Skip to main content
The ChainPatrol MCP server gives AI agents the whole public API as tools: asset checks and search, reports, proposal review, detections and detection configs, takedowns, threats, metrics, healthchecks, and organization management. If an operation is in the API reference, the agent can call it. There are two ways to connect:
  • Hosted: point your client at a URL and sign in through your browser. Nothing to install.
  • Local: run chainpatrol mcp from the CLI on your own machine.
Both expose the same tools and enforce the same permissions as your ChainPatrol account or API key.

Hosted server

The server uses OAuth. The first time your client connects, it opens a ChainPatrol sign-in and consent page in your browser. After you approve it, the client stores the token and reconnects on its own. Clients that support dynamic client registration need nothing but the URL.
Then run /mcp inside Claude Code and pick chainpatrol to sign in.

Using an API key instead

For service accounts and headless agents that can’t complete a browser sign-in, send an API key in the X-API-KEY header:

Local server (CLI)

The server also ships with the ChainPatrol CLI, which handles login for you:
Point your MCP client at that command. For Claude Code:
Or in any client that takes an mcpServers config:
To use a service account, set CHAINPATROL_API_KEY instead of running chainpatrol login.

Configuration

chainpatrol mcp --tools asset_check,asset_list does the same as CHAINPATROL_MCP_TOOLS for a single run, and wins when both are set. Narrowing the tool list saves context budget but is not an access control. The API enforces authorization against the credential in use.

What the server exposes

  • Tools: one for each public API operation. Most tools are scoped to one organization and there is no implicit default, so call user_orgs first and pass the organization slug explicitly.
  • Resources: the long value lists, such as chainpatrol://enums/asset_type, and guides explaining what each proposal label and reject reason means.
  • Prompts: ready-made workflows that take an organization slug:

Example prompts

Once connected, ask in plain language:
  • “Is claim-airdrop-example.xyz on the ChainPatrol blocklist?”
  • “Run the org healthcheck for acme.”
  • “Which reports for acme are waiting on customer review?”
  • “How many threats did we find for acme this week, and from which sources?”

Searching these docs from an agent

This page covers the server for ChainPatrol data. The documentation site also serves its own read-only MCP server at https://chainpatrol.com/docs/mcp, which lets an agent search these docs. Add it alongside the ChainPatrol server if you want the agent to look up how the API works while it uses it.