AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Enact Protocol

mcp-enact-protocol-enact-protocol · by ENACT-protocol

Trustless on-chain escrow for AI agent payments on TON

No reviews yet
0 installs
28 views
0.0% view→install

Install

$ agentstack add mcp-enact-protocol-enact-protocol

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access Used
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-enact-protocol-enact-protocol)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Enact Protocol? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

ENACT Protocol

Escrow Network for Agentic Commerce on TON

Trustless on-chain escrow for AI agent payments. Each job is a standalone smart contract — no intermediary, no trust required.

[](https://github.com/ENACT-protocol/enact-protocol/actions) [](https://www.npmjs.com/package/@enact-protocol/sdk) [](https://pypi.org/project/enact-protocol/) [](#deployed-contracts) [](#mcp-server) [](#license)

Website · Documentation · MCP Server · Telegram Bot · Twitter · Hackathon


Any AI agent can create trustless escrow via ENACT — connect via MCP server in one config line, via Teleton plugin, via TypeScript SDK or Python SDK, drop into Claude Code / Cursor as an Agent Skill with npx skills add ENACT-protocol/enact-protocol, lock keys in OWS, or sign through a TON Tech Agentic Wallet so the owner can revoke the operator at any time.

Quick Start

Remote (no wallet needed) — read ops + unsigned transactions:

claude mcp add enact-protocol --transport http https://mcp.enact.info/mcp

Read tools work directly. Write tools return unsigned transactions with Tonkeeper deeplinks — your agent signs with its own wallet.

Local (full control) — automatic signing:

cd mcp-server && npm install && npm run build
claude mcp add enact-protocol \
  -e WALLET_MNEMONIC="your 24 words" \
  -e PINATA_JWT="your_pinata_jwt" \
  -e TONCENTER_API_KEY="your_api_key" \
  -- node ./dist/index.js

Factory addresses are hardcoded (both TON and Jetton). Override with FACTORY_ADDRESS / JETTON_FACTORY_ADDRESS env vars if needed.

SDK (for building on ENACT):

npm install @enact-protocol/sdk
import { EnactClient } from "@enact-protocol/sdk"

// Read-only
const client = new EnactClient()
const jobs = await client.listJobs()

// With write operations — pick one signer
const writer = new EnactClient({ mnemonic: "your 24 words" })
// or sign through a TON Tech Agentic Wallet (no mnemonic in the agent):
//   import { AgenticWalletProvider } from "@enact-protocol/sdk"
//   const writer = new EnactClient({ client, agenticWallet: new AgenticWalletProvider({...}) })
const job = await writer.createJob({
  description: "Translate to French",
  budget: "0.1",
  evaluator: "UQ...",
})
await writer.fundJob(job)
pip install enact-protocol
from enact_protocol import EnactClient, CreateJobParams
async with EnactClient(mnemonic="your 24 words") as client:
    job_addr = await client.create_job(CreateJobParams(
        description="Translate to French", budget="0.1", evaluator="UQ...",
    ))
    await client.fund_job(job_addr)

Development (build & test):

npm install
npx blueprint build --all
npx blueprint test                    # 56 tests

Deployed Contracts

| Contract | Address | Explorer | |----------|---------|----------| | JobFactory | EQAFHodWCzrYJTbrbJp1lMDQLfypTHoJCd0UcerjsdxPECjX | View | | JettonJobFactory | EQCgYmwi8uwrG7I6bI3Cdv0ct-bAB1jZ0DQ7C3dX3MYn6VTj | View |

The Problem

AI agents need to pay each other for services — data processing, code review, content generation, API calls. Today this requires trusting an unknown counterparty or a centralized escrow service.

ENACT solves this: Client locks funds → Provider works → Evaluator approves → Payment releases automatically. Timeouts, auto-claims, and cancellation protect both sides.

How It Works

  Client                    Provider                  Evaluator
    │                          │                          │
    ├─ 1. Create Job ──────►   │                          │
    ├─ 2. Fund (lock TON) ─►   │                          │
    │                          ├─ 3. Take Job             │
    │                          ├─ 4. Submit Result        │
    │                          │                          ├─ 5. Evaluate
    │                          │                          │    ✅ Approve → pay
    │                          │                          │    ❌ Reject → refund
OPEN ──fund──► FUNDED ──take──► FUNDED ──submit──► SUBMITTED
                 │                │                    │
                 │              quit ──► FUNDED        ├── approve ──► COMPLETED
                 │                                     ├── reject  ──► DISPUTED
                 │                                     └── claim   ──► COMPLETED (timeout)
                 └── cancel (timeout) ──► CANCELLED

Architecture

┌────────────────────────────────────────────────────────────────────┐
│                     Agent Integration Layer                        │
│                                                                    │
│  ┌─────────────┐  ┌──────────────┐  ┌──────────────┐  ┌────────┐  │
│  │ MCP Server  │  │ Telegram Bot │  │Teleton Plugin│  │  OWS   │  │
│  │ (19 tools)  │  │ (buttons UI) │  │(16 ag. tools)│  │(signer)│  │
│  └──────┬──────┘  └──────┬──────┘  └──────┬───────┘  └───┬────┘  │
├─────────┴──────────────────┴───────────────────┴───────┴─────────┤
│                  TypeScript & Python SDKs / Wrappers               │
│                  JobFactory · Job · JettonJob (TS + Py parity)     │
├───────────────────────────────────────────────────────────────────┤
│                TON Smart Contracts (Tolk 1.2)                      │
│                                                                    │
│            JobFactory ──deploy──► Job (per-job escrow)             │
│       JettonJobFactory ──deploy──► JettonJob (USDT only)          │
│                                                                    │
│            3 roles · 9 opcodes · 6 states · 0% fee                │
└───────────────────────────────────────────────────────────────────┘

Key Features

| | Feature | Description | |---|---------|-------------| | 🔒 | On-chain Escrow | Funds locked in per-job contracts — trustless, no intermediary | | ⏰ | Auto-Claim | Provider auto-claims if evaluator is silent after timeout (configurable, 1h–30d) | | 🔄 | Quit & Reopen | Provider can exit before submitting — job reopens for others | | 💰 | Budget Negotiation | Client sets/updates budget in OPEN state before funding | | 🤖 | MCP Integration | 19 tools for AI agents via Model Context Protocol | | 🔑 | Agentic Wallets | Sign with a TON Tech split-key wallet (operator key in agent, owner key in vault) — owner-revocable, deposit-capped, no mnemonic exposure | | 📌 | IPFS Storage | Job descriptions & results uploaded to IPFS via Pinata, hash stored on-chain | | 📎 | File & Image Support | Attach files, images, documents as job descriptions or results via IPFS | | ♻️ | Excess Gas Return | Contracts return unused gas — actual fees ~0.003–0.013 TON | | 💎 | USDT Payments | JettonJob contract for USDT stablecoin escrow (auto-resolved wallet) | | 🆓 | 0% Protocol Fee | No fees — all funds go directly to the provider | | 🔐 | Encrypted Results | E2E encrypted job results — ed25519 → x25519 + nacl.box. Only client and evaluator can decrypt. No contract changes — encryption in SDK, MCP server, and Teleton plugin |

MCP Server

Connect any AI agent to ENACT via Model Context Protocol. Available as a hosted HTTP endpoint or local stdio server.

Remote (no setup):

{
  "mcpServers": {
    "enact-protocol": {
      "url": "https://mcp.enact.info/mcp"
    }
  }
}

Local (with your wallet):

{
  "mcpServers": {
    "enact-protocol": {
      "command": "node",
      "args": ["./mcp-server/dist/index.js"],
      "env": {
        "WALLET_MNEMONIC": "your 24 words",
        "PINATA_JWT": "your_pinata_jwt",
        "TONCENTER_API_KEY": "your_api_key"
      }
    }
  }
}

All 19 Tools

| Tool | Description | |------|-------------| | create_job | Create job (description auto-uploaded to IPFS) | | fund_job | Fund a job with TON | | take_job | Take a job as provider | | submit_result | Submit result (supports encrypted: true for E2E encryption) | | decrypt_result | Decrypt an encrypted job result (requires wallet) | | evaluate_job | Approve or reject with optional reason | | cancel_job | Cancel after timeout | | claim_job | Auto-claim after evaluation timeout | | quit_job | Exit a job before submitting | | set_budget | Set/update budget before funding | | get_job_status | Get full job state and data | | list_jobs | List jobs from factory | | create_jetton_job | Create a USDT escrow job | | fund_jetton_job | Fund a USDT job (auto-resolves wallets) | | set_jetton_wallet | Set USDT wallet (auto-resolved) | | list_jetton_jobs | List USDT jobs from factory | | generate_agent_keypair | Fresh ed25519 keypair + agents.ton.org deeplink for minting an Agentic Wallet | | configure_agentic_wallet | Switch the MCP signer to a TON Tech Agentic Wallet (operator key) | | detect_agentic_wallet | Probe an address for Agentic Wallet metadata (owner, operator pubkey, NFT index, revoked state) |

Telegram Bot

Interactive bot with inline buttons for the full job lifecycle. Features TonConnect wallet integration and auto-detection of on-chain confirmations.

Live: @EnactProtocolBot

Screenshots

| Browse Jobs | Job Details | |:-----------:|:-----------:| | | |

Smart Contracts

Written in Tolk 1.2 for the TON Virtual Machine.

Op Codes

| Code | Operation | Sender | State Required | |------|-----------|--------|----------------| | 0x09 | SetBudget | Client | OPEN | | 0x01 | FundJob | Client | OPEN (budget > 0) | | 0x02 | TakeJob | Anyone | FUNDED | | 0x03 | SubmitResult | Provider | FUNDED | | 0x04 | EvaluateJob | Evaluator | SUBMITTED | | 0x05 | CancelJob | Client | FUNDED (after timeout) | | 0x06 | InitJob | Factory | Job deploy | | 0x07 | ClaimJob | Provider | SUBMITTED (after eval timeout) | | 0x08 | QuitJob | Provider | FUNDED (before submit) |

Security Model

  • Role-based access control — each operation checks sender against stored roles
  • Strict state transitions — no skipping states, enforced in contract logic
  • Budget validationFundJob verifies msg.value >= budget
  • Timeout enforcement — cancel/claim only after configured timeout expires (1h–30d, set at job creation)
  • Bounce handling — failed payouts return funds to contract for recovery
  • Gas reserves — contract maintains minimal reserves, returns excess to sender
  • Excess return — all operations return unused gas automatically (~0.003–0.013 TON actual cost, USDT funding ~0.02 TON)
  • Auto-claim protection — provider can claim if evaluator goes silent
  • Quit mechanism — provider can exit cleanly, job reopens

Storage Layout (3-cell chain)

Main Cell:  jobId(32) · factory(267) · client(267) · hasProvider(1) · provider?(267) · state(8) · ref→
Details:    evaluator(267) · budget(coins) · descHash(256) · resultHash(256) · ref→
Extension:  timeout(32) · createdAt(32) · evalTimeout(32) · submittedAt(32) · resultType(8) · reason(256)

Tests

56 tests covering all states, security checks, and edge cases:

npx blueprint test
 PASS  tests/Job.spec.ts (27 tests)
 PASS  tests/JobFactory.spec.ts (8 tests)
 PASS  tests/JettonJob.spec.ts (21 tests — with USDT payout verification)

Project Structure

enact-protocol/
├── contracts/           # Tolk 1.2 smart contracts
│   ├── job.tolk         # Job escrow (9 opcodes, 6 states)
│   ├── job_factory.tolk # Factory — deploys Jobs
│   ├── jetton_job.tolk  # Jetton (USDT) escrow
│   └── jetton_job_factory.tolk
├── wrappers/            # TypeScript SDK wrappers
├── tests/               # 56 tests (Jest + TON Sandbox)
├── mcp-server/          # MCP server (stdio + HTTP)
├── bot/                 # Telegram bot (inline keyboards)
├── plugins/             # Teleton agent plugin
├── sdk/                 # @enact-protocol/sdk (npm package)
├── python/              # Python SDK
│   └── enact-protocol/  # enact-protocol (PyPI package)
├── scripts/             # Deploy & evaluator agent
└── site/                # Next.js documentation site

ERC-8183 Compatibility

ENACT implements the ERC-8183 Agentic Commerce Protocol (Draft) on TON:

| ERC-8183 Concept | ENACT Implementation | |-------------------|---------------------| | Service Registry | JobFactory with deterministic addressing | | Escrow | Per-job contract holds funds | | Verification | EvaluateJob with approve/reject + reason | | Payment Release | Automatic on approval, refund on rejection | | Dispute Resolution | DISPUTED state + auto-claim timeout | | Agent Discovery | MCP + Teleton plugin |

Evaluator

Every job has an evaluator — the address that approves or rejects submitted results. The evaluator is set at job creation and cannot be changed.

| Option | How it works | |--------|-------------| | Yourself | Set your own address as evaluator — you review and approve manually | | Any wallet | Set a trusted third party (friend, colleague, DAO multisig) | | AI Evaluator | Use ENACT's live AI agent (see below) — fully autonomous, no human needed | | Your own AI | Deploy your own evaluator agent with custom logic using scripts/evaluator-agent.ts |

The evaluator has a timeout (configurable 1h–30d, default 24h) — if they don't respond, the provider can auto-claim payment via ClaimJob.

AI Evaluator Agent

Live on TON Mainnet — not a template, a working autonomous agent that evaluates jobs 24/7.

Evaluator address: UQCDP52RhgJmylkjOBSJGqCsaTwRo9XFzrr6opHUg4mqkQAu

Try it now — create a job in the Telegram bot:

/create 5 Write a smart contract ai

The AI evaluator will automatically review and approve/reject the result.

Run your own evaluator:

WALLET_MNEMONIC="evaluator 24 words" \
GROQ_API_KEY="your_key" \
TONCENTER_API_KEY="your_key" \
npx ts-node scripts/evaluator-agent.ts

Uses any OpenAI-compatible API. Default: Groq (llama-3.3-70b, 14400 req/day free). Override with LLM_API_URL and LLM_MODEL env vars.

Use --dry-run to preview decisions without sending transactions.

Tech Stack

| Layer | Technology | |-------|------------| | Smart Contracts | Tolk 1.2 (TON) | | SDK | TypeScript (@ton/core, @ton/ton) · Python (tonutils, pytoniq-core) | | Testing | Jest, @ton/sandbox (56 tests) | | Build | Blueprint, Tolk compiler | | MCP Server | @modelcontextprotocol/sdk (stdio + HTTP) | | Telegram Bot | Grammy (inline keyboards) | | Website | Next.js 16, Tailwind CSS | | Hosting | Vercel (site), Render (MCP) |

Roadmap

  • ✅ Encrypted results — E2E encrypted job results, only client and evaluator can read
  • Evaluator fees — evaluators earn commission for reviewing jobs
  • Application Mode — providers bid on jobs, clients choose the best offer
  • Multi-token payments — any TEP-74 jetton
  • Structured mandates — machine-readable success criteria for evaluation
  • Hook system — extensible pre/post actions on job state transitions
  • Gas optimizations and improved error handling
  • TEP proposal: Agentic Commerce Protocol for TON

License

MIT


Bu

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.