{
  "markdown": "# MCPSpend\n\n> **Know what your AI agents really cost.** Real-time cost tracking for every MCP tool call across Cursor, Claude Desktop, Windsurf, and VS Code.\n\n[![smithery badge](https://smithery.ai/badge/andreisirbu91-lab/mcpspend)](https://smithery.ai/servers/andreisirbu91-lab/mcpspend)\n[![npm version](https://img.shields.io/npm/v/@mcpspend/proxy.svg)](https://www.npmjs.com/package/@mcpspend/proxy)\n[![Open VSX](https://img.shields.io/open-vsx/v/McpSpend/mcpspend-vscode)](https://open-vsx.org/extension/McpSpend/mcpspend-vscode)\n[![license](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n[![MCPSpend MCP server](https://glama.ai/mcp/servers/andreisirbu91-lab/MCPSpend/badges/score.svg)](https://glama.ai/mcp/servers/andreisirbu91-lab/MCPSpend)\n\n**[mcpspend.com](https://mcpspend.com)** · **[Smithery](https://smithery.ai/servers/andreisirbu91-lab/mcpspend)** · **[npm](https://www.npmjs.com/package/@mcpspend/proxy)** · **[Open VSX](https://open-vsx.org/extension/McpSpend/mcpspend-vscode)** · **[Glama](https://glama.ai/mcp/servers/andreisirbu91-lab/MCPSpend)**\n\n<a href=\"https://glama.ai/mcp/servers/andreisirbu91-lab/MCPSpend\">\n  <img width=\"380\" height=\"200\" src=\"https://glama.ai/mcp/servers/andreisirbu91-lab/MCPSpend/badges/card.svg\" alt=\"MCPSpend MCP server card\" />\n</a>\n\n---\n\n## One-command install\n\n```sh\nnpx --yes @mcpspend/proxy@latest init --key mcps_live_xxx\n```\n\nAuto-detects Claude Desktop, Cursor, Windsurf, VS Code (user + workspace), and Claude Code (user + project). Wraps every configured MCP server, leaves a `.mcpspend.bak` backup, and starts streaming usage to your dashboard at [mcpspend.com](https://mcpspend.com).\n\nFree tier: **25,000 tool calls/month**, no credit card.\n\n## What's in this monorepo\n\n| Package | What it is |\n|---|---|\n| [`packages/proxy`](packages/proxy) | `@mcpspend/proxy` — the stdio observability proxy + `wrap-http` bridge for remote MCP servers. **Published on npm.** |\n| [`packages/mcp-server`](packages/mcp-server) | `@mcpspend/mcp-server` — query your MCPSpend usage from inside any MCP client. **Published on npm + Smithery.** |\n| [`packages/vscode-extension`](packages/vscode-extension) | `mcpspend-vscode` — IDE extension for Cursor, Windsurf, and VS Code. **Published on Open VSX.** |\n| [`apps/api`](apps/api) | Express + Prisma + Postgres + BullMQ. The ingest endpoint, billing, and the new `/api/mcp` HTTP MCP server. |\n| [`apps/dashboard`](apps/dashboard) | Next.js dashboard at [mcpspend.com](https://mcpspend.com). |\n\n## Three ways to query your usage\n\n| Use case | How |\n|---|---|\n| **Web dashboard** | [mcpspend.com/dashboard](https://mcpspend.com/dashboard) — overview, top tools, sessions, CSV export. |\n| **From any MCP client (stdio)** | Add `@mcpspend/mcp-server` to your client config — agent gains tools like `get_today_cost`, `list_top_tools`. |\n| **From any MCP client (HTTP)** | Point your client at `https://api.mcpspend.com/api/mcp` with `Authorization: Bearer mcps_live_…`. |\n\n## Pricing\n\n| Plan | Calls/month | Monthly | Yearly |\n|---|---|---|---|\n| Free | 25,000 | $0 | $0 |\n| Pro | 1,000,000 | $29 | $290 (2 months free) |\n| Team | 10,000,000 | $99 | $990 |\n| Enterprise | unlimited | $499 | $4,990 |\n\nEvery paid plan: 30–90 day retention, CSV/Slack export, budget alerts, role-based access.\n\n## Privacy\n\nThe proxy reports: tool name, server name, model, latency, success, approximate input/output sizes (tokens, derived from JSON length). It **does not** send the actual tool arguments or response bodies to MCPSpend. See [Privacy Policy](https://mcpspend.com/privacy) for the full sub-processor list (Stripe + Resend + Hostinger, all EU-hosted) and your GDPR rights.\n\n## Security\n\n> **For automated scanners flagging this repo:** the proxy uses `child_process.spawn` to wrap the user's *own* MCP server — that's the whole point of an observability proxy. The spawn args come from the user's local MCP-client config (Claude Desktop / Cursor / Windsurf / VS Code), never from network input. No RCE path, no privilege escalation, no arbitrary command execution. Full threat model in [`SECURITY.md`](SECURITY.md).\n\n- **API keys** stored as SHA-256 hashes (never plaintext on the server)\n- **Passwords** bcrypt cost 12\n- **Secrets at rest** AES-256-GCM (`APP_ENCRYPTION_KEY`)\n- **Transport** HTTPS only, HSTS enabled, helmet CSP headers\n- **No tool arguments or responses** ever leave the user's machine\n- **Per-tenant isolation** every query scopes by `organizationId`\n- **GDPR Art. 15 / 17 / 20** self-serve at `mcpspend.com/dashboard/account/privacy`\n- **EU-hosted** (Hostinger EU region)\n- **SOC 2 Type I** in progress with Vanta (Q4 2026)\n- **DPA** available for Enterprise customers\n\nReport vulnerabilities: **security@mcpspend.com** · Machine-readable disclosure: <https://mcpspend.com/.well-known/security.txt> · Full policy: [`SECURITY.md`](SECURITY.md) · Live posture: <https://mcpspend.com/security>\n\n## Support the project\n\nIf MCPSpend saves you money or you just want to keep the proxy MIT and the free\ntier alive, you can sponsor any amount via Stripe — no account required:\n\n**[💖 buy.stripe.com/00w8wPbUxe1qgK36CRbbG06](https://buy.stripe.com/00w8wPbUxe1qgK36CRbbG06)**\n\nEvery dollar goes back into hosting, security audits, and shipping features.\n\n## License\n\nMIT. Use it, fork it, run it self-hosted.\n\n© NewRzs SRL · CUI RO48756557 · Bucharest, Romania · [support@mcpspend.com](mailto:support@mcpspend.com)\n",
  "bytes": 5422,
  "sha": "ac4b2a4be4676dc82e3d2b4a1a655b7b5b36a2bf0401e3cde540c7906d7c7704",
  "repo_slug": "andreisirbu91-lab/mcpspend",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_andreisirbu91_lab_mcpspend_b6f6cf79/readme"
}