
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@verusidx/data-mcp
Advanced tools
MCP server for Verus on-chain data retrieval, decryption, signing, and verification
MCP server for Verus on-chain data retrieval, decryption, signing, and verification. Completes the store-retrieve-decrypt pipeline that starts with sendcurrency:data (send-mcp), and provides signing/verification tools for off-chain data workflows.
Prerequisite: @verusidx/chain-mcp must be configured and refresh_chains called at least once so the chain registry exists.
Add to your MCP client config (e.g., Claude Code claude_desktop_config.json):
{
"mcpServers": {
"verusidx-data": {
"command": "npx",
"args": ["-y", "@verusidx/data-mcp"],
"env": {}
}
}
}
Alternative: local install. If you prefer a pinned version or offline use, install into a project directory with npm install @verusidx/data-mcp (or pnpm add / yarn add) and point your config at the local path instead of using npx.
| Variable | Default | Description |
|---|---|---|
VERUSIDX_READ_ONLY | false | Set to true to disable write tools (z_importviewingkey). All other tools including signdata and verifysignature remain available. |
VERUSIDX_AUDIT_LOG | true | Set to false to disable audit logging of write operations. |
VERUSIDX_AUDIT_DIR | OS default | Custom directory for audit log files. |
Set VERUSIDX_READ_ONLY=true to disable write tools. In read-only mode, 6 tools remain available:
z_listreceivedbyaddress — list data/transactions received at a z-addressdecryptdata — decrypt on-chain dataz_exportviewingkey — export viewing key for read-only decryption accessz_viewtransaction — inspect shielded transaction detailssigndata — sign data (does not modify chain or wallet state)verifysignature — verify signatures (does not modify chain or wallet state)Write tools (z_importviewingkey) are not registered and won't appear in the tool list.
You can set read-only mode independently per MCP server.
| Tool | Description |
|---|---|
z_listreceivedbyaddress | List transactions and data received at a shielded address. Data txs have amount: 0 with a data descriptor in the memo. |
decryptdata | Decrypt on-chain data using a data descriptor, optional viewing key, and txid. Supports both z-address data and identity content. |
z_exportviewingkey | Export the extended viewing key (EVK) for a z-address. Grants read-only decryption access. |
z_viewtransaction | View detailed shielded transaction information including spends, outputs, and memos. |
signdata | Sign data with a VerusID or R-address. Supports message, file, hex, base64, hash, vdxfdata, and MMR inputs. Can encrypt to a z-address. |
verifysignature | Verify a signature produced by signdata. Checks against identity keys at signing height or current keys. |
| Tool | Description |
|---|---|
z_importviewingkey | Import a viewing key to enable decryption of data encrypted to another z-address. |
Store: sendcurrency:data (send-mcp)
|
List: z_listreceivedbyaddress (data-mcp)
|
Decrypt: decryptdata + z_exportviewingkey (data-mcp)
Sign: signdata (data-mcp)
Verify: verifysignature (data-mcp)
Share access: z_exportviewingkey -> z_importviewingkey (data-mcp)
List received data — call z_listreceivedbyaddress with the z-address. Data transactions appear with amount: 0 and a memo containing the data descriptor.
Export viewing key (if needed) — call z_exportviewingkey to get the EVK. Skip this if the wallet already holds the z-address spending key.
Decrypt — call decryptdata with the data descriptor from step 1, the txid, retrieve: true, and the EVK from step 2. Returns hex-encoded decrypted content.
Decode — the objectdata field is hex. For text messages, decode hex to UTF-8.
Write operations (z_importviewingkey) are logged to date-stamped JSONL files in the audit directory. Each entry records the tool name, chain, parameters, result, and success status. Logs are append-only with 0600 permissions.
@verusidx/chain-mcp installed and refresh_chains called (chain registry must exist)FAQs
MCP server for Verus on-chain data retrieval, decryption, signing, and verification
The npm package @verusidx/data-mcp receives a total of 13 weekly downloads. As such, @verusidx/data-mcp popularity was classified as not popular.
We found that @verusidx/data-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.