cc.accrue/mcp
REMOTE · ACCRUE.CC · SCANNED SEP 20
Stablecoin Yield Index (SYX) and live USDC vault APYs across Ethereum, Base, Arbitrum.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2819 tokens (~140/item across 20 items; 20 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage97
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 91% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 20 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 20 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities20
- Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28. See how to fix → Fail
How do I install the cc.accrue/mcp server?
cc.accrue/mcp is a hosted endpoint at https://accrue.cc/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · accrue.cc
claude mcp add --transport http cc-accrue-mcp 'https://accrue.cc/mcp'
{
"mcpServers": {
"cc-accrue-mcp": {
"url": "https://accrue.cc/mcp"
}
}
} {
"servers": {
"cc-accrue-mcp": {
"type": "http",
"url": "https://accrue.cc/mcp"
}
}
} [mcp_servers.cc-accrue-mcp] url = "https://accrue.cc/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"cc-accrue-mcp": {
"type": "remote",
"url": "https://accrue.cc/mcp",
"enabled": true
}
}
} openclaw mcp add cc-accrue-mcp --url 'https://accrue.cc/mcp' --transport streamable-http
mcp_servers:
cc-accrue-mcp:
url: "https://accrue.cc/mcp" {
"McpServers": {
"cc-accrue-mcp": {
"Transport": "http",
"Url": "https://accrue.cc/mcp"
}
}
} assistant mcp add cc-accrue-mcp -t streamable-http -u 'https://accrue.cc/mcp'
{
"mcpServers": {
"cc-accrue-mcp": {
"type": "http",
"url": "https://accrue.cc/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 14 Sept 26 0
- Tool “build_user_operation” rewrote its description, which is the text the model reads security
- Tool “get_transaction_status” rewrote its description, which is the text the model reads security
- Tool “prepare_transaction” rewrote its description, which is the text the model reads security
- Tool “submit_user_operation” rewrote its description, which is the text the model reads security
- Schema quality: 127 → 140 ▼ functional
- New tool “get_gas_sponsorship” functional
- “build_user_operation” reworded the description of “draft” cosmetic
- “build_user_operation” reworded the description of “permit_signature” cosmetic
- “prepare_transaction” reworded the description of “gas” cosmetic
- “build_user_operation” made “permit_signature” optional cosmetic
- 13 Sept 26 −1
- Schema quality: 108 → 127 ▼ functional
- Tool coverage: 100% → 91% ▼ functional
- Server version: 2.0.0 → 2.1.0 functional
- New tool “build_user_operation” functional
- New tool “get_transaction_status” functional
- New tool “list_vault_contracts” functional
- New tool “prepare_transaction” functional
- New tool “submit_user_operation” functional
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 23 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Aug 26 0
- Tool “calculate_yield” rewrote its description, which is the text the model reads security
- Tool “get_portfolio_details” rewrote its description, which is the text the model reads security
- Schema quality: pass → fail ▼ functional
- “get_portfolio_details” reworded the description of “portfolio” cosmetic
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://accrue.cc/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=accrue.cc | CN=YR1,O=Let's Encrypt,C=US | 30 Jul 2026 | 28 Oct 2026 | RSA 2048 | SHA256-RSA | 5b2a630bd3de12c5418d4b6d3a84c239903 |
| SANs: accrue.cc | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of accrue.cc. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| cc. | present | 12593 | 13 | Verified |
| accrue.cc. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://iris-api.circle.com https://api.anthropic.com https://fonts.googleapis.com https://eth-mainnet.g.alchemy.com https://base-mainnet.g.alchemy.com https://ethereum-rpc.publicnode.com https://eth.llamarpc.com https://mainnet.base.org https://base-rpc.publicnode.com https://*.walletconnect.com https://*.walletconnect.org wss://*.walletconnect.com wss://*.walletconnect.org https://*.safe.global https://*.web3modal.org; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), payment=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://accrue.cc/mcp | Verified | 200 | |
| http (plaintext) | http://accrue.cc/mcp | HTTPS enforced | 308 | https://accrue.cc/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
build_user_operation ~232
Second step of the sponsored and USDC-gas paths. Pass back the draft from prepare_transaction unchanged. For usdc_path, add permit_signature (EIP-712 signature of the returned permit). For either path, add authorization_signature (EIP-7702) if prepare asked for one. For sponsored_path, ACCRUE obtains the sponsorship first, so the operation you receive is already approved — if it is not sponsored (limit or budget reached), you get NOT_SPONSORED and can use usdc_path or eth_path. Returns the final user operation plus its EIP-712 typed data and hash for you to sign. Nothing is sent.
| Name | Type | Req | Description |
|---|---|---|---|
| authorization_signature | – | – | Only on first use on the chain: the EIP-7702 authorisation signature, as 65-byte hex or {r, s, yParity}. |
| draft | object | yes | sponsored_path.draft or usdc_path.draft from prepare_transaction, unchanged. |
| permit_signature | string | – | usdc_path only: 65-byte hex signature of usdc_path.sign.permit (typed data or its digest). |
No output schema declared.
No examples provided.
calculate_yield ~196
Project compound returns for a USDC deposit into any ACCRUE vault or model portfolio over a given holding period. Uses live APY data and applies the ACCRUE platform fee, which is charged on PRINCIPAL (0.25%/yr standalone, 0.50%/yr managed falling to 0.25% above $1M) and never on yield. Returns gross yield, platform fee, net yield and final balance. Because the fee is on principal, net yield can be negative over a short horizon — net_is_negative flags that. Use this when the user asks "how much would I earn" or "what would my $X grow to".
| Name | Type | Req | Description |
|---|---|---|---|
| amount_usdc | number | yes | USDC deposit amount in dollars |
| months | number | yes | Holding period in months |
| target_id | string | – | Optional vault ID or portfolio ID. If omitted, projects across all vaults and portfolios. |
No output schema declared.
No examples provided.
compare_vaults ~106
Compare two or more ACCRUE vaults side by side. Returns each vault's live APYs, TVL, chain, and risk tier, plus a comparison summary highlighting the highest yield, highest TVL, and whether the vaults share a risk tier. Use this for "compare X and Y" or "is Aave or Compound better right now" type questions.
| Name | Type | Req | Description |
|---|---|---|---|
| vault_ids | array | yes | Array of 2–6 vault IDs or names to compare. |
No output schema declared.
No examples provided.
get_gas_sponsorship ~238
ACCRUE-sponsored gas for AI agents: where a wallet stands on one chain. Returns whether sponsorship is offered and live, whether the wallet is eligible this month (and, from the 20th, whether it is on next month's list), the fixed monthly limit per wallet and the per-transaction limit, how much has been sponsored this month and what remains, the reset date (the 1st, 00:00 UTC), and whether the chain's monthly budget has room. Limits are maximums, not guarantees: if a limit or the budget is reached, the agent pays its own fee in USDC or ETH and the transaction still goes through. Eligibility: a time-weighted average balance of at least $100 across ACCRUE vaults on the chain over the last 30 days, and a first ACCRUE deposit at least 14 days ago. Covers network fees on ACCRUE deposits and withdrawals only — never ACCRUE platform fees.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | Optional 0x address; adds eligibility, amount sponsored and amount remaining. |
| chain | string | yes | Chain to check. |
No output schema declared.
No examples provided.
get_platform_info ~83
Get high-level facts about the ACCRUE platform: fee structure, custody model, supported chains, wallets, KYC requirements, withdrawal terms, and AI agent integration status. Use this when the user asks "what is ACCRUE", "how does ACCRUE work", "what are the fees", or anything about the platform itself rather than a specific vault.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_portfolio_details ~100
Get full details on a single model portfolio: its underlying vault allocations, the live APY of each underlying vault, and the blended portfolio APY. Use this when the user asks about a specific portfolio like "what is in Core on Ethereum" or "how does Foundation on Base work".
| Name | Type | Req | Description |
|---|---|---|---|
| portfolio | string | yes | Portfolio ID or name. Examples: "foundation-eth", "Core Portfolio", "growth-eth", "Foundation Portfolio Base". |
No output schema declared.
No examples provided.
get_syx_components ~106
List the current SYX components with their live weights, APYs, and total value locked. SYX is composed of 8 onchain USDC supply markets: Aave v3 (Ethereum, Base, Arbitrum), Compound v3 (Ethereum), and Morpho v2 Prime USDC vaults from Steakhouse Financial and Gauntlet (Ethereum, Base). Use this when the user asks what is inside SYX, or wants to see the per-component breakdown.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_syx_history ~56
Get historical SYX index readings. Use this when the user asks how SYX has moved over time, wants a chart of recent readings, or wants to compare current SYX to its recent trend. Returns time-series data points.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_syx_methodology ~75
Get the full SYX methodology — how the index is constructed, which onchain components are included, how weights are calculated, the measurement windows, and the exclusion rules. Use this when the user asks "how is SYX calculated" or "what does SYX measure" or "what protocols does SYX include".
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_syx_value ~111
Get the current Stablecoin Yield Index (SYX) value and rolling averages (7-day, 30-day, 90-day). SYX is a TVL-weighted benchmark for conservative USDC yield, calculated directly from canonical onchain contracts on Ethereum, Base, and Arbitrum — not aggregated from third-party APIs. Use this when the user asks "what is the current stablecoin yield" or "what is SYX right now" or any benchmark/reference-rate question about USDC yield.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_transaction_status ~80
Status of a submitted operation: pending, success or reverted, the transaction hash and explorer link, and who paid the network fee — ACCRUE (sponsored, with the fee) or the account (the exact USDC Circle charged).
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | yes | – |
| user_op_hash | string | yes | user_op_hash from submit_user_operation. |
No output schema declared.
No examples provided.
get_vault_details ~143
Get full details on a single ACCRUE yield vault by ID or name. Returns the live spot APY, 7-day realized APY, 30-day realized APY, TVL, chain, risk tier, underlying protocol, and metadata. Use this when the user asks about a specific vault like "tell me about Steakhouse Prime on Ethereum" or "how is the Aave Base vault doing".
| Name | Type | Req | Description |
|---|---|---|---|
| vault | string | yes | Vault ID, name, or partial name. Examples: "aave-eth", "Aave USDC Supply (Base)", "Gauntlet Frontier", "morpho-steakhouse-prime-eth". |
No output schema declared.
No examples provided.
list_model_portfolios ~101
List all model portfolios on ACCRUE, organised per chain. Each portfolio is a pre-built blend of underlying vaults sized to a risk profile. Returns each portfolio with its live blended APY computed from underlying vault yields. Use this when the user asks "what portfolios are available" or wants a one-click diversified option.
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | – | Filter to a specific chain |
| risk_tier | string | – | Filter to a risk tier |
No output schema declared.
No examples provided.
list_vault_contracts ~158
List the ACCRUE vault and model-portfolio CONTRACTS an agent can deposit into on one chain, read live from the ACCRUE Registry (registry.approvedVaults()). Returns address, on-chain symbol and name, whether it is a portfolio, the minimum deposit, and — if you pass your account — whether you are allowlisted and your current share balance. Vault addresses differ between chains and three of them name DIFFERENT markets on Ethereum and Base: always use the address returned for the chain you transact on. During guarded testing, deposits require the account to be allowlisted.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | Optional 0x address; adds allowlist status and share balance. |
| chain | string | yes | Chain to list. |
No output schema declared.
No examples provided.
list_vaults ~85
List all stablecoin yield vaults available on ACCRUE with their current live APYs, risk tiers, chains, and underlying protocols. Returns spot, 7-day realized, and 30-day realized APYs for each vault. Use this when the user asks "what vaults are available", "what strategies does ACCRUE offer", or wants to browse options.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
prepare_transaction ~440
Prepare a deposit into or withdrawal from an ACCRUE vault for the calling agent's own wallet. Nothing is signed or sent. Returns (1) eth_path: ordinary unsigned transactions to send in order from the account, paying gas in ETH — ALWAYS returned; (2) sponsored_path: when the wallet is eligible and within its limits, ACCRUE pays the network fee — sign the EIP-7702 authorisation if asked (first use on the chain), then call build_user_operation, which returns the operation with the sponsorship already approved; and (3) usdc_path: when available, the account can instead pay gas in USDC and hold no ETH at all — sign the returned USDC permit (and, on first use on the chain, the EIP-7702 authorisation, which keeps your address), then call build_user_operation. Prefer sponsored_path, then usdc_path; eth_path always works. The USDC path shows a gas ceiling: the most the operation can cost; the actual charge is lower. Every precondition is checked first (allowlist, minimum deposit, balance, withdrawable liquidity), so a failure is reported before you sign anything. Amounts are in USDC, e.g. "25" or "12.5"; for a full withdrawal use amount "all".
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | yes | The agent's own 0x address. Positions are permanently tied to the address that deposits. |
| action | string | yes | – |
| amount | string | yes | USDC amount ("25", "12.5"), or "all" to withdraw the whole withdrawable position. |
| chain | string | yes | Chain of the vault. Gas can be paid in ETH or USDC on both. |
| gas | string | – | auto (default): return every route available — sponsored, USDC and ETH. eth: ETH path only. |
| vault | string | yes | Vault address or on-chain symbol (e.g. acrAAVE) on this chain, from list_vault_contracts. To withdraw from a retired ACCRUE vault (no longer listed, but always withdrawable), pass its address. |
No output schema declared.
No examples provided.
recommend_strategy ~121
Recommend a vault or model portfolio for a user based on their risk profile and chain preference. Uses live APY data to choose the best current option. Returns a recommendation with reasoning. Use this when the user describes what they want ("I want safe yield on Base", "maximise returns on Ethereum") rather than asking about a specific vault. Always reminds users this is informational, not financial advice.
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | – | Preferred chain (optional) |
| goal | string | – | User's primary goal |
| risk_profile | string | yes | User's risk tolerance |
No output schema declared.
No examples provided.
search ~71
Natural-language search across all ACCRUE vaults and portfolios. Use this for vague queries like "find me high-yield options", "show me lending strategies on Base", or "what aggressive options are there". Returns matching vaults and portfolios with live data.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Free-form search query |
No output schema declared.
No examples provided.
search_vaults ~165
Filter ACCRUE vaults by chain, risk tier, protocol, and/or minimum APY. Returns the matching vaults with live APY data. Use this when the user wants to narrow down by criteria like "Base vaults only", "highest yield on Arbitrum", or "show me conservative options above 4%".
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | – | Filter to a specific chain |
| min_apy_pct | number | – | Minimum effective APY in percent (e.g. 4 for 4%). |
| protocol | string | – | Filter by protocol substring, e.g. "Aave", "Compound", "Morpho", "Steakhouse", "Gauntlet" |
| risk_tier | string | – | Filter to a risk tier |
No output schema declared.
No examples provided.
submit_user_operation ~152
Final step of the sponsored and USDC-gas paths. Pass user_operation from build_user_operation and your signature over its typed data (or hash). ACCRUE checks that the operation is an ACCRUE deposit or withdrawal for this account, paid either by ACCRUE's gas sponsorship or through Circle's paymaster in USDC, and that you signed it — then relays it to the bundler. Returns user_op_hash; follow up with get_transaction_status. ACCRUE cannot alter a signed operation.
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | yes | – |
| signature | string | yes | 65-byte hex signature over sign.user_operation. |
| user_operation | object | yes | user_operation from build_user_operation, unchanged. |
No output schema declared.
No examples provided.
What is the cc.accrue/mcp server?
cc.accrue/mcp is listed in the public MCP registry as cc.accrue/mcp. Stablecoin Yield Index (SYX) and live USDC vault APYs across Ethereum, Base, Arbitrum. This page covers its hosted endpoint (https://accrue.cc/mcp).
Is the cc.accrue/mcp server safe to use?
cc.accrue/mcp scores 84 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the cc.accrue/mcp server expose?
cc.accrue/mcp exposes 20 tools: get_syx_value, get_syx_methodology, get_syx_components, get_syx_history, list_vaults, and 15 more. Their descriptions and schemas cost roughly 2,819 tokens of context every time the server is loaded.
Does the cc.accrue/mcp server require authentication?
No. We connected to cc.accrue/mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the cc.accrue/mcp server still maintained?
cc.accrue/mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.