traql MCP server
Officialtraql MCP server
Скоринг AML- и комплаенс-рисков для криптовалютных адресов и транзакций, предоставляемый ИИ-агентам через Model Context Protocol.
Спросите своего агента: «безопасно ли отправлять на этот адрес?» — и он вернёт оценку риска от 0 до 100, группу оценок, категории риска, а при наличии API-ключа — каждый отдельный сигнал с источником и уровнем уверенности.
ethereum address 0x8589427373d6d84e98730d7795d8f6f8731fda16
RISK 100/100 — CRITICAL
Flags: sanctions, mixer, scam
Signals (21):
+80 [sanctions/eth_labels] direct.sanctions — sanctions label "Tornado.Cash: Donate" [entity Tornado.Cash: Donate, confidence 0.80]
+68 [mixer/eth_labels] direct.mixer — mixer label "Tornado.Cash: Donate" [entity Tornado.Cash: Donate, confidence 0.80]
+10 [mixer] behavior.mixer_contact — direct contact with mixer 0xdd4c48c0b24039969fc16d1cdf626eab821d3384
+9 [sanctions/ofac_sdn] indirect.sanctions — sent to Semenov Roman (sanctions, 18% of USDC volume) [entity Semenov Roman, confidence 1.00]
... and 17 more
Computed at 2026-08-23T11:42:49Z.Работает на базе traql: санкционные списки OFAC SDN, UK OFSI, EU и UN, инциденты заморозок Tether/Circle, выверенные атрибуции взломов и миксеров, а также анализ контрагентских рисков в Ethereum, BSC, TRON, TON и Bitcoin.
Быстрый старт
Требуется Node.js 18+.
npx -y @traql/mcpСервер общается с MCP через stdio, поэтому обычно вы подключаете к нему клиент, а не запускаете его вручную.
Claude Code
claude mcp add traql --env TRAQL_API_KEY=your_key -- npx -y @traql/mcpClaude Desktop
Добавьте в claude_desktop_config.json:
{
"mcpServers": {
"traql": {
"command": "npx",
"args": ["-y", "@traql/mcp"],
"env": { "TRAQL_API_KEY": "your_key" }
}
}
}Cursor
Добавьте в ~/.cursor/mcp.json (или .cursor/mcp.json в проекте), используя тот же блок mcpServers, что и выше.
VS Code
Добавьте в .vscode/mcp.json:
{
"servers": {
"traql": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@traql/mcp"],
"env": { "TRAQL_API_KEY": "your_key" }
}
}
}Related MCP server: zarq-risk-intelligence
Получение API-ключа
Зарегистрируйтесь на app.traql.io, подтвердите адрес электронной почты — бесплатные проверки включены — и выпустите ключ в разделе Ключи API. Секрет показывается один раз; его можно перевыпустить или отозвать в любое время.
Без ключа сервер всё равно работает, но в тарифе без ключа: одна укрупнённая формулировка причины вместо детализированных сигналов, жёсткие лимиты запросов, а на облачном API — требование оплаты за каждый вызов x402. Для использования с агентами установите ключ.
Конфигурация
Переменная | Обязателен | По умолчанию | Описание |
| рекомендуется | — | API-ключ из панели управления traql. Передаётся как |
| нет |
| Базовый URL API. Если вы разворачиваете traql самостоятельно, укажите адрес собственного развёртывания. |
| нет |
| Таймаут одного запроса в миллисекундах. |
Инструменты
check_address
Оценивает один адрес.
Аргумент | Тип | Обязательность | Описание |
|
| да | Сеть, к которой относится адрес. |
| string | да | Адрес в собственном формате сети. |
screen_transaction
Оценивает обе стороны перевода в одном из двух режимов:
Pre-flight — передайте
fromиto(по желаниюamountиasset), чтобы проверить перевод перед его отправкой в сеть. Работает во всех поддерживаемых сетях.By hash — передайте только
tx_hash, чтобы найти транзакцию, уже находящуюся в блокчейне. Поддерживается на Ethereum, BSC, TRON и TON.
Аргумент | Тип | Обязательность | Описание |
| chain enum | да | Сеть, к которой относится транзакция. |
| string | pre-flight | Адрес отправителя. |
| string | pre-flight | Адрес получателя. |
| string | no | Целочисленное количество в базовых единицах актива (например, |
| string | no | Символ актива или токена, например |
| string | by-hash | Хеш транзакции, отправленной в сеть. Взаимоисключающий с |
Ответ
Оба инструмента возвращают читаемый текст и structuredContent:
{
"subject": { "type": "address", "chain": "ethereum", "address": "0x…" },
"result": {
"score": 100,
"band": "critical",
"flags": ["sanctions", "mixer", "scam"],
"partial": false,
"computed_at": "2026-08-23T11:42:49Z",
"reasons": [
{
"code": "direct.sanctions",
"message": "sanctions label \"Tornado.Cash: Donate\" from eth_labels (severity 100 × confidence 0.80 = 80.0)",
"contribution": 80,
"category": "sanctions",
"source": "eth_labels",
"entity": "Tornado.Cash: Donate",
"severity": 100,
"confidence": 0.8,
"eff": 80.0
}
]
}
}Диапазоны оценок: clean 0–9, low 10–39, elevated 40–69, high 70–89, critical 90–100.
partial: true означает, что при вычислении результата источник данных работал с деградацией — воспринимайте оценку как нижнюю границу, а не как окончательный вердикт.
Каждый успешный вызов расходует одну проверку из настроенного аккаунта. Некорректный ввод по возможности отклоняется локально, поэтому такой вызов ничего не стоит.
Разработка
npm install
npm run build
npm testПримечания
Оценки — это рекомендательные сигналы для триажа и автоматизации. Они не являются юридическим заключением о нарушении и сами по себе не снимают регуляторных обязательств.
Ссылки
traql.io — продукт
API documentation — документация API
Dashboard — панель управления
Лицензия
MIT
Available Tools
2 toolscheck_addressCheck address riskARead-only
Score a single crypto address for AML and compliance risk.
Returns a risk score from 0 (clean) to 100 (critical), the band it falls into, and the risk categories that drove it — sanctions, mixer, scam, darknet, stolen_funds, ransomware, high_risk_exchange and others. With an API key configured, the response also itemizes every contributing signal with its data source, severity and confidence, so the verdict can be explained rather than just asserted.
Use it before sending funds to an unfamiliar address, to triage an address a user pasted, to check a counterparty in an investigation, or to vet a deposit address. Covers Ethereum, BSC, TRON, TON and Bitcoin. Each call consumes one check from the configured traql account.
| Name | Required | Description | Default |
|---|---|---|---|
| chain | Yes | Blockchain network the subject belongs to. | |
| address | Yes | Address in the chain's native format: 0x-hex for ethereum and bsc, base58 starting with T for tron, EQ/UQ for ton, and legacy or bech32 for bitcoin. |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes | |
| subject | Yes | Echo of the canonical subject that was scored. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate readOnlyHint and non-destructive, and the description adds meaningful behavioral detail beyond that: the exact return semantics (risk score 0-100, bands, categories), conditional verbosity with an API key, and the resource cost ('Each call consumes one check'). It doesn't contradict annotations, and the additional consumption caveat is valuable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the purpose and returns, then use cases, then chains and consumption. It is concise at four sentences, with no fluff. It could be slightly tighter (the chain list is redundant with the schema enum), but it remains efficiently structured and readable.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the presence of an output schema, the description need not detail return types, but it still explains the risk score range, band concept, and categories. It also covers supported chains, use cases, and the API-key enhancement. Everything an agent needs to invoke and interpret the result is present, so it is fully complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema already provides full descriptions for both parameters (chain enum and address format), so the baseline is 3. The description adds no extra parameter semantics—it only references the chain coverage implicitly, which the schema already communicates. No additional meaning is introduced beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description begins with a clear verb-resource pair ('Score a single crypto address for AML and compliance risk') that precisely states the tool's function. It also differentiates from the sibling tool screen_transaction by focusing on address-level vetting rather than transaction screening.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description lists concrete use cases ('before sending funds', 'triage a pasted address', 'vet a deposit address'), giving clear context for when to use it. It does not explicitly exclude transaction screening, but the single sibling tool makes the distinction evident; mentioning that tool as an alternative would make this a perfect 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
screen_transactionScreen transaction riskARead-only
Screen a transaction for AML and compliance risk by scoring both sides of the transfer.
Two modes, chosen by which arguments are given:
Pre-flight — pass
fromandto(optionallyamountandasset) to screen a transfer before it is broadcast. Works on every supported chain.By hash — pass only
tx_hashto look up a transaction that is already on-chain. Supported on ethereum, bsc, tron and ton.
Returns the same score, band, flags and itemized signals as an address check, with each signal marked as applying to the sending or receiving side. Use it as a pre-send safety gate, or to review a payment that already went out. Each call consumes one check from the configured traql account.
| Name | Required | Description | Default |
|---|---|---|---|
| to | No | Recipient address, for screening a transfer that has not been broadcast yet. | |
| from | No | Sender address, for screening a transfer that has not been broadcast yet. | |
| asset | No | Optional asset or token symbol being transferred, for example USDT. | |
| chain | Yes | Blockchain network the subject belongs to. | |
| amount | No | Optional transfer amount as an integer string in the asset's base units (for example 1000000 for 1 USDT, which has 6 decimals). Never a decimal fraction. | |
| tx_hash | No | Hash of an already-broadcast transaction. Mutually exclusive with `from`/`to`. Supported on ethereum, bsc, tron and ton only. |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes | |
| subject | Yes | Echo of the canonical subject that was scored. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false. The description adds valuable behavioral context beyond annotations: 'Each call consumes one check from the configured traql account' (a quota side effect) and describes the return structure ('score, band, flags and itemized signals'). This is consistent with annotations and provides useful operational detail.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Well-structured with a clear opening statement followed by a bulleted breakdown of modes. The information is front-loaded and each sentence serves a purpose—no filler or redundancy. It is slightly long but contains only necessary details, earning a 4 rather than 5 due to the length.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (two modes, six parameters, chain restrictions, and an existing output schema), the description covers all essential usage context: modes, which chains support which mode, use cases, and the quota side effect. Nothing critical is missing for an agent to invoke it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3. The description adds meaning by explaining the two modes and how parameters relate (pre-flight: from/to, optional amount/asset; by-hash: tx_hash only, mutually exclusive). It also gives an example for the amount format, reinforcing the schema description. This is helpful clarification beyond the schema's individual parameter descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a clear verb+resource: 'Screen a transaction for AML and compliance risk by scoring both sides.' It explicitly differentiates from the sibling address-check tool by focusing on transactions and even references the shared return format ('same score, band, flags and itemized signals as an address check'). This leaves no ambiguity about what the tool does and how it differs from check_address.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description clearly states when to use it: 'Use it as a pre-send safety gate, or to review a payment that already went out.' It also details two explicit modes with the exact parameters to pass ('pass from and to...' vs 'pass only tx_hash') and lists chain support for each. While it doesn't explicitly name check_address as an alternative, the mention of 'same... as an address check' implies routing, so guidance is strong but not exhaustive.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
2 tool updates
v0.1.0- First observed
check_address - First observed
screen_transaction
TDQS
The two tools target distinctly different entities: check_address evaluates a single address, while screen_transaction evaluates a transaction by scoring both sides. They are clearly separated by purpose and input requirements, with no overlapping functionality.
Both tool names follow a consistent verb_noun pattern: check_address and screen_transaction. The verbs ('check' vs 'screen') are semantically appropriate and the noun targets (address, transaction) are clear, maintaining a uniform naming style.
With only two tools, the server is compact but well-scoped for its narrow AML screening purpose. Each tool covers a fundamental operation (address check and transaction screening), so the count feels appropriate rather than insufficient, though it is below the typical 3-15 range.
The tool surface covers the primary use cases for AML risk assessment: pre-transaction screening and single-address checks. Minor gaps exist, such as lack of batch processing or historical investigation features, but these are not essential for the stated purpose and do not create dead ends in common workflows.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Pre-transaction risk screening for Ethereum addresses: signed score, sanctions, audit trail.
KYC, KYB, AML, wallet screening, transaction monitoring, and fraud workflows for AI agents.
Solana address risk grades and token scans for AI agents. Pay-per-call via x402 (USDC on Base).
AML/CFT compliance oracle: wallet screening, sanctions, PEPs, jurisdiction risk.
Related MCP Servers
- AlicenseBqualityDmaintenanceProvides blockchain address risk scoring and asset information through the BICScan API, allowing users to assess risks for crypto addresses, domains, and dApps on a scale of 0-100.217MIT

zarq-risk-intelligenceofficial
AlicenseNot gradedqualityDmaintenanceReal-time crypto risk scoring for AI agents. Trust Score, crash probability, and distance-to-default for 205 tokens. Free, no API key needed.MIT
anchain-data-mcpofficial
AlicenseAqualityCmaintenanceEnables AI assistants to access AnChain.AI blockchain intelligence APIs for risk assessment, sanctions screening, and transaction analysis on blockchain addresses and transactions.206AGPL 3.0- FlicenseNot gradedqualityDmaintenanceEnables AI agents to access real-time crypto risk intelligence with two tools: Flare for precursor detection and Core for overall risk environment assessment.4-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/traql/mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server