bsl-agent-mcp
An MCP server that lets an agent operate a testnet Bitcoin wallet on the Bitcoin-IPC testnet: deposits, payments, balance checks
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- The pay and deposit_btc tools move wallet funds, even if only on testnet
- Below the SPEND_CAP_SATS limit, operations go through without extra user confirmation
Install
Manual install
docker build -t ghcr.io/bitcoinscalinglabs/bsl-agent-mcp:testnet . && docker run -d --env-file ./bsl.env --network container:bsl-client --name bsl-agent-mcp ghcr.io/bitcoinscalinglabs/bsl-agent-mcp:testnetThe main way to run it next to an already running bsl-client container.
This is third-party code. Review the repository files before installing.
What it does
The server runs alongside a bsl-client container and lets an agent (Claude Desktop, Claude Code or any MCP client) operate a user-owned wallet on the Bitcoin-IPC testnet: deposit L1 BTC into subnet1, pay wBTC within subnet1 or across to subnet2, check balances by address book entry or raw address, and fetch a Bitcoin-anchored receipt for a payment. The agent never holds keys. The server signs locally, and any operation above SPEND_CAP_SATS requires explicit user approval via confirmed=true.
Who it is for. For developers testing payment flows on the Bitcoin-IPC testnet through a chat with an AI agent.
Good fit when
- You want to try a wBTC transfer between subnet1 and subnet2 on testnet from a chat with an agent
- You need an agent that checks the balance and spend cap before a payment
Not a fit when
- You need real funds or mainnet: the project is explicitly unaudited and testnet-only
- The project is unrelated to Russian services or 1C: it was a name-match false positive
Example request
Check the wallet balance on subnet1 and pay 10000 sats to a payee from the address bookLimitations
The author explicitly warns the code is not audited, testnet-only, and not for mainnet or keys with real value. Requires a separately running bsl-client container with AGENT_PRIVATE_KEY configured. The project has nothing to do with the Russian stack; it turned up by an acronym coincidence between BSL and 1C's language.
How to disable. Stop the bsl-agent-mcp container and remove the server from your MCP client configuration.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| API_TOKEN required, secret | Access key for the L2 gateways and the bsl-client provider. |
| AGENT_PRIVATE_KEY required, secret | EVM key the server pays from. |
| SPEND_CAP_SATS | Per-operation cap above which explicit user approval is required. |
Security check
- The pay and deposit_btc tools move wallet funds, even if only on testnet
- Below the SPEND_CAP_SATS limit, operations go through without extra user confirmation
README in short
The README describes seven MCP tools from wallet_status to subnet_info, requirements for a running bsl-client container with the provider port and an imported key, Docker launch next to bsl-client or a from-source Node.js run, and a table of environment variables including the required API_TOKEN, AGENT_PRIVATE_KEY, SUBNET_ID and SUBNET2_ID. It carries an explicit disclaimer that the code is not audited and is testnet-only.
FAQ
Can the agent spend any amount without approval?
No, operations above SPEND_CAP_SATS are refused until the user explicitly approves them with confirmed=true.
Does the server expose private keys to the agent?
No, keys are never passed to the agent; signing happens locally on the server.
Related
A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice
Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data
Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language
inn-check-ru: counterparty risk traffic light
inn-check-ru
An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict