Codex, Cursor, VS Code and other clients
Every client below launches the same stdio server; only the config file
differs. The read-only checks (X402-01–05) need no keys at all, so the
environment can be left out until you want the checks that pay.
Keep keys out of a project config file that might be committed. The examples
read them from your existing .env (which .gitignore already covers) or
forward them from your shell, rather than writing them into the config.
Codex
In ~/.codex/config.toml, or .codex/config.toml for one project:
[mcp_servers.wasit]
command = "npx"
args = ["-y", "@wasit-dev/server"]
env_vars = ["STELLAR_PRIVATE_KEY", "MPP_PAYER_SECRET", "COMMITMENT_SECRET_HEX"]
[mcp_servers.wasit.env]
MPP_STELLAR_NETWORK = "stellar:testnet"env_vars forwards those variables from the shell Codex was started in, so
export them first (set -a; source .env; set +a). For the read-only checks
alone, codex mcp add wasit -- npx -y @wasit-dev/server is enough. Check it
with codex mcp list.
Cursor
In .cursor/mcp.json at the project root, or ~/.cursor/mcp.json for every
project:
{
"mcpServers": {
"wasit": {
"command": "npx",
"args": ["-y", "@wasit-dev/server"],
"envFile": "${workspaceFolder}/.env"
}
}
}In the global file, where there is no workspace .env, pass each variable as
"env": { "STELLAR_PRIVATE_KEY": "${env:STELLAR_PRIVATE_KEY}", ... } instead.
VS Code
For Copilot's agent mode, in .vscode/mcp.json. The top-level key is
servers, not mcpServers:
{
"servers": {
"wasit": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@wasit-dev/server"],
"envFile": "${workspaceFolder}/.env"
}
}
}To be asked for a key instead of reading .env, declare it under inputs with
"password": true and reference it as "${input:id}" in env.
envFile is read by VS Code's own agent. A chat session that runs on
Copilot CLI inside VS Code launches the server itself and does not read
envFile: the server starts, but without keys, so only the read-only checks
run and the paying tools answer that their key is not set. For those sessions,
register the server as described under GitHub Copilot CLI below.
GitHub Copilot CLI
The same shape as claude mcp add. It writes the user-level
~/.copilot/mcp-config.json, outside any project:
copilot mcp add wasit \
--env MPP_STELLAR_NETWORK=stellar:testnet \
--env STELLAR_PRIVATE_KEY=S... \
--env MPP_PAYER_SECRET=S... \
--env COMMITMENT_SECRET_HEX=... \
-- npx -y @wasit-dev/serverBy hand, the entry goes under mcpServers with "type": "local", the same
command and args, an env object, and "tools": ["*"]. In a
non-interactive run (copilot -p "..."), allow the server's tools with
--allow-tool wasit.
Copilot CLI does not read envFile. It does pass its own environment to the
server, so exporting the keys before starting it also works and keeps them out
of every config file: set -a; source .env; set +a, then copilot.
Other clients
Any MCP client that runs stdio servers takes the same three things: command
set to npx, args set to ["-y", "@wasit-dev/server"], and the environment
variables MPP_STELLAR_NETWORK, STELLAR_PRIVATE_KEY, MPP_PAYER_SECRET and
COMMITMENT_SECRET_HEX, plus EVM_PRIVATE_KEY for x402 payment checks on Base
Sepolia (network: "eip155:84532") and SVM_PRIVATE_KEY for Solana devnet
(network: "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1"). Use absolute paths for node packages/server/dist/index.js
if launching from a local checkout instead of npx, since a client launches the
server from a working directory you don't control.
What has been run. Three clients have run Wasit's MCP server end to end
against its fixtures, each with X402-01–07 all passing and X402-06
settled on-chain, then MPP-01 and the channel checks in the same session:
Claude Code, in the session recorded in the README; GitHub Copilot CLI 1.0.91;
and VS Code 1.140's own Copilot agent with the .vscode/mcp.json above, both
on 3 October 2026. The same VS Code config in a session that ran on Copilot CLI
started the server without its keys, which is how the envFile note above was
found. Every CI run also installs the published package and completes an MCP
handshake with it over stdio (npm run verify:clean-install), which is the same
exchange any of these clients performs. The Codex and Cursor configurations
follow each client's own documentation as of October 2026. Client names and logos are trademarks of
their owners, shown only to say which client a configuration is for.