SCRIPTMASTERLABS
NPM PACKAGE · GITLAB SOURCE AUTHORITY · RELEASES SEPARATE

@scriptmasterlabs/mcp-x402

The SCRIPTMASTERLABS x402 Gateway discovers x402 paid APIs and inspects fresh payment requirements before a caller chooses whether to pay. It does not autonomously spend.

Public npm state

Latest verified public npm: 2.1.3

npm install @scriptmasterlabs/mcp-x402@2.1.3

GitLab main is ahead of npm. Do not infer that an unreleased GitLab version is already published.

GitLab source state

Current source package version: 2.1.8

https://gitlab.com/timothy.walton45/sml-portfolio/-/tree/main/mcp-x402

GitLab is the only current source-control authority.

Publication boundary

npm publication is a separate release action and is not automatic. Until a newer npm release is explicitly approved and published, package consumers should treat 2.1.3 as the public npm version and GitLab main as unreleased source.

Canonical MCP role

Discover x402 paid APIs and inspect their payment requirements before calling them. Caller controls spending policy.

https://mcp-x402.onrender.com/mcp

Canonical hosted payment boundary

Current hosted SML rail: x402 v2 · USDC · Base mainnet (eip155:8453).

Fetch the target resource's fresh PAYMENT-REQUIRED challenge immediately before payment. A challenge or signature is not settlement proof. The fresh runtime challenge is authority for exact amount, asset, network, receiver, and accepted payment header.

Public npm metadata warning

The current public npm page still contains historical autonomous USDC/RLUSD positioning, historical tool-count claims, and a GitHub repository pointer. Those are publication metadata drift and are not current SML authority.

Source of truth

npm package →

GitLab source →

Canonical MCP stack →

Buyer evidence →