# io.fuse/mcp

MCP server for Fuse Network: balances, tokens, staking, DeFi data, swaps and on-chain transactions.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** io.fuse
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.fuse.io/mcp
- **Source:** https://www.fuse.io
- **Endpoint health:** reachable (last checked 2026-09-26T17:07:56.527Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 27 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-07T21:47:10.054Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

50 declared. Observed from a live `tools/list` probe.
- `fuse_get_balance` — Returns the native FUSE balance for an address, or an ERC-20 token balance when `tokenAddress` is supplied.
- `fuse_get_transaction` — Fetches a transaction by hash. Returns null if the transaction is not found.
- `fuse_get_receipt` — Fetches the receipt for a mined transaction (status, gasUsed, logs). Returns null if the transaction is pending or unknown.
- `fuse_read_contract` — Calls a view/pure function on a Fuse contract. ABI is auto-fetched from the verified Fuse explorer when not supplied.
- `fuse_get_token_metadata` — Reads name, symbol, decimals, and totalSupply for an ERC-20 token deployed on Fuse.
- `fuse_get_gas_price` — Returns the current Fuse network gas price (in wei and gwei) along with EIP-1559 fee suggestions when available.
- `fuse_resolve_ens` — Resolves an ENS name to its EVM address. ENS is not deployed on Fuse — resolution requires `ENS_RPC_URL` to be configured (typically pointing at Ethereum mainne
- `fuse_get_account_abstraction_info` — Reads ERC-4337 state for a smart account on Fuse: deployment status, EntryPoint nonce, and the account's deposit balance at the EntryPoint. Paymaster eligibilit
- `fuse_list_wallet_tokens` — Lists all ERC-20 tokens held by a wallet on Fuse, enriched with Fusebox metadata (symbol, decimals, USD value). Powered by the Fusebox SDK BalancesModule.
- `fuse_list_wallet_nfts` — Lists all NFTs (ERC-721 / ERC-1155 collectibles) owned by a wallet on Fuse. Powered by the Fusebox SDK BalancesModule.
- `fuse_get_staking_options` — Lists every staking option supported by Fuse — token, APR, TVL, expiry, and the matching unstake token. Powered by the Fusebox SDK StakingModule.
- `fuse_get_staked_tokens` — Returns the active staking positions for a wallet — staked amount, USD value, earned rewards, and APR per position. Powered by the Fusebox SDK StakingModule.
- `fuse_get_token_price` — Returns the current USD price for an ERC-20 token tracked by Fusebox. Powered by the Fusebox SDK TradeModule.
- `fuse_get_token_price_change` — Returns the 24-hour percentage price change for an ERC-20 token tracked by Fusebox. Powered by the Fusebox SDK TradeModule.
- `fuse_get_token_price_history` — Returns OHLC / interval price stats for an ERC-20 token over a week, month, or year. Powered by the Fusebox SDK TradeModule.
- `fuse_list_supported_tokens` — Returns the catalogue of ERC-20 tokens tracked by Fusebox (tradable, indexed, priced). Powered by the Fusebox SDK TradeModule.
- `fuse_get_trade_quote` — Quotes a token swap on Fuse — expected output amount, route, and price impact. Read-only: returns the quote without submitting a trade. Powered by the Fusebox S
- `fuse_get_user_operations` — Returns the ERC-4337 UserOperation history for a smart account on Fuse, indexed via the Fusebox GraphQL service. Powered by the Fusebox SDK GraphQLModule.
- `fuse_notification_create_webhook` — Create a Fusebox Notification webhook for a project. Requires `FUSEBOX_SECRET_API_KEY` (Notification API endpoints authenticate with both apiKey and API-SECRET)
- `fuse_notification_get_webhook` — Retrieve details of a single Fusebox Notification webhook. Requires `FUSEBOX_SECRET_API_KEY`.
- `fuse_notification_list_project_webhooks` — List every Fusebox Notification webhook configured for a given project. Requires `FUSEBOX_SECRET_API_KEY`.
- `fuse_notification_update_webhook` — Update a Fusebox Notification webhook's URL or event type. Requires `FUSEBOX_SECRET_API_KEY`.
- `fuse_notification_delete_webhook` — Permanently delete a Fusebox Notification webhook. Destructive — the webhook stops receiving events. Requires `FUSEBOX_SECRET_API_KEY`.
- `fuse_notification_add_addresses` — Add one or more EVM addresses to a webhook's listening scope. Requires `FUSEBOX_SECRET_API_KEY`.
- `fuse_notification_remove_addresses` — Remove EVM addresses from a webhook's listening scope. Requires `FUSEBOX_SECRET_API_KEY`.
- `fuse_notification_list_addresses` — List every EVM address monitored by a given webhook. Requires `FUSEBOX_SECRET_API_KEY`.
- `fuse_smart_wallet_authenticate` — Exchange an EIP-191 signature for a JWT used as Bearer auth on Smart Wallet API calls (e.g. `fuse_smart_wallet_get_actions`). Signing happens client-side; this 
- `fuse_smart_wallet_get_actions` — List the paginated action history (transfers, contract calls) of an authenticated smart wallet. The JWT comes from `fuse_smart_wallet_authenticate`.
- `fuse_trade_indicative_price` — Returns an indicative price + route for a swap on Fuse (0x-style response). One of `sellAmount` / `buyAmount` must be provided.
- `fuse_trade_liquidity_sources` — Returns the liquidity sources currently enabled for Fuse-chain trades (e.g. voltage.finance, sub-pools).
- `fuse_trade_price_change_over_duration` — Returns a token's price change over a custom day-count window (`{ priceChange, currentPrice, previousPrice }`).
- `fuse_explorer_query` — Generic dispatcher for the Fusebox Explorer API (`/api/v0/explorer/`). Pass `module` + `action` + any additional query params. Covers all 40+ etherscan-compatib
- `fuse_get_signer_address` — Returns the EOA address controlled by the server's configured `FUSE_PRIVATE_KEY`. Use this before any write tool to confirm which account will pay gas and send 
- `fuse_send_native` — Submits a signed transaction transferring native FUSE from the server's signer to a recipient. Returns the transaction hash; use `fuse_get_receipt` to confirm i
- `fuse_send_erc20` — Submits a signed `ERC20.transfer(to, amount)` from the server's signer. Decimals are auto-fetched from the token; use `unit: "base"` to skip scaling.
- `fuse_write_contract` — Signs and submits a state-mutating contract call from the server's signer. ABI is auto-fetched from the Fuse explorer when not supplied. Returns the transaction
- `fuse_deploy_contract` — Signs and submits a contract-deployment transaction using the server's signer. Returns the transaction hash, and the deployed contract address when `waitForRece
- `fuse_sign_message` — Signs a message with the server's signer using EIP-191 (`personal_sign`). Returns the 65-byte signature as hex. No on-chain transaction is submitted.
- `fuse_sign_typed_data` — Signs a structured EIP-712 payload with the server's signer. Returns the 65-byte signature as hex. No on-chain transaction is submitted.
- `fuse_smart_get_info` — Returns the ERC-4337 smart-wallet address derived from the configured signer, plus whether the Fuse paymaster (gasless mode) is enabled.
- …and 10 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.fuse.io/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive blast radius — deletes data; runs on someone else's infrastructure.
- Floor 34, ceiling 58 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.fuse%2Fmcp
- Install plan: https://forgeregistry.com/api/v1/packages/io.fuse%2Fmcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.fuse%2Fmcp
- HTML page: https://forgeregistry.com/registry/io.fuse%2Fmcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
