
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
cambrian-api-mcp
Advanced tools
Model Context Protocol server for Cambrian API - Access comprehensive DeFi data across Solana and EVM chains
Model Context Protocol server for the Cambrian API. It exposes the same product surface as the cambrian CLI for agents that need live DeFi, social intelligence, risk, and API documentation tools.
Every call needs a Cambrian API key supplied by the caller. The hosted server and local package both require one; the server never ships or proxies a shared key.
Create a key at https://console.cambrian.org/. For x402 pay-per-call access
without an API key, use cambrian pay --help; MCP transport still requires a
caller-supplied key.
cambrian_docs for live endpoint and guide docs from https://docs.cambrian.org/llms.txtNew users and agent runtimes should start here: skills/cambrian-mcp/SKILL.md. It covers Cambrian API key auth, hosted and local client config, tool naming, cambrian_docs lookup, composite tools, response limits, and error handling in one document.
For the CLI instead of MCP, see the cambrian CLI skill.
The cambrian CLI prints and tests ready-to-use MCP client config:
npm install -g cambrian
cambrian mcp config --mode hosted
cambrian mcp config --mode local
cambrian mcp install --client claude --mode hosted
cambrian mcp test --mode hosted
Run the published package directly:
export CAMBRIAN_API_KEY=<your-api-key>
npx -y cambrian-api-mcp
Or install it globally:
npm install -g cambrian-api-mcp
export CAMBRIAN_API_KEY=<your-api-key>
cambrian-api-mcp
Use the CLI to print the current hosted URL and client-specific config:
cambrian mcp config --mode hosted
Direct Claude setup:
claude mcp add --transport http cambrian \
https://mcp.cambrian.org/mcp \
--header "Authorization: Bearer YOUR_CAMBRIAN_API_KEY"
HTTP requests must include one of:
Authorization: Bearer <CAMBRIAN_API_KEY>
X-Cambrian-Api-Key: <CAMBRIAN_API_KEY>
npm install
npm run build
node dist/index.js --transport http --host 127.0.0.1 --port 8080
Health endpoint:
curl http://127.0.0.1:8080/health
For hosted deployments, bind to 0.0.0.0:
node dist/index.js --transport http --host 0.0.0.0 --port 8080
Tool names are canonical and prefixed with cambrian_.
Examples:
cambrian_base_dexescambrian_ethereum_dexescambrian_solana_price_currentcambrian_deep42_social_data_alpha_tweet_detectioncambrian_risk_perp_risk_enginecambrian_docscambrian_solana_token_snapshotCall cambrian_docs without a path to discover the live root index, or use
guides/<slug> (for example, guides/x402) for any guide listed there.
Endpoint tools come from the same validated runtime registry as the CLI. MCP rechecks that local cache for each tool-list/tool-call request, while OpenAPI network attempts are coalesced and limited to once per source every 15 minutes. If runtime discovery is unavailable, the installed bundled inventory remains available without changing existing tool names or schemas.
Visible EVM operations that advertise chain_id=1 also expose
cambrian_ethereum_* tools. Base tools fix chain_id to 8453. Ethereum
tools fix it to 1.
npm ci
npm test
npm run build
npm pack --dry-run
The package depends on the published cambrian package for shared metadata and the API client. Publish cambrian first when changing both packages together, then refresh this package lock and deploy the MCP server through CI/CD.
Deployments are handled by GitHub Actions and Cloud Run from the private source repository. Do not deploy manually.
The workflow:
package.json#mcpName matches server.json#namepackage.json#version matches server.json#versionThe official MCP Registry publishes this server under:
io.github.cambriannetwork/cambrian-api
The manifest uses https://mcp.cambrian.org/mcp, which matches the production edge URL. The public release workflow publishes each new Registry version after npm publication.
FAQs
Model Context Protocol server for Cambrian API - Access comprehensive DeFi data across Solana and EVM chains
We found that cambrian-api-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.