Atlas / MCP servers / tolenonetwork / Toleno

TolenoSAFE

mcp/tolenonetwork/toleno

Toleno Network MCP Server — Control your Toleno mining account directly from Claude AI using natural language.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
13 11r · 2w · 0d
Transport
stdio
License
—
Stars
227
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@toleno/mcp) [](https://www.npmjs.com/package/@toleno/mcp) [](https://nodejs.org) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io)

Toleno Network MCP Server — Control your Toleno mining account directly from Claude AI using natural language.

Check balance · Start mining · View referrals — all without opening the app.

Quick Start

npx @toleno/mcp setup

The setup wizard will:

  1. Ask for your Toleno API key
  2. Validate it against the Toleno API
  3. Automatically update your Claude Desktop config
  4. Remind you to restart Claude Desktop

Or non-interactive:

npx @toleno/mcp setup --key tlno_your_key_here

Get Your API Key

  1. Open the Toleno app on your phone
  2. Go to Settings → API Keys
  3. Tap "Create New Key"
  4. Name it (e.g. Claude Desktop)
  5. Copy it immediately — starts with tlno_, shown only once

Manual Setup

Claude Desktop

Tip: `npx @tolen
Read from source at commit 686089a5b685OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp --env TOLENO_API_KEY=${TOLENO_API_KEY} -- npx -y @toleno/[email protected]
03

Exposed tools (13)

11 read · 2 write · 0 destructive.

ToolRiskDescription
claim_miningreadClaim mining rewards after a completed 24-hour session. Can only be called when a session has ended and rewards are ready to collect. Returns the amount of tokens claimed and the new balance.
generate_invite_linkwriteGenerate a shareable invite link and ready-to-send invite messages (in English and Turkish) for the authenticated Toleno user. Use this when the user wants to invite friends or share their referral link.
get_faqreadGet frequently asked questions about Toleno Network: what it is, how mining works, token withdrawal, blockchain info, pricing, referral system, Claude AI integration, and trustworthiness. This is a public tool — no API key required.
get_global_statsreadGet global Toleno Network statistics: total tokens mined across all users and total registered user count. This is a public endpoint — no API key required.
get_leaderboardreadGet the TOP 50 leaderboard of Toleno users ranked by token balance. Returns username, display name, token balance, mining power, and rank for each user. This is a public endpoint and requires no API key.
get_mining_statusreadGet the current mining session status for the authenticated Toleno user. Returns whether a session is active or completed, start/end times, elapsed and remaining time in milliseconds, tokens mined so far, total tokens to be earned, and whether rewards are ready to claim.
get_project_inforeadGet general information about Toleno Network: what it is, blockchain, token details, website, social links, and app download links. This is a public tool — no API key required.
get_referral_inforeadGet referral program details for the authenticated Toleno user. Returns the referral code (same as username), total number of users referred, number of currently active mining referrals, the referral bonus percentage applied to earnings, and the shareable referral link.
get_roadmapreadGet the Toleno Network development roadmap: completed phases, current progress, and upcoming milestones including Solana deployment and DEX listing. This is a public tool — no API key required.
get_security_inforeadGet Toleno Network security and trust information: security measures, trust indicators, and upcoming milestones. Use this when users ask
get_tokenomicsreadGet TOLENO tokenomics: total supply, distribution breakdown (mining, ecosystem, team, liquidity, marketing), mining mechanism details (session duration, rewards, halving model). This is a public tool — no API key required.
get_wallet_inforeadGet comprehensive wallet information for the authenticated Toleno user. Returns the available (withdrawable) token balance, locked mining balance, total tokens ever mined, the connected wallet address and preferred network (Solana), withdrawal statistics (today
start_miningwriteStart a new 24-hour mining session for the authenticated Toleno user. Can only be called when no active session exists. Returns the session details including start/end times and expected token earnings.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha 686089a5b685full audit observations/trust-audit/mcp-server/tolenonetwork__toleno.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06686089a5b685SAFEB89first audit
06

Questions

What is the Toleno MCP server?

Toleno Network MCP Server — Control your Toleno mining account directly from Claude AI using natural language.

What tools does Toleno expose?

13 in total: 11 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Toleno safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Toleno need?

It reads TOLENO_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Toleno run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @toleno/mcp at 1.0.6.

How current is this page?

The grade is for one exact copy of the source (686089a5b685), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement