mcp server
FortFi Treasury MCP
Policy-gated MCP treasury for AI agents — x402 subscribe, 50+ tools, multi-chain.
Description as published by the maintainer. Source
- version 1.0.0
- active
active — Registry entry last updated 2026-07-14.
What this server can do
73 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
accept_cosigner_invite(inviteId)- Accept a pending co-signer invite. After accepting, you will be able to approve/reject pending actions for that account. Required: inviteId.
add_recipient(address, chainId, nickname, challengeId, walletSignature)- Add a payout address to the allowlist. Human developer key (frtfi_hu_* + DA): added with 24h cooldown (no Assist passkey). Agent key (frtfi_ag_*): GOVERN — funding-wallet signature required; then approved immediately. Required: address, chainId.
approve_cosigner_action(pendingApprovalId)- Approve a pending action as co-signer. Use with list_pending_cosigner_approvals. Required: pendingApprovalId.
approve_recipient(challengeId, recipientId, walletSignature)- Approve a recipient still in cooldown (early release). A distinct active cosigner may approve directly; owner self-approval via an agent key is a GOVERN action requiring a funding-wallet signature (challengeId + walletSignature). Required: recipientId.
cancel_governance_change(challengeId)- Veto/cancel a pending governance challenge before it is signed and applied. Cancelling TIGHTENS security, so it needs only the agent key (no signature). Also cancels legacy scheduled rows from before immediate-apply parity. Required: challengeId.
cancel_payment_request(idOrPid)- Cancel an open payment request with no verified settlement. Required: idOrPid.
cancel_pending_action(pendingApprovalId)- Cancel a pending approval that you (the account owner) initiated. Required: pendingApprovalId.
check_trade_allowance(flow, fromWalletId, tokenAddress, requiredAmountSmallest)- Check ERC-20 allowance for an upcoming CoW swap (cow_swap) or Fusion bridge (fusion_bridge). Call before propose_swap / propose_bridge; if insufficient, use propose_token_approve then confirm. Required: fromWalletId, tokenAddress, requiredAmountSmallest, flow.
confirm_proposal(proposalId, confirmToken)- Confirm a pending proposal returned by a propose_* tool. Reuses the same policy, risk, allowlist, vault-grant, delegated-authority, and cosign checks as POST /api/mcp/confirm. Returns executed, pending-approval, or passkey-required status. Required: proposalId.
create_payment_request(metadata, amountUsd, expiryDays, description, walletMappingId, externalReference, amountSmallestUnit)- Create a shareable payment request for a vault. Returns pid, paymentUrl, and qrPayload for humans or agents. Required: walletMappingId.
create_provisioning_job(items, idempotencyKey)- Bulk-provision up to 20 customer vaults per job (treasury + keys:manage + wallets:write). Requires idempotencyKey in args. Poll get_provisioning_job until terminal; bearer secrets reveal once on first terminal GET. Required: idempotencyKey, items.
create_vault_credential(name, access, expiresAt, vaultGrants, agentPublicKey)- Mint a vault-scoped credential for an existing wallet (treasury + keys:manage). Returns bearerKey once when agentPublicKey is omitted. Requires FORTFI_VAULT_CREDENTIALS_ENABLED. Required: name, access, vaultGrants.
discover_tokens(sort, limit, query, chainId, verifiedOnly)- Market-wide token discovery on a FortFi chain (USD). Use for trending/gainers/losers/volume/mcap — NOT the browser Explore REST route. Sorts: gainers_1d, gainers_30d, gainers_90d, gainers_365d, losers_1d, losers_30d, losers_90d, losers_365d, market_cap, volume_1d. No 7d or 30d-volume sort exists upstream — closest available gainers granularity to '1 week' is gainers_1d or gainers_30d; say so explicitly rather than silently picking one. Returns contract addresses for propose_swap / propose_bridge. Required: chainId.
extend_payment_request(idOrPid, expiryDays)- Extend an open payment request expiry (default extension window in days). Required: idOrPid, expiryDays.
get_account_holdings(walletId)- Token holdings for a specific wallet, with USD values and 24h change. Required: walletId.
get_cosigner_rules- Amount-banded cosigner quorum rules for sends and swaps. Below-band amounts auto-execute; matching bands require N cosigner votes.
get_fusion_order_status(orderHash)- Track an owned Fusion+ cross-chain order by orderHash. Returns authoritative settlement/refund status, source and destination transactions, receiver, and the real destination token contract. Required: orderHash.
get_mcp_guide(topic)- FortFi MCP capability guide: onboarding paths, pricing, limits, workflows, and full tool catalog. Call first when unsure which tool to use (e.g. market research → discover_tokens, not the Explore UI REST route).
get_payment_request(idOrPid)- Get a payment request by internal id or public pid, including settlement attempts. Required: idOrPid.
get_policy_limits- Current policy limits: per-tx/daily/monthly caps (USDC smallest units). Agent accounts include billingPlan (personal|startup), billingPlanName, maxWallets, tier, and subscription expiry.
get_portfolio- Full portfolio summary across all wallets: token balances with USD values, 24h change, and total net worth.
get_provisioning_job(jobId)- Poll a bulk provisioning job (treasury + keys:manage + wallets:read). bearerKey appears once when secretsDelivery is revealed. Required: jobId.
get_swap_routing_guide(toChainId, fromChainId)- Returns which swap/bridge tool to use for a given from→to chain pair, with notes on protocols supported. Required: fromChainId, toChainId.
get_token_chart(period, address, chainId, fungibleId, indicators, includePoints)- Fetch a compact Zerion chart summary plus deterministic EMA, RSI, MACD, Bollinger, return, max-drawdown, and data-quality analysis. Raw points are omitted by default; set includePoints:true only for visual charting or external analysis. Discontinuous pre-migration/launch samples are excluded from TA. Required: chainId.
get_yield_market_detail(apyDays, chainId, tvlDays, vaultAddress)- Evidence for one Morpho vault: current net APY/TVL, historical APY and TVL series, period averages/volatility/drawdown, quality flags, allocation, separated eligibility/readiness status, and timestamp. Use before recommending or proposing a deposit. Required: chainId, vaultAddress.
invite_agent_cosigner(email, nickname, challengeId, cosignerUserId, walletSignature)- Invite a co-signer. Agents: pass cosignerUserId (GOVERN / funding-wallet sign when using an agent API key). Humans: pass email — opens instructions for Security UI passkey provision (Turnkey dual-control with MCP DA).
invite_cosigner(email, nickname, challengeId, cosignerUserId, walletSignature)- Alias of invite_agent_cosigner. Humans: email → Security UI. Agents: cosignerUserId.
list_activity_report(category, walletId)- Treasury activity timeline (JSON) for reconciliation: normalized labels, USD hints, vault scope, and categories. Optional walletId narrows to one vault. Requires reporting:read (or account:read).
list_audit_log(limit, cursor, walletId)- Recent account activity: transfers, swaps, security events. Optional walletId filters to one vault's history. Pass cursor (from a previous page's nextCursor, even as an empty string on the first call) to switch the response to { items, nextCursor } and page back through full history instead of only the most recent entries.
list_cosigner_memberships- Active co-signers on this account.
list_funding_wallet_agents- List all FortFi agent accounts funded by the same payment wallet as this agent. Use to discover agentLabel / userId when renewing or spawning siblings (treasury multi-agent setups).
list_governance_requests- List open governance requests on this account: pending (awaiting signature) and legacy scheduled rows. Use to monitor for unexpected loosening attempts.
list_incoming_cosigner_invites- List pending co-signer invites sent TO this account (where this account is the invitee). Use to discover accounts you can become a co-signer for.
list_payment_requests(status, walletMappingId)- List payment requests for the authenticated account.
list_pending_cosigner_approvals(limit)- Pending actions that require this account's co-signer approval. Use when this agent is a co-signer on another account.
list_recipients- List all allowlisted recipients. Includes cooldown status: `cooldownActive: true` means the recipient cannot yet receive funds (24-hour gate).
list_token_spender_grants- List active ERC-20 token approvals (spender grants) on this account. Useful before proposing a swap to confirm the CoW vault is approved.
list_wallets(limit, cursor, metadataKey, metadataValue)- List FortFi wallets for this account: chain, address, nickname, metadata tags, and default flag. Optional metadataKey/metadataValue filter (exact match). Pass cursor and/or limit to page through large fleets — response becomes { items, nextCursor } when either is set; omit both for the plain array of all wallets.
list_yield_markets(asset, limit, sortBy, chainId, minTvlUsd, verifiedOnly)- Open Morpho yield discovery by chain with discovered, policyEligible, manuallyCurated, executionReady, and eligibilityReasons. Default minimum TVL is $500K everywhere (listing, policy, Turnkey). executionReady means TVL qualifies and you have a wallet on that chain; POLICY_SYNC_RECOMMENDED is advisory only.
list_yield_positions- User's Morpho yield positions from FortFi history.
plan_rebalance(targets, minLegUsd, driftThresholdPercent)- Read-only rebalance planner toward target weights. Returns suggested legs (swap, yield_deposit, yield_withdraw) without executing. Use propose_* + confirm_proposal to act. Required: targets.
preview_bridge_quote(amountUsd, buySymbol, sellSymbol, toWalletId, fromWalletId)- Optional advanced step: fetch a cross-chain bridge quote (Fusion+ or deBridge) and return previewQuoteId. Omit previewQuoteId on propose_bridge to bundle quote+proposal in one call. Required: fromWalletId, toWalletId, sellSymbol, buySymbol, amountUsd.
preview_swap_quote(buyMint, sellMint, amountUsd, buySymbol, sellSymbol, toWalletId, fromWalletId, buyTokenAddress, slippagePercent, sellTokenAddress)- Optional advanced step: fetch a same-chain swap quote (CoW on EVM, Jupiter on Solana) and return previewQuoteId. Omit previewQuoteId on propose_* to bundle quote+proposal in one call. Does not execute or move funds. Required: fromWalletId, sellSymbol, buySymbol, amountUsd.
propose_bridge(amountUsd, buySymbol, sellSymbol, toWalletId, fromWalletId, previewQuoteId, buyTokenAddress, sellTokenAddress)- Propose a Fusion+ or deBridge cross-chain swap. FortFi resolves chain-specific verified token contracts from sellSymbol/buySymbol; optional token addresses are mismatch assertions, never routing overrides. Inline quote by default, or use previewQuoteId for two-step review. Required: fromWalletId, toWalletId, sellSymbol, buySymbol, amountUsd.
propose_create_account(chainId, metadata, walletName)- Create a new wallet on a supported chain. Optional metadata tags (e.g. customer_id). Then call confirm_proposal with the returned proposalId. Agent accounts execute server-side when no cosigners are configured. Required: chainId, walletName.
propose_payout_manifest(lines, dryRun, fromWalletId)- Execute a validated payout manifest sequentially (one ActionIntent per line). Requires Delegated Access or agent wallet. Set dryRun:true to validate only. Required: fromWalletId, lines.
propose_recipient_manifest(recipients)- Apply a validated recipient manifest (human/developer key). Adds new allowlist rows with normal 24h cooldown. Agent keys: use add_recipient per row (GOVERN). Required: recipients.
propose_rename_account(nickname, accountId)- Rename a wallet (account nickname), then call confirm_proposal with the returned proposalId. Required: accountId, nickname.
propose_solana_swap(buyMint, sellMint, amountUsd, buySymbol, sellSymbol, toWalletId, fromWalletId, previewQuoteId, slippagePercent)- Propose a Solana Jupiter swap. Autonomous agents: inline quote by default, or previewQuoteId for two-step review. confirm signs the bound quote. Required: fromWalletId, toWalletId, sellMint, buyMint, sellSymbol, buySymbol, amountUsd.
propose_swap(amountUsd, buySymbol, sellSymbol, fromWalletId, previewQuoteId, buyTokenAddress, slippagePercent, sellTokenAddress)- Propose an EVM CoW swap. Autonomous agents: fetches and binds a quote inline (default), or pass previewQuoteId from preview_swap_quote for a two-step review. confirm always signs the bound quote — same principle as FortFi Assist. Human session MCP: confirm requires passkey in the app. Required: fromWalletId, sellTokenAddress, buyTokenAddress, sellSymbol, buySymbol, amountUsd.
propose_token_approve(flow, fromWalletId, tokenAddress)- Propose max ERC-20 approval for CoW or Fusion spenders. Returns proposalId — call confirm_proposal before swap/bridge. Required: fromWalletId, tokenAddress, flow.
propose_transfer(memo, amountUsdc, recipientId, fromWalletId)- Transfer USDC to an allowlisted recipient. The recipient must be approved (no active cooldown). Rejected with POLICY_LIMIT_EXCEEDED if above tier limits. Rejected with RECIPIENT_NOT_APPROVED if in cooldown. Required: recipientId, amountUsdc, fromWalletId.
propose_yield_deposit(amountUsd, assetSymbol, fromWalletId, vaultAddress, fromAccountQuery)- Propose Morpho vault deposit, then call confirm_proposal. With Delegated Access / agent key this executes server-side when policy permits. Use list_yield_markets for vaultAddress. Required: vaultAddress, amountUsd.
propose_yield_withdraw(vaultName, assetSymbol, fromWalletId, vaultAddress, amountDisplay, fromAccountQuery)- Propose Morpho vault withdraw, then call confirm_proposal. With Delegated Access this executes server-side when policy permits. Use list_yield_positions for vaultAddress. Required: vaultAddress, amountDisplay.
rank_tokens(mode, sorts, chains, periods, deepOptIn, verifiedOnly, candidateLimit, minVolume1dUsd, minMarketCapUsd, includeUnverified, chartCandidateLimit)- Two-stage token ranking: run the cheap screen, then concurrently fetch deterministic chart evidence only for the strongest candidates. Quick charts 5 candidates over month+3months; standard charts 10 over day+month+3months+year; deep charts 20 and requires explicit opt-in. Returns evidence for user review and never creates a proposal. Required: chains.
rank_yield_markets(asset, limit, apyDays, chainId, tvlDays, minTvlUsd)- Batch-rank Morpho markets using current net APY, APY average/range/volatility, TVL trend/drawdown, vault age, curation, warnings, and current-user execution eligibility. Runs evidence requests concurrently and never creates a proposal.
register_backup_governance_wallet(challengeId, walletAddress, walletSignature)- Register (or replace) a single backup governance wallet — the agentic equivalent of a backup passkey. Either the funding wallet or this backup can authorize future governance. GOVERN action: sign the challenge with your CURRENT funding wallet (challengeId + walletSignature); applies immediately once signed. Max one backup. Required: walletAddress.
reject_cosigner_action(reason, pendingApprovalId)- Reject a pending action as co-signer. Required: pendingApprovalId.
remove_backup_governance_wallet(challengeId, walletSignature)- Remove the registered backup governance wallet. GOVERN action: sign with your funding wallet (challengeId + walletSignature); applies immediately once signed. After removal, only the funding wallet may authorize governance.
remove_cosigner(challengeId, membershipId, walletSignature)- Remove an active co-signer from this account. GOVERN action (it shrinks the approver set): via an agent key, sign a challenge with your funding wallet (challengeId + walletSignature); applies immediately once signed. Required: membershipId.
remove_recipient(recipientId)- Remove a recipient from the FortFi allowlist (tightening policy — no funding-wallet GOVERN). Human developer key, session, or agent treasury key. Re-sync Turnkey policies in the app so the enclave matches. Required: recipientId.
resend_claim_link- Resend the dashboard claim email to contactEmail (MCP agent API key only; keys:manage scope). Use when the original link expired (72h) or was lost. Rate limit: 3/hour.
review_portfolio(targets, minLegUsd, driftThresholdPercent)- Read-only treasury review: allocation buckets (cash, yield, tokens), top holdings, and optional drift vs target weights. Safe for cron — no proposals created.
revoke_cosigner_invite(inviteId)- Revoke a pending outbound co-signer invite before it is accepted. Required: inviteId.
revoke_vault_credential(credentialId)- Revoke a vault-scoped credential (treasury + keys:manage). Idempotent if already revoked. Required: credentialId.
screen_tokens(mode, sorts, chains, deepOptIn, verifiedOnly, candidateLimit, minVolume1dUsd, minMarketCapUsd, includeUnverified)- Batch cheap-screen tokens across requested chains. Defaults to verified assets, $5M market cap, $50K daily volume, top 30-day performers plus volume leaders, stablecoin removal, and cross-chain deduplication. Returns no proposal. Required: chains.
search_credentials(limit, query, access, cursor, status, walletId, metadataKey, metadataValue, credentialKind, externalCustomerId)- Parent-treasury key-centric credential search (treasury credential + keys:manage + wallets:read). Complements search_vaults. Never returns raw bearer keys.
search_vaults(limit, query, cursor, chainId, metadataKey, metadataValue, credentialAccess, credentialStatus, externalCustomerId)- Parent-treasury vault inventory search (treasury credential + keys:manage + wallets:read). Matches nicknames, wallet IDs, addresses, external customer IDs, credential names, and prefixes. Never returns raw bearer keys.
update_cosigner_rules(rules, challengeId, walletSignature)- Set cosigner quorum rules (send + swap USD bands). Tightening rules works with the agent key alone. WEAKENING them (lower required cosigners / raise the amount floor) is a GOVERN action: sign a challenge with your funding wallet (challengeId + walletSignature); applies immediately once signed (same as passkey in the UI). Amounts use USDC micro-units (1 USDC = 1000000). Required: rules.
update_vault_credential(name, access, expiresAt, vaultGrants, credentialId)- Atomically replace a vault credential's name, access mode, grants, and expiry (treasury + keys:manage). Revoked credentials cannot be updated. Required: credentialId, name, access, vaultGrants.
update_wallet_metadata(metadata, accountId)- Set metadata tags on a wallet (flat string key/value pairs; replaces existing tags). Not a money-moving action. Required: accountId, metadata.
validate_payout_manifest(lines, fromWalletId)- Preview batch payroll/payout (max 50 lines). Each line: { recipientId, amountUsdc, memo? }. All recipients must be allowlisted, same chain as fromWalletId, and past cooldown. Required: fromWalletId, lines.
validate_recipient_manifest(recipients)- Preview a batch recipient import (max 50 rows). Each row: { address, chainId, nickname? }. Returns ready_new, already_exists, or invalid per line. Read-only. Required: recipients.
Last successful function declaration observed on . Source: https://fortfiapp.com/api/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://fortfiapp.com/api/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 1.0.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-07-14 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-07-14 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| mcp tools declared | 73 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | fortfiapp.com | |
| mcp endpoint status | ok | The server listed 73 functions when asked. | as of probe | fortfiapp.com |
Where to get it
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json