xrpl-identity-mcp
xrpl-identity-mcp is the first identity-focused MCP server for the XRP Ledger: DIDs (XLS-40), credentials (XLS-70), multisig signer lists, and safe transaction prepare/verify/submit workflows. It prepares unsigned transactions, reads ledger state, verifies signed blobs against intent, and can submit pre-signed blobs without ever taking custody of keys.
Built by Jarod Vyent, from the team behind SciPHR.
Security Model
These invariants are core behavior:
- No key custody. The server has no seed, private key, mnemonic, wallet import, or signing path. Signing happens in the user's wallet or agent.
- Network is explicit.
XRPL_NETWORKismainnet,testnet, ordevnet. The default istestnet. Every tool result includesnetwork. - Mainnet submit is opt-in.
tx_submit_signedon mainnet is blocked unlessALLOW_MAINNET_SUBMIT=trueis set. - Prepare, verify, then submit. Write workflows return unsigned JSON with instructions to sign externally, call
tx_decode_verify, and only then calltx_submit_signed.
Quickstart
Claude MCP:
claude mcp add xrpl-identity -- npx -y xrpl-identity-mcp
Generic MCP client config:
{
"mcpServers": {
"xrpl-identity": {
"command": "npx",
"args": ["-y", "xrpl-identity-mcp"],
"env": {
"XRPL_NETWORK": "testnet"
}
}
}
}
Environment variables:
| Variable | Values | Default | Purpose |
|---|---|---|---|
XRPL_NETWORK | mainnet, testnet, devnet | testnet | Selects the XRPL network. |
XRPL_ENDPOINT | WebSocket URL | Network default | Overrides the rippled WebSocket endpoint. |
ALLOW_MAINNET_SUBMIT | true or unset | unset | Required for tx_submit_signed on mainnet. |
Default endpoints:
| Network | Endpoint |
|---|---|
mainnet | wss://xrplcluster.com |
testnet | wss://s.altnet.rippletest.net:51233 |
devnet | wss://s.devnet.rippletest.net:51233 |
Tools
| Tool | What it does | Network writes? |
|---|---|---|
did_resolve | Resolve an XLS-40 DID object and fetch an ipfs:// or https:// DID document when present. | No |
did_prepare_set | Prepare an unsigned DIDSet transaction. | No |
did_prepare_delete | Prepare an unsigned DIDDelete transaction. | No |
credential_prepare_create | Prepare an unsigned CredentialCreate transaction. | No |
credential_prepare_accept | Prepare an unsigned CredentialAccept transaction. | No |
credential_prepare_delete | Prepare an unsigned CredentialDelete transaction. | No |
credential_verify | Read a credential object and report existence, acceptance, and expiration. | No |
credential_list | List up to 400 credential objects visible to an account, with issuer/subject filtering. | No |
account_identity_summary | Summarize auth posture, signer list, DID presence, and credential counts for an account. | No |
signer_list_prepare_set | Prepare an unsigned SignerListSet transaction for multisig create, replace, or delete. | No |
tx_decode_verify | Decode a signed blob, compute hash, and compare against expected intent. | No |
tx_submit_signed | Submit a pre-signed blob and poll for validation. Mainnet requires ALLOW_MAINNET_SUBMIT=true. | Yes |
Example Agent Flows
Resolve a DID and read its document:
- Call
did_resolvewithaddressset to a classic XRPL address ordid:xrpl:<address>. - Inspect
decoded.URI,decoded.Data, anddecoded.DIDDocument. - If the URI is
ipfs://orhttps://, inspectdocumentanddocumentSource. Only text and JSON documents are inlined; binary content (for example an image) is reported asdocumentSource,documentContentType, anddocumentByteLengthwithdocumentSkippedexplaining why the body was omitted.
Issue and accept a credential on testnet:
- Set
XRPL_NETWORK=testnet. - Call
credential_prepare_createwith issuer, subject, credential type, optional expiration, and optional URI. - Sign the returned
unsignedTxexternally with the issuer account. - Call
tx_decode_verifywith the signed blob and the expected intent. - Call
tx_submit_signed. - Call
credential_prepare_acceptfor the subject, sign externally, verify withtx_decode_verify, then submit. - Call
credential_verifyto confirmaccepted: trueandexpired: false.
Verify a signed blob before submitting:
- Call
tx_decode_verifywithsignedBloband anexpectedIntentpartial transaction JSON. - Check
matchesand anymismatches. - Submit only when the decoded transaction matches the user's intent.
Development
npm install
npm run typecheck
npm run build
SKIP_INTEGRATION=1 npm test
Integration tests target testnet and are skipped when SKIP_INTEGRATION=1. To run the account summary integration test, set XRPL_INTEGRATION_ACCOUNT to a funded testnet account address.
License
MIT