mcp-opcode
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-opcodeswap 1 ETH for USDC"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-opcode
Python SDK for the opcode gasless trading API, and the MCP server built on top of it. It lets an agent, bot or script do what a user does in the opcode app — over plain HTTP, with its own wallet.
Today this repo holds opcode_sdk. The MCP server lands on top of it.
Design
Sign-then-submit. The client never holds a private key. Every signed action is two calls:
prepare_X(...)returns the exact EIP-712 / EIP-7702 payload(s) to sign, the caller signs them with whatever custody they have, andsubmit_X(prepared, sig)POSTs the result.OpcodeClienttakes no signer.No EVM RPC. Everything needed to build a signature comes off the quote or the session — the authorization nonce and the approve nonce are both carried in the quote descriptor. The SDK never opens a node connection.
Trusted values are pinned, not accepted. Chain id, gateway and approve-delegate are checked against client-side constants before anything is signed, so a compromised backend cannot get a signature over an address of its choosing. See
TrustedValues.Guards run before the key is touched. A quote that failed the server's safety verdict, is over the effective cap, or no longer has enough of its submit window left is refused at
prepare_order()— not after a signature exists.Typed errors. Every wire error kind maps to an exception class chosen for what the caller should do about it, so retry-vs-fatal is a type, not a string match.
Sync first. Built on
httpx.Client.
Session token rides in the x-opcode-session header, held in memory only.
Related MCP server: seashail
Install
uv syncUsage
from opcode_sdk import OpcodeClient, KeystoreSigner, EnvPassword, WalletKind, TrustedValues
client = OpcodeClient("https://app.opcode.fi", chain_id=1)
signer = KeystoreSigner("wallet.json", EnvPassword("OPCODE_KEYSTORE_PASSWORD"))
prep = client.auth.prepare_login(signer.address)
client.auth.submit_login(prep, signer.sign_typed_data(prep.signable))
quote = client.trade.quote(token_in, token_out, amount_in, wallet=WalletKind.embedded)
order = client.trade.prepare_order(quote, trusted=TrustedValues.mainnet())
sigs = {
k: (signer.sign_authorization(s) if k == "authorization" else signer.sign_typed_data(s))
for k, s in order.signables.items()
if s is not None
}
res = client.trade.submit_order(order, sigs)OpcodeWallet(client, signer) wraps these into one-call flows (login, accept_terms, trade,
wait_for_order) and re-logs in automatically on a 401.
Custody
KeystoreSigner reads a standard V3 eth-keystore and is the default. Two things are hooked
separately, so you can replace either without the other:
PasswordSource— where the password comes from.EnvPassword,FilePassword,PromptPassword, or your own callable.UnlockGate— whether a given signature is allowed to happen at all.AlwaysUnlocked,ConfirmEachSignature,CachedConfirmation, or your own. The gate is handed aSignRequestdescribing what is about to be signed, and raisesUnlockDeniedto refuse.
For any other custody (HSM, remote signer, MPC, hardware) implement the Signer protocol —
sign_typed_data and sign_authorization — and pass it anywhere a signer is taken. Nothing in the
SDK reaches for a key on its own.
An EIP-7702 authorization is called out as its own SignKind: it delegates the EOA's code and is
not something a gasless client can undo, so a gate can treat it differently from an ordinary order
signature. CachedConfirmation never caches it.
Surfaces
client.auth, .onboarding, .market, .account, .compliance, .explorer, .trade, .feed,
.recipients.
Buys, sells and withdrawals all go through the same quote-and-sign path — a withdrawal is a
same-token swap to another receiver. Paying an address other than the signer requires that address
to be in the recipient book first (client.recipients), and the book's entries are re-verified
locally against your own signature rather than trusted as returned.
Membership and terms status are read from GET /api/session; there are no standalone
/invite/status, /terms/status or /session_limits endpoints.
tradable_now() answers whether an asset can be traded right now from the catalog entry plus market
status. It is a client-side read of side-collapsed data and cannot see a per-side halt; a quote is
the only authority.
Tests
uv run pytestThe suite pins the EIP-712 digests, the order meta bit packing, the grant plan, and the
tradability gate. It makes no network calls.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
AlicenseCqualityCmaintenanceAn MCP server providing unified access to blockchain operations, bridging, swapping, and crypto trading strategies for AI agents.Last updated37178GPL 3.0- Alicense-qualityCmaintenanceAgent-native, self-hosted MCP server for crypto trading and DeFi management. Enables agents to query balances, execute trades, and manage positions with a policy engine and secure key storage.Last updated7Apache 2.0
- AlicenseCqualityAmaintenanceWeb3 MCP proxy server for AI agents: EVM execution, DeFi swaps, bridges, advanced orders, market data, wallet management, and confirmation-gated writes.Last updated10056MIT
- Alicense-qualityBmaintenanceA set of MCP servers that provide AI agents with safe, composable access to web3 market data and trading, featuring read-only intelligence and execution modes with SIM/PAPER/LIVE safeguards.Last updatedMIT
Related MCP Connectors
No-KYC managed MCP for AI agents: sandboxed TypeScript trading SDK, isolated sub-accounts, futures.
Hosted AgentLux MCP server for marketplace, identity, creator, services, and social flows.
MCP server connecting AI agents to non-custodial staking data across 130+ networks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/opcode-fi/mcp-opcode'
If you have feedback or need assistance with the MCP directory API, please join our Discord server