Paid MCP tools: refused clearly, never paid

  • MCP
  • Chat
  • CLI
  • Gateway

MCP servers give an agent tools: search an issue tracker, query a database, read a wiki. Most are free to call, or are paid for by the account you connect with. A newer kind charges for each call. The server answers an unpaid call with a price and payment instructions, and the client is expected to pay, usually a few cents in a stablecoin, and try again. Two protocols for this have appeared, x402 and MPP, and Cloudflare's agents toolkit lets a server make any of its tools a paid one.

Tempr doesn't pay for tools. This post is about what happens instead, because before this release that was a confusing error.

What used to happen

An agent calls a tool. The tool says "pay first". Each of Tempr's four MCP clients, in the CLI, VS Code, JetBrains and Visual Studio, turned that into some kind of failure, and none of them said what it was:

  • The model saw an unexplained error, so it often tried the same call again, and again.
  • You saw a failed tool call with no reason.
  • In some clients it didn't even look like an error. The payment instructions came back as if they were the tool's answer, or as an empty result.

Part of the reason is that there's no single way for a tool to refuse. We found four. The x402 MCP spec puts the payment terms in an error result. Cloudflare's toolkit puts them in the result's metadata. MPP uses a JSON-RPC error code. And a payment gateway in front of a server can answer with a plain HTTP 402, the status code the web reserved for "payment required" decades ago and barely used since. Our clients, and the MCP libraries under them, handled each of these differently.

What happens now

When a tool asks to be paid, in any of the four forms, every Tempr client does the same thing:

  • The agent is told plainly. The tool's result says it requires payment, at what price when the server gives one, that Tempr doesn't pay for tools so it wasn't run, and not to call it again, but to tell you if the task needs it.
  • You see it in the chat. The tool call shows "Paid tool, not run", with the price per call.
  • It's asked once. Later calls to the same tool are answered straight away, without contacting the server again, until the MCP servers restart.
  • Paid tools can be marked in advance. Where a server lists a tool as paid, as Cloudflare's toolkit does, the agent sees that before its first call, so it can plan around the tool instead of discovering the price by trying it.
  • A server that charges just to connect says so. Its startup error explains that it requires payment, instead of looking like a broken server.

The price is shown when the terms give it in USDC, a dollar stablecoin, or when a server lists a tool's price in dollars. When there are several options, the cheapest is shown. Anything else is shown as "a fee".

Why only the price gets through

A payment request carries text the seller wrote: a description of the resource, an error message, an address to pay. To the agent, that text would look like instructions from a tool it's using, and a seller could write anything there, including instructions meant for the agent. So nothing from a payment request reaches the model or your screen except the price, parsed as a number. The agent gets a message Tempr wrote, with that number in it.

All four clients, and the Gateway, are tested against the same set of refusals in every form, including one with an injection attempt in its description, and the clients must produce exactly the same messages.

Through the Gateway

MCP traffic that goes through Tempr's Gateway gets the same treatment on the server side. When a remote MCP server answers with HTTP 402, the headers that carry its terms now reach your client unchanged, and the request log records the call as mcp_payment_required, with the price when the terms give one in USDC. The Gateway doesn't pay either.

Why not just pay?

For a few cents, paying might seem easy. But an agent that can pay is an agent that can spend your money on its own judgement, many times over in one run. Paying means holding a wallet and funding it, deciding who approves which purchases, and handling the support cases that follow when an agent buys something nobody meant it to. No customer has asked us for that from their coding agent.

If that changes, the work done here still counts. A client that pays has to know a call is a purchase, must never retry one blindly, and should count it against the run's budget, the same price ceiling that limits model spend. Until then, a paid tool is a tool your agent knows it can't use, and says so.

The MCP servers page lists servers you can connect, and the MCP docs show how to set one up.