
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@three-ws/pumpfun-mcp
Advanced tools
Free, read-only pump.fun + Solana MCP server — token discovery, on-chain bonding-curve & holder analysis, creator fee-claim tracking, SNS resolution, KOL signals, and swap quotes. No API keys.
Free, read-only pump.fun + Solana MCP server — token discovery, on-chain analysis, and live 3D snapshots. No API keys.
Install · Quick start · Tools · Configuration · three.ws
A free, read-only Model Context Protocol server for pump.fun and Solana. It gives Claude — or any MCP client — live token discovery, on-chain bonding-curve and holder analysis, creator fee-claim tracking, Solana Name Service resolution, KOL signals, read-only swap quotes, and shareable live 3D token snapshots. Every Solana RPC and pump.fun API call runs server-side on the canonical three.ws backend, so the data is live and on-chain while the client stays zero-config: no API keys, no RPC URL, no wallet.
claude mcp add pumpfun -- npx -y @three-ws/pumpfun-mcp
Add to your MCP config (claude_desktop_config.json, .cursor/mcp.json, .mcp.json, etc.):
{
"mcpServers": {
"pumpfun": {
"command": "npx",
"args": ["-y", "@three-ws/pumpfun-mcp"]
}
}
}
Restart the client and the pump.fun tools appear. No install step required.
npx -y @three-ws/pumpfun-mcp
# or install globally and run the bin
npm i -g @three-ws/pumpfun-mcp && pumpfun-mcp
The server speaks stdio JSON-RPC — your MCP client spawns it via the npx command above. Once configured, ask your client natural-language questions and it picks the right tool:
"What's trending on pump.fun right now?" → get_trending_tokens
"Show the bonding curve for <mint>" → get_bonding_curve
"Who are the top holders of <mint>?" → get_token_holders
"Resolve bonfida.sol" → sns_resolve
"Build a 3D snapshot for <mint>" → pumpfun_token_3d
All tools are read-only — nothing signs or sends a transaction. pumpfun_quote_swap only quotes; pumpfun_vanity_mint returns a keypair for you to use yourself.
| Tool | What it does |
|---|---|
search_tokens | Search pump.fun tokens by name, symbol, or mint. |
get_token_details | Full metadata for a mint. |
get_bonding_curve | Real/virtual quote reserves + graduation progress for a coin still on the curve (on-chain). |
get_token_trades | Recent buy/sell history for a token. |
get_trending_tokens | Top tokens by market cap. |
get_new_tokens | Most recently launched tokens. |
get_graduated_tokens | Tokens that graduated to the Raydium AMM. |
get_king_of_the_hill | Highest-cap token still on the bonding curve. |
get_token_holders | Top holders with concentration analysis (on-chain). |
get_creator_profile | A creator's tokens with rug-pull risk flags. |
kol_radar | gmgn-style early-detection radar signals. |
kol_leaderboard | Top KOL traders ranked by P&L. |
pumpfun_list_claims | Recent creator fee-claim events (on-chain). |
pumpfun_watch_claims | Fee claims for a creator within a look-back window. |
pumpfun_first_claims | First-ever creator claims — a cash-out signal. |
pumpfun_quote_swap | Read-only PumpSwap AMM swap quote for a graduated coin (no signing). |
pumpfun_watch_whales | Collect large trades on a token over a short window. |
pumpfun_vanity_mint | Grind a vanity Solana keypair (secret returned to caller, never stored). |
sns_resolve | Resolve a .sol domain to its owner wallet. |
sns_reverseLookup | Reverse-lookup a wallet to its primary .sol domain. |
social_cashtag_sentiment | Deterministic lexicon sentiment over supplied posts. |
social_x_post_impact | Correlate an X post to bonding-curve price impact. |
pumpfun_token_3d | Live 3D snapshot of a token — composes metadata, holders, and graduation into a shareable three.ws/coin3d viewer (spinning coin medallion + holder galaxy + graduation ring) and returns the deep-link, an embeddable iframe, and the underlying data. |
The live tool list is fetched from the backend at startup; a bundled copy ships as an offline fallback so a fresh install always advertises a correct surface.
A pump.fun coin has two lifetimes, priced by two different on-chain accounts. Every tool here belongs to exactly one of them, and reading a number from the wrong one is the classic way to get a confidently wrong answer.
Before graduation: the pump program BondingCurve account. Spot price is virtual_quote_reserves / virtual_token_reserves. Those quote-side fields were renamed upstream (virtual_sol_reserves → virtual_quote_reserves, real_sol_reserves → real_quote_reserves) when a non-SOL quote asset became possible, and the curve gained a quote_mint, which is the SOL default on every coin created to date. The rename is the same u64 at the same offset, so the response fields virtualSolReserves / solReserves keep their names and stay SOL-denominated. Served by get_bonding_curve and social_x_post_impact.
After graduation: the PumpSwap (pump_amm) Pool account. Quotes price against the effective quote reserve:
effective_quote_reserves = pool_quote_token_account.amount + pool.virtual_quote_reserves
pool.virtual_quote_reserves is an appended Pool field that carries a non-zero value on launchpad coins from 2026-07-20; on every other pool it is 0 and the effective reserve equals the vault balance exactly. Buys and sells both price on the effective figure, and priceImpactBps measures execution against the spot price it implies, so virtual liquidity reads as depth rather than as impact. The base side is unchanged: still the raw pool_base_token_account.amount. Served by pumpfun_quote_swap.
The two virtual_quote_reserves are different fields on different accounts that happen to share a name. A coin has one or the other, never both. If get_bonding_curve returns complete: true, stop reading the curve and quote the pool.
Upstream reference: pump-public-docs.
npx -y @modelcontextprotocol/inspector npx @three-ws/pumpfun-mcp
No configuration is required. One optional override exists:
| Env var | Default | Purpose |
|---|---|---|
PUMPFUN_MCP_URL | https://three.ws/api/pump-fun-mcp | Backend endpoint. Override only to self-host the handler. |
This package is a small stdio ↔ HTTP bridge. It forwards MCP tools/call requests to the canonical three.ws pump.fun JSON-RPC backend, which performs the actual Solana RPC reads and pump.fun API queries. That keeps one authoritative implementation, ships no secrets to clients, and means the tool surface stays current automatically.
pumpfun_token_3d is a native tool: it runs in-process, orchestrating several backend reads (metadata + bonding curve + holders) and resolving the token logo from its on-chain metadata URI, then returns a deep-link into the three.ws 3D viewer. It needs no extra keys and adds no new backend dependency.
engines).PUMPFUN_MCP_URL).@three-ws/mcp-server — the paid, x402-settled three.ws MCP (text→3D mesh, avatars, pose seeds, ERC-8004 reputation, and a paid pump_snapshot).
Part of the three.ws SDK suite — 3D AI agents, on-chain identity, and agent payments.
Website · Changelog · GitHub
All rights reserved. See LICENSE.
FAQs
Free, read-only pump.fun + Solana MCP server — token discovery, on-chain bonding-curve & holder analysis, creator fee-claim tracking, SNS resolution, KOL signals, and swap quotes. No API keys.
We found that @three-ws/pumpfun-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.