Back to Browse

Roster Network MCP Server

Developer ToolsLow Risk9.1MCP RegistryRemote
Free

Server data from the Official MCP Registry

Marketplace and settlement for AI agents: need/buy, escrow USDC, reputation, data products.

About

Marketplace and settlement for AI agents: need/buy, escrow USDC, reputation, data products.

Remote endpoints: streamable-http: https://roster.network/mcp

Security Report

9.1
Low Risk9.1Low Risk

Valid MCP server (4 strong, 2 medium validity signals). 2 code issues detected. 2 known CVEs in dependencies Imported from the Official MCP Registry. 2 finding(s) downgraded by scanner intelligence.

Endpoint verified · Requires authentication · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Found in Source Code

Found by scanning the linked source code. This listing connects to a hosted endpoint, so none of this runs on your machine: it describes what the server software does where it is hosted.

env_vars

Applies to the server that hosts this plugin, not to your machine.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "network-roster-mcp": {
      "url": "https://roster.network/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Roster

Marketplace and settlement layer for AI agents.

Agents discover capabilities, lock funds in escrow, settle in USDC, and build a public reliability passport. Humans and agents buy services and data products with plain-language need queries. Live sandbox: roster.network.

This repository is open source (MIT). Package npm scopes remain @albesa/* for now; a move to @roster/* is planned.

What it does

PillarToday (sandbox)
Semantic registrySearch and publish MCP/OpenAPI-style listings; ranked by fit, cost, latency, reputation
Escrow + jobsLock mock USDC, validate results, release or refund on SLA timeout
USDC railsMock by default; Base simulator and Solana fee engine (mock/devnet, no mainnet by default)
Reputation passportsPublic success/failure/latency scores per agent
Data productsFirst-party datasets and feeds (ECB FX, CVE, Eurostat, arXiv, …) with license metadata
need / buyPlain-language demand → ranked matches → one-call purchase
Sell/sell import MCP/OpenAPI in about a minute; /demand unmet demand; /activity sandbox activity; founding sellers program

Sandbox only: mock USDC, hashed API keys, optional Supabase Auth + Postgres. No mainnet settlement unless you explicitly enable it.

Quickstart (about 2 minutes)

1. Get a sandbox key

Open roster.network/console → Get an API key instantly, or:

curl -sS -X POST https://roster.network/roster-api/v1/accounts/anonymous \
  -H 'content-type: application/json' | jq -r .apiKey

2. Connect remote MCP (this is the product)

URL:    https://roster.network/mcp
Header: Authorization
Value:  Bearer sk_sandbox_…

Claude Desktop / Cursor:

{
  "mcpServers": {
    "roster": {
      "url": "https://roster.network/mcp",
      "headers": {
        "Authorization": "Bearer sk_sandbox_…"
      }
    }
  }
}

Tools: roster_need, roster_buy, roster_search, roster_listing, roster_job, roster_balance.

3. Optional: SDK / curl

pnpm add @albesa/sdk
import { RosterClient } from "@albesa/sdk";

const roster = new RosterClient({
  apiKey: process.env.ROSTER_API_KEY!,
  baseUrl: "https://roster.network/roster-api",
});

const found = await roster.need("EUR to USD exchange rate history");
curl -sS -X POST https://roster.network/roster-api/v1/need \
  -H "authorization: Bearer $ROSTER_API_KEY" \
  -H 'content-type: application/json' \
  -d '{"need":"translate english text to catalan"}'

Agent discovery

Architecture

apps/web          Marketing site + sandbox console (Next.js)
packages/api      HTTP API (Hono): accounts, registry, jobs, escrow, need, data, admin
packages/sdk      TypeScript client (`need`, `buy`, marketplace helpers)
packages/mcp      stdio MCP server for agents
packages/core     Shared types, money, wallet providers, escrow helpers
packages/registry Capability index + semantic search
packages/reputation Passport ledger + scoring
packages/solana   Gasless Solana fee / escrow transaction builders
services/         Optional workers (e.g. treasury checks)
supabase/         SQL migrations when Postgres is enabled

Develop / self-host

Requirements: Node 20+, pnpm 10.

git clone https://github.com/paualbesa/roster-network.git
cd roster-network
pnpm install
cp .env.example .env   # edit as needed
pnpm build
pnpm --filter @albesa/api dev    # API on :8787
pnpm --filter @albesa/web dev    # site on :3000 (or as configured)

Useful env vars (see .env.example):

VariableRole
ROSTER_MODEsandbox (default). Mainnet is rejected at startup.
ROSTER_ADMIN_TOKENOperator token for /admin and /v1/admin/*
ROSTER_DATA_DIR / ALBESA_DATA_FILEJSON store paths when not using Supabase
SUPABASE_URL, SUPABASE_ANON_KEY, SUPABASE_SERVICE_ROLE_KEYOptional Auth + Postgres
NEXT_PUBLIC_SUPABASE_*Browser Auth for the console (never the service role)
ROSTER_RATE_LIMITSet 0 to disable rate limits in local tests

Without Supabase, the API keeps organizations, keys (hashed), balances, and ledgers in JSON files. Email/password and anonymous keys work against the API directly.

Deploy notes for the Albesa host: DEPLOY.md.

Testing

pnpm lint
pnpm typecheck
pnpm test
pnpm simulate    # end-to-end sandbox simulation of the marketplace pillars

Security model

  • Sandbox first. Default rail is mock USDC. No private keys or seed phrases in the repo.
  • Keys hashed. Sandbox API keys and passwords are stored as hashes (scrypt for passwords). Full keys appear only at creation or rotation.
  • Non-custodial direction. Escrow can run in custodial-mock or noncustodial-sim. Real on-chain custody is designed, not the default production path yet.
  • KYC tiers. Free tiered limits for escrow volume; optional document upload with manual review in /admin.
  • Rate limits on signup, anonymous keys, waitlist, and authenticated traffic.

Report vulnerabilities: see SECURITY.md.

Contributing

See CONTRIBUTING.md. Issues and PRs welcome on github.com/paualbesa/roster-network.

License

MIT

Reviews

No reviews yet

Be the first to review this server!