Описание товара
# USDT Payment Verifier
Stop delivering the wrong order to the wrong payer.
| | |
| --- | --- |
| Version | 1.0.0 |
| Price | 79 USD |
| Licence | Single-seat |
| Entry point | `server.py` |
| Source | Reimplemented from scratch in English; TRC-20 and BEP-20 logic referenced from the local CLI without modifying it |
## What it does
Read-only MCP server that checks a USDT payment record against an order on TRC-20 and BEP-20. A payment is accepted only when all of these hold:
- the record is for the transaction you asked about (hash match)
- the token is the official USDT contract for that network
- the recipient matches exactly (TRON addresses are case-sensitive)
- the amount matches exactly
- the status is confirmed
- the timestamp is present, not in the future and within the age limit (seconds and milliseconds both handled)
- the hash is not in your list of transactions already delivered
## What it does not do
It does not look the transaction up. You fetch the chain record from a source you trust (your own node, or a gateway you call yourself) and pass it in as `record_json`. The server then judges whether that record satisfies the order. It cannot tell a forged record from a real one, so never pass a record that came from the payer. Replay protection is stateless: you keep the list of delivered hashes and pass it as `already_used_json`.
## Tools
| Tool | Description |
| --- | --- |
| `verify_payment` | Проверить одну запись цепи против заказа: та же транзакция, официальный USDT, точный получатель и сумма, подтверждён, свежий, не повторён. |
| `recent_orders` | Подвести итоги недавних транзакций по кошельку. |
| `wallet_status` | Сообщить адрес кошелька, сеть и статус только для чтения. Никогда не подписывает. |
## Network
Любой исходящий запрос ограничен этим разрешённым списком шлюзов (сам сервер их не делает; список управляет получателем, который вы подключаете): `api.trongrid.io`, `tronscan.org`, `bsc-dataseed.binance.org`, `bsc-dataseed1.binance.org`.
## Security
- Только для чтения: никаких файловых записей и ни один процесс не запускается.
- Любой исходящий запрос должен проходить через белый список хостов и охрану частной сети.
## Requirements
- Python 3.10 или выше
- Без учётной записи, без API-ключа, без телеметрии
## Агентские навыки
| Skill | Purpose |
| --- | --- |
| `payment-verification-triage` | Подтверждать оплату USDT перед доставкой заказа. |
## Tests
```bash
python -m pytest -q # набор тестов для этого сервера
```
Каждое вышеупомянутое утверждение о безопасности ссылается на существующий тест:
- `test_ssrf_blocks_private_network`
- `test_no_subprocess_spawn`
- `test_read_only_policy_holds`
## Licence and exclusions
- Лицензия на одиночную учётную запись, если иное не указано выше как командная лицензия.
- Нет выполнения shell-команд, нет браузера или автоматизации аккаунтов, нет хранения ключей.
- Список исключений опубликован в `security/EXCLUSIONS.md` в командном наборе, чтобы рецензент мог проверить его независимо.
Что вы получите
1 файл · 236.67 KB
- payment-verifier_v1.zipZIP · 236.67 KB