# Realmint (remote · mcp.realmint.io)

Agent-native scoring, search and routing for tokenized real-world assets across multi-chain.

- Trust score: 23/100 (low)
- Change this week: −34
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `mcp.realmint.io`: 23/100 (this document), [markdown](https://verifymcp.io/servers/realmint-io-mcp/mcp.md), [page](https://verifymcp.io/servers/realmint-io-mcp/mcp)

## Channel facts

- Endpoint: `https://mcp.realmint.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 0/100
  - Transport check failed: declared streamable-http, but the endpoint returned HTTP 502.
- **Schema Quality & AI Usability**: 0/100
  - Schema not yet verified: we couldn't read the endpoint's schema.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage not yet verified: we couldn't read the endpoint's tools.
- **Capabilities**: 0/100
  - Capabilities not yet verified: we couldn't read the endpoint's capabilities.

**Unverified: 4 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add --transport http realmint-io-mcp https://mcp.realmint.io/mcp
```

### Codex

```toml
[mcp_servers.realmint-io-mcp]
url = "https://mcp.realmint.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "realmint-io-mcp": {
      "type": "remote",
      "url": "https://mcp.realmint.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add realmint-io-mcp --url https://mcp.realmint.io/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  realmint-io-mcp:
    url: "https://mcp.realmint.io/mcp"
```

### Other

```json
{
  "mcpServers": {
    "realmint-io-mcp": {
      "type": "http",
      "url": "https://mcp.realmint.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 23, −38)

- [security regression] Endpoint reachability: reachable → not serving MCP
- [security regression] Stability: 0.20 → unverified
- [security regression] Authorization: fail → unverified
- [security regression] Transport: pass → fail
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-07-31 (score 61, +2)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 59, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-28 (score 58, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 57, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 56)

First indexed and scored.

## MCP tools (16)

### `realmint_my_wallet` (~42 tokens)

Show your Realmint wallet (EVM + Solana), smart account, and balances.
    **Requires sign-in.** Read-only; moves no funds.

Output parameters:

- `result` (string)

### `realmint_deposit` (~48 tokens)

Show where to send USDC to fund your buying power. **Requires sign-in.**
    Send USDC on Base to your EVM wallet; it funds your smart account for buys.

Output parameters:

- `result` (string)

### `realmint_buy` (~125 tokens)

Buy `amount_usdc` of USDC worth of the RWA `asset_id` (e.g. 'paxg').
    **Requires sign-in + a one-time wallet delegation** at
    app.realmint.io/mcp/delegate. Realmint signs server-side via your Privy
    delegation, capped per-trade — no key, no per-trade approval. Your smart
    account must already hold USDC (see realmint_deposit). Moves real funds.

Input parameters:

- `amount_usdc` (number, required)
- `asset_id` (string, required)

Output parameters:

- `result` (string)

### `realmint_sell` (~115 tokens)

Sell `amount` of the RWA `asset_id` you hold, settling USDC back on
    Injective. **Requires sign-in + a one-time wallet delegation** at
    app.realmint.io/mcp/delegate. Realmint signs server-side via your Privy
    delegation — no key, no per-trade approval. Sells positions bought over MCP
    (held in your derived Realmint Wallet). Moves real funds.

Input parameters:

- `amount` (number, required)
- `asset_id` (string, required)

Output parameters:

- `result` (string)

### `realmint_withdraw` (~166 tokens)

Withdraw `amount_usdc` USDC from your Realmint smart account to `recipient`
    (any address). **Requires sign-in + a one-time wallet delegation** at
    app.realmint.io/mcp/delegate. Realmint signs server-side via your Privy
    delegation, capped per-transaction — no key, no per-withdraw approval. Native
    USDC on Injective. Moves real funds.

    `smart_account_address` (advanced/recovery, normally leave empty): sweep from
    a specific smart account you own that a factory rotation left behind. Only an
    SA CREATE2-owned by you is accepted.

Input parameters:

- `amount_usdc` (number, required)
- `recipient` (string, required)
- `smart_account_address` (string)

Output parameters:

- `result` (string)

### `realmint_logout` (~61 tokens)

Sign out note: Realmint keeps no signing session — server-side signing is
    your standing Privy **delegation**. To fully revoke it, go to
    app.realmint.io/mcp/delegate. Disconnecting the connector ends this session.

Output parameters:

- `result` (string)

### `realmint_list_assets` (~53 tokens)

List all tokenized real-world assets (RWAs) indexed by Realmint.
    Returns the full schema for each asset including ownership, control,
    transferability, redemption terms, and legal metadata.

Output parameters:

- `result` (string)

### `realmint_list_instruments` (~106 tokens)

List instruments — the real-world things tokens represent: an underlying
    at a specific denomination ("Silver · 1 oz") or a stock ("Apple"). Tokens
    sharing an instrument are interchangeable representations of the same
    thing. Each entry carries its member token ids, the recommended member
    (buyable > priced > score), and the floor price across members — use it to
    pick the best token for an instrument before quoting or buying.

Output parameters:

- `result` (string)

### `realmint_list_market` (~111 tokens)

Market snapshots for indexed RWAs: spot price, 24h change, volume, market
    cap, venue count, and a short price history series. Combine with
    `realmint_get_score` to compare risk against liquidity.

    Args:
        ids: Optional comma-separated asset IDs to filter (e.g. "xaut,paxg").
             Empty = all assets. Assets without fresh market data are omitted
             from the response.

Input parameters:

- `ids` (string)

Output parameters:

- `result` (string)

### `realmint_get_asset` (~171 tokens)

Get the full schema for a specific RWA by asset ID.
    Includes issuer details, control capabilities (freeze/mint/burn/blacklist),
    transferability restrictions, redemption mechanics, and legal documents.

    The asset ID is the lowercased ticker (e.g. "xaut", "paxg", "kau", "agri",
    "cgo"). Use `realmint_list_assets` to discover all available IDs — the
    catalog spans ~30 tokens across multiple chains and changes over time.

    Always read `metadata.lifecycle` from the response: a non-null lifecycle
    means the token is migrated/discontinued/abandoned and trading is
    disallowed (score is hard-capped at 49).

Input parameters:

- `asset_id` (string, required)

Output parameters:

- `result` (string)

### `realmint_get_asset_history` (~63 tokens)

Get the versioned metadata change history for an asset.
    Each entry records what changed (created, updated) and a full schema snapshot.
    Useful for detecting when an issuer changes terms or control parameters.

Input parameters:

- `asset_id` (string, required)

Output parameters:

- `result` (string)

### `realmint_get_score` (~308 tokens)

Get the Risk & Rights Score for an asset across six dimensions:
    - backing (0-100): proof of reserves, audit cadence, backing mechanism
    - enforceability (0-100): governing law, issuer verification, legal documents
    - control (0-100): issuer power risk — freeze, mint, burn, blacklist, upgrade
    - exit (0-100): redemption, transferability, KYC/whitelist, settlement, holding periods
    - liquidity (0-100): market data, venue count, evidence docs
    - social (0-100): Twitter activity (recency-weighted; unverified handles
      are penalized below the worst observed tier)
    Also returns a weighted composite (0-100, higher is better). Weights and
    penalty tiers are versioned server-side — see `policy_version` in the
    response.

    Combine with the asset's `metadata.lifecycle` field (from
    `realmint_get_asset`) to detect dead/migrated tokens — those are
    score-capped at 49.

    Suggested thresholds for decision-making:
    - composite ≥ 75: typical case, proceed
    - 55 ≤ composite < 75: elevated friction (gates, missing audits, etc.);
      review the asset's flags before proceeding
    - composite < 55: high risk; abort or require explicit user override

Input parameters:

- `asset_id` (string, required)

Output parameters:

- `result` (string)

### `realmint_get_route_support` (~90 tokens)

List the venues and chains that can route this asset, plus per-venue
    backing/liquidity/social scores and policy flags. Use this to check
    whether a trade is even feasible before quoting — `routing_enabled=false`
    or an empty venue list means the asset can be inspected but not traded
    via Realmint.

Input parameters:

- `asset_id` (string, required)

Output parameters:

- `result` (string)

### `realmint_get_price_history` (~144 tokens)

Time-series price history for an asset.

    Args:
        asset_id: Asset identifier
        days: Lookback in days (1-730, default 30)
        granularity: Optional explicit bucket — "5m" | "1h" | "1d". Omit to
            auto-pick (≤2d → 5m, ≤30d → 1h, else 1d). The server cascades to
            coarser buckets when the requested one is empty for this asset.

Input parameters:

- `asset_id` (string, required)
- `days` (integer)
- `granularity` (string)

Output parameters:

- `result` (string)

### `realmint_x402_buy_challenge` (~417 tokens)

Get the x402 payment requirements to fund yourself in USDC so you can buy
    RWAs — the agent-native on-ramp. This returns the 402 challenge only; it
    moves no funds.

    To complete funding (two signatures total, the same a human gives), the
    agent then, ENTIRELY CLIENT-SIDE:
      1. Reads `accepts[0]` from the returned body: `payTo` is YOUR Base smart
         account (derived from `owner_eoa`), `maxAmountRequired` the USDC atomic
         amount, `asset` the Base USDC contract, `extra` the EIP-712 domain.
      2. Signs an EIP-3009 `transferWithAuthorization(from=owner_eoa, to=payTo,
         value=maxAmountRequired, ...)` over that domain, base64-encodes the
         x402 PaymentPayload, and re-POSTs to `/v1/route/x402-buy` with it in the
         `X-PAYMENT` header. On settlement the USDC bridges custody-free to your
         Injective smart account.
      3. Buys any RWA from that Injective balance via `POST /v1/route/intent`
         (signing the route as usual). The asset rests in your smart account;
         `send` it elsewhere if you want — exactly like a human user.

    Always verify `payTo` derives from your own `owner_eoa` before signing.

    Args:
        owner_eoa: Your EVM EOA — the payment signer and smart-account owner.
        amount_usdc: USDC to fund yourself with (human units, e.g. 25.0).
        asset_id: Optional RWA you intend to buy, recorded for context.

Input parameters:

- `amount_usdc` (number, required)
- `asset_id` (string)
- `owner_eoa` (string, required)

Output parameters:

- `result` (string)

### `realmint_whoami` (~60 tokens)

Return the signed-in user's identity. This tool **requires authentication**
    — calling it triggers the Realmint sign-in (OAuth) if you're not signed in.
    Use it to confirm who you're acting as. Read-only; moves no funds.

Output parameters:

- `result` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/realmint-io-mcp/mcp#diagnostics

## Score history

- 2026-08-03: 23
- 2026-08-02: 23
- 2026-08-01: 61
- 2026-07-31: 61
- 2026-07-30: 59
- 2026-07-29: 58
- 2026-07-28: 58
- 2026-07-27: 57
- 2026-07-26: 56

## Links

- Remote endpoint: https://mcp.realmint.io/mcp
- Repository: https://github.com/realmint-io/mcp
- Website: https://realmint.io/
- Changelog RSS feed: https://verifymcp.io/servers/realmint-io-mcp/mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/realmint-io-mcp/mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/realmint-io-mcp/mcp
