Install
$ agentstack add mcp-enact-protocol-enact-protocol ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ● Filesystem access Used
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
ENACT Protocol
Escrow Network for Agentic Commerce on TON
Trustless on-chain escrow for AI agent payments. Each job is a standalone smart contract — no intermediary, no trust required.
[](https://github.com/ENACT-protocol/enact-protocol/actions) [](https://www.npmjs.com/package/@enact-protocol/sdk) [](https://pypi.org/project/enact-protocol/) [](#deployed-contracts) [](#mcp-server) [](#license)
Website · Documentation · MCP Server · Telegram Bot · Twitter · Hackathon
Any AI agent can create trustless escrow via ENACT — connect via MCP server in one config line, via Teleton plugin, via TypeScript SDK or Python SDK, drop into Claude Code / Cursor as an Agent Skill with npx skills add ENACT-protocol/enact-protocol, lock keys in OWS, or sign through a TON Tech Agentic Wallet so the owner can revoke the operator at any time.
Quick Start
Remote (no wallet needed) — read ops + unsigned transactions:
claude mcp add enact-protocol --transport http https://mcp.enact.info/mcp
Read tools work directly. Write tools return unsigned transactions with Tonkeeper deeplinks — your agent signs with its own wallet.
Local (full control) — automatic signing:
cd mcp-server && npm install && npm run build
claude mcp add enact-protocol \
-e WALLET_MNEMONIC="your 24 words" \
-e PINATA_JWT="your_pinata_jwt" \
-e TONCENTER_API_KEY="your_api_key" \
-- node ./dist/index.js
Factory addresses are hardcoded (both TON and Jetton). Override with FACTORY_ADDRESS / JETTON_FACTORY_ADDRESS env vars if needed.
SDK (for building on ENACT):
npm install @enact-protocol/sdk
import { EnactClient } from "@enact-protocol/sdk"
// Read-only
const client = new EnactClient()
const jobs = await client.listJobs()
// With write operations — pick one signer
const writer = new EnactClient({ mnemonic: "your 24 words" })
// or sign through a TON Tech Agentic Wallet (no mnemonic in the agent):
// import { AgenticWalletProvider } from "@enact-protocol/sdk"
// const writer = new EnactClient({ client, agenticWallet: new AgenticWalletProvider({...}) })
const job = await writer.createJob({
description: "Translate to French",
budget: "0.1",
evaluator: "UQ...",
})
await writer.fundJob(job)
pip install enact-protocol
from enact_protocol import EnactClient, CreateJobParams
async with EnactClient(mnemonic="your 24 words") as client:
job_addr = await client.create_job(CreateJobParams(
description="Translate to French", budget="0.1", evaluator="UQ...",
))
await client.fund_job(job_addr)
Development (build & test):
npm install
npx blueprint build --all
npx blueprint test # 56 tests
Deployed Contracts
| Contract | Address | Explorer | |----------|---------|----------| | JobFactory | EQAFHodWCzrYJTbrbJp1lMDQLfypTHoJCd0UcerjsdxPECjX | View | | JettonJobFactory | EQCgYmwi8uwrG7I6bI3Cdv0ct-bAB1jZ0DQ7C3dX3MYn6VTj | View |
The Problem
AI agents need to pay each other for services — data processing, code review, content generation, API calls. Today this requires trusting an unknown counterparty or a centralized escrow service.
ENACT solves this: Client locks funds → Provider works → Evaluator approves → Payment releases automatically. Timeouts, auto-claims, and cancellation protect both sides.
How It Works
Client Provider Evaluator
│ │ │
├─ 1. Create Job ──────► │ │
├─ 2. Fund (lock TON) ─► │ │
│ ├─ 3. Take Job │
│ ├─ 4. Submit Result │
│ │ ├─ 5. Evaluate
│ │ │ ✅ Approve → pay
│ │ │ ❌ Reject → refund
OPEN ──fund──► FUNDED ──take──► FUNDED ──submit──► SUBMITTED
│ │ │
│ quit ──► FUNDED ├── approve ──► COMPLETED
│ ├── reject ──► DISPUTED
│ └── claim ──► COMPLETED (timeout)
└── cancel (timeout) ──► CANCELLED
Architecture
┌────────────────────────────────────────────────────────────────────┐
│ Agent Integration Layer │
│ │
│ ┌─────────────┐ ┌──────────────┐ ┌──────────────┐ ┌────────┐ │
│ │ MCP Server │ │ Telegram Bot │ │Teleton Plugin│ │ OWS │ │
│ │ (19 tools) │ │ (buttons UI) │ │(16 ag. tools)│ │(signer)│ │
│ └──────┬──────┘ └──────┬──────┘ └──────┬───────┘ └───┬────┘ │
├─────────┴──────────────────┴───────────────────┴───────┴─────────┤
│ TypeScript & Python SDKs / Wrappers │
│ JobFactory · Job · JettonJob (TS + Py parity) │
├───────────────────────────────────────────────────────────────────┤
│ TON Smart Contracts (Tolk 1.2) │
│ │
│ JobFactory ──deploy──► Job (per-job escrow) │
│ JettonJobFactory ──deploy──► JettonJob (USDT only) │
│ │
│ 3 roles · 9 opcodes · 6 states · 0% fee │
└───────────────────────────────────────────────────────────────────┘
Key Features
| | Feature | Description | |---|---------|-------------| | 🔒 | On-chain Escrow | Funds locked in per-job contracts — trustless, no intermediary | | ⏰ | Auto-Claim | Provider auto-claims if evaluator is silent after timeout (configurable, 1h–30d) | | 🔄 | Quit & Reopen | Provider can exit before submitting — job reopens for others | | 💰 | Budget Negotiation | Client sets/updates budget in OPEN state before funding | | 🤖 | MCP Integration | 19 tools for AI agents via Model Context Protocol | | 🔑 | Agentic Wallets | Sign with a TON Tech split-key wallet (operator key in agent, owner key in vault) — owner-revocable, deposit-capped, no mnemonic exposure | | 📌 | IPFS Storage | Job descriptions & results uploaded to IPFS via Pinata, hash stored on-chain | | 📎 | File & Image Support | Attach files, images, documents as job descriptions or results via IPFS | | ♻️ | Excess Gas Return | Contracts return unused gas — actual fees ~0.003–0.013 TON | | 💎 | USDT Payments | JettonJob contract for USDT stablecoin escrow (auto-resolved wallet) | | 🆓 | 0% Protocol Fee | No fees — all funds go directly to the provider | | 🔐 | Encrypted Results | E2E encrypted job results — ed25519 → x25519 + nacl.box. Only client and evaluator can decrypt. No contract changes — encryption in SDK, MCP server, and Teleton plugin |
MCP Server
Connect any AI agent to ENACT via Model Context Protocol. Available as a hosted HTTP endpoint or local stdio server.
Remote (no setup):
{
"mcpServers": {
"enact-protocol": {
"url": "https://mcp.enact.info/mcp"
}
}
}
Local (with your wallet):
{
"mcpServers": {
"enact-protocol": {
"command": "node",
"args": ["./mcp-server/dist/index.js"],
"env": {
"WALLET_MNEMONIC": "your 24 words",
"PINATA_JWT": "your_pinata_jwt",
"TONCENTER_API_KEY": "your_api_key"
}
}
}
}
All 19 Tools
| Tool | Description | |------|-------------| | create_job | Create job (description auto-uploaded to IPFS) | | fund_job | Fund a job with TON | | take_job | Take a job as provider | | submit_result | Submit result (supports encrypted: true for E2E encryption) | | decrypt_result | Decrypt an encrypted job result (requires wallet) | | evaluate_job | Approve or reject with optional reason | | cancel_job | Cancel after timeout | | claim_job | Auto-claim after evaluation timeout | | quit_job | Exit a job before submitting | | set_budget | Set/update budget before funding | | get_job_status | Get full job state and data | | list_jobs | List jobs from factory | | create_jetton_job | Create a USDT escrow job | | fund_jetton_job | Fund a USDT job (auto-resolves wallets) | | set_jetton_wallet | Set USDT wallet (auto-resolved) | | list_jetton_jobs | List USDT jobs from factory | | generate_agent_keypair | Fresh ed25519 keypair + agents.ton.org deeplink for minting an Agentic Wallet | | configure_agentic_wallet | Switch the MCP signer to a TON Tech Agentic Wallet (operator key) | | detect_agentic_wallet | Probe an address for Agentic Wallet metadata (owner, operator pubkey, NFT index, revoked state) |
Telegram Bot
Interactive bot with inline buttons for the full job lifecycle. Features TonConnect wallet integration and auto-detection of on-chain confirmations.
Live: @EnactProtocolBot
Screenshots
| Browse Jobs | Job Details | |:-----------:|:-----------:| | | |
Smart Contracts
Written in Tolk 1.2 for the TON Virtual Machine.
Op Codes
| Code | Operation | Sender | State Required | |------|-----------|--------|----------------| | 0x09 | SetBudget | Client | OPEN | | 0x01 | FundJob | Client | OPEN (budget > 0) | | 0x02 | TakeJob | Anyone | FUNDED | | 0x03 | SubmitResult | Provider | FUNDED | | 0x04 | EvaluateJob | Evaluator | SUBMITTED | | 0x05 | CancelJob | Client | FUNDED (after timeout) | | 0x06 | InitJob | Factory | Job deploy | | 0x07 | ClaimJob | Provider | SUBMITTED (after eval timeout) | | 0x08 | QuitJob | Provider | FUNDED (before submit) |
Security Model
- Role-based access control — each operation checks sender against stored roles
- Strict state transitions — no skipping states, enforced in contract logic
- Budget validation —
FundJobverifiesmsg.value >= budget - Timeout enforcement — cancel/claim only after configured timeout expires (1h–30d, set at job creation)
- Bounce handling — failed payouts return funds to contract for recovery
- Gas reserves — contract maintains minimal reserves, returns excess to sender
- Excess return — all operations return unused gas automatically (~0.003–0.013 TON actual cost, USDT funding ~0.02 TON)
- Auto-claim protection — provider can claim if evaluator goes silent
- Quit mechanism — provider can exit cleanly, job reopens
Storage Layout (3-cell chain)
Main Cell: jobId(32) · factory(267) · client(267) · hasProvider(1) · provider?(267) · state(8) · ref→
Details: evaluator(267) · budget(coins) · descHash(256) · resultHash(256) · ref→
Extension: timeout(32) · createdAt(32) · evalTimeout(32) · submittedAt(32) · resultType(8) · reason(256)
Tests
56 tests covering all states, security checks, and edge cases:
npx blueprint test
PASS tests/Job.spec.ts (27 tests)
PASS tests/JobFactory.spec.ts (8 tests)
PASS tests/JettonJob.spec.ts (21 tests — with USDT payout verification)
Project Structure
enact-protocol/
├── contracts/ # Tolk 1.2 smart contracts
│ ├── job.tolk # Job escrow (9 opcodes, 6 states)
│ ├── job_factory.tolk # Factory — deploys Jobs
│ ├── jetton_job.tolk # Jetton (USDT) escrow
│ └── jetton_job_factory.tolk
├── wrappers/ # TypeScript SDK wrappers
├── tests/ # 56 tests (Jest + TON Sandbox)
├── mcp-server/ # MCP server (stdio + HTTP)
├── bot/ # Telegram bot (inline keyboards)
├── plugins/ # Teleton agent plugin
├── sdk/ # @enact-protocol/sdk (npm package)
├── python/ # Python SDK
│ └── enact-protocol/ # enact-protocol (PyPI package)
├── scripts/ # Deploy & evaluator agent
└── site/ # Next.js documentation site
ERC-8183 Compatibility
ENACT implements the ERC-8183 Agentic Commerce Protocol (Draft) on TON:
| ERC-8183 Concept | ENACT Implementation | |-------------------|---------------------| | Service Registry | JobFactory with deterministic addressing | | Escrow | Per-job contract holds funds | | Verification | EvaluateJob with approve/reject + reason | | Payment Release | Automatic on approval, refund on rejection | | Dispute Resolution | DISPUTED state + auto-claim timeout | | Agent Discovery | MCP + Teleton plugin |
Evaluator
Every job has an evaluator — the address that approves or rejects submitted results. The evaluator is set at job creation and cannot be changed.
| Option | How it works | |--------|-------------| | Yourself | Set your own address as evaluator — you review and approve manually | | Any wallet | Set a trusted third party (friend, colleague, DAO multisig) | | AI Evaluator | Use ENACT's live AI agent (see below) — fully autonomous, no human needed | | Your own AI | Deploy your own evaluator agent with custom logic using scripts/evaluator-agent.ts |
The evaluator has a timeout (configurable 1h–30d, default 24h) — if they don't respond, the provider can auto-claim payment via ClaimJob.
AI Evaluator Agent
Live on TON Mainnet — not a template, a working autonomous agent that evaluates jobs 24/7.
Evaluator address: UQCDP52RhgJmylkjOBSJGqCsaTwRo9XFzrr6opHUg4mqkQAu
Try it now — create a job in the Telegram bot:
/create 5 Write a smart contract ai
The AI evaluator will automatically review and approve/reject the result.
Run your own evaluator:
WALLET_MNEMONIC="evaluator 24 words" \
GROQ_API_KEY="your_key" \
TONCENTER_API_KEY="your_key" \
npx ts-node scripts/evaluator-agent.ts
Uses any OpenAI-compatible API. Default: Groq (llama-3.3-70b, 14400 req/day free). Override with LLM_API_URL and LLM_MODEL env vars.
Use --dry-run to preview decisions without sending transactions.
Tech Stack
| Layer | Technology | |-------|------------| | Smart Contracts | Tolk 1.2 (TON) | | SDK | TypeScript (@ton/core, @ton/ton) · Python (tonutils, pytoniq-core) | | Testing | Jest, @ton/sandbox (56 tests) | | Build | Blueprint, Tolk compiler | | MCP Server | @modelcontextprotocol/sdk (stdio + HTTP) | | Telegram Bot | Grammy (inline keyboards) | | Website | Next.js 16, Tailwind CSS | | Hosting | Vercel (site), Render (MCP) |
Roadmap
- ✅ Encrypted results — E2E encrypted job results, only client and evaluator can read
- Evaluator fees — evaluators earn commission for reviewing jobs
- Application Mode — providers bid on jobs, clients choose the best offer
- Multi-token payments — any TEP-74 jetton
- Structured mandates — machine-readable success criteria for evaluation
- Hook system — extensible pre/post actions on job state transitions
- Gas optimizations and improved error handling
- TEP proposal: Agentic Commerce Protocol for TON
License
MIT
Bu
…
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ENACT-protocol
- Source: ENACT-protocol/enact-protocol
- License: MIT
- Homepage: https://enact.info
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.