MidnightSAFE
Midnight MCP server giving AI assistants access to Midnight blockchain — search contracts, analyze code, explore docs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
## ⚠️ Deprecated — use Kapa + Midnight Expert midnight-mcp is being wound down. Midnight has standardised on two official tools: - Kapa MCP (docs Q&A / search):claude mcp add --transport http midnight https://midnight.mcp.kapa.ai- Midnight Expert (hands-on dev, Claude Code plugins):curl -fsSL https://midnightntwrk.expert/install.sh | bashMigration guide → https://docs.midnight.network/blog/migrating-to-kapa-and-midnight-expert
[](https://www.npmjs.com/package/midnight-mcp) [](https://npm-stat.com/charts.html?package=midnight-mcp) [](./LICENSE) [](https://www.typescriptlang.org/) [](https://github.com/Olanetsoft/midnight-mcp/actions/workflows/ci.yml)
MCP server that gives AI assistants access to Midnight blockchain—search contracts, analyze code, and explore documentation.
This project extends the Midnight Network with additional developer tooling.
Requirements
- Node.js 20+ (LTS recommended)
Check your version: node --version
Using nvm? Click for Claude Desktop setup
If you use nvm, Claude Desktop may not see your nvm-managed Node. Use this config instead:
{
"mcpServers": {
"midnight": {
"command": "/bin/sh",
"args": [
"-c",
"source ~/.nvm/nvm.sh && nvm use 20 >/dev/null 2>&1 && npx -y midnight-mcp@latest"
]
}
}
}Quick Start
Claude Desktop
Add to your claude_desktop_config.json:
{
"mcpServers": {
"midnight": {
"command": "npx",
"args": ["-y", "midnight-mcp@latest"]
}
}
}*Config file locations:
4316c1b7477dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add midnight-mcp --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env MIDNIGHT_API_TOKEN=${MIDNIGHT_API_TOKEN} --env MIDNIGHT_GITHUB_TOKEN=${MIDNIGHT_GITHUB_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"midnight-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}",
"MIDNIGHT_API_TOKEN": "${MIDNIGHT_API_TOKEN}",
"MIDNIGHT_GITHUB_TOKEN": "${MIDNIGHT_GITHUB_TOKEN}"
}
}
}
}Exposed tools (36)
33 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Documentation | read | Access documentation by section (guides, api, concepts) and topic |
approaches | read | Specific approaches to compare (comma-separated) |
complexity | read | Expected complexity level (beginner, intermediate, advanced) |
concept | read | The concept to explain (zk-proofs, circuits, witnesses, ledger, etc.) |
contractCode | read | The Compact contract code to review |
contractType | read | Type of contract (token, voting, credential, custom) |
errorMessage | read | Error message or description of the issue |
focusAreas | read | Specific areas to emphasize (security, performance, privacy, readability) |
level | read | Expertise level (beginner, intermediate, advanced) |
midnight-analyze-contract | read | ⚠️ STATIC ANALYSIS ONLY - Analyze contract structure and patterns. 🚫 THIS DOES NOT COMPILE THE CONTRACT. Cannot catch: sealed field rules, disclose() requirements, semantic errors. 👉 Use |
midnight-auto-update-config | write | ⚠️ DEPRECATED: Auto-update is NOT possible because AI agents run in sandboxed environments without access to local filesystems. |
midnight-check-breaking-changes | read | Check if there are breaking changes between your current version and the latest release. Essential before upgrading dependencies. |
midnight-check-version | read | 🔄 Check if you |
midnight-compare-syntax | read | Compare a file between two versions to see what changed. Use this before recommending code patterns to ensure they work with the user |
midnight-document-contract | read | 📝 AI-POWERED DOCUMENTATION GENERATION Generates comprehensive documentation for Compact smart contracts. Uses the client |
midnight-extract-contract-structure | read | Extract and analyze Compact contract structure (circuits, witnesses, ledger). |
midnight-generate-contract | read | 🔮 AI-POWERED CONTRACT GENERATION Generates Compact smart contracts from natural language requirements. Uses the client |
midnight-get-file | read | Retrieve a specific file from Midnight repositories. Use repository aliases like |
midnight-get-file-at-version | read | Get the exact content of a file at a specific version. CRITICAL: Use this to ensure code recommendations match the user |
midnight-get-latest-updates | read | Retrieve recent changes and commits across Midnight repositories. Useful for staying up-to-date with the latest developments. |
midnight-get-migration-guide | read | Get a detailed migration guide for upgrading between versions, including all breaking changes, deprecations, and recommended steps. |
midnight-get-repo-context | write | 🚀 COMPOUND TOOL: Get everything needed to start working with a repository in ONE call. Combines version info + syntax reference + relevant examples. Use this at the start of a coding session instead of multiple individual calls. Saves ~50% tokens. |
midnight-get-status | read | Get current server status including rate limits and cache statistics. Quick status check without external API calls. |
midnight-get-update-instructions | write | 📋 Get detailed, platform-specific instructions for updating Midnight MCP to the latest version. |
midnight-get-version-info | read | Get the latest version, release notes, and recent breaking changes for a Midnight repository. Use this to ensure you |
midnight-health-check | read | Check the health status of the Midnight MCP server. Returns server status, API connectivity, and resource availability. |
midnight-list-category-tools | read | 📋 DISCOVERY TOOL: List tools within a specific category. Use after midnight-list-tool-categories to see detailed tool information for a category of interest. Supports progressive disclosure pattern. |
midnight-list-examples | read | List available Midnight example contracts and DApps with descriptions, complexity ratings, and key features. |
midnight-list-tool-categories | read | 📋 DISCOVERY TOOL: List available tool categories for progressive exploration. Use this FIRST to understand what capabilities are available, then drill into specific categories with midnight-list-category-tools. Reduces cognitive load by organizing the available tools into logical groups. |
midnight-new-mcp | read | Show where midnight-mcp has moved. midnight-mcp is deprecated; Midnight |
midnight-review-contract | read | 🔍 AI-POWERED CONTRACT REVIEW Performs security review and analysis of Compact smart contracts. Uses the client |
midnight-search-compact | read | Semantic search across Compact smart contract code and patterns. Use this to find circuit definitions, witness functions, ledger declarations, and best practices for Midnight smart contracts. USAGE GUIDANCE: • Call at most 2 times per question - if first search doesn |
midnight-suggest-tool | read | 🎯 SMART DISCOVERY: Describe what you want to do in natural language, and get tool recommendations. EXAMPLES: • |
midnight-upgrade-check | read | 🚀 COMPOUND TOOL: Complete upgrade analysis in ONE call. Combines version check + breaking changes + migration guide. Use this instead of calling midnight-get-version-info, midnight-check-breaking-changes, and midnight-get-migration-guide separately. Saves ~60% tokens. |
privacyLevel | read | Required privacy features (full, partial, public) |
problem | read | The problem to solve |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
.prettierrc.json
config({ path: resolve(__dirname, "../../.env") });import type { ToolCall } from "../../interfaces";import { parseCompactFile, CodeUnit } from "../../pipeline/index.js";import { logger } from "../../utils/index.js";} from "../../services/compiler.js";
"http://127.0.0.1:3000",
"https://127.0.0.1:3000",
@types/tar-stream, hono, tar-stream, @cloudflare/workers-types, dotenv, octokit, openai, tsx
@modelcontextprotocol/sdk, chromadb, dotenv, express, js-yaml, octokit, openai, yargs
> - **Midnight Expert** (hands-on dev, Claude Code plugins): `curl -fsSL https://midnightntwrk.expert/install.sh | bash`
Gates applied: no_behavioural_pass.
4316c1b7477dfull audit observations/trust-audit/mcp-server/olanetsoft__midnight.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4316c1b7477d | SAFE | B | 89 | first audit |
Questions
What is the Midnight MCP server?
Midnight MCP server giving AI assistants access to Midnight blockchain — search contracts, analyze code, explore docs
What tools does Midnight expose?
36 in total: 33 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Midnight safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Midnight need?
It reads CLOUDFLARE_API_TOKEN, GITHUB_TOKEN, MIDNIGHT_API_TOKEN, MIDNIGHT_GITHUB_TOKEN and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Midnight run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as midnight-mcp at 0.3.0.
How current is this page?
The grade is for one exact copy of the source (4316c1b7477d), read on 2026-10-08. The repository is watched and re-audited when it changes.