Hash Encoding Direct Credits
Deterministic SHA, HMAC, Base64 and JWT decode tools with prepaid direct-USDC API credits on Base.
- 0.1.0
- Version
- remote
- Transport
- 8
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 8 tools scanned
- metadata: scanned
No findings.
Tools (8)
get_payment_info
Return the complete purchase and redemption instructions for this service's prepaid API credits. Use this before paying or when an agent needs the Base Mainnet network, native USDC contract, receiver address, exact package amount, credit quantity, buyer-gas requirement, or redemption steps. This call is free and does not require a bearer token. It does not return a balance; use get_credit_balance after you already have a redeemed bearer token. This payment scheme is direct USDC credits, not x402.
get_credit_balance
Check the remaining prepaid API credits for the bearer token configured on this MCP connection. Use this after redeeming a payment when you need to decide whether a protected tool can be called. The bearer token is read from the Authorization header, not from tool arguments. This call is free, does not spend credits, and does not purchase or redeem credits.
hash_sha256
Create an unkeyed SHA-256 fingerprint of UTF-8 text. Use this for checksums, deduplication, content fingerprints, or integrity comparisons when no shared secret is involved; use hmac_sha256 instead when keyed authentication is required. Returns the 32-byte digest as 64 lowercase hexadecimal characters. Costs 1 credit.
hash_sha512
Create an unkeyed SHA-512 fingerprint of UTF-8 text. Use this when a 512-bit digest is specifically required for checksums, fingerprints, or compatibility; use hash_sha256 for the more common 256-bit digest and hmac_sha256 when keyed authentication is required. Returns 128 lowercase hexadecimal characters. Costs 1 credit.
hmac_sha256
Authenticate a UTF-8 message with a UTF-8 secret key using HMAC-SHA256. Use this when you need keyed integrity/authentication with a shared secret; use hash_sha256 instead for an unkeyed checksum or fingerprint. Returns the 32-byte HMAC as 64 lowercase hexadecimal characters. Costs 1 credit.
base64_encode
Encode UTF-8 text as standard Base64. Use this for transport/storage encoding of text bytes; Base64 is reversible encoding, not encryption and not a cryptographic hash. Returns the encoded Base64 string. Costs 1 credit.
base64_decode
Decode a standard Base64 string into UTF-8 text. Use this only when the decoded bytes are expected to be valid UTF-8; this tool is not for arbitrary binary output. Base64 is reversible encoding, not encryption. Costs 1 credit.
jwt_decode
Decode a compact JWT's header and payload for inspection without verifying its signature. Use this for debugging or reading claims only; never treat the returned claims as authenticated or trusted. The response always reports signatureVerified=false, even when a signature segment is present. Costs 1 credit.