Back to Browse

Blazephoenix MCP Server

Developer ToolsModerate5.7MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

On-chain DEX aggregator: quotes and verified swap calldata computed on your own RPC. No API key.

About

On-chain DEX aggregator: quotes and verified swap calldata computed on your own RPC. No API key.

Remote endpoints: streamable-http: https://blazephoenix.xyz/mcp

Security Report

5.7
Moderate5.7Moderate Risk

This is a well-designed MCP server for on-chain DEX aggregation with strong security practices. The server is read-only, never holds keys, and enforces strict separation between RPC credentials (environment-only) and tool arguments. Code quality is high with proper input validation, comprehensive error handling, and no malicious patterns detected. Minor findings around logging and type safety do not meaningfully impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity).

4 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

stdio

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

BlazePhoenix MCP server

solvency

On-chain DEX aggregator tools for AI agents. The defining property: every quote is computed by the on-chain Quoter contract (previewPlan, a free eth_call), the same logic that executes the swap, and it runs on your own RPC. There is no pricing server to trust, and every number an agent relays is reproducible by anyone.

  • Local server: @blazephoenix/mcp over stdio. Quotes, unsigned calldata, simulation and solvency, all read through the node you configure.
  • Remote endpoint: https://blazephoenix.xyz/mcp (streamable HTTP, stateless). Deployment registry, ABIs and the pure quote codec. It performs no RPC call.
  • Auth: none · API key: none
  • Chains: Base (8453), Ethereum (1), Optimism (10), Arbitrum (42161), Robinhood Chain (4663)

Local server

claude mcp add blazephoenix -e BLAZEPHOENIX_RPC_BASE=<your Base node URL> -- npx -y @blazephoenix/mcp

Any MCP client (JSON config):

{
  "mcpServers": {
    "blazephoenix": {
      "command": "npx",
      "args": ["-y", "@blazephoenix/mcp"],
      "env": { "BLAZEPHOENIX_RPC_BASE": "<your Base node URL>" }
    }
  }
}

The RPC comes from the environment only, never from a tool argument:

VariableMeaning
BLAZEPHOENIX_RPC_URLOne node, used for every chain it serves
BLAZEPHOENIX_RPC_BASE, _ETH, _OPTIMISM, _ARBITRUM, _ROBINHOODA node per chain. Use either this or BLAZEPHOENIX_RPC_URL, not both

A value may hold several URLs separated by commas; they are your fallback order. The server never prints your URLs, since they may carry a key.

Tools

ToolWhat it does
get_quoteSwap quote through your RPC: net output after the fee, the minimum the Router enforces, price impact and the Phoenix Check verdict (ok / caution / danger / blocked, fails closed). exact: true dry-runs every concentrated leg.
build_swapQuote and return verified unsigned Router calldata, with the minimum output and deadline baked in.
simulate_swapBuild the swap and dry-run it from a given account with an eth_call.
check_solvencyLive staking solvency: isSolvent() and the decoded solvency() struct.
get_token_infoSymbol, decimals and name of a token, read from the chain.
get_deploymentsThe versioned deployment registry: Core, Hub, Solver, Quoter and Router per chain and version.
verify_deploymentCheck that the registry addresses for a chain and version match what is deployed on-chain.

Every tool is read-only. The server never signs and never holds a key. build_swap returns calldata for you to review and sign in your own wallet, and the SDK's wallet-taking execute() is deliberately not exposed.

Remote endpoint

claude mcp add --transport http blazephoenix https://blazephoenix.xyz/mcp
{ "mcpServers": { "blazephoenix": { "type": "http", "url": "https://blazephoenix.xyz/mcp" } } }
ToolWhat it does
prepare_quoteThe exact eth_call to run on your node for a quote, plus a request object
decode_quoteTurns your node's answer into the quote, the Phoenix Check verdict and verified calldata (pure)
get_deploymentsThe versioned deployment registry
get_abiGenerated ABI of a protocol contract

The source of the endpoint is in Blaze-Phoenix-API.

Install as a plugin or extension

Claude Code plugin (hosted MCP endpoint plus the BlazePhoenix agent skill):

claude plugin marketplace add blazephoenixxyz-crypto/blazephoenix-mcp
claude plugin install blazephoenix@blazephoenix

Gemini CLI extension (hosted MCP endpoint plus a context file):

gemini extensions install https://github.com/blazephoenixxyz-crypto/blazephoenix-mcp

Both connect https://blazephoenix.xyz/mcp, which needs no key and performs no RPC. For the full toolset on your own node, use the local server.

Verify instead of trusting

Nothing here requires trusting BlazePhoenix:

# the solvency claim, straight from the chain, bypassing the site entirely
cast call 0x3f60C7aa0c36a78D200405feBE143d2Cf3fA0c77 "isSolvent()(bool)" --rpc-url https://mainnet.base.org

# re-execute any published fact live, with its block height
curl -s "https://blazephoenix.xyz/api/verify?fact=solvency-live"

# reproduce every live claim in ~60 seconds
curl -sO https://blazephoenix.xyz/repro/verify-everything.sh && bash verify-everything.sh

Build and test

npm install
npm run build
npm test

The test spawns the built server over stdio with no RPC configured and checks the tool surface, that failures come back as tool results, and that no tool takes an RPC, key or signer argument or signs anything.

More machine surfaces

Security

To report a vulnerability, see SECURITY.md.

License

The code is MIT (see LICENSE). This documentation is CC BY 4.0. The protocol contracts are BUSL-1.1 (free to read, audit and verify; production use before the 2030 change date requires a license). The mechanisms and terminology (Iron Law Φ, Monoslot, Master Conservation Identity) are original BlazePhoenix work: attribute with a link.

Contact: contact@blazephoenix.xyz · Security: https://blazephoenix.xyz/.well-known/security.txt

Reviews

No reviews yet

Be the first to review this server!