Product Description
# USDT Payment Verifier
Stop delivering the wrong order to the wrong payer.
| | |
| --- | --- |
| Version | 1.0.0 |
| Price | 79 USD |
| Licence | Single-seat |
| Entry point | `server.py` |
| Source | Reimplemented from scratch in English; TRC-20 and BEP-20 logic referenced from the local CLI without modifying it |
## What it does
Read-only MCP server that checks a USDT payment record against an order on TRC-20 and BEP-20. A payment is accepted only when all of these hold:
- the record is for the transaction you asked about (hash match)
- the token is the official USDT contract for that network
- the recipient matches exactly (TRON addresses are case-sensitive)
- the amount matches exactly
- the status is confirmed
- the timestamp is present, not in the future and within the age limit (seconds and milliseconds both handled)
- the hash is not in your list of transactions already delivered
## What it does not do
It does not look the transaction up. You fetch the chain record from a source you trust (your own node, or a gateway you call yourself) and pass it in as `record_json`. The server then judges whether that record satisfies the order. It cannot tell a forged record from a real one, so never pass a record that came from the payer. Replay protection is stateless: you keep the list of delivered hashes and pass it as `already_used_json`.
## Tools
| Tool | Description |
| --- | --- |
| `verify_payment` | Check one chain record against an order: same transaction, official USDT, exact recipient and amount, confirmed, fresh, not reused. |
| `recent_orders` | Summarise recent transactions for a wallet. |
| `wallet_status` | Report wallet address, network and read-only posture. Never signs. |
## Network
Any outbound request is limited to these allow-listed gateways (the server itself makes none; the list governs a fetcher you wire in): `api.trongrid.io`, `tronscan.org`, `bsc-dataseed.binance.org`, `bsc-dataseed1.binance.org`.
## Security
- Read-only: no file is written and no process is started.
- Any outbound request must pass the host allow-list and the private-network guard.
## Requirements
- Python 3.10 or above
- No account, no API key, no telemetry
## Agent Skills
| Skill | Purpose |
| --- | --- |
| `payment-verification-triage` | Confirm a USDT payment before delivering an order. |
## Tests
```bash
python -m pytest -q # suite tests for this server
```
Every security claim above names a test that exists:
- `test_ssrf_blocks_private_network`
- `test_no_subprocess_spawn`
- `test_read_only_policy_holds`
## Licence and exclusions
- Single-seat licence unless a team licence is stated above.
- No shell execution, no browser or account automation, no key custody.
- The exclusion list is published in `security/EXCLUSIONS.md` in the team
bundle so a reviewer can check it independently.
What you get
1 file · 236.67 KB
- payment-verifier_v1.zipZIP · 236.67 KB