Cofferline
REMOTE · MCP.COFFERLINE.COM · SCANNED SEP 27
Treasury and risk controls for agent wallets: policies, quotes, prediction-market orders.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 47 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability81
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 3633 tokens (~77/item across 47 items; 47 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 96% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "revoke_delegation" implies "revoke" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 48 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the Cofferline MCP server?
Cofferline is a hosted endpoint at https://mcp.cofferline.com/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.cofferline.com
claude mcp add --transport http com-cofferline-treasury 'https://mcp.cofferline.com/'
{
"mcpServers": {
"com-cofferline-treasury": {
"url": "https://mcp.cofferline.com/"
}
}
} {
"servers": {
"com-cofferline-treasury": {
"type": "http",
"url": "https://mcp.cofferline.com/"
}
}
} [mcp_servers.com-cofferline-treasury] url = "https://mcp.cofferline.com/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-cofferline-treasury": {
"type": "remote",
"url": "https://mcp.cofferline.com/",
"enabled": true
}
}
} openclaw mcp add com-cofferline-treasury --url 'https://mcp.cofferline.com/' --transport streamable-http
mcp_servers:
com-cofferline-treasury:
url: "https://mcp.cofferline.com/" {
"McpServers": {
"com-cofferline-treasury": {
"Transport": "http",
"Url": "https://mcp.cofferline.com/"
}
}
} assistant mcp add com-cofferline-treasury -t streamable-http -u 'https://mcp.cofferline.com/'
{
"mcpServers": {
"com-cofferline-treasury": {
"type": "http",
"url": "https://mcp.cofferline.com/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 19 Sept 26 +1
- Stability: 0.97 → pass security
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
- 8 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Probed https://mcp.cofferline.com
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=cofferline.com | CN=WE1,O=Google Trust Services,C=US | 10 Aug 2026 | 8 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | ee741b6ecec50d04130d12f860f57ebd |
| SANs: cofferline.com, mcp.cofferline.com, *.mcp.cofferline.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.cofferline.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| cofferline.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.cofferline.com | Verified | 200 | |
| http (plaintext) | http://mcp.cofferline.com | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
cancel_all_pm_orders ~49
Cancel every resting order for the credential, optionally within one market. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| credential_id | string | yes | stored credential id (uuid) |
| market | string | – | optional market filter |
No output schema declared.
No examples provided.
cancel_intent ~37
Cancel a planned intent (a few-second window before execution claims it). Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | intent id (uuid) |
No output schema declared.
No examples provided.
cancel_pm_order ~59
Cancel one resting prediction-market order. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| credential_id | string | yes | stored credential id (uuid) |
| order_id | string | yes | the venue's order id |
| venue | string | – | prediction-market venue (default polymarket) |
No output schema declared.
No examples provided.
check_pm_order ~101
Pre-flight policy check for a prediction-market order: would this cost be allowed right now? Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| condition_id | string | yes | market/condition identifier |
| cost_usd | string | yes | order cost in USD, decimal string |
| state | object | – | optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings |
| wallet | string | yes | wallet address |
No output schema declared.
No examples provided.
check_spend ~84
Pre-flight policy check: would this spend be allowed under the wallet's policy right now? Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_usd | string | yes | spend amount in USD, decimal string |
| counterparty | string | – | optional counterparty address to screen |
| token | string | yes | token symbol, e.g. USDC |
| wallet | string | yes | wallet address |
No output schema declared.
No examples provided.
complete_siwe_login ~82
Finish wallet sign-in: exchanges the signed SIWE message for a cl_sess_… session token — use it as the Authorization bearer on every authenticated tool. Free, no auth.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | yes | the exact SIWE message from start_siwe_login |
| signature | string | yes | the wallet's signature over the message, 0x… |
No output schema declared.
No examples provided.
confirm_delegation ~75
Activate a prepared delegation by supplying the owner's signature over its enable digest. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| enable_sig | string | yes | owner's 65-byte signature over the digest, 0x… |
| id | string | yes | delegation id (uuid) |
| owner | string | – | optional owner address, when it differs from the caller |
No output schema declared.
No examples provided.
create_intent ~116
Create a conversion or gas_topup intent; the executor pipeline plans and fills it under policy. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| buy_token | string | yes | ERC-20 address being bought |
| kind | string | yes | – |
| max_slippage_bps | number | – | optional per-intent slippage cap |
| sell_amount | string | yes | base units, decimal string |
| sell_token | string | yes | ERC-20 address being sold |
| venues | array | – | optional venue override |
| wallet | string | yes | wallet address |
No output schema declared.
No examples provided.
create_pm_order ~223
Place a prediction-market limit order under policy, signed server-side with the stored credential. Polymarket: condition_id, token_id, action, price_usd (e.g. '0.55'), size_shares. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| client_order_id | string | – | optional idempotency uuid |
| condition_id | string | – | Polymarket: market condition id |
| credential_id | string | yes | stored credential id (uuid) |
| price_usd | string | – | Polymarket: limit price, '0.xx' |
| size_shares | string | – | Polymarket: share count, decimal string |
| state | object | – | optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings |
| token_id | string | – | Polymarket: outcome token id, decimal string |
| venue | string | – | prediction-market venue (default polymarket) |
| wallet | string | yes | treasury wallet whose policy governs the order |
No output schema declared.
No examples provided.
export_account ~22
Export all of this account's data in one document. Auth required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_auto_topup ~28
The auto-topup rule and how many pre-signed authorizations remain. Auth required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_balance ~23
Prepaid fee balance: settled credits minus fee debits. Auth required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_benchmarks ~36
Measured execution benchmarks: median savings vs arrival quote by USD size bucket, from real completed intents only. Free, no auth.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_delegation ~28
Fetch one delegation. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | delegation id (uuid) |
No output schema declared.
No examples provided.
get_intent ~38
Fetch an intent, including fills and the post-trade report once filled. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | intent id (uuid) |
No output schema declared.
No examples provided.
get_me ~22
Identify the authenticated account: address, kind, scopes. Auth required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_pm_onboarding ~55
Polymarket trade-readiness for an address: live approval status plus the calldata for anything missing (executed outside MCP — this server cannot sign). Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | the trading address to check |
No output schema declared.
No examples provided.
get_pm_signer_rotation ~68
Calldata to swap the Polymarket funder Safe's owner to a new EOA — the owner executes it outside MCP (this server cannot sign). Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | credential id (uuid) |
| new_owner | string | yes | the replacement owner address |
No output schema declared.
No examples provided.
get_policy ~43
List policy versions, newest first (the first entry is active). Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | max results |
| wallet | string | – | optional wallet filter |
No output schema declared.
No examples provided.
get_quotes ~87
Live venue quote comparison for a token conversion (CoW + ParaSwap on Base). Free, no auth.
| Name | Type | Req | Description |
|---|---|---|---|
| buy_token | string | yes | ERC-20 address being bought |
| chain_id | number | – | 8453 (Base) |
| sell_amount | string | yes | sell amount in base units, decimal string |
| sell_token | string | yes | ERC-20 address being sold |
No output schema declared.
No examples provided.
get_statement ~66
Deterministic monthly statement derived from the append-only ledger — same period, same bytes. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | 'json' (default) or 'csv' |
| period | string | yes | calendar month, YYYY-MM |
| wallet | string | yes | wallet address |
No output schema declared.
No examples provided.
list_delegations ~40
List delegations, newest first. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | optional smart-account filter |
| limit | number | – | max results |
No output schema declared.
No examples provided.
list_feedback ~31
Every feature request ever submitted, public and unauthenticated. Free.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | max results |
No output schema declared.
No examples provided.
list_intents ~47
List intents, newest first. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | max results |
| offset | number | – | skip this many |
| wallet | string | – | optional wallet filter |
No output schema declared.
No examples provided.
list_pm_credentials ~23
List stored venue credentials — metadata only, never material. Auth required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_pm_orders ~51
The credential's resting orders straight from the venue — recover state after a disconnect. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| credential_id | string | yes | stored credential id (uuid) |
| market | string | – | optional market filter |
No output schema declared.
No examples provided.
list_tokens ~49
Tokens the platform accepts on an intent, per chain — what create_intent will admit. Free, no auth.
| Name | Type | Req | Description |
|---|---|---|---|
| chain_id | number | – | limit to one chain; omit for every supported chain |
No output schema declared.
No examples provided.
offboard_account ~81
Close this account for good: revokes every credential, scrubs personal data, retires the account. Irreversible; confirm_wallet_address must be the account's own wallet address, typed exactly. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm_wallet_address | string | yes | the account's wallet address, typed to confirm |
| reason | string | – | optional reason, recorded |
No output schema declared.
No examples provided.
panic ~54
Emergency stop, one call: suspends the account, revokes every API key, session, delegation and venue credential, and returns all unwind calldata for the owner. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | optional reason, recorded |
No output schema declared.
No examples provided.
poll_events ~81
Poll typed treasury events with a monotonic cursor (intent lifecycle, budget thresholds, reconciliation, security alerts). Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | number | – | resume after this event id |
| limit | number | – | max results |
| type | string | – | optional event-type filter, e.g. intent.filled |
| wallet | string | – | optional wallet filter |
No output schema declared.
No examples provided.
prepare_delegation ~185
Prepare a scoped session-key grant for a Kernel smart account: exact call allowlist, expiry, optional rate limit. Returns the ONE EIP-712 digest the account owner signs outside MCP (this server cannot sign) — then call confirm_delegation with the signature. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | yes | the Kernel smart account granting scope |
| calls | array | yes | allowed calls: each {target: contract address, selector: 0x + 4 bytes, value_limit: max native value in wei as decimal string} |
| chain_id | number | yes | 8453 (Base) or 84532 (Base Sepolia) |
| rate_limit | object | – | optional {count, interval_secs}: max delegated calls per interval |
| valid_after | number | – | optional start, unix seconds |
| valid_until | number | yes | expiry, unix seconds |
No output schema declared.
No examples provided.
prepare_pm_order ~200
Prepare a client-signed Polymarket order: policy-checked, then returns the exact EIP-712 payload to sign outside MCP (this server cannot sign) plus a prepare_id — submit both via submit_pm_order. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| client_order_id | string | – | optional idempotency uuid |
| condition_id | string | yes | market condition id |
| credential_id | string | yes | stored credential id (uuid) |
| price_usd | string | yes | limit price, '0.xx' |
| size_shares | string | yes | share count, decimal string |
| state | object | – | optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings |
| token_id | string | yes | outcome token id, decimal string |
| venue | string | yes | – |
| wallet | string | yes | treasury wallet whose policy governs the order |
No output schema declared.
No examples provided.
put_policy ~111
Create or update the wallet's treasury policy (immutable versioning; PUT creates the next version). Auth required. Body must match /schemas/policy-v1.json — only version, wallet and chain_id are required; omitted fields take the platform defaults published in the manifest and are stored into the document, and the response lists them in `defaulted`.
| Name | Type | Req | Description |
|---|---|---|---|
| policy | object | yes | PolicyV1 document; {"version":1,"wallet":"0x…","chain_id":8453} is a complete one |
No output schema declared.
No examples provided.
remove_auto_topup ~25
Remove the auto-topup rule and its unused authorizations. Auth required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
renew_delegation ~74
Renew an active delegation: same scope, fresh expiry, no authority gap. Returns a NEW digest to sign and confirm exactly like prepare_delegation. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | delegation id (uuid) |
| valid_until | number | – | optional new expiry, unix seconds; defaults to the original duration |
No output schema declared.
No examples provided.
resolve_pm_funder ~39
Resolve an owner EOA to its Polymarket funder Safe candidates. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| owner | string | yes | owner EOA address |
No output schema declared.
No examples provided.
revoke_delegation ~44
Revoke a delegation. The reply includes calldata the owner can send on-chain for hard finality. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | delegation id (uuid) |
No output schema declared.
No examples provided.
revoke_pm_credential ~36
Revoke a venue credential; its sealed ciphertext is destroyed. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | credential id (uuid) |
No output schema declared.
No examples provided.
screen_address ~36
OFAC SDN counterparty screening for an address. Free, no auth.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | EVM address to screen |
No output schema declared.
No examples provided.
set_auto_topup ~129
Configure auto-topup: when the prepaid balance falls below threshold_usd, the platform settles one of the pre-signed EIP-3009 authorizations you supply (signed outside MCP — this server cannot sign). Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| authorizations | array | yes | pre-signed transferWithAuthorization payloads: each {from, to, value, valid_after, valid_before, nonce, signature} |
| max_per_month | number | – | cap on automatic top-ups per month (default 10) |
| threshold_usd | string | yes | refill when balance drops below this, USD decimal string |
No output schema declared.
No examples provided.
start_siwe_login ~70
Start wallet sign-in: returns a single-use SIWE message. Sign it with the wallet outside MCP (this server cannot sign), then call complete_siwe_login. Free, no auth.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | wallet address to authenticate |
| chain_id | number | – | 8453 |
No output schema declared.
No examples provided.
store_pm_credential ~239
Store a prediction-market venue credential (verified live against the venue, sealed at rest, material never returned). Polymarket, either shape: signer_private_key + maker (derives API creds), or api_key + secret + passphrase + maker + signer. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | Polymarket: CLOB API key (explicit-creds shape) |
| label | string | – | optional display label |
| maker | string | – | Polymarket: funder (maker) address |
| passphrase | string | – | Polymarket: CLOB API passphrase (explicit-creds shape) |
| secret | string | – | Polymarket: CLOB API secret (explicit-creds shape) |
| signature_type | number | – | Polymarket: 0 EOA, 1 Magic/email, 2 browser proxy (default 1) |
| signer | string | – | Polymarket: signer address (explicit-creds shape) |
| signer_private_key | string | – | Polymarket: signer EOA private key, 0x… |
| venue | string | – | prediction-market venue (default polymarket) |
No output schema declared.
No examples provided.
submit_feedback ~169
Submit a feature request ($1 anti-spam fee, charged to the prepaid balance when funded). Auth required. Payment flow: call once without x_payment — a 402 reply lists the exact EIP-3009 requirements (amount, USDC asset, recipient, EIP-712 domain). Sign a transferWithAuthorization for them outside MCP (this server cannot sign), then call again with x_payment set to the base64 of {x402Version:1, scheme:'exact', network, payload:{signature, authorization}}.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | the request, 20-4000 chars |
| title | string | yes | short title, 8-120 chars |
| x_payment | string | – | base64 X-PAYMENT value from a previously answered 402 (see description) |
No output schema declared.
No examples provided.
submit_pm_order ~72
Submit a prepared Polymarket order with the maker's EIP-712 signature from prepare_pm_order. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| prepare_id | string | yes | prepare id (uuid) from prepare_pm_order |
| signature | string | yes | the maker's 65-byte EIP-712 signature, 0x… |
No output schema declared.
No examples provided.
sync_pm_fills ~62
Pull the venue's fills for a credential into the wallet's ledger. Idempotent — safe to repeat. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| credential_id | string | yes | stored credential id (uuid) |
| wallet | string | yes | treasury wallet whose books receive the fills |
No output schema declared.
No examples provided.
topup_balance ~146
Top up the prepaid balance with USDC. Auth required. Payment flow: call once without x_payment — a 402 reply lists the exact EIP-3009 requirements (amount, USDC asset, recipient, EIP-712 domain). Sign a transferWithAuthorization for them outside MCP (this server cannot sign), then call again with x_payment set to the base64 of {x402Version:1, scheme:'exact', network, payload:{signature, authorization}}.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_usd | string | yes | top-up amount in USD, decimal string |
| x_payment | string | – | base64 X-PAYMENT value from a previously answered 402 (see description) |
No output schema declared.
No examples provided.
wrap_pm_usdc ~81
Wrap the funder Safe's USDC.e into Polymarket's pUSD, platform-relayed so the user pays no gas. Omit amount_base_units to wrap the full balance. Auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_base_units | string | – | optional amount in base units, decimal string |
| credential_id | string | yes | stored credential id (uuid) |
No output schema declared.
No examples provided.
What is the Cofferline MCP server?
Cofferline is an MCP server listed in the public MCP registry as com.cofferline/treasury. Treasury and risk controls for agent wallets: policies, quotes, prediction-market orders. This page covers its hosted endpoint (https://mcp.cofferline.com).
Is the Cofferline MCP server safe to use?
Cofferline scores 72 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Cofferline MCP server expose?
Cofferline exposes 47 tools: get_quotes, get_benchmarks, screen_address, list_tokens, list_feedback, and 42 more. Their descriptions and schemas cost roughly 3,517 tokens of context every time the server is loaded.
Does the Cofferline MCP server require authentication?
No. We connected to Cofferline without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Cofferline MCP server still maintained?
Cofferline is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.