# Basis Protocol (remote · basisprotocol.xyz)

Attested risk scores for stablecoins, DeFi protocols and wallets, with receipts.

- Trust score: 67/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-08

## Components

- remote · `basisprotocol.xyz`: 67/100 (this document), [markdown](https://verifymcp.io/servers/basis-protocol-basis/basisprotocol.md), [page](https://verifymcp.io/servers/basis-protocol-basis/basisprotocol)

## Channel facts

- Endpoint: `https://basisprotocol.xyz/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-08.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 24 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 69/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 2212 tokens (~92/item across 24 items; 24 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 24 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 25 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Basis Protocol MCP server?

Basis Protocol is a hosted endpoint at https://basisprotocol.xyz/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http basis-protocol-basis 'https://basisprotocol.xyz/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "basis-protocol-basis": {
      "url": "https://basisprotocol.xyz/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "basis-protocol-basis": {
      "type": "http",
      "url": "https://basisprotocol.xyz/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.basis-protocol-basis]
url = "https://basisprotocol.xyz/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "basis-protocol-basis": {
      "type": "remote",
      "url": "https://basisprotocol.xyz/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add basis-protocol-basis --url 'https://basisprotocol.xyz/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  basis-protocol-basis:
    url: "https://basisprotocol.xyz/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "basis-protocol-basis": {
      "Transport": "http",
      "Url": "https://basisprotocol.xyz/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add basis-protocol-basis -t streamable-http -u 'https://basisprotocol.xyz/mcp'
```

### Other

```json
{
  "mcpServers": {
    "basis-protocol-basis": {
      "type": "http",
      "url": "https://basisprotocol.xyz/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-08 (score 67, +1)

- [security] Tool “basis_governance_activity” rewrote its description, which is the text the model reads
- [security] Tool “query_template” rewrote its description, which is the text the model reads
- [functional] New tool “basis_asset_footprint”

### 2026-10-06 (score 66, +1)

- [security] Tool “get_stablecoin_scores” rewrote its description, which is the text the model reads
- [cosmetic] “get_stablecoin_scores” added an optional parameter “full”

### 2026-10-03 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-01 (score 64, +1)

- [functional improvement] Stability: unverified → 0.03
- [functional] New tool “basis_venue_shift”

### 2026-09-30 (score 63, +38)

- [security improvement] Injection markers: unverified → pass
- [security improvement] Transport: fail → pass
- [security] First check of Judged manipulation: pass
- [security] Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 22 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] MCP protocol: unverified → pass
- [functional] First check of Tool coverage: 0
- [functional] First check of Schema quality: fail
- [functional] First check of Destructive annotations: pass
- [functional] First check of Schema quality: pass
- [functional] First check of Schema quality: good
- [functional] First check of Tool coverage: 100

### 2026-09-28 (score 25)

First indexed and scored.

## MCP tools (24)

### `get_stablecoin_scores` (~118 tokens)

Get current SII scores (0-100) for all scored stablecoins. Use before any decision involving stablecoins.

    Returns a compact summary per coin (score, grade, confidence, category
    scores). Call get_stablecoin_detail for one coin's full breakdown.

    Parameters:
        sort_by: "score_desc" (default), "score_asc", or "symbol"
        full: true returns every field per coin (large)

Input parameters:

- `full` (boolean)
- `sort_by` (string)

Output parameters:

- `result` (string)

### `get_stablecoin_detail` (~33 tokens)

Full score breakdown for a specific stablecoin including category scores and methodology version.

Input parameters:

- `coin` (string, required)

Output parameters:

- `result` (string)

### `get_wallet_risk` (~35 tokens)

Get risk profile for a specific Ethereum wallet — composite risk score, concentration, coverage quality.

Input parameters:

- `address` (string, required)

Output parameters:

- `result` (string)

### `get_wallet_holdings` (~32 tokens)

Detailed holdings breakdown for an Ethereum wallet with per-asset SII scores.

Input parameters:

- `address` (string, required)

Output parameters:

- `result` (string)

### `get_riskiest_wallets` (~36 tokens)

Wallets with the most capital at risk — lowest risk scores weighted by total value.

Input parameters:

- `limit` (integer)

Output parameters:

- `result` (string)

### `get_scoring_backlog` (~34 tokens)

Unscored stablecoin assets ranked by total capital exposure across all indexed wallets.

Input parameters:

- `limit` (integer)

Output parameters:

- `result` (string)

### `check_transaction_risk` (~51 tokens)

Composite risk assessment for a stablecoin transaction — evaluates asset, sender, and receiver.

Input parameters:

- `asset_symbol` (string, required)
- `from_address` (string, required)
- `to_address` (string, required)

Output parameters:

- `result` (string)

### `get_methodology` (~26 tokens)

Returns the current SII formula, category weights, score scale, and version information.

Output parameters:

- `result` (string)

### `get_divergence_signals` (~101 tokens)

Check for divergence signals before executing transactions.

    Detects capital-flow / quality mismatches:
    - Asset quality: stablecoin score declining while capital flows in
    - Wallet concentration: HHI rising while wallet value grows
    - Quality-flow: score declining with net inflows from wallet graph

    Call this BEFORE executing any stablecoin swap, deposit, or rebalance
    to check if capital is flowing toward deteriorating assets.

Output parameters:

- `result` (string)

### `query_template` (~176 tokens)

Run a pre-built query template against the Basis risk database.

    Available templates:
    - high_risk_whales: Wallets with high value AND poor risk scores
    - contagion_hotspots: Wallets with the most counterparty connections
    - stablecoin_concentration: Per-stablecoin holder concentration
    - score_movers: Assets whose SII score changed most over N days
    - disclosure_gaps: Issuers with the oldest attestation documents
    - cross_chain_exposure: Wallets active on multiple chains

    Call GET /api/query/templates first to list the exact template names
    and their parameters; an unknown name returns the list of valid names
    (do not invent names such as "basis protocol").

Input parameters:

- `params` (object)
- `template_name` (string, required)

Output parameters:

- `result` (string)

### `get_treasury_events` (~130 tokens)

Get recent behavioral events from labeled treasury wallets.

    Detects: TWAP conversions, protocol rebalancing, concentration drift,
    quality shifts, and large transfers (>$1M) from known treasury wallets.

    Parameters:
        wallet_address: Filter to a specific wallet (optional)
        event_type: Filter by type: twap_conversion, rebalance, concentration_drift, quality_shift, large_transfer
        days: Lookback period in days (default 30)

Input parameters:

- `days` (integer)
- `event_type` (string)
- `wallet_address` (string)

Output parameters:

- `result` (string)

### `basis_liquidity_depth` (~119 tokens)

Per-asset, per-venue liquidity profile for any stablecoin.

    Returns DEX pool depth (Uniswap, Curve, etc.) and CEX ticker data
    (Binance, Coinbase, etc.) with bid/ask depth, spread, volume, and
    trade counts. Use before any large stablecoin transaction to check
    venue liquidity.

    Parameters:
        asset_id: Stablecoin ID (e.g. "usdc", "usdt", "dai")

Input parameters:

- `asset_id` (string, required)

Output parameters:

- `result` (string)

### `basis_yield_data` (~102 tokens)

Pool-level yield, TVL, and utilization for any DeFi protocol.

    Returns APY, base APY, reward APY, TVL, and pool metadata for all
    tracked lending/vault pools. Use to evaluate yield sustainability
    and protocol health.

    Parameters:
        protocol: Protocol slug (e.g. "aave-v3", "compound-v3"). Omit for all protocols.

Input parameters:

- `protocol` (string)

Output parameters:

- `result` (string)

### `basis_governance_activity` (~133 tokens)

Governance proposal counts, voter participation, and pass rates.

    Returns full proposal history with vote counts, quorum status, and
    voter concentration data. Use to assess DAO health and governance quality.

    Parameters:
        protocol: Protocol slug as used by the Basis protocol index (e.g. "aave", "lido", "curve-finance", "compound-finance", "uniswap"). Snapshot space names such as "aavedao" are not accepted.
        days: Lookback period in days (default 90)

Input parameters:

- `days` (integer)
- `protocol` (string, required)

Output parameters:

- `result` (string)

### `basis_bridge_flows` (~79 tokens)

Directional bridge volume per chain pair.

    Shows where capital is flowing: "$50M Ethereum → Arbitrum, $12M back."
    Use to assess cross-chain liquidity routing and chain health.

    Parameters:
        bridge_id: Specific bridge ID (optional). Omit for aggregate flows.

Input parameters:

- `bridge_id` (string)

Output parameters:

- `result` (string)

### `basis_exchange_health` (~88 tokens)

Exchange trust score, volume, and reserve status.

    Returns CoinGecko trust scores, 24h volume, year established, and
    stablecoin-specific trading pair data for top exchanges.

    Parameters:
        exchange_id: CoinGecko exchange ID (e.g. "binance", "coinbase-exchange"). Omit for all.

Input parameters:

- `exchange_id` (string)

Output parameters:

- `result` (string)

### `basis_correlation` (~85 tokens)

Cross-entity correlation matrix.

    Shows which assets move together. When USDC depegs, which protocols
    lose TVL in sync? Use for portfolio construction and systemic risk assessment.

    Parameters:
        matrix_type: "sii_30d", "sii_90d", or "cross_90d"

Input parameters:

- `matrix_type` (string)

Output parameters:

- `result` (string)

### `basis_volatility` (~91 tokens)

Realized volatility, drawdown, and recovery time for any asset.

    Returns 1d/7d/30d/90d realized vol, max drawdown, and correlation
    with BTC/ETH. Use for risk-adjusted position sizing.

    Parameters:
        asset_id: Asset ID (e.g. "usdc", "usdt")

Input parameters:

- `asset_id` (string, required)

Output parameters:

- `result` (string)

### `basis_incidents` (~79 tokens)

Structured event history: exploits, depegs, oracle failures.

    Returns timeline of incidents with severity, affected entities, and
    resolution status. Use for due diligence and insurance risk assessment.

    Parameters:
        entity_id: Entity ID to filter by (optional). Omit for all recent incidents.

Input parameters:

- `entity_id` (string)

Output parameters:

- `result` (string)

### `basis_peg_monitor` (~114 tokens)

5-minute peg resolution data for micro-depeg detection.

    Returns 5-minute price snapshots and deviation from $1.00. Catches
    micro-depegs that are invisible at hourly resolution. Early warning
    signal for peg instability.

    Parameters:
        stablecoin_id: Stablecoin ID (e.g. "usdc", "usdt")
        hours: Lookback period in hours (default 24)

Input parameters:

- `hours` (integer)
- `stablecoin_id` (string, required)

Output parameters:

- `result` (string)

### `basis_venue_shift` (~83 tokens)

Venue-shift findings: an operator's proposed venue markets overlapped
    against the markets its vaults currently allocate to.

    Each finding cites the proposal capture hash and the allocation-snapshot
    attestation it was computed from. Omit operator_slug to list all findings,
    sorted by share of venue supply.

Input parameters:

- `operator_slug` (string)

Output parameters:

- `result` (string)

### `basis_asset_footprint` (~111 tokens)

Where a collateral token is used across the lending venues we read:
    per venue and chain, supply and borrow against it and its share of the
    venue's supply. Supply/borrow are the markets' loan-side totals attributed
    to the collateral token (a footprint proxy, not collateral posted). Phantom /
    single-actor flagged markets are listed, not summed. A symbol matching several
    tokens returns them separately (ambiguous=true).

Input parameters:

- `token_or_symbol` (string, required)

Output parameters:

- `result` (string)

### `basis_data_catalog` (~59 tokens)

Every data type available in the universal data layer.

    Returns per data type: description, freshness, history depth, update
    frequency, provenance status, row count. Use to discover what data
    is available for building custom risk indices.

Output parameters:

- `result` (string)

### `basis_answer` (~285 tokens)

Ask the Basis Agent a question about attested risk state.

    Answers come ONLY from attested substrate state, cited to
    attestation hashes; queries the substrate cannot ground are refused
    (identical envelope, refusals, and receipts as the REST transport —
    the agent never recommends positions, never forecasts, never
    executes). Every call is logged as an attributed protocol read.

    Identity: pass your hub API key on the /mcp HTTP request
    (``x-api-key`` header or ``?apikey=`` query param) so reads are
    attributed to your service; keyless calls are attributed by IP.

    Multi-turn: the returned envelope carries ``session_id`` — pass it
    back as the ``session_id`` argument on your next call to hold a
    session (follow-ups like "and its liquidity?" then inherit the
    session's entity). An ``X-Basis-Session`` header on the /mcp
    request works too; the explicit argument wins. Omit both and each
    call is a fresh single-turn session.

    Parameters:
        query: The question (max 4000 chars).
        session_id: Session UUID from a previous basis_answer envelope
            (optional — enables multi-turn follow-ups).

Input parameters:

- `query` (string, required)
- `session_id` (string)

Output parameters:

- `result` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/basis-protocol-basis/basisprotocol#diagnostics

## Score history

- 2026-10-08: 67
- 2026-10-06: 66
- 2026-10-04: 65
- 2026-10-03: 65
- 2026-10-02: 64
- 2026-10-01: 64
- 2026-09-30: 63
- 2026-09-29: 25
- 2026-09-28: 25

## Common questions

### What is the Basis Protocol MCP server?

Basis Protocol is an MCP server listed in the public MCP registry as io.github.basis-protocol/basis. Attested risk scores for stablecoins, DeFi protocols and wallets, with receipts. This page covers its hosted endpoint (https://basisprotocol.xyz/mcp).

### Is the Basis Protocol MCP server safe to use?

Basis Protocol scores 67 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Basis Protocol MCP server expose?

Basis Protocol exposes 24 tools: get_stablecoin_scores, get_stablecoin_detail, get_wallet_risk, get_wallet_holdings, get_riskiest_wallets, and 19 more. Their descriptions and schemas cost roughly 2,200 tokens of context every time the server is loaded.

### Does the Basis Protocol MCP server require authentication?

No. We connected to Basis Protocol without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Basis Protocol MCP server still maintained?

Basis Protocol is still listed as active in the MCP registry. We last reached this channel on 8 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://basisprotocol.xyz/mcp
- Repository: https://github.com/basis-protocol/basis-hub
- Website: https://basisprotocol.xyz/
- Changelog RSS feed: https://verifymcp.io/servers/basis-protocol-basis/basisprotocol.xml
- Changelog JSON feed: https://verifymcp.io/servers/basis-protocol-basis/basisprotocol.json
- HTML version of this page: https://verifymcp.io/servers/basis-protocol-basis/basisprotocol
