Skip to main content
Glama

npm CI/CD MCP Registry License

๐Ÿš€ Install

npx bagos-mcp-server

Claude Desktop โ€” ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "bagos": {
      "command": "npx",
      "args": ["-y", "bagos-mcp-server"],
      "env": {
        "BAGS_API_KEY": "your-key-here"
      }
    }
  }
}

Claude Code:

claude mcp add bagos --env BAGS_API_KEY=your-key-here -- npx -y bagos-mcp-server

Restart the client, then ask it: "check the bagos heartbeat". The server prints a configuration report to stderr on startup; if something is missing it tells you which variable and why. A key alone gives you the 11 read tools โ€” writes stay off until you configure them (Getting Started).

Related MCP server: MAIN MCP

๐Ÿ”’ Why this is safe to hand an assistant

  • Nothing signs on the first call. A write tool answers with a preview and a single-use token fingerprinted to those exact arguments; nothing reaches the chain until you call again with it.

  • Hard SOL caps. 0.1 per transaction and 1 per session by default, refused before the Bags SDK is called.

  • Devnet by default. Writes are mainnet-only, so an unconfigured install cannot spend real money.

Full threat model, disclosure policy and the limits of each control: .github/SECURITY.md.

v2.0.0 corrects a serious defect. In 1.x the write tools built transactions, discarded them, and reported success โ€” nothing was ever signed or submitted. If you used 1.x and believed a trade or claim executed, it did not. See CHANGELOG.md.

2.x is live on npm and is what npx bagos-mcp-server installs โ€” see the latest release. Every release ships with npm provenance โ€” the tarball is cryptographically attested to this repository and the commit that built it. 1.x is deprecated on npm. If you are still on it, upgrade.


๐Ÿ“ฆ Where it's listed

npm MCP Registry Smithery GitHub Packages

Live Site Pitch Deck Run Receipts Security Policy Changelog

MCP TypeScript Solana Jest Publish CodeQL Release


๐Ÿ’ก The Problem & Solution

The Problem

An MCP server that can move money gives an AI assistant a signing key. The assistant decides, and the transaction is already on chain by the time a human reads about it. Nothing in the protocol makes the model pause, and nothing bounds what a single misunderstood instruction can spend.

The Solution

BagOS lets an AI assistant read Bags/Solana token data and โ€” with explicit confirmation โ€” execute swaps and claim creator fees from your wallet. Writes are off unless you configure them, they are mainnet-only, and the first call to a write tool signs nothing: it returns a preview and a single-use token that only authorizes the exact arguments it was issued for.


๐Ÿ—๏ธ Architecture & Tech Stack

Every write goes through this:

token gate โ†’ spend caps โ†’ confirmation โ†’ simulate โ†’ sign โ†’ send โ†’ confirm

Tool

Type

What it does

bags_heartbeat

read

Server status and wallet reachability

bags_get_token_analytics

read

Lifetime fee data for a token mint

bags_get_creators

read

Top token creators by lifetime fees

bags_get_trade_quote

read

Price quote for a swap. Does not trade.

bags_get_claimable_fees

read

Fees currently claimable by your wallet

bags_get_partner_stats

read

Partner config claim statistics

bags_get_token_claim_stats

read

Per-creator claim totals โ€” the royalty roster with amounts claimed

bags_get_token_claim_events

read

The claim audit trail for a token, paginated

bags_get_token_creators

read

Who shares a token's fees, and in what proportion

bags_resolve_launch_wallet

read

Social handle (twitter/tiktok/kick/github) โ†’ fee-share wallet

bags_authenticate

read

Verify wallet ownership via Ed25519 signature

bags_prepare_token_metadata

gated

Creates token info + metadata. Does not launch a token.

bags_execute_trade

write

Swap tokens. Signs and submits.

bags_claim_fees

write

Claim creator/LP fees. Signs and submits.

bags_prepare_token_metadata reserves a mint and uploads metadata. Completing a launch also requires a Meteora fee-share config, whose fee-claimer split has to be your decision โ€” so this server does not implement that step rather than guessing at it. Finish the launch at bags.fm.


๐Ÿ” Write Tools & Spend Controls

Writes are off unless you configure them, and they are mainnet-only.

Bags has no devnet deployment. Its API endpoint and its Meteora/fee-share program IDs are all mainnet. This server nonetheless defaults to devnet, so an unconfigured install cannot spend real money. Calling a write tool on devnet returns an explanation, not a cryptic program error.

The first call to a write tool signs nothing. It returns a preview and a single-use token:

โš ๏ธ  CONFIRMATION REQUIRED โ€” nothing has been signed or sent.

Action:  Swap 0.05 of So1111โ€ฆ1112
         for       EkJuyYโ€ฆdBAGS
         expect    4823917722 (min 4679199990)
         slippage  3%
         network   ๐Ÿ”ด MAINNET โ€” real funds

Spend:   0.05 SOL
Caps:    0.1 SOL/tx ยท 0/1 SOL used this session

To execute, call bags_execute_trade again with the identical arguments plus:
  confirm: "kR3nT9xQm2vP"

The token is a fingerprint of the tool name plus the exact arguments, so one issued for a 0.01 SOL swap cannot authorize a 10 SOL one. It expires in five minutes and is consumed on every outcome, so it cannot be replayed.

On success you get a real signature and explorer link โ€” never a success message for a transaction that did not land.

Set BAGS_ALLOW_UNCONFIRMED=true to skip the preview. Spend caps still apply.

The caps only bind on SOL. A swap whose input is some other token cannot be valued in SOL, so no cap can limit it. Those swaps are refused by default; set BAGS_ALLOW_UNCAPPED_TOKEN_SWAPS=true to permit them, and the preview will say plainly that the trade is uncapped.


๐Ÿ“Š Engineering Rigor

337 tests. The bypass tests around the spend caps and the confirmation step are load-bearing; treat a change there as a security change. They are mutation- checked: removing the cap guard, the confirmation check, the decimals lookup, or the spend recorder each makes the suite fail.

Layer

Status

Details

Real default path

โœ…

No kill-switch flag in any documented command. USE_MOCK_DATA defaults off; when on, it affects only the bags_get_claimable_fees tool, stamping โš ๏ธ [MOCK DATA ENABLED] on that tool's own response. The other 13 tools ignore it. Live-run receipts in DEMO.md

Code quality

โœ…

ESLint + tsc --noEmit, both clean

Unit testing

โœ…

Jest, 337 tests / 17 suites, 100% statements ยท branches ยท functions ยท lines, enforced

High-signal tests

โœ…

Mutation-checked cap/confirmation bypass tests ยท a leak-channel regression test (the API key used to be echoed into tool output) ยท network-mismatch refusal

Security

โœ…

CodeQL SAST ยท Dependabot SCA ยท gitleaks over full history (fetch-depth: 0) ยท secret scanning + push protection on ยท npm audit in CI as a ratchet โ€” see below

Dependency debt

โš ๏ธ

6 advisories, 0 critical โ€” down from 90. Everything patchable was cleared with version-scoped overrides (see package.json). The 6 that remain are one root cause, bigint-buffer GHSA-3gc7-fjrx-p6mg, counted once at each level of the chain it travels up to @bagsfm/bags-sdk. No patched bigint-buffer exists โ€” 1.1.5 is the installed version, the latest version, and vulnerable. CI blocks any critical and any increase over .audit-baseline.json. Note: npm honours overrides only in a root project, so these protect this repo and CI, not consumers of the published package.

CI

โœ…

4 stages (Quality โ†’ Security โˆฅ Test โ†’ Build) with cancel-in-progress concurrency; Node 22 + 24 matrix; packaged-artifact and entrypoint checks

CD

โœ…

Release โ†’ tarball audit โ†’ npm publish --provenance โ†’ deprecate the superseded version. A second workflow submits server.json to the MCP registry via OIDC. Both gated on the full CI suite. 1.0.0 is deprecated on npm with a pointer to the defect it carried.

On-chain proof

โœ…

npm run proof:devnet lands a real transaction through the production write path and re-fetches it from the chain. Captured 2026-08-16: 2kvu25xWโ€ฆU5Dm, slot 484219564, err: null. Anyone can re-verify it โ€” see DEMO.md

Community standards

โœ…

Code of Conduct ยท Contributing ยท Security policy ยท issue + PR templates

E2E browser tests and Lighthouse budgets are deliberately absent: this is a stdio/HTTP MCP server with no web UI, so both would measure nothing. The equivalent end-to-end coverage is npm run demo, which drives all read tools over real MCP JSON-RPC against the live API.


๐Ÿš€ Getting Started

Prerequisites

You need a Bags API key from dev.bags.fm. That alone enables the read-only tools. For trading and fee claims you also need a Solana keypair file and the gating token โ€” see Write Tools & Spend Controls.

Enabling writes

Writes stay off until all of these are set:

{
  "mcpServers": {
    "bagos": {
      "command": "npx",
      "args": ["-y", "bagos-mcp-server"],
      "env": {
        "BAGS_API_KEY": "your-key-here",
        "BAGS_NETWORK": "mainnet",
        "BAGS_KEYPAIR_PATH": "~/.config/bags/keypair.json",
        "BOS_TOKEN_MINT": "EkJuyYyD3to61CHVPJn6wHb7xANxvqApnVJ4o2SdBAGS",
        "BAGS_MAX_SOL_PER_TX": "0.1",
        "BAGS_MAX_SOL_PER_SESSION": "1.0"
      }
    }
  }
}

Configuration

Variable

Required

Default

Notes

BAGS_API_KEY

yes

โ€”

From dev.bags.fm

BAGS_NETWORK

no

devnet

devnet or mainnet. Writes need mainnet.

SOLANA_RPC_URL

no

public cluster RPC

Must agree with BAGS_NETWORK or the server refuses to start

BAGS_KEYPAIR_PATH

writes only

~/.config/bags/keypair.json

JSON byte-array keypair file

BOS_TOKEN_MINT

writes only

โ€”

Gating token mint

BOS_REQUIRED_BALANCE

no

10000

Minimum gating-token balance. 0 disables the gate (any balance passes); a non-numeric value is refused at startup rather than silently defaulting.

BAGS_MAX_SOL_PER_TX

no

0.1

Per-transaction spend cap

BAGS_MAX_SOL_PER_SESSION

no

1.0

Per-process spend cap

BAGS_ALLOW_UNCONFIRMED

no

false

Skip the confirmation step

BAGS_ALLOW_UNCAPPED_TOKEN_SWAPS

no

false

Permit swaps whose input is not SOL. The caps are SOL-denominated and cannot limit these.


๐Ÿงช Testing & CI

npm ci
npm run ci            # lint + typecheck + tests with coverage
npm run dev           # stdio server with watch
npm run inspector     # MCP Inspector against the built server
npm run proof:devnet  # land a real devnet transaction through the write path

proof:devnet uses a persisted throwaway keypair (.proof/, gitignored), funds it from the devnet faucet when needed, and pushes a transfer through the same simulate/sign/send/confirm path the write tools use โ€” then re-fetches the signature from the chain instead of trusting the function's return value. That last step is the whole point: a function returning success is a claim, and a signature you can open on an explorer is evidence.


๐Ÿ“ฝ๏ธ Demo Materials

  • DEMO.md โ€” receipts from a real run against the live Bags mainnet API: 7 scenarios, 8 steps, per-step latency, plus the network-mismatch guard and the token gate caught refusing a write.

  • docs/examples.md โ€” prompts you can type at your assistant and what each should do.

  • docs/KNOWN_ISSUES.md โ€” what is currently broken and why, including what has already been ruled out. Open advisories are explained there rather than left for you to discover.


๐Ÿ›ก๏ธ Security

Read SECURITY.md before pointing a funded wallet at this.

Summary: your private key is read from disk, used to sign, and never logged, never sent anywhere, and never placed in an error message. Tool errors return a message only โ€” no stack traces โ€” with key-shaped strings redacted. The startup report strips credentials from the RPC URL. If the RPC endpoint's cluster disagrees with BAGS_NETWORK, the server refuses to start rather than sign mainnet transactions under a devnet banner.

The same rule now covers the Bags API key: bags_authenticate writes it to ~/.config/bags/credentials.json and echoes only a four-character tail. It used to print the key in full, which published a live credential into the assistant's context and every transcript downstream of it. If you ran bags_authenticate on a version before this change, rotate that key at dev.bags.fm.

Report vulnerabilities via GitHub security advisories.


๐Ÿ“„ License

MIT โ€” see LICENSE.

A
license - permissive license
-
quality - not tested
A
maintenance

Maintenance

โ€“Maintainers
91dResponse time
2wRelease cycle
11Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    -
    quality
    C
    maintenance
    AI-to-AI marketplace MCP server with 46 tools โ€” swap 65+ crypto tokens on 7 chains, rent GPUs, trade 25 tokenized stocks, on-chain escrow (Solana + Base), DeFi yields, sentiment analysis, wallet monitoring, and image generation. Supports USDC payments across 14 blockchains.
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    MCP (Model Context Protocol) server for the MAIN DEX on Base. Provides AI agents (Claude, Cursor, etc.) with tools to interact with the protocol: swap tokens, manage liquidity, enter/exit ALM strategies(10% APY), and more.
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    Non-custodial Solana swap & limit order engine for AI agents. 21 tools - swap, limit, trailing, TWAP, DCA, combo orders - across Raydium, PumpSwap, Orca, Meteora. Jito MEV-protected execution. Ed25519-verified server messages. Private key never leaves the process.
    21
    232
    3
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server providing Solana/crypto/macro tools (wallet scan, password breach, Jito tip, GitHub health, FRED series, Drift exposure, premium chapters) with x402 payment gating (USDC on Base) for 7 of 8 tools.
    15
    MIT

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/edycutjong/BagOS'

If you have feedback or need assistance with the MCP directory API, please join our Discord server