io.github.Dempty-glitch/z-zero-mcp
NPM · Z-ZERO-MCP-SERVER · SCANNED SEP 20
Payments for AI agents: gasless USDC on Base + JIT single-use virtual cards, PAN never in context.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 98 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 28 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability83
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2297 tokens (~153/item across 15 items; 14 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management97
- Stability observed for 29 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage98
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 94% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.Dempty-glitch/z-zero-mcp server?
io.github.Dempty-glitch/z-zero-mcp runs locally as an npm package, launched with npx -y z-zero-mcp-server. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · z-zero-mcp-server
claude mcp add dempty-glitch-z-zero-mcp -- npx -y z-zero-mcp-server
{
"mcpServers": {
"dempty-glitch-z-zero-mcp": {
"command": "npx",
"args": [
"-y",
"z-zero-mcp-server"
]
}
}
} {
"servers": {
"dempty-glitch-z-zero-mcp": {
"command": "npx",
"args": [
"-y",
"z-zero-mcp-server"
]
}
}
} codex mcp add dempty-glitch-z-zero-mcp -- npx -y z-zero-mcp-server
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"dempty-glitch-z-zero-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"z-zero-mcp-server"
],
"enabled": true
}
}
} openclaw mcp add dempty-glitch-z-zero-mcp --command npx --arg -y --arg z-zero-mcp-server
mcp_servers:
dempty-glitch-z-zero-mcp:
command: "npx"
args: ["-y", "z-zero-mcp-server"] {
"McpServers": {
"dempty-glitch-z-zero-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"z-zero-mcp-server"
]
}
}
} assistant mcp add dempty-glitch-z-zero-mcp -t stdio -c npx -a -y z-zero-mcp-server
{
"mcpServers": {
"dempty-glitch-z-zero-mcp": {
"command": "npx",
"args": [
"-y",
"z-zero-mcp-server"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- Stability: pass → 0.97 functional
- 19 Sept 26 0
- Stability: 0.97 → pass security
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 −3
- Stability: pass → 0.80 functional
- 12 Sept 26 0
- Stability: 0.97 → pass security
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/z-zero-mcp-server@1.10.1
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 98 packages
| Packages resolved | 98 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
auto_pay_checkout Auto-Pay Checkout (charges the card) ~108
⚠️ MANDATORY: Read mcp://resources/sop first. Only use on PAYMENT pages where final total is visible. Auto-detects Web3 or Fiat and completes payment. For physical goods (Shopify, Etsy), get_merchant_hints first.
| Name | Type | Req | Description |
|---|---|---|---|
| card_alias | string | yes | Card alias to charge for JIT Fiat fallback, e.g. 'Card_01'. |
| checkout_url | string | yes | Full URL of the checkout/payment page to analyze and pay. |
No output schema declared.
No examples provided.
cancel_payment_token Cancel Token — Safe Refund ~70
Cancel unused token and refund instantly. Use when user cancels the purchase or to free up a card slot.
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | yes | Reason for cancellation, e.g. 'Price mismatch: checkout shows $20 but token is $15' |
| token | string | yes | The payment token to cancel |
No output schema declared.
No examples provided.
check_balance Check Balance ~51
Check spendable USD balance for a card alias. For active token limits, use list_cards instead.
| Name | Type | Req | Description |
|---|---|---|---|
| card_alias | string | yes | The alias of the card to check, e.g. 'Card_01' |
No output schema declared.
No examples provided.
execute_payment Execute Payment (charges the card) ~359
Execute a payment with a one-time token. TWO CALLS: call it first WITHOUT `recheck` — nothing is charged and it hands you what the owner actually asked for, locked when the card was issued; look at the page again, then call it a second time with `recheck` to pay or to pause. Then Z-Zero opens a headless browser, injects the card (you NEVER see the PAN), clicks Pay, and watches for a REAL confirmation before reporting success. Returns a `status`: `confirmed` (order placed → token burned, receipt_id may hold a real order #), `declined` (merchant rejected → token kept for refund), `unconfirmed` (submitted but no confirmation seen → do NOT retry blindly, verify first), `not_submitted` (no Pay button → supply a submit_selector hint), or `no_fields`. ALWAYS pass actual_amount so overcharges are blocked and underspend refunded.
| Name | Type | Req | Description |
|---|---|---|---|
| actual_amount | number | – | STRONGLY RECOMMENDED. The final total shown on the checkout page (incl. shipping + tax). Enables the overcharge block and the underspend refund — omit only if it is genuinely unreadable. |
| checkout_url | string | yes | The full URL of the checkout/payment page |
| hints | object | – | Optional hints from get_merchant_hints — selectors and pre-steps to guide Playwright. Use when default selectors fail or for complex multi-step checkouts. |
| recheck | object | – | Your answer to the purpose check. Omit it on the first call — this tool will hand you the owner's locked criteria to read, then you call again with this. |
| token | string | yes | The temporary payment token from request_payment_token |
No output schema declared.
No examples provided.
get_deposit_addresses Get Deposit Address ~32
Get your Base deposit address to top up your wallet with USDC (or any supported stablecoin on Base).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_merchant_hints Merchant Checkout Hints ~87
Get merchant navigation flow for a domain or platform key (e.g. '_platform_etsy'). Returns pre_steps (how to navigate checkout) and platform notes. Call BEFORE starting checkout to understand the multi-step flow.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The main domain of the checkout page, e.g. 'amazon.com' or 'shopify.com'. Strip 'www.' prefix. |
No output schema declared.
No examples provided.
list_cards List Cards ~24
List all available virtual card aliases and their balances. No sensitive data is returned.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
report_checkout_fail Report Checkout Failure ~344
Report a checkout you could not complete. Pick the failure_class that best matches what you saw — this feeds Z-ZERO's self-healing loop (labeled failures become better merchant hints for the next run). If nothing fits, use 'unknown' and describe what happened in error_message.
| Name | Type | Req | Description |
|---|---|---|---|
| error_message | string | – | Brief description of what you saw, e.g. 'Card number field is inside a new iframe' or 'Page redirected to CAPTCHA'. NEVER include card numbers. |
| failure_class | string | yes | Fixed failure class: 'card_declined_issuer' (card rejected by bank), 'card_declined_bin_block' (merchant refuses prepaid/virtual cards), 'avs_mismatch' (billing address rejected), '3ds_required' (ext… |
| remediation_tried | string | – | What you already tried before giving up, e.g. 'retried with submit_selector from hints'. |
| step | string | – | Where it failed: 'navigate' (page load), 'pre_steps' (shipping/navigation steps), 'fill_form' (card fields), 'submit' (Pay button), 'confirm' (after submitting). |
| url | string | yes | The checkout/payment page URL where the purchase failed. |
No output schema declared.
No examples provided.
request_human_approval Show Approval Instructions ~124
Pause and ask the user for approval before risky actions (price mismatch, large amount, unusual request).
| Name | Type | Req | Description |
|---|---|---|---|
| alternative_action | string | – | Alternative option if available |
| current_token | string | – | Current active token ID if any |
| recommended_action | string | yes | What the bot recommends doing, e.g. 'Cancel current $15 token and issue a new $20 token' |
| situation | string | yes | Clear description of what the bot found, e.g. 'Checkout shows $20 total (includes $3 tax) but current token is only $15' |
No output schema declared.
No examples provided.
request_payment_token Issue JIT Card (spends $0.10 fee) ~466
Request a single-use JIT virtual card ($1–$100) locked to one amount + merchant. ⚠️ Read mcp://resources/sop first. Only call once the FINAL total is visible — for physical goods that is AFTER shipping is submitted (use get_merchant_hints to navigate there). For digital goods with the price already visible, prefer auto_pay_checkout instead. BEFORE requesting: look at the checkout page one more time and compare it against what the user actually asked for — same items, same quantity, same variant, same destination? If anything differs, do NOT request a token; fix the cart or check with the user first. A mismatch you catch here costs nothing; after this point it costs a card. If you pass `cart`, the server signs your declared intent and binds the card to it — the user gets cryptographic proof of what this card was authorized for. Pass `criteria` too: the few things the owner actually cared about, which this purchase gets scored against at payment time.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Amount in USD to authorize (min: $1, max: $100) |
| card_alias | string | yes | Which card to charge, e.g. 'Card_01' |
| cart | array | – | RECOMMENDED: the items you are buying, as the USER agreed to them. This becomes a signed intent bound to the card — proof of what was authorized. |
| criteria | object | – | RECOMMENDED. The things this purchase will be judged against later — write ONLY what the owner actually stated. Attributes like price, colour, size, product type or delivery time are examples of the… |
| merchant | string | yes | Name or URL of the merchant/service being purchased |
| ship_to | string | – | Shipping destination as a single string (only a hash is stored, never the raw address). |
No output schema declared.
No examples provided.
set_api_key Change Passport Key (switches identity) ~68
Activate a new Passport Key instantly, no restart needed. Only call when user explicitly provides a key.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | The new Passport Key to activate. Must start with 'zk_live_' or 'zk_test_'. Get from: https://z-zero.xyz/dashboard/agents |
No output schema declared.
No examples provided.
show_api_key_status Passport Key Status ~24
Check if Passport Key is configured. Shows prefix only, for debugging.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
ucp_probe_checkout Probe UCP Checkout (creates draft) ~283
UCP discovery + quote — creates an UNPAID draft checkout; no money moves; NOT a payment rail yet. Checks whether a merchant speaks UCP (Shopify-native agent commerce), lists its declared payment handlers, and — when variant_gid or query is given — creates a DRAFT checkout and returns the merchant's real quote: total_minor (wire units, 8900 = $89.00), total_major, currency, status, blockers, continue_url. NO payment happens; drafts expire server-side. Completing a UCP checkout needs Shopify Token-tier agent auth, which Z-Zero does not hold yet — to PAY, hand the buyer continue_url or use the standard execute_payment flow where permitted. Call this first on Shopify stores: their robots.txt bans scripted checkout, so the UCP lane is the sanctioned path.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer_email | string | – | – |
| quantity | integer | – | – |
| query | string | – | Product search query when variant_gid is unknown — first in-stock hit is quoted. |
| ship_to | object | – | Shipping address — supply it to get the REAL total with market pricing + shipping. |
| shop_url | string | yes | Store URL, e.g. https://meanblvd.com |
| variant_gid | string | – | Exact Shopify variant GID to quote, e.g. gid://shopify/ProductVariant/123 |
No output schema declared.
No examples provided.
verify_receipt Verify Receipt ~221
Check where an order ENDED UP, and prove it. Returns TWO separate axes: `order_status` — 'completed' (bought, issuer not reported yet) · 'settled' (issuer confirmed) · 'reversed' (auth voided before clearing — the order does NOT stand) · 'partially_refunded' / 'refunded' (merchant returned money AFTER settlement — the order still happened) — and `funds_status` — 'no_payout_due' · 'payout_pending' (money owed back but not yet confirmed on-chain) · 'returned' (confirmed on-chain). Read BOTH before speaking: 'reversed' or 'refunded' with funds 'payout_pending' means the buyer has NOT got the money back yet — never say they have. If you told the user a purchase was done and a later check returns 'reversed', tell them unprompted.
| Name | Type | Req | Description |
|---|---|---|---|
| receipt_id | string | yes | The receipt_id returned by execute_payment / auto_pay_checkout (signed_receipt.receipt_id). |
No output schema declared.
No examples provided.
What is the io.github.Dempty-glitch/z-zero-mcp server?
io.github.Dempty-glitch/z-zero-mcp is listed in the public MCP registry as io.github.Dempty-glitch/z-zero-mcp. Payments for AI agents: gasless USDC on Base + JIT single-use virtual cards, PAN never in context. This page covers its npm package (z-zero-mcp-server).
Is the io.github.Dempty-glitch/z-zero-mcp server safe to use?
io.github.Dempty-glitch/z-zero-mcp scores 85 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.Dempty-glitch/z-zero-mcp server expose?
io.github.Dempty-glitch/z-zero-mcp exposes 14 tools: list_cards, check_balance, get_deposit_addresses, request_payment_token, get_merchant_hints, and 9 more. Their descriptions and schemas cost roughly 2,261 tokens of context every time the server is loaded.
Is the io.github.Dempty-glitch/z-zero-mcp server still maintained?
io.github.Dempty-glitch/z-zero-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.Dempty-glitch/z-zero-mcp server under?
io.github.Dempty-glitch/z-zero-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.