Atlas / MCP servers / tonnode / TON

TONCAUTION

mcp/tonnode/ton-2

TON MCP server for Claude, ChatGPT, Cursor, Codex and any MCP client — liteserver queries over native ADNL: balances, account state, transaction history, get-methods. Private & archive endpoints supported

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
16 15r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://glama.ai/mcp/servers/tonnode/mcp)

Русская версия

MCP server that gives AI agents direct liteserver access to The Open Network (TON) — no HTTP gateways in the middle. Balances, account state, transaction history and contract get-methods over TON's native ADNL protocol.

Built by TONNode — private TON liteservers, archive nodes, a mempool stream and a REST API (early access, on request).

Quick start

Add to Claude Desktop, Claude Code, ChatGPT, Cursor, Codex or any MCP client:

{
"mcpServers": {
"ton": {
"command": "npx",
"args": ["-y", "@tonnode/mcp"]
}
}
}

That's the whole integration. The server connects to TON mainnet via the public global config by default. Ready-made configs for every client — plus programmatic Node.js usage — live in examples/.

Tools

Naming note: the native coin was renamed from Toncoin to GRAM in June 2026; the network itself is still called TON. Tool outputs use *_gram fields.
Read from source at commit f4d0d7e9641fOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp -- npx -y @tonnode/[email protected]
03

Exposed tools (16)

15 read · 1 write · 0 destructive.

ToolRiskDescription
build_crosschain_refundread
build_crosschain_swap_txread
build_swap_txread
disclose_crosschain_secretread
generate_walletread
get_account_stateread
get_balanceread
get_crosschain_quoteread
get_jetton_balanceread
get_jetton_inforead
get_masterchain_inforead
get_swap_quoteread
get_transactionsread
parse_addressread
run_get_methodwrite
track_crosschain_swapread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/tonnode-mcp.service:12
# Check: curl -s http://127.0.0.1:8808/healthz
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/wallet.ts:30
"b5ee9c7241021001000228000114ff00f4a413f4bcf2c80b01020120020d02014803040078d020d74bc00101c060b0915be101d0d3030171b0915be0fa4030f828c705b39130e0d31f018210ae42e5a4ba9d8040d721d74cf82a01ed55fb04e03002012
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/allowlist.test.mjs:52
const res = await fetch(`http://127.0.0.1:${PORT}/mcp`, {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/allowlist.test.mjs:101
const res = await fetch(`http://127.0.0.1:${PORT}/mcp`, {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/auth-challenge.test.mjs:35
const URL_MCP = `http://127.0.0.1:${PORT}/mcp`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/usage-log-queue.test.mjs:58
const res = await fetch(`http://127.0.0.1:${PORT}/mcp`, {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @noble/hashes, @ston-fi/omniston-sdk, @ton/core, @ton/crypto, @ton/ton, ton-lite-client, zod
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:72
The agent drives the full atomic-swap lifecycle: quote → build (the tool generates the HTLC secret and hands it to the caller — the server keeps nothing) → sign & send → track both chains → disclose t
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f4d0d7e9641ffull audit observations/trust-audit/mcp-server/tonnode__ton-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f4d0d7e9641fCAUTIONB89first audit
06

Questions

What is the TON MCP server?

TON MCP server for Claude, ChatGPT, Cursor, Codex and any MCP client — liteserver queries over native ADNL: balances, account state, transaction history, get-methods. Private & archive endpoints supported

What tools does TON expose?

16 in total: 15 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is TON safe to connect to an agent?

With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does TON need?

It reads MAX_SESSIONS_PER_KEY, TONNODE_KEY, TONNODE_KEYS and TONNODE_KEYS_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does TON run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @tonnode/mcp at 0.9.3.

How current is this page?

The grade is for one exact copy of the source (f4d0d7e9641f), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement