READY, FAILED, or TIMEOUT
- `uploadId` (string): Unique upload identifier (e.g. up_a1b2c3d4e5f6g7h8)
- `url` (string): Unified page URL (includes marketplace listing context when listed)

### `get_upload_status` (~143 tokens)

Get Upload Status

Check the processing status of a previously uploaded file. Returns the current status (PENDING_UPLOAD, UPLOADING, READY, FAILED) and whether the file is ready for download. Rarely needed — the 'transfer' tool handles polling automatically. Use this only to check on uploads that timed out or for manual status inspection.No API key required — without one you upload as a guest (100 MB, 24-hour link); a key raises the limits and lets you sell.

Input parameters:

- `uploadId` (string, required): Upload ID returned from upload_file or upload_from_url (e.g. up_a1b2c3d4e5f6g7h8)

Output parameters:

- `ready` (boolean): True when the file is fully replicated and downloadable
- `status` (string): Current status: PENDING_UPLOAD, UPLOADING, READY, or FAILED
- `uploadId` (string): The upload identifier

### `get_download_url` (~110 tokens)

Get Download URL

Get a fresh shareable download URL for a previously uploaded file. The file must be in READY status. Share this URL with anyone — it works without authentication.No API key required — without one you upload as a guest (100 MB, 24-hour link); a key raises the limits and lets you sell.

Input parameters:

- `uploadId` (string, required): Upload ID returned from upload_file or upload_from_url (e.g. up_a1b2c3d4e5f6g7h8)

Output parameters:

- `downloadUrl` (string): Shareable download URL (works without auth)
- `expiresAt` (string): ISO 8601 expiration timestamp
- `ready` (boolean): True when the file is downloadable
- `uploadId` (string): The upload identifier

### `list_on_marketplace` (~157 tokens)

List on Marketplace

List an already-uploaded file on the public Payaion marketplace. The upload must be READY status and have a price set. Returns the unified page URL where buyers can view details and download. Requires the agent key owner to own the upload.

Input parameters:

- `category` (string): Optional file category
- `description` (string, required): What the buyer gets (40–500 characters). Required.
- `tags` (array): Optional tags for discoverability (max 8, alphanumeric with hyphens)
- `title` (string, required): Listing title (3–120 characters).
- `uploadId` (string, required): Upload ID to list (e.g. up_a1b2c3d4e5f6g7h8)

Output parameters:

- `listed` (boolean): Whether the file was successfully listed
- `uploadId` (string): Upload ID that was listed
- `url` (string|null): Unified page URL for the listing

### `browse_marketplace` (~118 tokens)

Browse Marketplace

Search and browse active listings on the Payaion marketplace. Filter by keyword, category, and paginate through results. Returns listing details including title, price, file info, and unified page URL. No API key required.

Input parameters:

- `category` (string): Filter by category.
- `page` (integer): Page number (default 1, max 100).
- `pageSize` (integer): Results per page (default 20, max 100).
- `q` (string): Search query — matches title and description (max 100 chars).

Output parameters:

- `listings` (array): Array of marketplace listings
- `page` (number): Current page number
- `pageSize` (number): Results per page
- `total` (number): Total number of matching listings

### `get_payment_requirements` (~76 tokens)

Get Payment Requirements

Retrieve payment requirements for a marketplace asset before purchasing. Returns whether the asset is free or paid. For paid assets, includes the x402 payment requirements object that must be signed by the buyer's wallet and passed to the purchase_asset tool.

Input parameters:

- `uploadId` (string, required): Upload ID of the marketplace asset to check payment requirements for.

Output parameters:

- `asset` (object): Asset metadata.
- `isFree` (boolean): Whether the asset can be downloaded for free.
- `paymentRequirements` (object): x402 payment requirements — present only for paid assets. Sign this with your wallet and pass to purchase_asset.

### `purchase_asset` (~125 tokens)

Purchase Asset

Finalize the purchase of a paid marketplace asset. Requires a signed x402 payment payload from the buyer's wallet. First call get_payment_requirements to obtain the payment requirements, sign them with your EVM wallet, then pass the signed payload here. Returns the purchase receipt including a directDownloadUrl — you can GET that URL with your X-Aion-Key header to download the file immediately, no extra steps needed.

Input parameters:

- `paymentPayload` (object, required): Signed x402 payment payload from the buyer's wallet.
- `uploadId` (string, required): Upload ID of the marketplace asset to purchase.

Output parameters:

- `directDownloadUrl` (string): Authenticated API endpoint for direct file download. GET this URL with your X-Aion-Key header to stream the file immediately after purchase.
- `downloadUrl` (string): Public URL to download the purchased asset.
- `payerAddress` (string): Wallet address that paid for the asset.
- `purchaseId` (string): Unique purchase receipt ID.
- `status` (string): Purchase status — "settled" on success.
- `txHash` (string|null): On-chain transaction hash, if available.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/defdone-payaion/payaion-mcp#diagnostics

## Score history

- 2026-08-07: 62
- 2026-08-06: 34

## Links

- npm package: https://www.npmjs.com/package/@payaion/mcp
- Socket report: https://socket.dev/npm/package/@payaion/mcp
- Website: https://payaion.com/
- Changelog RSS feed: https://verifymcp.io/servers/defdone-payaion/payaion-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/defdone-payaion/payaion-mcp.json
- HTML version of this page: https://verifymcp.io/servers/defdone-payaion/payaion-mcp
