Server data from the Official MCP Registry
Pre-trade safety checks and 40 oracle data tools for AI agents, paid per call via x402.
About
Pre-trade safety checks and 40 oracle data tools for AI agents, paid per call via x402.
Remote endpoints: streamable-http: https://www.oracleinsight.xyz/api/mcp
Security Report
This is a legitimate DeFi oracle risk assessment MCP server with appropriate network and API permissions for its purpose. Code quality is generally good with proper TypeScript configuration and dependency management. However, there are moderate concerns around API key handling in environment variables, limited input validation documentation, and the presence of a large bundled/minified file that reduces auditability. Supply chain analysis found 4 known vulnerabilities in dependencies (0 critical, 1 high severity).
4 files analyzed · 10 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
Insight — Oracle Transparency & Risk Intelligence
Insight helps DeFi applications, operators, developers, and AI agents inspect oracle prices and the risks of relying on them. It compares data from 10 oracle providers across 40+ blockchain networks, evaluates deviation, freshness, source independence, and protocol impact, and can issue signed evidence of its assessments.
Oracle observations → Cross-source comparison → Risk assessment → Verifiable evidence
Pre-Trade Safety Check assesses a proposed action. Oracle Watch monitors changing conditions between actions. The REST API, MCP server, Guard SDK, and independent verifier make these capabilities available to applications and agents. Insight also works independently of PriorSeal; see the product positioning guide for the combined assessment, authorization, execution, and review workflow.
Insight is not a real-time oracle tracker. Price snapshots and feed health are collected every 15 minutes, reputation scores are recalculated hourly, and data is aggregated into daily reports. Check each assessment's freshness and validity window before using it.
Start here
| Goal | Where to go |
|---|---|
| Assess a trade from an application or agent | Guard SDK or API reference |
| Verify a signed receipt with your own trusted keys | Independent verifier or browser demo |
| Explore the product | Website or AI/MCP hub |
| Run the website and API locally | Local development |
What Insight provides
Pre-Trade Safety Check
Before a swap, borrow, lend, liquidation, or repayment, an application can request a cross-oracle assessment. The response combines price agreement, deviation, freshness, stablecoin peg status, reputation, and relevant protocol risk into a PASS, CAUTION, DANGER, or BLOCK verdict with a recommended maximum position size. Agents should not execute when the verdict is DANGER or BLOCK.
The verdict comes from deterministic rules; experimental ML scores provide additional context but do not drive it. Lending checks can freeze new borrowing when sustained oracle dispersion consumes the protocol's liquidation buffer. Successfully returned judgments are audit-logged before issuance; an audit-storage failure prevents a successful response.
When signing is configured, the check can include an EIP-712 attestation. A signature proves who issued the signed fields and whether they changed. It does not prove that the underlying prices were correct or that an agent obeyed the verdict. See the verifier's supported schemas for version-specific verification requirements.
Oracle Watch
Oracle Watch gives a running strategy a cross-oracle NORMAL, CAUTION, or DANGER signal and a proceed, proceed_with_caution, or halt recommendation. Applications can poll it between trades and pause on halt. It checks deviation, agreement, stale or outlying feeds, coverage, and independent source groups; it can also issue signed receipts when an attester key is configured.
Historical coverage is guaranteed for ETH, BTC, USDC, and USDT on Ethereum, Arbitrum, and Base. Other pairs can return a current signal without a historical curve; check meta.historyGuaranteed rather than treating an empty series as evidence of no incidents. Use the AI/MCP hub or GET /api/v1/oracle-watch?symbol=ETH&chain=ethereum to explore the signal.
Explore oracle and protocol risk
The web app also provides cross-oracle price comparison, feed health and reputation, position safety and liquidation analysis, Peg Risk for stablecoins and wrapped assets, and daily reports. Researchers can inspect source timestamps and export results; developers can use the corresponding API endpoints.
Integrated providers include Chainlink, API3, RedStone, DIA, WINkLink, Supra, Uniswap V3 TWAP, Reflector, Flare, and Band. Position safety supports selected Aave V3, Compound V3, Morpho Blue, Venus, and BENQI markets. Coverage varies by asset and chain, so confirm the available sources and protocol parameters for the position being assessed.
SDK, API, MCP, and verifier
- Guard SDK — TypeScript integration for assessment, monitoring, and supported execution-price evidence.
assessSwap()supports an assessment-only workflow; optional helpers can gate transaction submission and request execution receipts. The SDK uses the Insight API and its credit wallet. - REST API — versioned
/api/v1/endpoints for prices, risk, safety checks, and Oracle Watch. Metered calls use anX-API-Key; public receipt-verification endpoints do not require one. The API reference has request and response details. - MCP server — exposes the same services to compatible agents through stdio, HTTP, or the app's
/api/mcpendpoint. See the AI/MCP hub for client configuration and tools. - Independent verifier — verifies receipt signatures and signed fields locally without depending on the Insight API. Consumers must independently establish trust in the attester key or key registry; successful signature verification is not an endorsement of a trade or verdict.
REST, MCP, and SDK calls draw from the same API-key credit wallet. Plans add credit capacity rather than separate feature tiers. See current pricing for plans and per-call costs.
MCP endpoint (production)
The hosted MCP server is live at https://www.oracleinsight.xyz/api/mcp (streamable HTTP).
- Anonymous discovery:
initialize,tools/list, andpingwork without credentials, so agents can browse the 40-tool oracle catalog before committing. - Authenticated calls: pass an API key and calls draw from the credit wallet.
- x402 pay-per-call: a single unauthenticated
tools/callreceives an x402 v2 402 quote priced by the tool's metering class (USDC on Base), then verify → execute → settle. A failed tool result is never settled. - One-click install (Cursor): Install Insight Oracle
- Discovery surfaces:
llms.txt,/.well-known/x402,/.well-known/mcp/server-card.json, andopenapi.jsonat the site root. - Registry listing: published to the official MCP registry as
io.github.imokokok/insight-oracle.
x402 quickstart (pay per call)
The pre-trade safety check is available with no account and no API key: an unauthenticated request gets an HTTP 402 quote ($0.02 USDC on Base), the client signs an EIP-3009 authorization and retries, and the facilitator settles only successful calls. Copy-paste client examples for curl, TypeScript (@x402/fetch), Python (x402[httpx,evm]), and MCP tools/call live in examples/x402-quickstart and on the x402 quickstart page.
Local development
Requires Node.js 22 or later. From the repository root:
npm install
npm run dev
See .env.local.example and src/lib/config/serverEnv.ts for environment configuration. Development can run with safe defaults for missing secrets; production requires Supabase credentials, CSRF_SECRET, and JWT_SECRET. Signed pre-trade attestations require ATTESTATION_SIGNER_PRIVATE_KEY.
To run the MCP server separately:
npm run mcp:stdio # local stdio transport
npm run mcp:http # HTTP transport at http://127.0.0.1:3001/mcp
The application is built with Next.js, React, TypeScript, Tailwind CSS, and Supabase. App routes and API handlers live in src/app/; core oracle, risk, attestation, and billing logic lives in src/lib/; MCP code lives in src/mcp/. Database migrations are under supabase/.
Documentation
| Topic | Details |
|---|---|
| Product scope and PriorSeal relationship | Product positioning and Guard SDK |
| Receipt schemas and independent verification | Verifier README and registry release policy |
| Partner protocol and release isolation | Mainline partner isolation and protocol README |
| Operations and data collection | Production readiness, cron dispatcher, and integration reliability |
| Database changes | SQL inventory and execution order |
| Experimental RWA work | RWA v1, RWA v2, and instrument registry |
RWA/tokenized-equity adaptations remain opt-in research; no production RWA signer or authorization policy is activated. The optional Robinhood Stock Token issuer context is read-only and does not count as an independent oracle source.
License
See LICENSE.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 89 tools.
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
