TONCAUTION
TON MCP server for Claude, ChatGPT, Cursor, Codex and any MCP client — liteserver queries over native ADNL: balances, account state, transaction history, get-methods. Private & archive endpoints supported
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://glama.ai/mcp/servers/tonnode/mcp)
Русская версия
MCP server that gives AI agents direct liteserver access to The Open Network (TON) — no HTTP gateways in the middle. Balances, account state, transaction history and contract get-methods over TON's native ADNL protocol.
Built by TONNode — private TON liteservers, archive nodes, a mempool stream and a REST API (early access, on request).
Quick start
Add to Claude Desktop, Claude Code, ChatGPT, Cursor, Codex or any MCP client:
{
"mcpServers": {
"ton": {
"command": "npx",
"args": ["-y", "@tonnode/mcp"]
}
}
}That's the whole integration. The server connects to TON mainnet via the public global config by default. Ready-made configs for every client — plus programmatic Node.js usage — live in examples/.
Tools
Naming note: the native coin was renamed from Toncoin to GRAM in June 2026; the network itself is still called TON. Tool outputs use *_gram fields.f4d0d7e9641fOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp -- npx -y @tonnode/[email protected]
Exposed tools (16)
15 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
build_crosschain_refund | read | |
build_crosschain_swap_tx | read | |
build_swap_tx | read | |
disclose_crosschain_secret | read | |
generate_wallet | read | |
get_account_state | read | |
get_balance | read | |
get_crosschain_quote | read | |
get_jetton_balance | read | |
get_jetton_info | read | |
get_masterchain_info | read | |
get_swap_quote | read | |
get_transactions | read | |
parse_address | read | |
run_get_method | write | |
track_crosschain_swap | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
# Check: curl -s http://127.0.0.1:8808/healthz
"b5ee9c7241021001000228000114ff00f4a413f4bcf2c80b01020120020d02014803040078d020d74bc00101c060b0915be101d0d3030171b0915be0fa4030f828c705b39130e0d31f018210ae42e5a4ba9d8040d721d74cf82a01ed55fb04e03002012
const res = await fetch(`http://127.0.0.1:${PORT}/mcp`, {const res = await fetch(`http://127.0.0.1:${PORT}/mcp`, {const URL_MCP = `http://127.0.0.1:${PORT}/mcp`;const res = await fetch(`http://127.0.0.1:${PORT}/mcp`, {@modelcontextprotocol/sdk, @noble/hashes, @ston-fi/omniston-sdk, @ton/core, @ton/crypto, @ton/ton, ton-lite-client, zod
The agent drives the full atomic-swap lifecycle: quote → build (the tool generates the HTLC secret and hands it to the caller — the server keeps nothing) → sign & send → track both chains → disclose t
Gates applied: no_behavioural_pass.
f4d0d7e9641ffull audit observations/trust-audit/mcp-server/tonnode__ton-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f4d0d7e9641f | CAUTION | B | 89 | first audit |
Questions
What is the TON MCP server?
TON MCP server for Claude, ChatGPT, Cursor, Codex and any MCP client — liteserver queries over native ADNL: balances, account state, transaction history, get-methods. Private & archive endpoints supported
What tools does TON expose?
16 in total: 15 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is TON safe to connect to an agent?
With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does TON need?
It reads MAX_SESSIONS_PER_KEY, TONNODE_KEY, TONNODE_KEYS and TONNODE_KEYS_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does TON run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @tonnode/mcp at 0.9.3.
How current is this page?
The grade is for one exact copy of the source (f4d0d7e9641f), read on 2026-10-08. The repository is watched and re-audited when it changes.