Hosted, by URL
- Approving takes a signature from your wallet. A signed-in session alone grants nothing.
- The grant appears under Developers as an ordinary API key. It expires after 90 days, you are told in Telegram (when linked) whenever one is created, and you can revoke it there.
- Clients that do not speak OAuth can send a key they created themselves:
Authorization: Bearer hk_….
How the OAuth flow works
How the OAuth flow works
Standard OAuth 2.1, so a compliant client drives it unattended.
Codes are single-use and expire in 60 seconds. Redirect URIs are allowlisted; loopback is permitted per RFC 8252. The issued token is the API key, so a grant is revocable from the same list as every other key.
hashlock and keeps the preimage.
Amounts in the hosted tools are base-unit integer strings, as in the REST API.
Hosted tools
Local, over stdio
Run the npm package with your own keys (testnet keys until launch). It logs in by itself (nonce → sign → session) and can fund and claim on chain with those keys.
The first configured key (EVM → TRON → BTC → Solana) opens the session; each key also signs settlement on its chain. With no key set, the read-only tools (
list_assets, list_open_rfqs, get_rfq) still work.
The swap secret is generated locally and stored at HASHLOCK_SECRETS_PATH (default ~/.hashlock/mcp-secrets.json, mode 0600). Only its hashlock leaves the machine.
Local amounts are human decimal strings ("0.5"), and prices are the total quote-asset amount, not per unit.
Local tools
With a key for each chain a swap touches, an agent can run the whole loop with no human:
create_rfq / respond_to_rfq → negotiate (accept) → set_settlement_address → fund_leg → claim_leg.
Errors return a structured envelope { error: { code, is_retryable, recovery_hint } } that an agent can branch on.