Back to Browse

Hogswap MCP Server

Developer ToolsModerate5.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Pay any Algorand x402 invoice with any asset, plus DEX swap quotes and unsigned builds.

About

Pay any Algorand x402 invoice with any asset, plus DEX swap quotes and unsigned builds.

Remote endpoints: streamable-http: https://hogswap-v1.liquihog.dev/mcp/

Security Report

5.2
Moderate5.2Moderate Risk

HOGSWAP MCP server is well-designed with strong security fundamentals. The server properly handles authentication through optional API keys, never touches user private keys (returning only unsigned transactions), and implements proper input validation with Zod schemas. Code is clean and well-documented. Minor findings relate to logging practices and error handling details that do not represent material security risks. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

5 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

hsk_ HOGSWAP API key for the paid tier (self-issue with the register_agent/verify_registration tools). Free tools work without it.Required

Environment variable: HOGSWAP_API_KEY

API base URL (default https://hogswap-v1.liquihog.dev).Optional

Environment variable: HOGSWAP_API_URL

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

hogswap-mcp

MCP server exposing HOGSWAP to AI agents: DEX-aggregated quotes, unsigned swap builds, zero-human API-key self-registration, and the star — pay_x402_invoice: pay any Algorand-settled x402 invoice with any 1–4 assets you hold, via an exact-out router swap. API reference: hogswap-v1.liquihog.dev/reference. Building an app rather than an agent? Official SDKs: hogswap-js-sdk (npm) and hogswap-py-sdk (PyPI).

Strictly non-custodial: every transaction-producing tool returns unsigned groups; you sign with your own wallet tooling and submit yourself. Never give any tool a mnemonic or private key.

Run (stdio)

npm install
HOGSWAP_API_KEY=hsk_... node src/index.mjs        # key optional

Claude Code: claude mcp add hogswap -e HOGSWAP_API_KEY=hsk_... -- node <abs-path>/src/index.mjs

EnvMeaning
HOGSWAP_API_URLAPI base (default https://hogswap-v1.liquihog.dev)
HOGSWAP_API_KEYhsk_ bearer key; self-issue via the register_agent / verify_registration tools

Tools

Free (no key): list_payable_assets, get_quote, register_agent, verify_registration. get_quote takes optional max_legs (1–16) to cap total route legs, splits included — for replaying the route under your own resource budget.

🔑 Require a HOGSWAP API key (set HOGSWAP_API_KEY, or self-issue one with register_agent → sign → verify_registration): build_swap, pay_x402_invoice, get_credit_offer, get_balance, plus the watch tools set_watch / list_watches / delete_watch (standing server-side price/target alerts — free of charge, but namespaced by key). Without a key these return an auth error, not a build.

Watch fires are numbers-only hints — re-quote with get_quote when one fires. From MCP, poll list_watches; outside MCP the server pushes events over SSE at GET /watches/stream.

pay_x402_invoice returns two groups (swap, then payment) — sign all txns in one pass, submit the groups in order; the swap's on-chain floor guarantees the payment is funded. A HOGSWAP credit top-up's 402 offer is itself an x402 invoice: feed its accepts[0] (with the note nonce) straight into pay_x402_invoice to buy credits with any asset.

Remote (no local process)

The same 12 tools are served over MCP Streamable HTTP at https://hogswap-v1.liquihog.dev/mcp/ — hosted by the HOGSWAP API itself, no local process needed. Use the trailing slash — the bare /mcp 307-redirects to /mcp/, costing an extra round trip per call. Point any remote-capable MCP client at it; pass your key as Authorization: Bearer hsk_... (the Claude API connector's authorization_token does exactly this).

Smoke tests

HOGSWAP_API_KEY=hsk_... \
SMOKE_PAY_TO=<any USDC-opted addr> node test/smoke.mjs        # stdio

HOGSWAP_API_KEY=hsk_... \
SMOKE_PAY_TO=<any USDC-opted addr> node test/smoke-remote.mjs # remote

Both default to the live API; set HOGSWAP_API_URL (stdio) or MCP_URL (remote) to point them at another instance. Read-only + build-only; nothing is signed or broadcast.

Reviews

No reviews yet

Be the first to review this server!