Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
SUI_DECOMPILER_PATHNoPath to the move-decompiler binary for decompiling Move bytecode (optional, only needed for decompile_module tool)

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
prompts
{
  "listChanged": true
}
resources
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
get_chain_infoA

Get current Sui network info: chain ID, epoch, checkpoint height, timestamp, and reference gas price. Optionally pass an epoch number to get details for a specific epoch.

get_objectA

Get a Sui object by its ID. Returns type, owner, version, content (JSON), and digest. Automatically extracts display metadata (name, description, image_url) for NFTs. For the LATEST version it also lists address_balances (funds the object holds in its own address balance, which are not among its fields and which only its defining module can withdraw) and, for a kiosk, kiosk_cap_holder: who actually controls it today, since content.owner is self-declared and not kept in sync with the KioskOwnerCap transfer that does. Neither is read for a specific version: both are current state and would misname a past snapshot's controller.

list_owned_objectsA

List raw objects owned by a Sui address with optional type filter and pagination. For NFTs specifically, prefer list_nfts (resolves kiosk storage, extracts display metadata). For a wallet summary, prefer get_wallet_overview.

get_balanceA

Get the liquid balance of one coin type for a Sui address or object (defaults to SUI), now or at a past time or checkpoint. balance is the total the owner can spend: coin_balance is held as Coin objects and address_balance sits in the owner's address balance, which holds funds without any coin object, so a wallet with no coins can still hold a large balance. For an object id, address_balance is funds held by the object itself, which only its defining module can withdraw. Staked SUI and value locked in DeFi positions do not appear here, so a wallet that looks nearly empty may not be: pair it with get_staking_summary and get_defi_positions before concluding anything about what an address holds. For every coin at once, use get_wallet_overview. With at or at_checkpoint, a checkpoint inside GraphQL's consistent range (about the last hour) is read directly (method: consistent_read). An older one is reconstructed (method: reconstructed): the balance at a recent anchor checkpoint minus the owner's balance changes in every transaction after the requested checkpoint, which is exact when complete is true. Reconstruction reads at most max_transactions; when that runs out, complete is false, balance is null and reached_checkpoint says how far back the scan got. A reconstructed balance has no coin/address split (coin_balance and address_balance are null); anchor carries the split at the anchor checkpoint.

get_transactionA

Get a Sui transaction by its digest. Returns sender, status, gas, balance changes, protocol-aware decoded actions (e.g. 'swap on Cetus', 'deposit on Suilend'), and events WITH their decoded fields — so there is no need to hand-write GraphQL to read an event's values. Protocols are identified from the events as well as the Move calls, which matters when a transaction calls an obfuscated wrapper: protocols_from_events_only marks that case. Funds can move without any coin object: address_balance_ops lists every deposit to and withdrawal from an address balance, funds_withdrawals the address-balance withdrawals the transaction requested, and gas_source whether gas came from coins or the gas owner's address balance. created_for lists objects minted to someone other than the sender; coins are never listed there, and when no other object moved coins_delivered_to names the addresses other than the sender that gained coins. mutated_capabilities lists a sender-owned capability the call mutated in place (a nonce, a rate limit) without changing its owner — the authorising capability itself, present even when nothing changed hands.

get_transactionsA

Read up to 50 Sui transactions in ONE call, given their digests. Returns sender, status, timing, balance changes, Move call targets and events WITH their decoded fields for each, plus the protocols involved. Use this whenever you hold several digests at once — the outputs of a fan-out, the evidence on a cluster edge, a set of hops to compare — instead of calling get_transaction repeatedly; ten digests go from ten round trips to one. Digests that could not be read come back in not_found rather than being dropped. For ONE transaction, or for a transaction with more than 50 events, prefer get_transaction: it pages events to the end.

query_transactionsA

Query raw Sui transactions with specific filters (sender, affected address/object, function, time or checkpoint range). Note: only ONE of affected_address, affected_object, or function can be used per query (Sui GraphQL limitation). Newest first by default; each page reports its order, oldest_shown/newest_shown and the resolved window, and next_cursor goes back as cursor with the same order and filters. For human-readable wallet activity, prefer get_transaction_history instead.

VERSIONS: a function filter matches calls made through that exact package version, and each version of an upgraded package sees its own share of the calls. function_scope names the lineage when the package has other versions; all_versions: true reads every version as one merged list.

ATTRIBUTION WARNING: the function filter matches any transaction containing that call, including PTBs where it is one leg among several protocols. A transaction's balance changes cover the WHOLE PTB, so summing them per protocol over-attributes: a big Cetus swap in the same PTB will be counted as your protocol's volume. Set include_functions to see every Move call in each transaction, and prefer the protocol's own events (query_events) when measuring per-protocol flow.

resolve_nameA

Resolve a SuiNS name (.sui domain) to an address, or reverse-lookup an address to its SuiNS name. At least one of 'name' or 'address' must be provided. A name that is not registered, has expired, or points at no address resolves to null with name_note saying which; a malformed name is an error.

IDENTITY WARNING: a SuiNS name is a self-chosen handle that anyone can buy. It is not identity and it is not verified. Names matching an exchange, a project or a person can be — and are — registered by unrelated parties, including by someone who wants an investigator to draw a particular conclusion. Treat a name as a label the holder picked, never as evidence of who they are, and do not carry it to other platforms as a matching key without independent corroboration.

get_wallet_overviewA

(Recommended first tool for wallets) Get a comprehensive overview of a Sui wallet: all token balances, SuiNS name, staked SUI count, kiosk/NFT count, and recent transactions. Set include_prices=true for USD values and total portfolio value. Start here before drilling into specific tools.

get_token_pricesA

Get USD prices for Sui tokens, current by default or at a past moment when at is set. Needs no API key. Current prices come from Aftermath, then DefiLlama, then Pyth, and the 24h change from DefiLlama (null when it does not list the coin). Historical prices come from Pyth when PYTH_API_KEY is set and the coin is on the verified list, and from DefiLlama otherwise. Every price names its source, confidence and the time of the sample it came from, and every coin that could not be priced is listed under unpriced with the reason. An unverified coin is priced only by its exact coin type, never by a symbol-matched feed. Accepts full coin type strings (e.g. 0x2::sui::SUI).

get_defi_positionsA

Find DeFi positions owned by a Sui wallet across major protocols: Suilend, Cetus LP, NAVI, Scallop, Bluefin, Bucket, and staked SUI. Returns extracted position summaries (deposits, borrows, liquidity, fees) instead of raw on-chain data.

list_nftsA

(Recommended for NFTs) List NFTs owned by a wallet, including kiosk-stored NFTs. Returns display metadata (name, description, image URL) and raw Move struct contents inline. Backed by GraphQL — single query per kiosk page, no fullnode rate-limit risk. Pagination: pass cursor from a prior response to fetch the next page; the response omits next_cursor when the wallet is fully enumerated. Returns at most limit NFTs. Use list_nft_collections for a cheaper count-only summary.

list_nft_collectionsA

Get a lightweight summary of NFT collections owned by a wallet. Walks all kiosks plus direct-owned objects and returns deduplicated collection types with counts. Backed by GraphQL.

get_staking_summaryA

Get a wallet's staking positions: every StakedSui object with its validator pool, principal, and activation epoch, and the total principal. Worth calling during an investigation or a net-worth check, because staked SUI does NOT appear in get_balance — a wallet that looks nearly empty can hold a large staked position, and the stake also ties it to a specific validator.

get_transaction_historyA

(Recommended for wallet activity) Get decoded transaction history for a Sui wallet: protocol names (e.g. Cetus, Suilend), action descriptions (e.g. 'Swap USDC → SUI') and token flow for each transaction. Newest first by default; order: 'oldest' starts from the address's first transaction instead. Each page reports its order and the oldest_shown/newest_shown timestamps; pass next_cursor back as cursor with the same order to continue. Rows are decoded from each transaction's complete balance changes and commands. address_poisoning is checked over the page shown, so the default page covers recent activity. Each row's subject_flow is the queried address's own signed balance change per coin, with formatted amounts and coin_verified; token_flow is the transaction sender's, so on a transfer this address received it shows the sender's outflow. counterparties names up to 25 addresses that received value in the row, with counterparty_count when there were more. Prefer this over query_transactions when exploring what a wallet has been doing. signed_as_alias, when present, lists transactions this address signed as an 0x2::address_alias delegate for another wallet; the page above cannot show them, because their sender is the other wallet. Which wallets name this address comes from a scan reused for up to five minutes, and alias_scan_as_of says when it read the chain. signed_as_alias_unavailable marks a scan that did not finish, including beside rows it did find.

find_poolsA

Find DeFi liquidity pools by token pair. Searches every Cetus pool, DeepBook v3 and v2 pool, and Turbos pool (across every fee tier in Turbos's pool config) for the pair, in either order. token_a and token_b on each pool are the pool's own order, read from its type. Use get_pool_stats on a returned pool_id for detailed stats.

identify_addressA

(Recommended first step) Identify what a Sui address is: wallet, package, validator, or object. Returns a type classification with contextual summary (e.g. balance + SuiNS for wallets, module list for packages, stake info for validators). Use this before deciding which other tools to call.

analyze_tokenA

(Recommended for token research) Get a comprehensive analysis of a Sui token in one call: metadata, current price, 24h change, total supply, and top 5 holders. Accepts either a coin type (e.g. '0x2::sui::SUI') or a symbol (e.g. 'DEEP', 'cetus'). A symbol several coins use returns status ambiguous_symbol with candidates (verified first, then by supply) from a symbol index of every mainnet coin up to its sync date. A symbol more than 100 coins use returns its count and no candidates, since the index keeps only the count; a coin published after the sync date is found only by a bounded live scan.

enable_toolsA

Turn on more Sui tool profiles for this session. When a tool you need is not in your list, call this first: it is disabled, not missing. Do not rebuild a tool by hand. Pass profile or profiles: one name, several, or 'all'. Enabled tools are callable at once.

'forensics' (incident investigation: tracing, attribution, clustering, packages, labels, case findings): resolve_protocol_packages, sample_control_addresses, trace_funds, trace_flow_graph, find_flow_path, resolve_bridge_transfer, find_funding_source, find_funding_sources, get_address_fanout, classify_deposit_address, screen_address, build_wallet_edges, analyze_multisig, find_shared_multisig, check_coin_restrictions, analyze_package, get_package, get_move_function, disassemble_module, build_timeline, trace_object_history, get_upgrade_history, manage_labels, query_events, check_activity, get_top_holders, compare_oracle_price, analyze_attack_tx, summarize_incident_losses, summarize_address_flows, aggregate_events, save_finding, list_findings, export_case, delete_finding, watch_addresses, poll_watch, get_nft_sales 'developer' (Move packages, bytecode, upgrades, PTBs, unsigned transactions, MVR): get_package_dependency_graph, decompile_module, diff_package_upgrade, decode_ptb, simulate_transaction, build_transfer, build_staking, get_checkpoint, list_dynamic_fields, mvr_resolve, mvr_reverse_resolve, mvr_get_package_info, mvr_search, mvr_resolve_struct 'market' (DeepBook, pools, token search, validators): deepbook_orderbook, deepbook_trades, get_pool_stats, search_token, get_coin_info, get_validators On: core.

Prompts

Interactive templates invoked by user choice

NameDescription
investigate_addressWork out what a Sui address is, where its money came from and went, and what can be claimed about it, following the sui-forensics method.
trace_incidentReconstruct an exploit or theft from its transaction or the attacker's address: what was taken, how, and where it went, following the sui-forensics method.
attribute_clusterAssess whether several Sui addresses share an operator, with a control group and the evidence tier of each link, following the sui-forensics method.

Resources

Contextual data attached and managed by the client

NameDescription
chain-infoCurrent Sui chain info (chain ID, epoch, checkpoint)

TDQS

A4.4/5.0

Scored across 19 tools

Disambiguation5/5

Every tool has a clearly distinct purpose with extensive cross-references and recommendations (e.g., 'prefer list_nfts', 'prefer get_wallet_overview'), so agents can confidently choose the right tool. Overlapping tools like get_transaction vs get_transactions are differentiated by batch size and event pagination.

Naming Consistency5/5

All 19 tools follow a consistent verb_noun pattern in lowercase snake_case (list_*, get_*, query_*, find_*, analyze_*, resolve_*, enable_*). No style mixing or ambiguous verbs.

Tool Count4/5

At 19 tools, the count is slightly above the 3-15 sweet spot, but the domain (blockchain analytics) justifies the breadth. The enable_tools mechanism keeps the default set focused while allowing expansion, so the count feels intentional rather than bloated.

Completeness4/5

The core tools cover major workflows: wallet analysis (overview, balances, history, NFTs, staking, DeFi), token research (prices, analysis), and chain basics. Minor gaps exist (e.g., pool stats require the market profile), but the enable_tools feature explicitly addresses this, and the default set handles the most common use cases without dead ends.

Maintenance

ActivityActive
ResponsivenessResponsive