Hyblock Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Hyblock Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server exposing the full Hyblock Capital API as tools for AI assistants (Claude, Gemini, etc.).
Transport: HTTP (MCP over stdio → upstream calls via HTTPS to Hyblock API)
| Category | Tools |
|---|---|
| System | ping, catalog, data_availability |
| Orderflow | klines, buy_volume, sell_volume, volume_delta, volume_ratio, anchored_cvd, bot_tracker, slippage, transfer_of_contracts, participation_ratio, market_order_count, market_order_average_size, limit_order_count, limit_order_average_size, buy_sell_trade_count_ratio, limit_order_count_ratio, market_order_count_ratio, exchange_premium, pd_levels |
| Funding Rate | funding_rate |
| Longs & Shorts | top_trader_accounts, top_trader_positions, global_accounts, net_long_short, whale_retail_delta, trader_sentiment_gap |
| Orderbook | bid_ask, bid_ask_ratio, bid_ask_delta, combined_book, market_imbalance_index |
| Global Metrics | global_bid_ask_ratio, global_combined_book |
| Open Interest | open_interest, open_interest_delta |
| Options | bvol, dvol |
| Sentiment | margin_lending_ratio, fear_and_greed_index, user_bot_ratio |
| Liquidity | liquidation, liq_levels_count, liq_levels_size, liquidation_heatmap, avg_leverage_used |
| Profile Tool | indicator_profile, coin_profile |
client_id, client_secret, and x-api-key from the API Explorergit clone <repo-url>
cd mcp
npm install
npm run buildSet these environment variables before running (locally or in Railway):
export HYBLOCK_CLIENT_ID="your_client_id"
export HYBLOCK_CLIENT_SECRET="your_client_secret"
export HYBLOCK_API_KEY="your_api_key"Add the server to your MCP client configuration (e.g., claude_desktop_config.json).
Use this if you are running the server on your own machine.
{
"mcpServers": {
"hyblock-local": {
"command": "node",
"args": ["mcp/dist/index.js"],
"env": {
"HYBLOCK_CLIENT_ID": "your_client_id",
"HYBLOCK_CLIENT_SECRET": "your_client_secret",
"HYBLOCK_API_KEY": "your_api_key"
}
}
}
}Use this if you have deployed the server to Railway. This uses the SSE (Server-Sent Events) over HTTP transport.
#### Setup in Railway
HYBLOCK_CLIENT_IDHYBLOCK_CLIENT_SECRETHYBLOCK_API_KEYDockerfile to build and deploy. It will automatically assign a PORT.#### How to "Enter" in MCP Clients Once live, your server will have a base URL (e.g., https://hyblock-mcp-production.up.railway.app).
For most MCP clients (like Claude Desktop), you must point them to the /sse endpoint, not the bare root:
{
"mcpServers": {
"hyblock-remote": {
"url": "https://your-railway-app.up.railway.app/sse"
}
}
}Note: If your client doesn't support the `url` field yet, you can use a small node bridge or the local version.
If you see ❌ API Error (401) or ❌ API Error (403) from any Hyblock tools, first verify that:
HYBLOCK_CLIENT_ID, HYBLOCK_CLIENT_SECRET, and HYBLOCK_API_KEY are correctly set in the server environment (Railway or local)./sse endpoint as shown above.The server implements the OAuth2 Client Credentials flow automatically:
client_id:client_secret (Base64 encoded) for a Bearer token via POST /oauth2/tokenThe server exposes 53 tools across these areas:
Most tools accept these optional parameters:
| Parameter | Type | Description |
|---|---|---|
timeframe | string | 1m, 5m, 15m, 1h, 4h, 1d |
limit | number | Records to return (max 1000) |
startTime | number | Start of range (Unix ms) |
endTime | number | End of range (Unix ms) |
sort | string | asc or desc |
Tip: Callhyblock_catalogfirst to discover validcoinandexchangevalues.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.