Cofferline
Treasury and risk controls for agent wallets: policies, quotes, prediction-market orders.
Should I use this
Quality & Safety
Findings (10)
- LOWin get_quotes
- LOWin complete_siwe_login
- LOWin get_auto_topup
- LOWin store_pm_credential
- LOWin revoke_pm_credential
- LOWin create_pm_order
- LOWin list_pm_orders
- LOWin resolve_pm_funder
- LOWin sync_pm_fills
- LOWin wrap_pm_usdc
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"treasury": {
"url": "https://mcp.cofferline.com"
}
}
}Remote endpoints
https://mcp.cofferline.comstreamable-httpWhat it can do
Tool inventory
Tools (47)
🟢get_quotes(sell_token, buy_token, sell_amount, chain_id)
Live venue quote comparison for a token conversion (CoW + ParaSwap on Base). Free, no auth.
Input Schema
{
"type": "object",
"properties": {
"sell_token": {
"type": "string",
"description": "ERC-20 address being sold"
},
"buy_token": {
"type": "string",
"description": "ERC-20 address being bought"
},
"sell_amount": {
"type": "string",
"description": "sell amount in base units, decimal string"
},
"chain_id": {
"type": "number",
"description": "8453 (Base)"
}
},
"required": [
"sell_token",
"buy_token",
"sell_amount"
]
}🟢get_benchmarks
Measured execution benchmarks: median savings vs arrival quote by USD size bucket, from real completed intents only. Free, no auth.
Input Schema
{
"type": "object",
"properties": {},
"required": []
}⚪screen_address(address)
OFAC SDN counterparty screening for an address. Free, no auth.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "EVM address to screen"
}
},
"required": [
"address"
]
}🟡list_tokens(chain_id)
Tokens the platform accepts on an intent, per chain — what create_intent will admit. Free, no auth.
Input Schema
{
"type": "object",
"properties": {
"chain_id": {
"type": "number",
"description": "limit to one chain; omit for every supported chain"
}
},
"required": []
}🟢list_feedback(limit)
Every feature request ever submitted, public and unauthenticated. Free.
Input Schema
{
"type": "object",
"properties": {
"limit": {
"type": "number",
"description": "max results"
}
},
"required": []
}🟡submit_feedback(title, body, x_payment)
Submit a feature request ($1 anti-spam fee, charged to the prepaid balance when funded). Auth required. Payment flow: call once without x_payment — a 402 reply lists the exact EIP-3009 requirements (amount, USDC asset, recipient, EIP-712 domain). Sign a transferWithAuthorization for them outside MCP (this server cannot sign), then call again with x_payment set to the base64 of {x402Version:1, scheme:'exact', network, payload:{signature, authorization}}.
Input Schema
{
"type": "object",
"properties": {
"title": {
"type": "string",
"description": "short title, 8-120 chars"
},
"body": {
"type": "string",
"description": "the request, 20-4000 chars"
},
"x_payment": {
"type": "string",
"description": "base64 X-PAYMENT value from a previously answered 402 (see description)"
}
},
"required": [
"title",
"body"
]
}⚪start_siwe_login(address, chain_id)
Start wallet sign-in: returns a single-use SIWE message. Sign it with the wallet outside MCP (this server cannot sign), then call complete_siwe_login. Free, no auth.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "wallet address to authenticate"
},
"chain_id": {
"type": "number",
"description": "8453"
}
},
"required": [
"address"
]
}⚪complete_siwe_login(message, signature)
Finish wallet sign-in: exchanges the signed SIWE message for a cl_sess_… session token — use it as the Authorization bearer on every authenticated tool. Free, no auth.
Input Schema
{
"type": "object",
"properties": {
"message": {
"type": "string",
"description": "the exact SIWE message from start_siwe_login"
},
"signature": {
"type": "string",
"description": "the wallet's signature over the message, 0x…"
}
},
"required": [
"message",
"signature"
]
}🟢get_me
Identify the authenticated account: address, kind, scopes. Auth required.
Input Schema
{
"type": "object",
"properties": {},
"required": []
}⚪export_account
Export all of this account's data in one document. Auth required.
Input Schema
{
"type": "object",
"properties": {},
"required": []
}⚪offboard_account(confirm_wallet_address, reason)
Close this account for good: revokes every credential, scrubs personal data, retires the account. Irreversible; confirm_wallet_address must be the account's own wallet address, typed exactly. Auth required.
Input Schema
{
"type": "object",
"properties": {
"confirm_wallet_address": {
"type": "string",
"description": "the account's wallet address, typed to confirm"
},
"reason": {
"type": "string",
"description": "optional reason, recorded"
}
},
"required": [
"confirm_wallet_address"
]
}🟡put_policy(policy)
Create or update the wallet's treasury policy (immutable versioning; PUT creates the next version). Auth required. Body must match /schemas/policy-v1.json — only version, wallet and chain_id are required; omitted fields take the platform defaults published in the manifest and are stored into the document, and the response lists them in `defaulted`.
Input Schema
{
"type": "object",
"properties": {
"policy": {
"type": "object",
"description": "PolicyV1 document; {\"version\":1,\"wallet\":\"0x…\",\"chain_id\":8453} is a complete one"
}
},
"required": [
"policy"
]
}🟢get_policy(wallet, limit)
List policy versions, newest first (the first entry is active). Auth required.
Input Schema
{
"type": "object",
"properties": {
"wallet": {
"type": "string",
"description": "optional wallet filter"
},
"limit": {
"type": "number",
"description": "max results"
}
},
"required": []
}🟢check_spend(wallet, amount_usd, token, counterparty)
Pre-flight policy check: would this spend be allowed under the wallet's policy right now? Auth required.
Input Schema
{
"type": "object",
"properties": {
"wallet": {
"type": "string",
"description": "wallet address"
},
"amount_usd": {
"type": "string",
"description": "spend amount in USD, decimal string"
},
"token": {
"type": "string",
"description": "token symbol, e.g. USDC"
},
"counterparty": {
"type": "string",
"description": "optional counterparty address to screen"
}
},
"required": [
"wallet",
"amount_usd",
"token"
]
}🟢check_pm_order(wallet, condition_id, cost_usd, state)
Pre-flight policy check for a prediction-market order: would this cost be allowed right now? Auth required.
Input Schema
{
"type": "object",
"properties": {
"wallet": {
"type": "string",
"description": "wallet address"
},
"condition_id": {
"type": "string",
"description": "market/condition identifier"
},
"cost_usd": {
"type": "string",
"description": "order cost in USD, decimal string"
},
"state": {
"type": "object",
"description": "optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings"
}
},
"required": [
"wallet",
"condition_id",
"cost_usd"
]
}⚪poll_events(wallet, cursor, limit, type)
Poll typed treasury events with a monotonic cursor (intent lifecycle, budget thresholds, reconciliation, security alerts). Auth required.
Input Schema
{
"type": "object",
"properties": {
"wallet": {
"type": "string",
"description": "optional wallet filter"
},
"cursor": {
"type": "number",
"description": "resume after this event id"
},
"limit": {
"type": "number",
"description": "max results"
},
"type": {
"type": "string",
"description": "optional event-type filter, e.g. intent.filled"
}
},
"required": []
}🟢get_statement(wallet, period, format)
Deterministic monthly statement derived from the append-only ledger — same period, same bytes. Auth required.
Input Schema
{
"type": "object",
"properties": {
"wallet": {
"type": "string",
"description": "wallet address"
},
"period": {
"type": "string",
"description": "calendar month, YYYY-MM"
},
"format": {
"type": "string",
"description": "'json' (default) or 'csv'"
}
},
"required": [
"wallet",
"period"
]
}🟡create_intent(wallet, kind, sell_token, buy_token, sell_amount, ...)
Create a conversion or gas_topup intent; the executor pipeline plans and fills it under policy. Auth required.
Input Schema
{
"type": "object",
"properties": {
"wallet": {
"type": "string",
"description": "wallet address"
},
"kind": {
"type": "string",
"enum": [
"conversion",
"gas_topup"
]
},
"sell_token": {
"type": "string",
"description": "ERC-20 address being sold"
},
"buy_token": {
"type": "string",
"description": "ERC-20 address being bought"
},
"sell_amount": {
"type": "string",
"description": "base units, decimal string"
},
"max_slippage_bps": {
"type": "number",
"description": "optional per-intent slippage cap"
},
"venues": {
"type": "array",
"items": {
"type": "string"
},
"description": "optional venue override"
}
},
"required": [
"wallet",
"kind",
"sell_token",
"buy_token",
"sell_amount"
]
}🟡get_intent(id)
Fetch an intent, including fills and the post-trade report once filled. Auth required.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "intent id (uuid)"
}
},
"required": [
"id"
]
}🟢list_intents(wallet, limit, offset)
List intents, newest first. Auth required.
Input Schema
{
"type": "object",
"properties": {
"wallet": {
"type": "string",
"description": "optional wallet filter"
},
"limit": {
"type": "number",
"description": "max results"
},
"offset": {
"type": "number",
"description": "skip this many"
}
},
"required": []
}🔴cancel_intent(id)
Cancel a planned intent (a few-second window before execution claims it). Auth required.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "intent id (uuid)"
}
},
"required": [
"id"
]
}⚪prepare_delegation(account, chain_id, calls, valid_after, valid_until, ...)
Prepare a scoped session-key grant for a Kernel smart account: exact call allowlist, expiry, optional rate limit. Returns the ONE EIP-712 digest the account owner signs outside MCP (this server cannot sign) — then call confirm_delegation with the signature. Auth required.
Input Schema
{
"type": "object",
"properties": {
"account": {
"type": "string",
"description": "the Kernel smart account granting scope"
},
"chain_id": {
"type": "number",
"description": "8453 (Base) or 84532 (Base Sepolia)"
},
"calls": {
"type": "array",
"description": "allowed calls: each {target: contract address, selector: 0x + 4 bytes, value_limit: max native value in wei as decimal string}",
"items": {
"type": "object",
"properties": {
"target": {
"type": "string",
"description": "contract address"
},
"selector": {
"type": "string",
"description": "function selector, 0x + 8 hex chars"
},
"value_limit": {
"type": "string",
"description": "max native value per call, wei, decimal string"
}
},
"required": [
"target",
"selector",
"value_limit"
]
}
},
"valid_after": {
"type": "number",
"description": "optional start, unix seconds"
},
"valid_until": {
"type": "number",
"description": "expiry, unix seconds"
},
"rate_limit": {
"type": "object",
"description": "optional {count, interval_secs}: max delegated calls per interval"
}
},
"required": [
"account",
"chain_id",
"calls",
"valid_until"
]
}⚪confirm_delegation(id, enable_sig, owner)
Activate a prepared delegation by supplying the owner's signature over its enable digest. Auth required.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "delegation id (uuid)"
},
"enable_sig": {
"type": "string",
"description": "owner's 65-byte signature over the digest, 0x…"
},
"owner": {
"type": "string",
"description": "optional owner address, when it differs from the caller"
}
},
"required": [
"id",
"enable_sig"
]
}⚪renew_delegation(id, valid_until)
Renew an active delegation: same scope, fresh expiry, no authority gap. Returns a NEW digest to sign and confirm exactly like prepare_delegation. Auth required.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "delegation id (uuid)"
},
"valid_until": {
"type": "number",
"description": "optional new expiry, unix seconds; defaults to the original duration"
}
},
"required": [
"id"
]
}🟡revoke_delegation(id)
Revoke a delegation. The reply includes calldata the owner can send on-chain for hard finality. Auth required.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "delegation id (uuid)"
}
},
"required": [
"id"
]
}🟢get_delegation(id)
Fetch one delegation. Auth required.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "delegation id (uuid)"
}
},
"required": [
"id"
]
}🟢list_delegations(account, limit)
List delegations, newest first. Auth required.
Input Schema
{
"type": "object",
"properties": {
"account": {
"type": "string",
"description": "optional smart-account filter"
},
"limit": {
"type": "number",
"description": "max results"
}
},
"required": []
}⚪panic(reason)
Emergency stop, one call: suspends the account, revokes every API key, session, delegation and venue credential, and returns all unwind calldata for the owner. Auth required.
Input Schema
{
"type": "object",
"properties": {
"reason": {
"type": "string",
"description": "optional reason, recorded"
}
},
"required": []
}🟢get_balance
Prepaid fee balance: settled credits minus fee debits. Auth required.
Input Schema
{
"type": "object",
"properties": {},
"required": []
}🟡topup_balance(amount_usd, x_payment)
Top up the prepaid balance with USDC. Auth required. Payment flow: call once without x_payment — a 402 reply lists the exact EIP-3009 requirements (amount, USDC asset, recipient, EIP-712 domain). Sign a transferWithAuthorization for them outside MCP (this server cannot sign), then call again with x_payment set to the base64 of {x402Version:1, scheme:'exact', network, payload:{signature, authorization}}.
Input Schema
{
"type": "object",
"properties": {
"amount_usd": {
"type": "string",
"description": "top-up amount in USD, decimal string"
},
"x_payment": {
"type": "string",
"description": "base64 X-PAYMENT value from a previously answered 402 (see description)"
}
},
"required": [
"amount_usd"
]
}🟡set_auto_topup(threshold_usd, max_per_month, authorizations)
Configure auto-topup: when the prepaid balance falls below threshold_usd, the platform settles one of the pre-signed EIP-3009 authorizations you supply (signed outside MCP — this server cannot sign). Auth required.
Input Schema
{
"type": "object",
"properties": {
"threshold_usd": {
"type": "string",
"description": "refill when balance drops below this, USD decimal string"
},
"max_per_month": {
"type": "number",
"description": "cap on automatic top-ups per month (default 10)"
},
"authorizations": {
"type": "array",
"description": "pre-signed transferWithAuthorization payloads: each {from, to, value, valid_after, valid_before, nonce, signature}",
"items": {
"type": "object",
"properties": {
"from": {
"type": "string",
"description": "payer address"
},
"to": {
"type": "string",
"description": "platform recipient address"
},
"value": {
"type": "string",
"description": "USDC base units, decimal string"
},
"valid_after": {
"type": "string",
"description": "unix seconds, decimal string"
},
"valid_before": {
"type": "string",
"description": "unix seconds, decimal string"
},
"nonce": {
"type": "string",
"description": "32-byte nonce, 0x…"
},
"signature": {
"type": "string",
"description": "EIP-3009 signature, 0x…"
}
},
"required": [
"from",
"to",
"value",
"valid_after",
"valid_before",
"nonce",
"signature"
]
}
}
},
"required": [
"threshold_usd",
"authorizations"
]
}🟢get_auto_topup
The auto-topup rule and how many pre-signed authorizations remain. Auth required.
Input Schema
{
"type": "object",
"properties": {},
"required": []
}🔴remove_auto_topup
Remove the auto-topup rule and its unused authorizations. Auth required.
Input Schema
{
"type": "object",
"properties": {},
"required": []
}⚪store_pm_credential(venue, label, signer_private_key, maker, signer, ...)
Store a prediction-market venue credential (verified live against the venue, sealed at rest, material never returned). Polymarket, either shape: signer_private_key + maker (derives API creds), or api_key + secret + passphrase + maker + signer. Auth required.
Input Schema
{
"type": "object",
"properties": {
"venue": {
"type": "string",
"enum": [
"polymarket"
],
"default": "polymarket",
"description": "prediction-market venue (default polymarket)"
},
"label": {
"type": "string",
"description": "optional display label"
},
"signer_private_key": {
"type": "string",
"description": "Polymarket: signer EOA private key, 0x…"
},
"maker": {
"type": "string",
"description": "Polymarket: funder (maker) address"
},
"signer": {
"type": "string",
"description": "Polymarket: signer address (explicit-creds shape)"
},
"api_key": {
"type": "string",
"description": "Polymarket: CLOB API key (explicit-creds shape)"
},
"secret": {
"type": "string",
"description": "Polymarket: CLOB API secret (explicit-creds shape)"
},
"passphrase": {
"type": "string",
"description": "Polymarket: CLOB API passphrase (explicit-creds shape)"
},
"signature_type": {
"type": "number",
"description": "Polymarket: 0 EOA, 1 Magic/email, 2 browser proxy (default 1)"
}
},
"required": []
}🟢list_pm_credentials
List stored venue credentials — metadata only, never material. Auth required.
Input Schema
{
"type": "object",
"properties": {},
"required": []
}⚪revoke_pm_credential(id)
Revoke a venue credential; its sealed ciphertext is destroyed. Auth required.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "credential id (uuid)"
}
},
"required": [
"id"
]
}🟢get_pm_signer_rotation(id, new_owner)
Calldata to swap the Polymarket funder Safe's owner to a new EOA — the owner executes it outside MCP (this server cannot sign). Auth required.
Input Schema
{
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "credential id (uuid)"
},
"new_owner": {
"type": "string",
"description": "the replacement owner address"
}
},
"required": [
"id",
"new_owner"
]
}🟡create_pm_order(venue, wallet, credential_id, action, condition_id, ...)
Place a prediction-market limit order under policy, signed server-side with the stored credential. Polymarket: condition_id, token_id, action, price_usd (e.g. '0.55'), size_shares. Auth required.
Input Schema
{
"type": "object",
"properties": {
"venue": {
"type": "string",
"enum": [
"polymarket"
],
"default": "polymarket",
"description": "prediction-market venue (default polymarket)"
},
"wallet": {
"type": "string",
"description": "treasury wallet whose policy governs the order"
},
"credential_id": {
"type": "string",
"description": "stored credential id (uuid)"
},
"action": {
"type": "string",
"enum": [
"buy",
"sell"
]
},
"condition_id": {
"type": "string",
"description": "Polymarket: market condition id"
},
"token_id": {
"type": "string",
"description": "Polymarket: outcome token id, decimal string"
},
"price_usd": {
"type": "string",
"description": "Polymarket: limit price, '0.xx'"
},
"size_shares": {
"type": "string",
"description": "Polymarket: share count, decimal string"
},
"client_order_id": {
"type": "string",
"description": "optional idempotency uuid"
},
"state": {
"type": "object",
"description": "optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings"
}
},
"required": [
"wallet",
"credential_id",
"action"
]
}🟢list_pm_orders(credential_id, market)
The credential's resting orders straight from the venue — recover state after a disconnect. Auth required.
Input Schema
{
"type": "object",
"properties": {
"credential_id": {
"type": "string",
"description": "stored credential id (uuid)"
},
"market": {
"type": "string",
"description": "optional market filter"
}
},
"required": [
"credential_id"
]
}🔴cancel_pm_order(venue, order_id, credential_id)
Cancel one resting prediction-market order. Auth required.
Input Schema
{
"type": "object",
"properties": {
"venue": {
"type": "string",
"enum": [
"polymarket"
],
"default": "polymarket",
"description": "prediction-market venue (default polymarket)"
},
"order_id": {
"type": "string",
"description": "the venue's order id"
},
"credential_id": {
"type": "string",
"description": "stored credential id (uuid)"
}
},
"required": [
"order_id",
"credential_id"
]
}🔴cancel_all_pm_orders(credential_id, market)
Cancel every resting order for the credential, optionally within one market. Auth required.
Input Schema
{
"type": "object",
"properties": {
"credential_id": {
"type": "string",
"description": "stored credential id (uuid)"
},
"market": {
"type": "string",
"description": "optional market filter"
}
},
"required": [
"credential_id"
]
}🟡prepare_pm_order(venue, wallet, credential_id, condition_id, token_id, ...)
Prepare a client-signed Polymarket order: policy-checked, then returns the exact EIP-712 payload to sign outside MCP (this server cannot sign) plus a prepare_id — submit both via submit_pm_order. Auth required.
Input Schema
{
"type": "object",
"properties": {
"venue": {
"type": "string",
"enum": [
"polymarket"
]
},
"wallet": {
"type": "string",
"description": "treasury wallet whose policy governs the order"
},
"credential_id": {
"type": "string",
"description": "stored credential id (uuid)"
},
"condition_id": {
"type": "string",
"description": "market condition id"
},
"token_id": {
"type": "string",
"description": "outcome token id, decimal string"
},
"action": {
"type": "string",
"enum": [
"buy",
"sell"
]
},
"price_usd": {
"type": "string",
"description": "limit price, '0.xx'"
},
"size_shares": {
"type": "string",
"description": "share count, decimal string"
},
"client_order_id": {
"type": "string",
"description": "optional idempotency uuid"
},
"state": {
"type": "object",
"description": "optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings"
}
},
"required": [
"venue",
"wallet",
"credential_id",
"condition_id",
"token_id",
"action",
"price_usd",
"size_shares"
]
}🟡submit_pm_order(prepare_id, signature)
Submit a prepared Polymarket order with the maker's EIP-712 signature from prepare_pm_order. Auth required.
Input Schema
{
"type": "object",
"properties": {
"prepare_id": {
"type": "string",
"description": "prepare id (uuid) from prepare_pm_order"
},
"signature": {
"type": "string",
"description": "the maker's 65-byte EIP-712 signature, 0x…"
}
},
"required": [
"prepare_id",
"signature"
]
}🟢get_pm_onboarding(address)
Polymarket trade-readiness for an address: live approval status plus the calldata for anything missing (executed outside MCP — this server cannot sign). Auth required.
Input Schema
{
"type": "object",
"properties": {
"address": {
"type": "string",
"description": "the trading address to check"
}
},
"required": [
"address"
]
}⚪resolve_pm_funder(owner)
Resolve an owner EOA to its Polymarket funder Safe candidates. Auth required.
Input Schema
{
"type": "object",
"properties": {
"owner": {
"type": "string",
"description": "owner EOA address"
}
},
"required": [
"owner"
]
}⚪sync_pm_fills(wallet, credential_id)
Pull the venue's fills for a credential into the wallet's ledger. Idempotent — safe to repeat. Auth required.
Input Schema
{
"type": "object",
"properties": {
"wallet": {
"type": "string",
"description": "treasury wallet whose books receive the fills"
},
"credential_id": {
"type": "string",
"description": "stored credential id (uuid)"
}
},
"required": [
"wallet",
"credential_id"
]
}⚪wrap_pm_usdc(credential_id, amount_base_units)
Wrap the funder Safe's USDC.e into Polymarket's pUSD, platform-relayed so the user pays no gas. Omit amount_base_units to wrap the full balance. Auth required.
Input Schema
{
"type": "object",
"properties": {
"credential_id": {
"type": "string",
"description": "stored credential id (uuid)"
},
"amount_base_units": {
"type": "string",
"description": "optional amount in base units, decimal string"
}
},
"required": [
"credential_id"
]
}Community
Evidence