Back to Browse

Traql MCP Server

by Traql
Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

AML risk scoring for crypto addresses and transactions on Ethereum, BSC, TRON, TON, Bitcoin

About

AML risk scoring for crypto addresses and transactions on Ethereum, BSC, TRON, TON, Bitcoin

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (3 strong, 2 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

9 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

What You'll Need

Set these up before or after installing:

API key from https://app.traql.io. Without it the server runs on the keyless tier, which returns a coarse verdict and is payment-gated on the hosted API.Required

Environment variable: TRAQL_API_KEY

Base URL of the traql API. Override only when self-hosting.Optional

Environment variable: TRAQL_API_URL

Per-request timeout in milliseconds.Optional

Environment variable: TRAQL_TIMEOUT_MS

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-traql-mcp-server": {
      "env": {
        "TRAQL_API_KEY": "your-traql-api-key-here",
        "TRAQL_API_URL": "your-traql-api-url-here",
        "TRAQL_TIMEOUT_MS": "your-traql-timeout-ms-here"
      },
      "args": [
        "-y",
        "@traql/mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

traql MCP server

npm CI License: MIT

AML and compliance risk scoring for crypto addresses and transactions, exposed to AI agents over the Model Context Protocol.

Ask your agent "is it safe to send to this address?" and it gets back a 0–100 risk score, a band, the risk categories behind it, and — with an API key — every individual signal with its source and confidence.

ethereum address 0x8589427373d6d84e98730d7795d8f6f8731fda16
RISK 100/100 — CRITICAL
Flags: sanctions, mixer, scam

Signals (21):
  +80  [sanctions/eth_labels] direct.sanctions — sanctions label "Tornado.Cash: Donate" [entity Tornado.Cash: Donate, confidence 0.80]
  +68  [mixer/eth_labels] direct.mixer — mixer label "Tornado.Cash: Donate" [entity Tornado.Cash: Donate, confidence 0.80]
  +10  [mixer] behavior.mixer_contact — direct contact with mixer 0xdd4c48c0b24039969fc16d1cdf626eab821d3384
  +9   [sanctions/ofac_sdn] indirect.sanctions — sent to Semenov Roman (sanctions, 18% of USDC volume) [entity Semenov Roman, confidence 1.00]
  ... and 17 more

Computed at 2026-08-23T11:42:49Z.

Backed by traql: OFAC SDN, UK OFSI, EU and UN sanctions lists, Tether/Circle freeze events, curated hack and mixer attributions, and counterparty exposure analysis across Ethereum, BSC, TRON, TON and Bitcoin.

Quick start

Requires Node.js 18+.

npx -y @traql/mcp

The server speaks MCP over stdio, so you normally point a client at it rather than running it by hand.

Claude Code

claude mcp add traql --env TRAQL_API_KEY=your_key -- npx -y @traql/mcp

Claude Desktop

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "traql": {
      "command": "npx",
      "args": ["-y", "@traql/mcp"],
      "env": { "TRAQL_API_KEY": "your_key" }
    }
  }
}

Cursor

Add to ~/.cursor/mcp.json (or .cursor/mcp.json in a project) using the same mcpServers block as above.

VS Code

Add to .vscode/mcp.json:

{
  "servers": {
    "traql": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@traql/mcp"],
      "env": { "TRAQL_API_KEY": "your_key" }
    }
  }
}

Getting an API key

Sign up at app.traql.io, confirm your email — free checks are included — and issue a key under API keys. The secret is shown once; it can be rotated or revoked at any time.

Without a key the server still runs, but on the keyless tier: a single coarse reason phrase instead of itemized signals, tight rate limits, and on the hosted API a per-call x402 payment requirement. For agent use, set a key.

Configuration

VariableRequiredDefaultDescription
TRAQL_API_KEYrecommendedAPI key from the traql dashboard. Sent as X-API-Key. Unlocks itemized signals and higher limits.
TRAQL_API_URLnohttps://api.traql.ioBase URL of the API. Point it at your own deployment if you self-host traql.
TRAQL_TIMEOUT_MSno30000Per-request timeout in milliseconds.

Tools

check_address

Scores a single address.

ArgumentTypeRequiredDescription
chainethereum | bsc | tron | ton | bitcoinyesNetwork the address belongs to.
addressstringyesAddress in the chain's native format.

screen_transaction

Scores both sides of a transfer, in one of two modes:

  • Pre-flight — pass from and to (optionally amount and asset) to screen a transfer before broadcasting it. Works on every supported chain.
  • By hash — pass tx_hash alone to look up a transaction that is already on-chain. Supported on Ethereum, BSC, TRON and TON.
ArgumentTypeRequiredDescription
chainchain enumyesNetwork the transaction belongs to.
fromstringpre-flightSender address.
tostringpre-flightRecipient address.
amountstringnoInteger amount in the asset's base units (e.g. 1000000 for 1 USDT).
assetstringnoAsset or token symbol, e.g. USDT.
tx_hashstringby-hashHash of a broadcast transaction. Mutually exclusive with from/to.

Response

Both tools return human-readable text plus structuredContent:

{
  "subject": { "type": "address", "chain": "ethereum", "address": "0x…" },
  "result": {
    "score": 100,
    "band": "critical",
    "flags": ["sanctions", "mixer", "scam"],
    "partial": false,
    "computed_at": "2026-08-23T11:42:49Z",
    "reasons": [
      {
        "code": "direct.sanctions",
        "message": "sanctions label \"Tornado.Cash: Donate\" from eth_labels (severity 100 × confidence 0.80 = 80.0)",
        "contribution": 80,
        "category": "sanctions",
        "source": "eth_labels",
        "entity": "Tornado.Cash: Donate",
        "severity": 100,
        "confidence": 0.8,
        "eff": 80.0
      }
    ]
  }
}

Score bands: clean 0–9, low 10–39, elevated 40–69, high 70–89, critical 90–100.

partial: true means an upstream data source was degraded while computing the result — read the score as a lower bound, not a final verdict.

Each successful call consumes one check from the configured account. Malformed input is rejected locally where possible, so it costs nothing.

Development

npm install
npm run build
npm test

Notes

Scores are advisory signals for triage and automation. They are not a legal determination of wrongdoing, and they do not by themselves discharge any regulatory obligation.

Links

License

MIT

Reviews

No reviews yet

Be the first to review this server!