Codex, Cursor, VS Code and other clients

Every client below launches the same stdio server; only the config file differs. The read-only checks (X402-01–05) need no keys at all, so the environment can be left out until you want the checks that pay.

Keep keys out of a project config file that might be committed. The examples read them from your existing .env (which .gitignore already covers) or forward them from your shell, rather than writing them into the config.

Codex

In ~/.codex/config.toml, or .codex/config.toml for one project:

toml
[mcp_servers.wasit]
command = "npx"
args = ["-y", "@wasit-dev/server"]
env_vars = ["STELLAR_PRIVATE_KEY", "MPP_PAYER_SECRET", "COMMITMENT_SECRET_HEX"]

[mcp_servers.wasit.env]
MPP_STELLAR_NETWORK = "stellar:testnet"

env_vars forwards those variables from the shell Codex was started in, so export them first (set -a; source .env; set +a). For the read-only checks alone, codex mcp add wasit -- npx -y @wasit-dev/server is enough. Check it with codex mcp list.

Cursor

In .cursor/mcp.json at the project root, or ~/.cursor/mcp.json for every project:

json
{
  "mcpServers": {
    "wasit": {
      "command": "npx",
      "args": ["-y", "@wasit-dev/server"],
      "envFile": "${workspaceFolder}/.env"
    }
  }
}

In the global file, where there is no workspace .env, pass each variable as "env": { "STELLAR_PRIVATE_KEY": "${env:STELLAR_PRIVATE_KEY}", ... } instead.

VS Code

For Copilot's agent mode, in .vscode/mcp.json. The top-level key is servers, not mcpServers:

json
{
  "servers": {
    "wasit": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@wasit-dev/server"],
      "envFile": "${workspaceFolder}/.env"
    }
  }
}

To be asked for a key instead of reading .env, declare it under inputs with "password": true and reference it as "${input:id}" in env.

envFile is read by VS Code's own agent. A chat session that runs on Copilot CLI inside VS Code launches the server itself and does not read envFile: the server starts, but without keys, so only the read-only checks run and the paying tools answer that their key is not set. For those sessions, register the server as described under GitHub Copilot CLI below.

GitHub Copilot CLI

The same shape as claude mcp add. It writes the user-level ~/.copilot/mcp-config.json, outside any project:

bash
copilot mcp add wasit \
  --env MPP_STELLAR_NETWORK=stellar:testnet \
  --env STELLAR_PRIVATE_KEY=S... \
  --env MPP_PAYER_SECRET=S... \
  --env COMMITMENT_SECRET_HEX=... \
  -- npx -y @wasit-dev/server

By hand, the entry goes under mcpServers with "type": "local", the same command and args, an env object, and "tools": ["*"]. In a non-interactive run (copilot -p "..."), allow the server's tools with --allow-tool wasit.

Copilot CLI does not read envFile. It does pass its own environment to the server, so exporting the keys before starting it also works and keeps them out of every config file: set -a; source .env; set +a, then copilot.

Other clients

Any MCP client that runs stdio servers takes the same three things: command set to npx, args set to ["-y", "@wasit-dev/server"], and the environment variables MPP_STELLAR_NETWORK, STELLAR_PRIVATE_KEY, MPP_PAYER_SECRET and COMMITMENT_SECRET_HEX, plus EVM_PRIVATE_KEY for x402 payment checks on Base Sepolia (network: "eip155:84532") and SVM_PRIVATE_KEY for Solana devnet (network: "solana:EtWTRABZaYq6iMfeYKouRu166VU2xqa1"). Use absolute paths for node packages/server/dist/index.js if launching from a local checkout instead of npx, since a client launches the server from a working directory you don't control.

What has been run. Three clients have run Wasit's MCP server end to end against its fixtures, each with X402-01–07 all passing and X402-06 settled on-chain, then MPP-01 and the channel checks in the same session: Claude Code, in the session recorded in the README; GitHub Copilot CLI 1.0.91; and VS Code 1.140's own Copilot agent with the .vscode/mcp.json above, both on 3 October 2026. The same VS Code config in a session that ran on Copilot CLI started the server without its keys, which is how the envFile note above was found. Every CI run also installs the published package and completes an MCP handshake with it over stdio (npm run verify:clean-install), which is the same exchange any of these clients performs. The Codex and Cursor configurations follow each client's own documentation as of October 2026. Client names and logos are trademarks of their owners, shown only to say which client a configuration is for.