Add PathGuard MCP
Run it locally for development or connect through Streamable HTTP for remote agent platforms.
PathGuard MCP lets MCP-compatible agents check crypto destinations and preflight transaction details before funds move. Get a risk score, actionable flags, and a clear decision inside the agent workflow.
Run it locally for development or connect through Streamable HTTP for remote agent platforms.
Use preflight_transaction to evaluate the destination and optional amount before an agent proceeds.
Use the decision, score, and flags to warn, require confirmation, or block a risky action.
The standard PathGuard MCP server exposes six tools for transaction safety, community reporting, account usage, and authenticated profile access.
Run the PathGuard risk engine before a send and receive an ALLOW, REVIEW, or BLOCK decision with the supporting score and flags.
Scan a destination for known scam signals, invalid formats, new-address risk, suspicious similarity, and amount anomalies.
TRANSACTION SAFETYReview up to 1,000 transactions in one call. The default MCP response is a compact summary; request detail_level="full" when you need every result.
Submit a suspicious address and optional reason to PathGuard's community reporting system.
COMMUNITY SIGNALInspect the current plan, quota, and usage for the authenticated PathGuard account.
ACCOUNTReturn a safe, opaque profile identifier and account context for the authenticated PathGuard user.
ACCOUNTChoose local MCP when the client can run a server process. Use Streamable HTTP when the client or platform needs a remote HTTPS endpoint.
Use the public PathGuard MCP package in your development environment. Your API key stays with your client and authenticates requests to PathGuard.
PUBLIC REPOSITORYINSTALLgit clone https://github.com/Utee/pathguard-mcp.git cd pathguard-mcp python -m pip install .AUTHENTICATION
PATHGUARD_API_KEY=pg_your_key_here
Requirements: Python 3.10+ and mcp >= 2.0. See the repository README for client-specific MCP configuration.
For remote MCP clients, connect to the standard public PathGuard MCP endpoint over HTTPS.
CURRENT PRODUCTION ENDPOINThttps://pathguard-v2.up.railway.app/mcp/
Authentication: remote MCP uses OAuth. Sign in with an existing PathGuard account and provide that account's PathGuard API key on the PathGuard consent page to authorize the connection.
Key handling: the API key is used to verify and authorize your existing PathGuard account. It is not returned to the AI client or exposed through MCP tool calls. Never paste a PathGuard API key into an AI prompt or public repository.
A branded MCP hostname will be documented here when its production routing is finalized.
PATHGUARD_API_KEY directly.preflight_transaction is the decision-oriented MCP tool for putting PathGuard directly before a signing or broadcast step.
{
"address": "0x0000000000000000000000000000000000000001",
"chain": "EVM",
"amount": 0.01
}The tool uses the same transaction fields and production risk engine as the PathGuard preflight API.
{
"decision": "REVIEW",
"risk_score": 15,
"flags": ["new_address"],
"should_block": false,
"recommendation": "Review the flagged risk signals before sending."
}ALLOW: no risk signals. REVIEW: signals exist but PathGuard is not blocking. BLOCK: the risk assessment recommends blocking.
PathGuard provides a risk signal before a transaction reaches your signing or broadcast step. It does not replace your own authorization controls and does not execute transactions.
API keys authenticate access to your PathGuard account and associated context. Never expose them to end users or client-side applications.
Run preflight before the transaction reaches your signing or broadcast step.
Combine PathGuard's decision, score, and flags with your own authorization, policy, and transaction controls.
Private or partner-specific MCP integrations may use separate access controls. Their endpoints and credentials are not published in the public documentation.
For API request schemas, preflight responses, risk flags, rate limits, pricing, and examples, continue to the full API reference.