DEV Community

OpenClaw Cash
OpenClaw Cash

Posted on

Why your coding agent should get its wallet as an MCP tool

Your agent already has tools. It can read files, run a shell, fetch a URL. The moment it needs to move money, most people leave that world and start writing integration code: an HTTP client, a key in an env var, retry logic, and somewhere a function that decides whether this particular send is allowed. That glue is the part that gets agents drained, and it is the part nobody wants to own forever.

MCP changes the shape of the problem. Instead of your agent guessing at an HTTP surface, it gets the wallet as a set of tools it calls the same way it calls everything else. OpenClawCash ships that as one public package, so the setup is a single line and the API key is the only secret you hand over.

The whole setup is one package

npx -y @openclawcash/mcp-server
Enter fullscreen mode Exit fullscreen mode

That runs the server over stdio. To point a client at it, add the same block to the client's MCP config (Claude Desktop, Cursor, VS Code, or an OpenClaw runtime):

{
  "mcpServers": {
    "openclawcash": {
      "command": "npx",
      "args": ["-y", "@openclawcash/mcp-server"],
      "env": {
        "AGENTWALLETAPI_KEY": "occ_your_api_key_here",
        "AGENTWALLETAPI_URL": "https://openclawcash.com"
      }
    }
  }
}
Enter fullscreen mode Exit fullscreen mode

Node.js 20+ and an agent API key is all it needs. AGENTWALLETAPI_URL is optional.

Why this is safer than glue code

Nothing gets written into your repo, and no private key ever lands in the config. The agent holds a scoped API key and the wallet is hosted, so if that key leaks you revoke the key, not the wallet.

The part that matters more is that writes arrive with a permission story instead of by accident. The MCP page lists four approval modes and expects the agent to ask once, at the first write intent, which one the user wants:

  1. read_only_discovery allows wallet reads, balances, quotes and metadata only.
  2. confirm_each_write asks before every transfer, swap, approval, import or wallet creation.
  3. operate_on_my_behalf runs later write requests in the same session without re-asking, after onboarding approval.
  4. session_write_window grants write access for a limited session, then reverts to confirmation mode.

An agent that can reason but cannot be trusted with an unbounded send is exactly the case these cover.

What shows up as a tool

The server is a thin adapter over https://openclawcash.com/api/agent/*, so the tool names track the API you can read in the docs: wallets_list, wallet_create, balances_get, transactions_list, user_tag_set, transfer_send, swap_quote, swap_execute, approve_token, the checkout_* escrow lifecycle, and the polymarket_* venue tools. One tool, skill_latest, is public and needs no key, so a client can discover the current skill version before it is configured.

You can check the package runs before touching any client config:

npx -y @openclawcash/mcp-server --self-test
npx -y @openclawcash/mcp-server --print-openclaw-config
Enter fullscreen mode Exit fullscreen mode

The second one prints the config block for you, so the JSON above is not something you have to type from memory.

The honest trade-off

MCP does not add a policy layer of its own. The server adapts the API; the spending limits and allow-lists are the ones on your account, enforced server side before anything is signed. If you have not set a policy in the dashboard, the tools still do what you ask. Set the policy first, then hand the agent the tools.

The other thing to know: wallet webhooks and escrow webhooks stay separate products. If your server needs to hear about a move, that is its own webhook endpoint and its own tools, not a side effect of a send.

Docs: https://openclawcash.com/docs
MCP page with the config examples: https://openclawcash.com/mcp

Top comments (0)