hive-mcp-aml-screen
Enables AML screening of blockchain addresses against OFAC SDN lists and chain heuristics, returning risk scores and flags.
README
hive-mcp-aml-screen
AML screening broker for the A2A network. Send an address and a chain. Receive a 0–100 observational risk score, an OFAC SDN match flag, and chain-heuristic categories. Cached for 24 hours.
Hive does not block, freeze, or settle. This is observational AML data only. Customer is responsible for compliance decisions.
- Sources — daily-refreshed OFAC SDN list (treasury.gov), live Base mainnet RPC reads, conservative mixer-contract seed list
- Scoring — 0–100 with bands (
minimal,low,medium,high,critical) - Pricing — $0.03 per single address, $0.025 per address for bulk (10-address minimum), settled via x402 in USDC on Base
- Cache — 24 hours per
(chain, address) - Mode — inbound only,
ENABLE=trueby default
The shim is a broker. It returns observational data. It never blocks, freezes, or settles on behalf of a customer, and it never replaces a regulated KYC/AML provider.
Endpoints
| Method | Path | Cost | Purpose |
|---|---|---|---|
POST |
/v1/aml/screen |
$0.03 | Screen one address |
POST |
/v1/aml/bulk |
$0.025/addr (min 10) | Screen many addresses in one call |
GET |
/v1/aml/today |
free | UTC-day counters and OFAC list status |
GET |
/health |
free | Liveness, OFAC list status, pricing |
POST |
/mcp |
— | JSON-RPC 2.0 entry for MCP clients |
GET |
/.well-known/mcp.json |
free | MCP descriptor |
POST |
/v1/x402/submit |
— | Settle a 402 quote, mint an access token |
MCP tools
| Tool | Cost | Description |
|---|---|---|
aml_screen |
$0.03 | Single-address screening |
aml_bulk_screen |
$0.025/addr | Bulk screening, 10-address minimum |
aml_today |
free | Counters and OFAC list status |
Every response — JSON-RPC and REST alike — carries the disclaimer field:
"disclaimer": "Hive does not block, freeze, or settle. This is observational AML data only. Customer is responsible for compliance decisions."
Quickstart
curl -sX POST https://hive-mcp-aml-screen.onrender.com/v1/aml/screen \
-H 'content-type: application/json' \
-d '{"address":"0x8589427373d6d84e98730d7795d8f6f8731fda16","chain":"base"}'
The first call returns a 402 envelope with a quote. Settle on Base in USDC, then resubmit the proof to /v1/x402/submit to mint an access token, and replay the request with X-Hive-Access: <token>.
curl -sX POST https://hive-mcp-aml-screen.onrender.com/v1/x402/submit \
-H 'content-type: application/json' \
-d '{"nonce":"...","payer":"0x...","chain":"base","tx_hash":"0x..."}'
Response shape
{
"ok": true,
"address": "0x8589427373d6d84e98730d7795d8f6f8731fda16",
"chain": "base",
"risk_score": 100,
"risk_band": "critical",
"flags": [
{"category": "ofac_sdn_match", "severity": "critical", "detail": "OFAC SDN list match: program=CYBER2 sdn_uid=12345"},
{"category": "mixer_contract", "severity": "high", "detail": "address is a known mixer/sanctioned-protocol contract"}
],
"sdn_match": true,
"sdn_record": {"sdn_uid": "12345", "sdn_name": "TORNADO CASH", "program": "CYBER2"},
"chain_detail": {"nonce": 0, "is_contract": true, "balance_wei": "0", "head_block": 12345678},
"sources": {
"ofac_sdn": {"list_size": 8421, "last_refresh_ms": 1745798400000},
"heuristics": {"chain": "base", "version": "v1"}
},
"cache_hit": false,
"cache_ttl_seconds": 86400,
"screened_at": 1745875200000,
"screening_id": "8a3f...",
"disclaimer": "Hive does not block, freeze, or settle. This is observational AML data only. Customer is responsible for compliance decisions."
}
Heuristics
For EVM chains the shim performs four real Base RPC reads — getTransactionCount, getCode, getBalance, getBlockNumber — plus a binary search over historical blocks to estimate the wallet's earliest activity. Categories returned in flags:
| Category | Severity | Trigger |
|---|---|---|
ofac_sdn_match |
critical | Address appears in the daily OFAC SDN list |
mixer_contract |
high | Address is a known mixer/sanctioned-protocol contract |
very_new_wallet |
medium | First on-chain activity within 24 hours |
high_velocity |
medium | ≥ 20 outbound tx per hour over wallet lifetime |
mixer_adjacent_balance |
low | Balance is exactly 0.1 / 1 / 10 / 100 ETH (Tornado pool denominations) |
no_outbound_history |
low | Address has never sent a transaction on this chain |
rpc_unavailable |
low | RPC read failed; SDN-only signal returned |
heuristic_error |
low | Internal heuristic error; SDN-only signal returned |
Non-EVM chains return the SDN match signal only with a note in chain_detail.
Configuration
| Env | Default | Purpose |
|---|---|---|
PORT |
3000 |
HTTP port |
ENABLE |
true |
Master switch. Set false to short-circuit all paid endpoints with 503 |
WALLET_ADDRESS |
0x15184bf50b3d3f52b60434f8942b7d52f2eb436e |
x402 settlement recipient (W1 MONROE) |
BASE_RPC_URL |
https://mainnet.base.org |
Base mainnet RPC for chain heuristics |
OFAC_SDN_URL |
https://www.treasury.gov/ofac/downloads/sdn.csv |
Source URL for the SDN list |
DB_PATH |
/tmp/aml.db |
SQLite database file |
MIXER_ADDRESSES |
(empty) | Comma-separated list of extra mixer contract addresses to flag |
X402_BYPASS |
(unset) | Set to any value to bypass payment in development |
Persistence
SQLite at /tmp/aml.db with WAL journaling.
ofac_sdn—(address PK, sdn_uid, sdn_name, program, list_type, inserted_at)— wiped and re-inserted on each refreshofac_meta— refresh timestamp, count, byte size, last errorscreenings— every screen call, billed or cachedcache—(chain:address) → JSON payload, 24-hour TTL
Operational notes
- The OFAC list is refreshed at boot and every 24 hours thereafter
- Cache entries are pruned hourly
- Body limit is 256 KB on JSON requests
- Inbound only — the shim never initiates outbound calls beyond the OFAC fetch and Base RPC reads
License
MIT — see LICENSE.
Hive Civilization Directory
Part of the Hive Civilization — agent-native financial infrastructure.
- Endpoint Directory: https://thehiveryiq.com
- Live Leaderboard: https://hive-a2amev.onrender.com/leaderboard
- Revenue Dashboard: https://hivemine-dashboard.onrender.com
- Other MCP Servers: https://github.com/srotzin?tab=repositories&q=hive-mcp
Brand: #C08D23 <!-- /hive-footer -->
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。