Desktop installer for the local IronWallet MCP server. It adds the wallet to Cursor, Claude Code, VS Code, and ChatGPT so agents can use a non-custodial hot wallet on this machine.
Download the signed binary for your OS from ironwallet.io/ai or GitHub Releases. Source is not published — only those binaries.
The installer is a one-shot GUI. It does not copy itself onto the system, does not stay resident, and does not phone home. What it may write is listed in SECURITY.md.
Version: see VERSION. Changes: CHANGELOG.md.
The MCP server is not inside this installer. Cursor and VS Code get
npx -y @ironwallet/mcp-server. The wizard prefetches that package into the
npx cache (install only, the wallet server is not started) so Claude’s first
MCP handshake does not stall on a download. Claude and ChatGPT
also install the marketplace plugin from
github.com/ironwallet/ironwallet-agent-kit.
- After you pick environments, checks for Node.js 20+. If it is missing, installs
it via
winget/ Homebrew / the distro package manager (nocurl | sh). If that fails, opens the official Node.js download page; Retry re-checks PATH. - Detects Cursor, Claude Code, VS Code, and ChatGPT. Found apps are pre-checked. Missing ones show a Download link instead of a checkbox.
- Install MCP stays disabled until at least one found app is selected.
- Asks selected GUI apps to quit, prefetches
@ironwallet/mcp-serverinto the npx cache, then writes configs. One agent failure does not abort the others. A failed prefetch is a hint, not a hard stop. - Cursor and VS Code: merge MCP JSON (does not wipe other servers).
- Claude Code: Git +
claudeCLI if needed, thenclaude plugin marketplace add ironwallet/ironwallet-agent-kitandclaude plugin install ironwallet-mcp@ironwallet --scope user. If the Claude Desktop app is installed, the chat is configured too: the sameironwalletentry is merged intoclaude_desktop_config.jsonwith an absolutenpxpath (loaded on the next full restart of Claude). Claude counts as installed when either channel worked; if the CLI flow failed but the chat was configured, Open starts a chat, not a Code session. - ChatGPT (if the bundled or standalone
codexCLI is present):codex plugin marketplace add ironwallet/ironwallet-agent-kitandcodex plugin add ironwallet-mcp@ironwallet.
Chat is never used as an install channel. Missing CLIs get a Download button.
Releases include amd64 and arm64 for Windows and Linux. macOS is one
universal2 .dmg (both slices).
| File | Arch |
|---|---|
ironwallet-setup-windows-amd64.exe / windows-arm64.exe |
both |
ironwallet-setup-linux-amd64 / linux-arm64 |
both |
ironwallet-setup-macos.dmg |
universal2 |
The installer does not declare a minimum OS version. Practical floor:
| OS | Auto Node.js | Notes |
|---|---|---|
| Windows | winget (OpenJS.NodeJS.LTS) — typically Windows 10 1709+ / Windows 11 |
No console window |
| macOS | Homebrew node |
Signed/notarized .app in a dmg |
| Linux | apt-get or dnf (nodejs, npm), via pkexec when present |
X11 or Wayland |
No zypper/pacman path: install Node.js 20+ yourself, then Retry.
| Environment | What the installer configures | First-run Open |
|---|---|---|
| Cursor | Merge ~/.cursor/mcp.json |
Deeplink with the starter prompt |
| VS Code | Merge user mcp.json |
Copilot Chat URI with the starter prompt |
| Claude Code | claude CLI plugins, --scope user; plus claude_desktop_config.json when Claude Desktop is installed |
claude:// new-chat URI |
| ChatGPT | codex CLI plugins |
codex://new?prompt= when the ChatGPT desktop app is installed; none for a plain CLI |
Detection looks at PATH, well-known app paths, and ~/.cursor / ~/.claude /
~/.codex. When the Claude Desktop app itself is found, the
installer also merges the ironwallet entry into that client’s
claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/;
Windows classic: %APPDATA%\Claude\; Windows Store: the containerized
%LOCALAPPDATA%\Packages\Claude_*\LocalCache\Roaming\Claude\ path the MSIX
build actually reads). Desktop does not inherit the shell PATH, so this entry
uses an absolute npx path — cmd /c around npx.cmd on Windows. The chat
picks it up after a full quit and relaunch of Claude.
For ChatGPT, when codex is not on PATH the installer falls back to the CLI
that ships with the app: on Windows the copy the app
materializes under %LOCALAPPDATA%\OpenAI\Codex\bin (the binary inside the
MSIX package itself is not executable from outside), then the standalone
install under %LOCALAPPDATA%\Programs\OpenAI\Codex\bin, then the npm shim;
on macOS ~/.local/bin/codex or ChatGPT.app/Codex.app
Contents/Resources/codex. That CLI shares ~/.codex with the app, so the
plugin it installs is visible in the desktop app too.
If the environment is already configured: Cursor/VS Code overwrite only the
ironwallet key; other MCP servers stay. Claude/ChatGPT treat
already/exists/duplicate from the CLI as success. Node.js 20+ already on PATH
is left as-is (no pin, no upgrade). The npx entry does not pin a package
version — the next agent start may pull latest @ironwallet/mcp-server.
Parent directories are created with mode 0755 only when a file is written.
| OS | Cursor | VS Code |
|---|---|---|
| Windows | %USERPROFILE%\.cursor\mcp.json |
%APPDATA%\Code\User\mcp.json |
| macOS | ~/.cursor/mcp.json |
~/Library/Application Support/Code/User/mcp.json |
| Linux | ~/.cursor/mcp.json |
$XDG_CONFIG_HOME/Code/User/mcp.json or ~/.config/Code/User/mcp.json |
On Windows, if APPDATA is empty, VS Code uses
%USERPROFILE%\AppData\Roaming\Code\User\mcp.json.
Entry written (Cursor, and VS Code when the file already uses mcpServers):
{
"mcpServers": {
"ironwallet": {
"command": "npx",
"args": ["-y", "@ironwallet/mcp-server"]
}
}
}New VS Code files use servers plus "type": "stdio" on that entry. If a VS
Code file already has mcpServers and no servers, the installer keeps
mcpServers and does not invent a servers object.
Invalid JSON is an error; the file is not replaced with an empty document.
Claude / ChatGPT configs are written by those CLIs (typically under
~/.claude, ~/.codex). This installer does not edit those files
directly.
On the done screen, Open prefills this text. Finish only closes the wizard. It is not written into MCP JSON or plugin files.
IronWallet MCP is installed. First open https://github.com/ironwallet/ironwallet-agent-kit and read skills/ironwallet-mcp/SKILL.md plus the Tools section in README.md (or llms.txt) so you learn the intended tool workflow. Then explain to me in this chat what I can do: wallets, balances, deposit QR codes, transfers, and swaps.
The prompt sends the agent to the public kit repo to read the skill and the tool workflow, then to explain wallets, balances, transfers, swaps, and deposit QR codes. It does not mention a seed, recovery phrase, private key, or mnemonic, and it does not ask the agent to sign or export secrets.
There is no uninstaller, silent flag, or reverse wizard. Close the
installer and delete the binary (or the macOS .app) if you still have it.
The installer never removes other people’s MCP servers. To undo IronWallet only:
- Cursor — in
mcp.json(path above), delete theironwalletkey frommcpServers. Delete the file if it is otherwise empty. - VS Code — same key in
serversormcpServersin the usermcp.json. - Claude Code — uninstall
ironwallet-mcp@ironwalletwith the currentclaude plugincommand (the installer does not invoke uninstall). Remove the marketplaceironwallet/ironwallet-agent-kitif you want a full rollback. If Claude Desktop was configured, also delete theironwalletkey frommcpServersinclaude_desktop_config.json(paths above). - ChatGPT — remove
ironwallet-mcp@ironwalletwith the currentcodex plugincommand.
Left on purpose, because the installer does not record whether it installed
them: Node.js, Git, global @anthropic-ai/claude-code, other MCP servers, and
any ~/.cursor / ~/.claude / ~/.codex directory that already
existed or that a CLI created.
- Interrupted install. No checkpoint. Re-run the installer: Node.js 20+ is
skipped, JSON upsert is idempotent for the
ironwalletkey, plugin add treats “already present” as success. A kill whilemcp.jsonis being written can leave a truncated file. A kill during winget/brew/apt leaves whatever that tool already committed. The only in-UI resume is Retry on the failed Node.js step in the same window (the environment selection is kept in memory). - Running clients. Config is not pushed into a live process. The installer
asks selected GUIs to quit (
WM_CLOSE/osascript quit/pkill -TERM -x) and waits 800 ms. The done screen says to open a new chat and reload the app if it was still open. That reload is not guaranteed. - Restricted machines. No proxy settings. winget, Homebrew, apt/dnf, and
npm use the ambient environment. Writing
mcp.jsonin the user profile usually works without admin; auto Node.js/Git often does not. No winget on Windows → Node.js step fails and opens nodejs.org/en/download. GitHub/npm must be reachable for plugins and for laternpx. UAC /pkexecare the only elevation prompts; there is no silent enterprise install.
| File | Audience |
|---|---|
| SECURITY.md | System impact, network, privileges, leftovers |
| CHANGELOG.md | User-facing changes per release |
Apache License 2.0. Copyright 2026 INWAY AG. See LICENSE and NOTICE.
The installer embeds Manrope fonts under the SIL Open Font License. That license applies to the fonts only, not to the installer.