Reputation MCP server
not respondingQuery cryptographically-verified trading reputations (humans + AI agents). ed25519-signed.
1 stars35 downloads/wk
Reviews
Write oneNobody has reviewed Reputation yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Reputation tools
Tool list not cached yet. `describe` through the gateway fetches it live.
Public scan report
scanner v0.1.9 · 2026-09-21 · same rubric, same numbers if you re-run it
- Code scan7 source files scanned25/25
- Live reliabilityremote unreachable: AbortError: This operation was aborted0/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 140 days ago8/15
- Maintainer identityregistry namespace matches repository owner; website matches verified namespace9/10
Findings (1)
- highRemote endpoint did not respond
reliability.unreachableAbortError: This operation was aborted
Install Reputation in Claude Code, Cursor or VS Code
claude mcp add --transport http reputation https://mcp.tradallo.com/mcp
What the publisher says
From the Reputation repository's README, as published. We do not edit it. Read it on GitHub
@tradallo/reputation
MCP server + TypeScript client + CLI for the Tradallo Verified Record Protocol. Three ways to query cryptographically-verified human and agent trading records:
# CLI — pretty terminal cards, no install required
npx @tradallo/reputation card alpha-momentum-v3 --agent
# MCP — drop into Claude Desktop / Cursor / any MCP client (config below)
# Programmatic — typed TS/JS client
import { TradalloClient } from "@tradallo/reputation";Every response is JCS-canonicalized + ed25519-verified against Tradallo's published pubkey at tradallo.com/.well-known/tradallo-pubkeys.json before being surfaced. The signature lives in the envelope; this client fetches the pubkey registry, resolves the keyid, verifies the signature, and only then returns the data. Replay protection via servedat + maxageseconds.
Install
Claude Desktop
Add to your claudedesktopconfig.json (Settings → Developer → Edit Config):
{
"mcpServers": {
"tradallo-reputation": {
"command": "npx",
"args": ["-y", "@tradallo/reputation"]
}
}
}Restart Claude Desktop. The Tradallo tools should appear in the tool palette.
Cursor
Add to ~/.cursor/mcp.json (or via Cursor Settings → MCP):
{
"mcpServers": {
"tradallo-reputation": {
"command": "npx",
"args": ["-y", "@tradallo/reputation"]
}
}
}Generic MCP client
npx @tradallo/reputationSpeaks MCP over stdio.
Local dev / staging
Point at your own deploy by setting TRADALLOBASEURL:
{
"mcpServers": {
"tradallo-reputation": {
"command": "npx",
"args": ["-y", "@tradallo/reputation"],
"env": { "TRADALLO_BASE_URL": "http://localhost:3000" }
}
}
}CLI
The same binary doubles as a terminal CLI when invoked with a subcommand:
# Pretty card with verification status, stats, version metadata
npx @tradallo/reputation card alpha-momentum-v3 --agent
# Raw verified JSON (for piping into jq, etc.)
npx @tradallo/reputation track-record alpha-momentum-v3 --agent
# Discovery
npx @tradallo/reputation search --min-sharpe 1.5 --min-trades 200 --sort-by sharpe
# Agent version history
npx @tradallo/reputation versions alpha-momentum-v3
# Paginated UTRs
npx @tradallo/reputation utrs alpha-momentum-v3 --limit 50
# Look up a specific UTR by hash
npx @tradallo/reputation verify <sha256-hex> alpha-momentum-v3
# Help
npx @tradallo/reputation helpNOCOLOR=1 disables ANSI. TRADALLOBASE_URL overrides the API base.
Programmatic client
Embed the verifying client in your own TS/JS code:
import { TradalloClient } from "@tradallo/reputation";
const client = new TradalloClient(); // defaults to https://tradallo.com
// Throws if signature invalid, replay window expired, or pubkey unknown.
// Returns the verified `data` payload (not the envelope wrapper).
const record = await client.getSigned<{ stats: { all_time: { sharpe_ratio: number | null } } }>(
"/api/v1/agents/alpha-momentum-v3/track-record",
);
if ((record.stats.all_time.sharpe_ratio ?? 0) >= 1.5) {
// ... delegate capital, copy trades, etc.
}The verification flow happens INSIDE getSigned. If anything fails — bad signature, expired envelope, unknown key, schema mismatch — the call throws. You never see unverified data.
Tools
gettrackrecord(handle, principal_type?)
Fetch a verified track record for a Tradallo profile or agent.
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Reputation: common questions
- Is Reputation MCP server safe?
- With care: it is graded C, so read the findings first (64/100). Read the Reputation safety report
- How do I install Reputation?
- It runs remotely at mcp.tradallo.com. Add it to Claude Code, Cursor, VS Code or Claude Desktop with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Reputation need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Reputation maintained?
- The last commit was 147 days ago (2026-05-04). The latest release is v0.3.2.
- Is Reputation up?
- 0% of our last 28 checks got an answer. We check remote servers about four times a day.