Abstraxn

Abstraxn Agent Kit的公共MCP服务器让任何AI代理无需注册或API密钥即可即时访问Web3和市场数据。查询实时区块链数据,包括区块号、Gas价格、交易状态,以及主要EVM链和Solana上的ERC-20代币信息和价格。您还可以访问x402engine的按次付费API,用于加密货币市场数据、钱包、代币和ENS查询、链上交易模拟,以及航班和酒店搜索。付费调用通过x402协议直接从调用者自己的加密钱包结算,Abstraxn从不持有或托管资金。非常适合需要实时区块链、Web3和市场数据且无需接入摩擦的AI代理。

文档

Abstraxn Public Web3 MCP Service

License: MIT Node

A free, public MCP (Model Context Protocol) server for Web3 data. Point any MCP client — Claude Desktop, Cursor, your own agent — at it and it can read live chain data (block height, gas, transaction status, ERC-20 info, spot prices) and, for a handful of pay-per-call tools, look up market data, wallets/tokens/ENS, and travel search.

No API key, no account, no signup. Free tools are open to anyone; paid tools are settled directly from the caller's own wallet via the x402 payment protocol — this service never holds or signs funds on your behalf.

Built on the official @modelcontextprotocol/sdk and NestJS 11.

Contents


Quick start

git clone https://github.com/Abstraxn-Labs/abstraxn-agent-layer.git
cd abstraxn-agent-layer
npm install
cp .env.example .env
# Edit .env: Postgres connection + UPSTREAM_RELAY_BASE_URL (required for the 3 paid tools)
npm run start:dev
  • Health check: GET http://localhost:3011/health
  • MCP endpoint: POST http://localhost:3011/mcp
  • API docs (health only): http://localhost:3011/api/docs

Database migrations run automatically on boot — no separate CLI step needed.

Use it from Claude Desktop / Cursor

Add this to your MCP client's config (e.g. claude_desktop_config.json or Cursor's mcp.json):

{
  "mcpServers": {
    "abstraxn-public-web3": {
      "url": "http://localhost:3011/mcp"
    }
  }
}

Restart the client and the tools below become available to it — no further setup.

Available tools

ToolPaid?What it does
network.blocknumberNoCurrent EVM block number or Solana slot. Query one chain or all at once.
network.transaction_statusNoLook up a transaction/signature by hash on EVM or Solana.
network.gas_infoNoCurrent gas price + EIP-1559 fee hints for an EVM chain.
network.token_infoNoERC-20 name / symbol / decimals / total supply.
network.token_priceNoSpot price via CoinGecko (defaults to ETH/USD).
market.cryptoYesCrypto market-data lookups (CoinGecko-sourced), 6 actions.
web3.lookupYesMulti-chain wallet / token / ENS / tx-simulation lookups, 7 actions.
travel.searchYesFlight and hotel search, 2 actions.

Tools are namespaced by area (network.*, market.*, web3.*, travel.*) so an MCP client can browse them as a tree rather than a flat list.

How paid tools work: call one with no payment, and you get back a paymentRequired challenge (not an error). Your wallet client signs it and retries the same call with paymentPayload set — your wallet pays directly; this service only relays the request.

Calling tools directly (curl)

Most people will use an MCP client (above), but the endpoint is plain JSON-RPC over HTTP if you want to script against it directly:

BASE=http://localhost:3011
ACCEPT='Accept: application/json, text/event-stream'   # required by the MCP spec

# 1. Initialize a session
curl -s -X POST "$BASE/mcp" -H 'Content-Type: application/json' -H "$ACCEPT" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"my-client","version":"1.0"}}}'

# 2. List available tools
curl -s -X POST "$BASE/mcp" -H 'Content-Type: application/json' -H "$ACCEPT" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/list"}'

# 3. Call a tool
curl -s -X POST "$BASE/mcp" -H 'Content-Type: application/json' -H "$ACCEPT" \
  -d '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"network.token_price","arguments":{"symbol":"bitcoin"}}}'

GET /mcp returns 405 by design — every call is stateless, so there's no session to resume.

Configuration

Copy .env.example to .env. Everything has a safe default except the one marked required:

VariableRequiredDescription
PORTNoHTTP port (default 3011)
POSTGRES_HOST / PORT / USER / PASSWORD / DBNoPostgres connection, used only for abuse tracking
PUBLIC_MCP_RATE_LIMIT_PER_MIN / _WINDOW_MSNoGlobal per-IP rate limit (default 30/min)
CHAIN_RPC_*NoPer-chain EVM RPC overrides — public defaults are used if unset (see src/mcp/utils/chain-registry.util.ts)
SOLANA_RPC_URL / SOLANA_DEVNET_RPC_URLNoSolana cluster RPC overrides
UPSTREAM_RELAY_BASE_URLYesBase URL for the upstream relay behind the 3 paid tools — no default is committed, so market.crypto / web3.lookup / travel.search fail until this is set

There is no auth-related variable — there's nothing to authenticate on a service with no accounts or API keys.

How it works

MCP client (Claude Desktop, Cursor, your agent)
    → POST /mcp  (this service, stateless — a fresh McpServer per request)
    → free tools: direct chain RPC / CoinGecko calls
    → paid tools: relayed upstream, settled by the caller's wallet via x402

This is a single, standalone deployable — it doesn't share a workspace or database with any other Abstraxn service. That's deliberate: several MCP registries expect a public MCP server to live in its own repo with one route and one fixed tool set, reviewable end to end.

Stack: Node.js 20+ · NestJS 11 · @modelcontextprotocol/sdk ^1.30.0 (official SDK) · PostgreSQL + TypeORM · @x402/core · viem (EVM) + raw JSON-RPC (Solana) · helmet, @nestjs/throttler

Database

Postgres is used for abuse tracking only — no tenant, policy, or config tables exist:

TablePurpose
observed_ipsOne row per caller IP, with a running call count and last-seen time.
observed_walletsOne row per wallet address seen paying via x402.
public_mcp_transactionsAppend-only history of completed paid calls.

If Postgres is unreachable, a call still succeeds — tracking writes are best-effort and never block or fail a real MCP request.

Security

Since anyone can call this service with no key, a few invariants matter:

  • No SSRF surface: every outbound URL (chain RPC, upstream relay, CoinGecko) comes from server-side config — no tool accepts a caller-supplied URL.
  • Rate limiting is global and IP-keyed — the only lever available with no accounts. If you deploy behind a reverse proxy, set app.set('trust proxy', ...) in main.ts, or the limiter ends up rate-limiting the proxy instead of real callers.
  • No secrets beyond the DB password, which is env-only and never logged.
  • CORS is wildcard by design — nothing tenant-specific ever crosses an origin here.

Found a security issue? See CONTRIBUTING.md before opening a public issue.

Scripts

ScriptDescription
npm run start:devRun in watch mode
npm run buildCompile to dist/
npm run start:prodRun the compiled build (dist/main)
npm run lintESLint
npm testJest — unit, SDK-level integration, and HTTP smoke tests

Contributing

Issues and PRs are welcome — see CONTRIBUTING.md for how to add a new tool and the project's definition of done.

License: MIT