GBLIN MCP Server
Model Context Protocol server for the GBLIN protocol on Base mainnet: an on-chain index of cbBTC, WETH and USDC whose shares are minted at NAV and redeemed pro rata in kind. The server reads live state, verifies governance and risk attestations, and returns unsigned calldata to enter, leave and bid. It never holds keys, signs or broadcasts.
Published on npm as @gblin-protocol/mcp-server.

Documentation and quick start: gblin.digital/agents. Starter examples: examples/.
Features
- Market risk regime (
calm / elevated / crash) read from the vault's on-chain Crash Shield, with a severity score and a risk posture
- Quotes at NAV for minting and redeeming, with a dynamic slippage buffer
- One tool that prepares any operation on the vault (mint with ETH, WETH or USDC, redeem in kind, exit to ETH or USDC, bid in the auction), each step with its gas limit
- Simulation of those steps before signing, in sequence against the latest block, with decoded revert reasons and the gas limit each vault step really needs
- The outcome of a sent transaction, and the NAV per share over time beside ETH and BTC
- Treasury health of an agent wallet: balances, gas runway, cooldown, allocation advice
- Governance verification: owner, pending owner, timelock roles and scheduled operations, computed from the chain
- The state of the rebalancing auction, row by row, with the bid to send
- Gasless payments in GBLIN (EIP-3009): prepare the authorization to sign, check it against the chain before anyone spends gas, and, when nobody else will carry it, have GBLIN's relay settle it with the fee in GBLIN, in one atomic transaction
- Offline verification of Risk Attestations (EIP-712) and of AI Action Receipts (RFC 6962)
- A portable skill seed to onboard a peer agent
- Four prompts (ready-made workflows) and four resources (deployment, payments, keys, limits)
- An
outputSchema on every tool that returns an object, so a client can validate results and generate types
Every tool is free. The server never charges: revenue comes from the on-chain protocol fee when an agent actually uses GBLIN. Verifiable pay-per-call lives on the HTTP endpoints listed under x402 endpoints.
Contracts (Base mainnet, chain id 8453)
| Component | Address | Role |
|---|
| Vault | 0xc2181d975c05c8c724b334bcED0764c0b86B1D53 | The ERC-20 share and the basket. Mints at NAV, redeems in kind, rebalances by Dutch auction, accepts payments by signature (EIP-3009). Never swaps. |
| Lens | 0xfCFea8027019E8551A1f09AD91532471F5D26f61 | Read-only views beside the vault: quotes, configuration, basket rows, auction state. |
| Zap | 0x0E9D6Ceb6D313b021622C121Cda9C62e86e60200 | The only contract that swaps: mints with any token, exits to ETH by redeeming in kind and selling every leg, all or nothing. |
| Timelock | 0x6aBeC8716fFeEcf7C3D6e68255b4797113E8e5Dd | 48-hour minimum delay, 14-day grace period, open executor. Proposer and canceller roles are held by separate addresses. |
Previous deployments (0x36C81d7E1966310F305eA637e761Cf77F90852f0, 0x38DcDB3A381677239BBc652aed9811F2f8496345) are superseded. Nothing is read from them; holders migrate through the web app.
Fees: 0.10% on every mint with ETH or WETH (0.05% stays in the vault and lifts the NAV of every share, 0.05% is minted as shares to the fee recipient); in-kind deposits pay a 0.50% floor plus a deviation tax; a 0.50% yearly management fee accrues as shares; redemption in kind and transfers carry no fee.
Hosted variant
A stateless Streamable HTTP server runs at https://mcp.gblin.digital/mcp — no install, no auth, no session, 60 requests per minute per IP. It serves the vault, action and payment tools of this package under two-level names (treasury.*, actions.*, payments.*, governance.state, auction.state, attestation.verify), built from the same source, plus the risk, receipts and coherence tools; the snake_case names below are accepted there as aliases. It also serves search and fetch, the two read-only tools research clients expect (ChatGPT deep research among them): search returns matching documents (the protocol's documentation, one card per tool, the live vault state) and fetch returns one document's full text. Every step returned by the action tools carries both spellings, target/calldata and to/data/chainId, so it maps one to one onto wallet batch APIs such as send_calls. GET-only audit surfaces: /meta, /tools.json, /resources.json, /conformance. Also listed on Smithery.
Agent treasury (library and CLI)
packages/agent-treasury — npm @gblin-protocol/agent-treasury. Operating cash stays in USDC, the surplus above a
reserve is parked in GBLIN, and USDC is pulled back from GBLIN just in time when an x402 invoice arrives. The x402 client is
Coinbase's reference x402Client with the refill attached to its onBeforePaymentCreation hook, so a 402 for USDC on Base
triggers the refill before the authorization is signed and a price above the cap is refused before anything is signed.
Self-custody, no key leaves the process. Verified end to end on a fork of Base (24 checks: park, refill, cooldown, a
mock invoice with the challenge bytes of gblin.digital and a verified EIP-712 signature, the cap).
export GBLIN_AGENT_PRIVATE_KEY=0x...
npx @gblin-protocol/agent-treasury status --json
npx @gblin-protocol/agent-treasury park --json
npx @gblin-protocol/agent-treasury pay https://gblin.digital/api/x402/attestation --max-amount 3000 --json
The matching agent skill is skills/gblin-agent-treasury (npx skills add gblinproject/gblin-treasury-risk-regime).
Details: packages/agent-treasury/README.md.
API
Every tool sets MCP tool annotations:
| Tool | readOnlyHint | idempotentHint | destructiveHint | openWorldHint |
|---|
| all except the three below | true | true | false | true |
prepare_gblin_payment | true | false | false | true |
seal_action_demo | false | false | false | true |
relay_gblin_payment | false | true | true | true |
Calldata builders are read-only: they return bytes, they do not send them. prepare_gblin_payment is not idempotent because every call draws a fresh nonce. Sealing appends to a public log and is never destructive. relay_gblin_payment moves the payer's funds on chain, so it is marked destructive and clients should confirm before calling it. Every tool also carries a human-readable title.
Output schemas
Every tool except seal_action_demo declares an outputSchema. A successful result carries the same object as structuredContent and as JSON text. The required list of each schema is the contract: fields a successful call always returns. Other fields are described but optional, and the schemas accept additional fields, so adding one is not a breaking change. Errors carry isError: true and no structured content.
Prompts
| Prompt | What it does |
|---|
risk_gate | Reads the regime and applies a rule stated before looking: proceed, halve, or stand down |
pay_in_gblin | Prepare, sign in the payer's wallet, verify, then hand on a gasless GBLIN payment |
pay_invoice_just_in_time | Exit just enough GBLIN to USDC to settle an invoice, after checking cooldown and gas |
seal_and_verify | Seal an action, read the receipt back, and state what it does and does not prove |
Resources
| URI | Content |
|---|
gblin://contracts | Every contract in service with its role, and the deprecated deployments not to use |
gblin://payments | The EIP-712 domain read live from the token, the x402 payload, and the accepts block a seller publishes |
gblin://keys | The attestor address to pin, and where the log and witness keys are published |
gblin://limits | Price (free by default), the metering switch, and where the limits come from |
Usage
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"gblin": {
"command": "npx",
"args": ["-y", "@gblin-protocol/mcp-server"]
}
}
}
Cursor, Windsurf and other MCP clients
{
"mcpServers": {
"gblin": {
"command": "npx",
"args": ["-y", "@gblin-protocol/mcp-server"],
"env": { "GBLIN_RPC_URL": "https://base-rpc.publicnode.com" }
}
}
}
Programmatic (TypeScript)
import { Client } from "@modelcontextprotocol/sdk/client/index.js";
import { StdioClientTransport } from "@modelcontextprotocol/sdk/client/stdio.js";
const transport = new StdioClientTransport({ command: "npx", args: ["-y", "@gblin-protocol/mcp-server"] });
const client = new Client({ name: "my-agent", version: "1.0.0" });
await client.connect(transport);
const jit = await client.callTool({
name: "swap_gblin_to_usdc_jit",
arguments: { usdc_needed: "0.50", wallet_address: "0xYourAgent..." },
});
AGENTS.md for coding assistants
npx -p @gblin-protocol/mcp-server gblin-init
Creates an AGENTS.md from the template at gblin.digital/AGENTS.template.md, or appends a delimited block to an existing one. Idempotent; --dry-run previews, --force refreshes the block. No files are written at install time; set GBLIN_SKIP_HINT=1 to silence the post-install hint.
Configuration
GBLIN_RPC_URL selects the Base RPC endpoint; the default is https://base-rpc.publicnode.com. For sustained load use a dedicated provider:
export GBLIN_RPC_URL="https://base-mainnet.g.alchemy.com/v2/YOUR_KEY"
npx @gblin-protocol/mcp-server
GBLIN_ATTESTOR_ADDRESS overrides the published attestor address used by verify_risk_attestation.
x402 endpoints
Pay-per-call data lives on HTTP, settled in USDC on Base through the Coinbase CDP facilitator with gasless EIP-3009 transferWithAuthorization. Clients such as @x402/fetch handle the 402 challenge, the signature and the retry.
| Endpoint | Price | Returns |
|---|
GET gblin.digital/api/x402/treasury-state | free | NAV, basket weights, Crash Shield status |
GET gblin.digital/api/x402/quote | free | Mint or redemption preview with the dynamic slippage buffer |
GET gblin.digital/api/x402/governance | free | Owner, timelock, pending operations |
GET gblin.digital/api/x402/health | free | Wallet balances, gas runway, allocation advice |
GET gblin.digital/api/x402/invest | free | Unsigned calldata: USDC → GBLIN |
GET gblin.digital/api/x402/jit | free | Unsigned calldata: GBLIN → USDC just in time |
GET gblin.digital/api/x402/attestation | $0.003 | Signed EIP-712 Risk Attestation, valid ten minutes |
POST gblin.digital/api/x402/seal | $0.0045 | A sealed AI Action Receipt |
Machine-readable manifest: https://gblin.digital/.well-known/x402. Payment recipient: 0x0ebA5d314F4f5Dcb7A094953Fa9311a45172dd1B.
Risk Attestation
GET https://gblin.digital/api/x402/attestation returns a ten-minute, verifiable snapshot of the BTC/ETH risk regime, signed under the EIP-712 domain GBLIN Risk Attestation, version 2, chain 8453, verifying contract = the vault in service. The response embeds its domain, types and message under eip712; a verifier recovers the signer and checks it against the published attestor address, which it should pin. verify_risk_attestation does this offline and also accepts attestations issued under domain version 1.
AI Action Receipts
A public, append-only RFC 6962 transparency log for AI actions. Input and output go in as hashes only; the short action, agent_id, tool and meta strings are published in clear, so put identifiers there, never secrets. Each seal returns a portable receipt:
receipt = canonical payload
+ Ed25519 signature (key: gblin.digital/receipts-log)
+ RFC 6962 inclusion proof (leaf → Merkle root)
+ C2SP signed checkpoint (origin, tree size, root)
Canonicalization is frozen as gblin-canonical-json/1: object keys sorted by UTF-16 code unit, no whitespace, JSON.stringify semantics for primitives, recursion for objects and arrays. Test vector: payload {"b":1,"a":null} → canonical {"a":null,"b":1} → leaf = SHA256(0x00 || canonical_bytes). The receipt signature is Ed25519 over "gblin-receipt/v1\n" + canonical.
- Seal (paid, unlimited):
POST https://gblin.digital/api/x402/seal, $0.0045 USDC via x402
- Seal (demo, 5 per day per IP):
POST <worker>/v1/seal-demo, or the tool seal_action_demo
- Read, free:
<worker>/v1/receipt/:index, /log, /log/checkpoint, /log/proof/:index, /log/consistency, /log/leaves, and the page /receipt/:index
- Daily anchor of the tree root on Base as an EAS attestation (schema
0x9f433a96…)
- Offline verifier with no dependencies:
verify-receipt.mjs — node verify-receipt.mjs receipt.json
The checkpoint is signed by the log operator and cosigned by an independent witness (Markovian Protocol). A cosignature attests that the log stayed append-only between the sizes the witness saw; it does not attest that a receipt's content is true. A seal proves existence and time; it is not a compliance certificate and not an endorsement. <worker> = https://gblin-mcp.gblin-mcp-worker.workers.dev.
Coherence Proof
GBLIN pre-registers hash-pinned promises and runs an automaton that probes them every ten minutes and seals each closed day as an EAS attestation on Base. Free report: /coherence. Live promises: uptime of the paid attestation endpoint, and honesty of the public agent-economy counters, with the protocol's own wallets disclosed. GBLIN is a registered ERC-8004 agent (#59286).
Architecture notes
- Mint at NAV, redeem in kind. The vault prices every mint from Chainlink feeds and issues shares against the deposit; redemption pays the exact pro-rata slice of every basket row, reads no price feed and cannot be paused. The vault never swaps.
- The Zap swaps. Entering with a token other than ETH or WETH, and leaving to ETH or USDC, go through the Zap, which swaps on a venue and mints or redeems on the vault in the same call. Exits are all or nothing: a leg that cannot be sold reverts the whole transaction instead of paying out less.
- Rebalancing is a Dutch auction. When a row drifts past its band the vault opens an auction; the counterparty trades toward the target weights at the oracle price adjusted by a premium that starts at a discount and rises to a cap over one ramp.
get_auction_state exposes it.
- Dynamic slippage. Minimum outputs are quoted from the Lens and buffered by 2.5%, or 4% while the Crash Shield is active. No calldata leaves this server with a zero minimum on a swap.
- Cooldown. The vault refuses a redemption for a short window after the same address minted; the window is read live and reported by
analyze_treasury_health.
- Payments by signature. The vault implements EIP-3009 (
transferWithAuthorization, receiveWithAuthorization, cancelAuthorization), so an agent can settle in GBLIN the way it settles in USDC. Transfers carry no fee.
Security notes
- The server is read-only: it never holds, signs or broadcasts. Calldata is plain ABI-encoded bytes for the agent's own wallet to review and send.
- Every quote comes from on-chain calls and Chainlink feeds. A stale or non-positive ETH/USD answer aborts the tool with an explicit error rather than a bad number; the vault's own
isNavReliable is reported alongside.
- No telemetry, no analytics, no remote dependencies beyond the configured RPC.
Development
git clone https://github.com/gblinproject/gblin-treasury-risk-regime
cd gblin-treasury-risk-regime
npm install
npm run build
npm test
npm run test:protocol
npm run test:schemas
npx tsx scripts/test-hosted.ts <url>
npm start
Two tests run against a local fork of Base and send transactions there, never on mainnet:
anvil --fork-url <base rpc> --port 8555 &
export GBLIN_RPC_URL=http://127.0.0.1:8555
npm run test:payments
npm run test:calldata
npm run test:actions
src/
config.ts # addresses, slippage and cache settings
abi.ts # vault, Lens, Zap, timelock, Chainlink and ERC-20 ABIs
client.ts # viem public client and on-chain timestamp
helpers.ts # NAV, basket state, slippage, cooldown, reverse quote
auction.ts # auction state and bid sizing
tools.ts # the treasury, auction and risk tools, and the tool list
payments.ts # gasless payments (EIP-3009): prepare, verify, relay
actions.ts # prepare_action, preview_steps, get_transaction_status, get_nav_history
shared.ts # result envelopes, builder code, Zap routing data and gas limit
version.ts # generated from package.json by scripts/write-version.mjs
receipts.ts # the three receipt tools
output-schemas.ts # the outputSchema of every tool
prompts.ts # the four prompts
resources.ts # the four resources
index.ts # MCP stdio server entry and initialize instructions
init.ts # the gblin-init command
worker/ # the hosted Streamable HTTP server (Cloudflare Workers)
scripts/ # test.ts, test-protocol.ts, test-output-schemas.ts, test-payments-fork.ts, test-calldata-fork.ts
Links
MIT © GBLIN Protocol