Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

arcgate

REMOTE · API.ARCGATE.DEV · SCANNED OCT 2

Token search, swap quotes and ready-to-sign swap transactions on Arc, paid per call via x402

Available components

54 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability56
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4129 tokens (~589/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management3
  • Stability observed for 1 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage68
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 4% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the arcgate MCP server?

arcgate is a hosted endpoint at https://api.arcgate.dev/trade/v1/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · api.arcgate.dev

# add to Claude Code
claude mcp add --transport http dev-arcgate-arcgate 'https://api.arcgate.dev/trade/v1/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "dev-arcgate-arcgate": {
      "url": "https://api.arcgate.dev/trade/v1/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "dev-arcgate-arcgate": {
      "type": "http",
      "url": "https://api.arcgate.dev/trade/v1/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.dev-arcgate-arcgate]
url = "https://api.arcgate.dev/trade/v1/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-arcgate-arcgate": {
      "type": "remote",
      "url": "https://api.arcgate.dev/trade/v1/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dev-arcgate-arcgate --url 'https://api.arcgate.dev/trade/v1/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  dev-arcgate-arcgate:
    url: "https://api.arcgate.dev/trade/v1/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "dev-arcgate-arcgate": {
      "Transport": "http",
      "Url": "https://api.arcgate.dev/trade/v1/mcp"
    }
  }
}
# add to Vellum
assistant mcp add dev-arcgate-arcgate -t streamable-http -u 'https://api.arcgate.dev/trade/v1/mcp'
// mcp.json
{
  "mcpServers": {
    "dev-arcgate-arcgate": {
      "type": "http",
      "url": "https://api.arcgate.dev/trade/v1/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 2 Oct 26 0
    • Stability: unverified → 0.03 ▲ functional
  • 1 Oct 26 54

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 2 Oct 2026 · Probed https://api.arcgate.dev/trade/v1/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=arcgate.dev CN=WE1,O=Google Trust Services,C=US 26 Sept 2026 25 Dec 2026 ECDSA 256 ECDSA-SHA256 517f4b9526cc19d113dcf8a845504336
SANs: arcgate.dev, *.arcgate.dev
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of api.arcgate.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
arcgate.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.arcgate.dev/trade/v1/mcp Verified 200
http (plaintext) http://api.arcgate.dev/trade/v1/mcp Served over HTTP 200
MCP tools · 7 exposed · ~4,129 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
health ~77

Reports whether the service is up, with its diagnostics. - **Cost:** free, never x402-gated. - **Returns:** DB import health, rule set version, the deployed commit, cache/RPC/spend counters and the payer-identity mode. - **Next:** call before search/quote/swap to check the service is up.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

tradeQuote ~951

Prices a swap between `sell` and `buy` across the indexed venues and stores it under a `quoteId`. - **Cost:** 0.01 USDC per call over x402: the first call gets a 402 with payment requirements in the `PAYMENT-REQUIRED` header (base64 JSON); sign them and retry with a `PAYMENT-SIGNATURE` header carrying the payment payload. - **`sell` / `buy`:** two different assets (native and ERC-20 USDC count as the same asset; either side may be USDC). Resolve a ticker with POST /trade/v1/search first. - **Response shape:** when one side is USDC, `best.type` is `direct`/`two_hop`/`split` and `best.legs` lists one leg per path actually used; `routes[]` lists every discovery candidate. When neither side is USDC, or when a USDC-side allocation can't be expressed as legs, `best.type` is `graph`, `best.legs` is empty, and the execution plan is in `best.graph`. Both shapes support `side: exactIn` and `exactOut`, and both execute the same way through POST /trade/v1/swap. - **`amount`:** a human-readable decimal string in the token's own units, e.g. "1.5" for 1.5 USDC, not base units. It is the `sell` amount for `side: exactIn` and the `buy` amount for `side: exactOut`. - **Optional:** `side` (exactIn/exactOut), `slippageBps`, split and hop limits, `venues`/`excludeVenues` (ids from GET /trade/v1/venues), `taker`, `ttlSec`. - **Executability:** POST /trade/v1/swap executes every quote through ArcgateRouter. `best.executable` is `false`, with warning `graph_execution_unavailable`, when no ArcgateRouter is configured (or, for an Aerodrome edge, no Aerodrome router), or when the operator has disabled a selected path's venue - even with both routers configured. In that last case, POST /trade/v1/swap may still fall back to an executable candidate the quote already priced instead of failing outright. - **Readiness:** name the wallet that will trade in `taker` and the answer carries `readiness`, read at the quote's block: whether that wallet holds the input (`balance`), which approval or Permi…

NameTypeReqDescription
allowSplitsboolean––
amountstringyes–
buystringyes–
excludeVenuesarray––
maxHops–––
maxSplitsinteger––
sellstringyes–
sidestring––
slippageBpsinteger––
sourcesarray––
taker–––
ttlSecinteger–How long the stored quote (and this response's expiresAt) stays live, in seconds (1-120, default 120). A caller may shorten it to re-quote sooner; it can never lengthen past 120s. Safe to shorten or…
venues–––

No output schema declared.

No examples provided.

tradeReceipt ~601

Tells you whether the transactions POST /trade/v1/swap returned did what the quote promised, once you've sent them. It only reads the chain. - **Cost:** free, never x402-gated. - **Key inputs:** `quoteId` (the one you called POST /trade/v1/swap with) and `txHashes`, the 1 to 4 transactions you sent for it: the swap, and any approvals. It answers for a quote /trade/v1/swap handed transactions for in the last hour, else 404 `swap_not_found`, and only for that quote's transactions, sent from its `taker`: an approval to the input token, or a swap to ArcgateRouter whose deadline one of the quote's /trade/v1/swap or /trade/v1/swap/tx answers issued and whose output goes to its `recipient`, else 400 `invalid_request`. - **Smart-contract wallets:** a Safe, an ERC-4337 account or a batching EIP-7702 wallet sends its transaction from an executor or bundler, or to itself, not from the taker to ArcgateRouter, so this answers 400 `invalid_request` for it. Check that transaction's own receipt and your wallet's success event instead. - **Returns:** `result`, from the swap transactions. One that filled decides it: `pass` when `delivered` is at least `minAmountOut`, else `fail` (a round 1 that reverted doesn't undo a round 2 that filled). With none filled: `pending` while one is not mined yet, else `fail`: it reverted or was never mined by 60s after its deadline (status `expired`, or `not_found` when the chain never saw it). Approvals are listed but don't change the result. `delivered` is what `recipient` received of `token` (the output), read from the swap transaction's Transfer logs, in base units. Also `block`, each transaction's `status`, and `reason`, one sentence on a fail or pending. The first result from a mined swap is final: asking again returns it. - **Limits:** one chain read per quote every 5s (the same `txHashes` inside that get the last answer; other hashes get 429 `receipt_rate_limited` with `retryAfterSec`), and at most 132 per quote (then 429 `receipt_reads_exhau…

NameTypeReqDescription
quoteIdstringyes–
txHashesarrayyes–

No output schema declared.

No examples provided.

tradeSearch ~235

Resolves a ticker, name, prefix or `0x` address to candidate ERC-20 tokens on Arc. - **Cost:** 0.005 USDC per call over x402: the first call gets a 402 with payment requirements in the `PAYMENT-REQUIRED` header (base64 JSON); sign them and retry with a `PAYMENT-SIGNATURE` header carrying the payment payload. - **Key inputs:** `query` (required), `limit` (1-25, default 10). - **Returns:** each match with its verification status, safety verdicts and USDC/hub pools, most relevant first. - **Next:** pass the chosen result's `address` as `sell` or `buy` to POST /trade/v1/quote. Costs 5000 base units (0.005 USDC) per call. Payment goes in params._meta["x402/payment"]; use an x402-aware MCP client (see https://docs.arcgate.dev/#arcgate/description/mcp-for-agents).

NameTypeReqDescription
limitinteger––
querystringyes–

No output schema declared.

No examples provided.

tradeSwap ~1,440

Turns a stored quote into unsigned transactions for the taker to sign and send. arcgate never signs, broadcasts or holds funds. - **Cost:** 0.01 USDC under $1,000; 0.05 USDC from $1,000 to $10,000; above that 0.05 USDC plus 0.5 bps of the amount over $10,000, capped at 5 USDC, size-tiered by the quote's USD notional (the USDC side for a USDC pair, or a token-to-token quote's USD valuation; a quote with no valuation prices at tier 1), over x402 (402 with `PAYMENT-REQUIRED`, retry with `PAYMENT-SIGNATURE`). Charged once per quote: POST /trade/v1/swap/tx, the Permit2 second round below, is free. - **Key inputs:** `quoteId` (from POST /trade/v1/quote), `taker`; optional `recipient` (defaults to `taker`), `deadlineSec`, `approval`. Never `permit` - that belongs to POST /trade/v1/swap/tx; sending one here is 400 `invalid_request` (the strict schema rejects the unknown key). - **Every quote executes through ArcgateRouter:** it is always the Permit2 `spender` and the ERC-20 `approve` spender below. When every source pool of the route being executed trades native USDC, the swap is funded by `value` instead - no approval transaction and no signature at all. - **Permit2 (default, one or two calls):** - Returns `transactions` - an unlimited ERC-20 `approve(Permit2, type(uint256).max)` first, if the token's ERC-20 allowance to Permit2 is below the amount, then the swap, which carries an empty Permit2 signature and is only directly sendable as-is when a Permit2 allowance to ArcgateRouter already covers the amount, in which case `signatures` is empty too. Otherwise it also returns `signatures: [{ kind: "permit2", typedData }]`; sign `typedData` with the taker's key (EIP-712, e.g. viem's `signTypedData`). - **Sign, then call POST /trade/v1/swap/tx** with the same `quoteId`, `taker` and `recipient`, and `permit: { message: typedData.message, signature }`, while the quote is live: free, because this call already paid the swap fee. The first call to it that succeeds uses the rou…

NameTypeReqDescription
approvalstring––
deadlineSecinteger––
quoteIdstringyes–
recipient–––
takerstringyes–

No output schema declared.

No examples provided.

tradeSwapTx ~745

The free Permit2 second round: finishes a POST /trade/v1/swap call whose `signatures` asked the taker to sign a Permit2 `PermitSingle`. - **Cost:** free, never x402-gated - a payment header, if one is sent anyway, is ignored and nobody is charged. Only reachable once, right after the paid call that opened it. - **Key inputs:** the SAME `quoteId`, `taker` and `recipient` (defaults to `taker`) as the paid POST /trade/v1/swap call, plus `deadlineSec` and the required `permit: { message: signatures[0].typedData.message, signature }` (sign `typedData` with the taker's key, EIP-712, e.g. viem's `signTypedData`). `permit` accepts only `message` and `signature`, end to end - any other field, at any level, is 400 `invalid_request` at parse. The service rebuilds the Permit2 domain itself and checks the signer, spender, token, amount, nonce and both deadlines: a mismatched spender or token, or an amount below `amountIn` (a larger amount is accepted), is 400 `invalid_request`; a stale nonce, an expired `sigDeadline`/`expiration`, or an invalid signature (verified via ERC-1271 on chain for a contract taker) is 422 `swap_reverts`. A contract taker can swap, but POST /trade/v1/receipt only reads transactions the taker sends itself, so it answers `invalid_request` for a Safe, ERC-4337 or batching EIP-7702 wallet: check your own transaction receipt instead. - **No pending round:** 409 `no_pending_swap` when this `quoteId`/`taker`/`recipient` never paid, named a different taker or recipient, or already used its one free call - call POST /trade/v1/swap first, which is paid and returns the permit this call takes. - **Freshness:** re-quotes and re-simulates exactly like POST /trade/v1/swap, and can answer the SAME 410 `quote_expired`/409 `quote_stale` it would - but never with a fresh `quote` (issue #124's free re-quote is /trade/v1/swap's own paid-quote courtesy, not this free route's). - **Attempts:** a permit round (`quoteId`, `taker`, `recipient`) gets at most 5 failed calls; the…

NameTypeReqDescription
deadlineSecinteger––
permitobjectyes–
quoteIdstringyes–
recipient–––
takerstringyes–

No output schema declared.

No examples provided.

tradeVenues ~80

Lists the DEX venues, hub tokens and launchpads this deployment indexes. - **Cost:** free, never x402-gated. - **Returns:** each venue with an `executable` flag, hubs and launchpads. - **Next:** use venue ids in POST /trade/v1/quote's `venues` / `excludeVenues`.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the arcgate MCP server?

arcgate is an MCP server listed in the public MCP registry as dev.arcgate/arcgate. Token search, swap quotes and ready-to-sign swap transactions on Arc, paid per call via x402. This page covers its hosted endpoint (https://api.arcgate.dev/trade/v1/mcp).

Is the arcgate MCP server safe to use?

arcgate scores 54 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the arcgate MCP server expose?

arcgate exposes 7 tools: tradeSearch, tradeQuote, tradeSwap, tradeSwapTx, tradeReceipt, and 2 more. Their descriptions and schemas cost roughly 4,129 tokens of context every time the server is loaded.

Does the arcgate MCP server require authentication?

No. We connected to arcgate without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the arcgate MCP server still maintained?

arcgate is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.