# Cofferline (remote · mcp.cofferline.com)

Treasury and risk controls for agent wallets: policies, quotes, prediction-market orders.

- Trust score: 72/100 (medium)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-27

## Components

- remote · `mcp.cofferline.com`: 72/100 (this document), [markdown](https://verifymcp.io/servers/com-cofferline-treasury/mcp.md), [page](https://verifymcp.io/servers/com-cofferline-treasury/mcp)

## Channel facts

- Endpoint: `https://mcp.cofferline.com`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-27.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 47 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 81/100
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 3633 tokens (~77/item across 47 items; 47 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 100/100
  - No destabilizing schema changes in the last 30 days.
- **Tool Coverage**: 99/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 96% of tool parameters carry a description.
- **Tool Safety**: 75/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 0 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "revoke_delegation" implies "revoke" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 48 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the Cofferline MCP server?

Cofferline is a hosted endpoint at https://mcp.cofferline.com/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-cofferline-treasury 'https://mcp.cofferline.com/'
```

### Cursor

```json
{
  "mcpServers": {
    "com-cofferline-treasury": {
      "url": "https://mcp.cofferline.com/"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-cofferline-treasury": {
      "type": "http",
      "url": "https://mcp.cofferline.com/"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-cofferline-treasury]
url = "https://mcp.cofferline.com/"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-cofferline-treasury": {
      "type": "remote",
      "url": "https://mcp.cofferline.com/",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-cofferline-treasury --url 'https://mcp.cofferline.com/' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-cofferline-treasury:
    url: "https://mcp.cofferline.com/"
```

### Netclaw

```json
{
  "McpServers": {
    "com-cofferline-treasury": {
      "Transport": "http",
      "Url": "https://mcp.cofferline.com/"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-cofferline-treasury -t streamable-http -u 'https://mcp.cofferline.com/'
```

### Other

```json
{
  "mcpServers": {
    "com-cofferline-treasury": {
      "type": "http",
      "url": "https://mcp.cofferline.com/"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-25 (score 72, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-19 (score 72, +1)

- [security] Stability: 0.97 → pass

### 2026-09-17 (score 71, +1)

No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-12 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-10 (score 68, +1)

No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-08 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-06 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (47)

### `get_quotes` (~87 tokens)

Live venue quote comparison for a token conversion (CoW + ParaSwap on Base). Free, no auth.

Input parameters:

- `buy_token` (string, required): ERC-20 address being bought
- `chain_id` (number): 8453 (Base)
- `sell_amount` (string, required): sell amount in base units, decimal string
- `sell_token` (string, required): ERC-20 address being sold

### `get_benchmarks` (~36 tokens)

Measured execution benchmarks: median savings vs arrival quote by USD size bucket, from real completed intents only. Free, no auth.

### `screen_address` (~36 tokens)

OFAC SDN counterparty screening for an address. Free, no auth.

Input parameters:

- `address` (string, required): EVM address to screen

### `list_tokens` (~49 tokens)

Tokens the platform accepts on an intent, per chain — what create_intent will admit. Free, no auth.

Input parameters:

- `chain_id` (number): limit to one chain; omit for every supported chain

### `list_feedback` (~31 tokens)

Every feature request ever submitted, public and unauthenticated. Free.

Input parameters:

- `limit` (number): max results

### `submit_feedback` (~169 tokens)

Submit a feature request ($1 anti-spam fee, charged to the prepaid balance when funded). Auth required. Payment flow: call once without x_payment — a 402 reply lists the exact EIP-3009 requirements (amount, USDC asset, recipient, EIP-712 domain). Sign a transferWithAuthorization for them outside MCP (this server cannot sign), then call again with x_payment set to the base64 of {x402Version:1, scheme:'exact', network, payload:{signature, authorization}}.

Input parameters:

- `body` (string, required): the request, 20-4000 chars
- `title` (string, required): short title, 8-120 chars
- `x_payment` (string): base64 X-PAYMENT value from a previously answered 402 (see description)

### `start_siwe_login` (~70 tokens)

Start wallet sign-in: returns a single-use SIWE message. Sign it with the wallet outside MCP (this server cannot sign), then call complete_siwe_login. Free, no auth.

Input parameters:

- `address` (string, required): wallet address to authenticate
- `chain_id` (number): 8453

### `complete_siwe_login` (~82 tokens)

Finish wallet sign-in: exchanges the signed SIWE message for a cl_sess_… session token — use it as the Authorization bearer on every authenticated tool. Free, no auth.

Input parameters:

- `message` (string, required): the exact SIWE message from start_siwe_login
- `signature` (string, required): the wallet's signature over the message, 0x…

### `get_me` (~22 tokens)

Identify the authenticated account: address, kind, scopes. Auth required.

### `export_account` (~22 tokens)

Export all of this account's data in one document. Auth required.

### `offboard_account` (~81 tokens)

Close this account for good: revokes every credential, scrubs personal data, retires the account. Irreversible; confirm_wallet_address must be the account's own wallet address, typed exactly. Auth required.

Input parameters:

- `confirm_wallet_address` (string, required): the account's wallet address, typed to confirm
- `reason` (string): optional reason, recorded

### `put_policy` (~111 tokens)

Create or update the wallet's treasury policy (immutable versioning; PUT creates the next version). Auth required. Body must match /schemas/policy-v1.json — only version, wallet and chain_id are required; omitted fields take the platform defaults published in the manifest and are stored into the document, and the response lists them in `defaulted`.

Input parameters:

- `policy` (object, required): PolicyV1 document; {"version":1,"wallet":"0x…","chain_id":8453} is a complete one

### `get_policy` (~43 tokens)

List policy versions, newest first (the first entry is active). Auth required.

Input parameters:

- `limit` (number): max results
- `wallet` (string): optional wallet filter

### `check_spend` (~84 tokens)

Pre-flight policy check: would this spend be allowed under the wallet's policy right now? Auth required.

Input parameters:

- `amount_usd` (string, required): spend amount in USD, decimal string
- `counterparty` (string): optional counterparty address to screen
- `token` (string, required): token symbol, e.g. USDC
- `wallet` (string, required): wallet address

### `check_pm_order` (~101 tokens)

Pre-flight policy check for a prediction-market order: would this cost be allowed right now? Auth required.

Input parameters:

- `condition_id` (string, required): market/condition identifier
- `cost_usd` (string, required): order cost in USD, decimal string
- `state` (object): optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings
- `wallet` (string, required): wallet address

### `poll_events` (~81 tokens)

Poll typed treasury events with a monotonic cursor (intent lifecycle, budget thresholds, reconciliation, security alerts). Auth required.

Input parameters:

- `cursor` (number): resume after this event id
- `limit` (number): max results
- `type` (string): optional event-type filter, e.g. intent.filled
- `wallet` (string): optional wallet filter

### `get_statement` (~66 tokens)

Deterministic monthly statement derived from the append-only ledger — same period, same bytes. Auth required.

Input parameters:

- `format` (string): 'json' (default) or 'csv'
- `period` (string, required): calendar month, YYYY-MM
- `wallet` (string, required): wallet address

### `create_intent` (~116 tokens)

Create a conversion or gas_topup intent; the executor pipeline plans and fills it under policy. Auth required.

Input parameters:

- `buy_token` (string, required): ERC-20 address being bought
- `kind` (string, required)
- `max_slippage_bps` (number): optional per-intent slippage cap
- `sell_amount` (string, required): base units, decimal string
- `sell_token` (string, required): ERC-20 address being sold
- `venues` (array): optional venue override
- `wallet` (string, required): wallet address

### `get_intent` (~38 tokens)

Fetch an intent, including fills and the post-trade report once filled. Auth required.

Input parameters:

- `id` (string, required): intent id (uuid)

### `list_intents` (~47 tokens)

List intents, newest first. Auth required.

Input parameters:

- `limit` (number): max results
- `offset` (number): skip this many
- `wallet` (string): optional wallet filter

### `cancel_intent` (~37 tokens)

Cancel a planned intent (a few-second window before execution claims it). Auth required.

Input parameters:

- `id` (string, required): intent id (uuid)

### `prepare_delegation` (~185 tokens)

Prepare a scoped session-key grant for a Kernel smart account: exact call allowlist, expiry, optional rate limit. Returns the ONE EIP-712 digest the account owner signs outside MCP (this server cannot sign) — then call confirm_delegation with the signature. Auth required.

Input parameters:

- `account` (string, required): the Kernel smart account granting scope
- `calls` (array, required): allowed calls: each {target: contract address, selector: 0x + 4 bytes, value_limit: max native value in wei as decimal string}
- `chain_id` (number, required): 8453 (Base) or 84532 (Base Sepolia)
- `rate_limit` (object): optional {count, interval_secs}: max delegated calls per interval
- `valid_after` (number): optional start, unix seconds
- `valid_until` (number, required): expiry, unix seconds

### `confirm_delegation` (~75 tokens)

Activate a prepared delegation by supplying the owner's signature over its enable digest. Auth required.

Input parameters:

- `enable_sig` (string, required): owner's 65-byte signature over the digest, 0x…
- `id` (string, required): delegation id (uuid)
- `owner` (string): optional owner address, when it differs from the caller

### `renew_delegation` (~74 tokens)

Renew an active delegation: same scope, fresh expiry, no authority gap. Returns a NEW digest to sign and confirm exactly like prepare_delegation. Auth required.

Input parameters:

- `id` (string, required): delegation id (uuid)
- `valid_until` (number): optional new expiry, unix seconds; defaults to the original duration

### `revoke_delegation` (~44 tokens)

Revoke a delegation. The reply includes calldata the owner can send on-chain for hard finality. Auth required.

Input parameters:

- `id` (string, required): delegation id (uuid)

### `get_delegation` (~28 tokens)

Fetch one delegation. Auth required.

Input parameters:

- `id` (string, required): delegation id (uuid)

### `list_delegations` (~40 tokens)

List delegations, newest first. Auth required.

Input parameters:

- `account` (string): optional smart-account filter
- `limit` (number): max results

### `panic` (~54 tokens)

Emergency stop, one call: suspends the account, revokes every API key, session, delegation and venue credential, and returns all unwind calldata for the owner. Auth required.

Input parameters:

- `reason` (string): optional reason, recorded

### `get_balance` (~23 tokens)

Prepaid fee balance: settled credits minus fee debits. Auth required.

### `topup_balance` (~146 tokens)

Top up the prepaid balance with USDC. Auth required. Payment flow: call once without x_payment — a 402 reply lists the exact EIP-3009 requirements (amount, USDC asset, recipient, EIP-712 domain). Sign a transferWithAuthorization for them outside MCP (this server cannot sign), then call again with x_payment set to the base64 of {x402Version:1, scheme:'exact', network, payload:{signature, authorization}}.

Input parameters:

- `amount_usd` (string, required): top-up amount in USD, decimal string
- `x_payment` (string): base64 X-PAYMENT value from a previously answered 402 (see description)

### `set_auto_topup` (~129 tokens)

Configure auto-topup: when the prepaid balance falls below threshold_usd, the platform settles one of the pre-signed EIP-3009 authorizations you supply (signed outside MCP — this server cannot sign). Auth required.

Input parameters:

- `authorizations` (array, required): pre-signed transferWithAuthorization payloads: each {from, to, value, valid_after, valid_before, nonce, signature}
- `max_per_month` (number): cap on automatic top-ups per month (default 10)
- `threshold_usd` (string, required): refill when balance drops below this, USD decimal string

### `get_auto_topup` (~28 tokens)

The auto-topup rule and how many pre-signed authorizations remain. Auth required.

### `remove_auto_topup` (~25 tokens)

Remove the auto-topup rule and its unused authorizations. Auth required.

### `store_pm_credential` (~239 tokens)

Store a prediction-market venue credential (verified live against the venue, sealed at rest, material never returned). Polymarket, either shape: signer_private_key + maker (derives API creds), or api_key + secret + passphrase + maker + signer. Auth required.

Input parameters:

- `api_key` (string): Polymarket: CLOB API key (explicit-creds shape)
- `label` (string): optional display label
- `maker` (string): Polymarket: funder (maker) address
- `passphrase` (string): Polymarket: CLOB API passphrase (explicit-creds shape)
- `secret` (string): Polymarket: CLOB API secret (explicit-creds shape)
- `signature_type` (number): Polymarket: 0 EOA, 1 Magic/email, 2 browser proxy (default 1)
- `signer` (string): Polymarket: signer address (explicit-creds shape)
- `signer_private_key` (string): Polymarket: signer EOA private key, 0x…
- `venue` (string): prediction-market venue (default polymarket)

### `list_pm_credentials` (~23 tokens)

List stored venue credentials — metadata only, never material. Auth required.

### `revoke_pm_credential` (~36 tokens)

Revoke a venue credential; its sealed ciphertext is destroyed. Auth required.

Input parameters:

- `id` (string, required): credential id (uuid)

### `get_pm_signer_rotation` (~68 tokens)

Calldata to swap the Polymarket funder Safe's owner to a new EOA — the owner executes it outside MCP (this server cannot sign). Auth required.

Input parameters:

- `id` (string, required): credential id (uuid)
- `new_owner` (string, required): the replacement owner address

### `create_pm_order` (~223 tokens)

Place a prediction-market limit order under policy, signed server-side with the stored credential. Polymarket: condition_id, token_id, action, price_usd (e.g. '0.55'), size_shares. Auth required.

Input parameters:

- `action` (string, required)
- `client_order_id` (string): optional idempotency uuid
- `condition_id` (string): Polymarket: market condition id
- `credential_id` (string, required): stored credential id (uuid)
- `price_usd` (string): Polymarket: limit price, '0.xx'
- `size_shares` (string): Polymarket: share count, decimal string
- `state` (object): optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings
- `token_id` (string): Polymarket: outcome token id, decimal string
- `venue` (string): prediction-market venue (default polymarket)
- `wallet` (string, required): treasury wallet whose policy governs the order

### `list_pm_orders` (~51 tokens)

The credential's resting orders straight from the venue — recover state after a disconnect. Auth required.

Input parameters:

- `credential_id` (string, required): stored credential id (uuid)
- `market` (string): optional market filter

### `cancel_pm_order` (~59 tokens)

Cancel one resting prediction-market order. Auth required.

Input parameters:

- `credential_id` (string, required): stored credential id (uuid)
- `order_id` (string, required): the venue's order id
- `venue` (string): prediction-market venue (default polymarket)

### `cancel_all_pm_orders` (~49 tokens)

Cancel every resting order for the credential, optionally within one market. Auth required.

Input parameters:

- `credential_id` (string, required): stored credential id (uuid)
- `market` (string): optional market filter

### `prepare_pm_order` (~200 tokens)

Prepare a client-signed Polymarket order: policy-checked, then returns the exact EIP-712 payload to sign outside MCP (this server cannot sign) plus a prepare_id — submit both via submit_pm_order. Auth required.

Input parameters:

- `action` (string, required)
- `client_order_id` (string): optional idempotency uuid
- `condition_id` (string, required): market condition id
- `credential_id` (string, required): stored credential id (uuid)
- `price_usd` (string, required): limit price, '0.xx'
- `size_shares` (string, required): share count, decimal string
- `state` (object): optional current exposure: {market_exposure_usd, realized_loss_today_usd, total_open_exposure_usd} as decimal strings
- `token_id` (string, required): outcome token id, decimal string
- `venue` (string, required)
- `wallet` (string, required): treasury wallet whose policy governs the order

### `submit_pm_order` (~72 tokens)

Submit a prepared Polymarket order with the maker's EIP-712 signature from prepare_pm_order. Auth required.

Input parameters:

- `prepare_id` (string, required): prepare id (uuid) from prepare_pm_order
- `signature` (string, required): the maker's 65-byte EIP-712 signature, 0x…

### `get_pm_onboarding` (~55 tokens)

Polymarket trade-readiness for an address: live approval status plus the calldata for anything missing (executed outside MCP — this server cannot sign). Auth required.

Input parameters:

- `address` (string, required): the trading address to check

### `resolve_pm_funder` (~39 tokens)

Resolve an owner EOA to its Polymarket funder Safe candidates. Auth required.

Input parameters:

- `owner` (string, required): owner EOA address

### `sync_pm_fills` (~62 tokens)

Pull the venue's fills for a credential into the wallet's ledger. Idempotent — safe to repeat. Auth required.

Input parameters:

- `credential_id` (string, required): stored credential id (uuid)
- `wallet` (string, required): treasury wallet whose books receive the fills

### `wrap_pm_usdc` (~81 tokens)

Wrap the funder Safe's USDC.e into Polymarket's pUSD, platform-relayed so the user pays no gas. Omit amount_base_units to wrap the full balance. Auth required.

Input parameters:

- `amount_base_units` (string): optional amount in base units, decimal string
- `credential_id` (string, required): stored credential id (uuid)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-cofferline-treasury/mcp#diagnostics

## Score history

- 2026-09-27: 72
- 2026-09-26: 72
- 2026-09-25: 72
- 2026-09-24: 72
- 2026-09-23: 72
- 2026-09-22: 72
- 2026-09-21: 72
- 2026-09-20: 72
- 2026-09-19: 72
- 2026-09-18: 71
- 2026-09-17: 71
- 2026-09-16: 70
- 2026-09-15: 70
- 2026-09-14: 69
- 2026-09-13: 69
- 2026-09-12: 69
- 2026-09-11: 68
- 2026-09-10: 68
- 2026-09-09: 67
- 2026-09-08: 67
- 2026-09-07: 66
- 2026-09-06: 66
- 2026-09-05: 65
- 2026-09-04: 65
- 2026-09-03: 64
- 2026-09-02: 64
- 2026-09-01: 63
- 2026-08-31: 63
- 2026-08-30: 62
- 2026-08-29: 62

## Common questions

### What is the Cofferline MCP server?

Cofferline is an MCP server listed in the public MCP registry as com.cofferline/treasury. Treasury and risk controls for agent wallets: policies, quotes, prediction-market orders. This page covers its hosted endpoint (https://mcp.cofferline.com).

### Is the Cofferline MCP server safe to use?

Cofferline scores 72 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Cofferline MCP server expose?

Cofferline exposes 47 tools: get_quotes, get_benchmarks, screen_address, list_tokens, list_feedback, and 42 more. Their descriptions and schemas cost roughly 3,517 tokens of context every time the server is loaded.

### Does the Cofferline MCP server require authentication?

No. We connected to Cofferline without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Cofferline MCP server still maintained?

Cofferline is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.cofferline.com/
- Website: https://cofferline.com/docs
- Changelog RSS feed: https://verifymcp.io/servers/com-cofferline-treasury/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-cofferline-treasury/mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-cofferline-treasury/mcp
