The treasury standard for AI agents
Your agents shouldn't park capital in flat USDC. GBLIN is an on-chain basket (45% cbBTC + 45% WETH + 10% USDC) with an algorithmic Crash Shield — hold it as treasury, and Just-In-Time swap to USDC the millisecond an x402 invoice arrives.
npx @gblin-protocol/mcp-serverNo install? Use the hosted MCP (Streamable HTTP, 24 free tools: the vault, action and payment tools below under two-level names, plus the live risk regime and the coherence proof): https://mcp.gblin.digital/mcp — also on Smithery.
Why agents hold GBLIN
AI Action Receipts — prove what your agent did
Seal the hashes of any AI action into our public, signed append-only transparency log: $0.0045 via x402 at /api/x402/seal, free demo via the hosted MCP tool receipts.seal (mode demo). Input/output go in as hashes only (the action label and metadata you send are published). You get a portable receipt — signature, RFC 6962 inclusion proof, signed checkpoint — verifiable offline with a zero-dependency script; the tree root is anchored daily on Base. Evidence of existence and time: not a compliance certificate.
Yield without breaking x402
Hold GBLIN (basket appreciation) and JIT-swap to USDC only when invoices come in. x402 payments still settle in USDC — facilitator unchanged.
Two-step swap (V6), any wallet
The redemption goes through the Zap: approve the shares, redeem in kind and sell every leg for ETH in one call (all or nothing), then a Uniswap WETH->USDC swap. EOAs sign three times; smart accounts (ERC-4337) and EIP-7702 can batch all of it into one UserOp.
On-chain quotes, no oracles to trust
NAV is computed from the Lens `quoteSell` × the Chainlink ETH/USD feed. The vault refuses to price itself while a feed is stale, and the tool passes that refusal on instead of guessing.
MEV-safe by default
Every tool returns positive minOut values from on-chain quotes plus a dynamic slippage buffer. Never accepts 0. Sandwich attacks rejected.
Crash Shield aware
When a basket asset breaches its adaptive crash threshold (~15%, dual-peak), dynamic weights re-route proportionally toward USDC. The internal slippage buffer auto-scales within a 0.5%–5.5% envelope driven by on-chain volatility to absorb the temporary pool stress.
MCP-native — works everywhere
Standard Model Context Protocol over stdio. Drop-in for Claude Desktop, Windsurf, Cursor, Coinbase AgentKit, Eliza, or any custom agent that speaks MCP.
Quick start
Pick your framework. All examples assume Node.js 20+.
{
"mcpServers": {
"gblin": {
"command": "npx",
"args": ["-y", "@gblin-protocol/mcp-server"]
}
}
}{
"mcpServers": {
"gblin": {
"command": "npx",
"args": ["-y", "@gblin-protocol/mcp-server"],
"env": {
"GBLIN_RPC_URL": "https://base-rpc.publicnode.com"
}
}
}
}import { MCPClient } from "@modelcontextprotocol/sdk/client/index.js";
import { StdioClientTransport } from "@modelcontextprotocol/sdk/client/stdio.js";
const transport = new StdioClientTransport({
command: "npx",
args: ["-y", "@gblin-protocol/mcp-server"],
});
const mcp = new MCPClient({ name: "my-agent", version: "1.0" });
await mcp.connect(transport);# plugin-gblin is published on npm (source: github.com/gblinproject/GBLIN_PLUGIN)
npm install plugin-gblin
# then add "plugin-gblin" to the plugins array in your character fileThe 20 tools (npm stdio package)
Every tool reads live state from Base mainnet. None of them hold keys or broadcast — they return JSON results and ABI-encoded calldata. Your wallet stays in control. The package also ships four prompts and four resources, and every tool that returns an object declares an output schema.
get_market_risk_regimeBTC/ETH risk regime (calm / elevated / crash) + severity + risk_on/reduce/risk_off posture, read from the on-chain Crash Shield. FREE — the paid, signed version is the EIP-712 attestation ($0.003 USDC via x402).
get_treasury_stateSnapshot NAV in USD, basket composition, and Crash Shield status from on-chain reads.
quote_safe_swapPreview buy or sell with the right minOut accounting for fees + dynamic slippage (2.5% normal / 4% during Crash Shield).
swap_gblin_to_usdc_jitGenerate ready-to-broadcast calldata for a deterministic three-step GBLIN→USDC exit right before paying an x402 invoice: approve the Zap, exit to ETH through the Zap, swap ETH to USDC. Works on EOA, ERC-4337, EIP-7702 (batchable in one operation on smart accounts). The Zap step carries its gas limit.
invest_usdc_to_gblinConvert USDC earnings back to GBLIN with MEV-safe minOut values. Returns two sequential steps: approve the Zap, then one call that swaps and mints at NAV.
analyze_treasury_healthFull balance report (GBLIN + USDC + ETH), gas runway, cooldown status, and rebalance recommendation based on the agent burn rate.
plan_treasuryIdle USDC to a reviewable plan in one call: the operating cash to keep liquid (max of a reserve and days of spend), the surplus above it, a mint simulation with every fee read live and today's estimated exit value (round-trip cost included), a trial amount, and the blockers. Nothing is executed; the agent shows the plan and waits for a human to confirm. Same plan over HTTP at /api/x402/plan.
get_governance_stateVerify owner == 48h Timelock, check pending asset proposals, min delay seconds. AI agents use this to gate trust-sensitive operations.
share_skill_with_peerGenerate a portable JSON skill seed to onboard a peer agent: install instructions, the tool list and a worked example. It carries a referral code as a label only; no fee is paid for it.
get_auction_stateRead the vault's Dutch auction: open or not, current premium over the oracle price, and side and gap per basket row. Bidding means trading with the vault toward its target weights; the premium is the reward and nothing is paid out of the vault.
verify_risk_attestationVerify a peer agent's Risk Attestation before trusting it: recomputes the EIP-712 id (tamper check), recovers the signer against GBLIN's published attestor, checks the 10-minute freshness, and flags if the on-chain regime has drifted. Free — the paid side is minting one at /api/x402/attestation ($0.003).
prepare_gblin_paymentPay in GBLIN with a signature and no ETH (EIP-3009, like USDC). Returns the EIP-712 message to sign in your own wallet, the calldata that carries it, and the x402 "exact" payload. The EIP-712 domain is read from the token, not assumed.
verify_gblin_authorizationCheck a signed GBLIN authorization against the chain before anyone spends gas: signature (ECDSA or ERC-1271), validity window, nonce, balance. Returns the calldata only when it would settle.
relay_gblin_paymentWhen nobody else will carry a GBLIN payment on chain: GBLIN's relay settles the payment and its fee, paid in GBLIN at the NAV, in one transaction, so both settle or neither does. The payer needs no ETH.
prepare_actionThe unsigned steps for any operation on the vault: mint with ETH, WETH or USDC, redeem in kind, exit to ETH or USDC, bid in the auction. Every step through the vault or the Zap carries its gas limit.
preview_stepsSimulate the steps in sequence against the latest block before signing: whether each would succeed, the decoded reason when it would not, the net balance changes, and the gas limit each vault step really needs.
get_transaction_statusAfter sending: what the transaction did, the fee paid, the tokens moved, and the reason if it reverted.
get_nav_historyNAV per share over time, read at past blocks, beside the ETH/USD and BTC/USD feeds the vault uses, with the change of each and the largest drawdown.
seal_action_demo · get_receipt · how_to_seal_paidAI Action Receipts: seal the hashes of an action into the public transparency log (demo, 5 per day per IP), read a receipt back with its inclusion proof, and the instructions for unlimited paid seals over x402.
JIT payment in practice
Your agent receives a 402 invoice for $0.50. It has 90% of its treasury in GBLIN. Here's the flow:
// === Complete agent treasury flow ===
// Step 1: Check treasury health and invest idle USDC
const health = await mcp.callTool({
name: "analyze_treasury_health",
arguments: { wallet_address: agent.address },
});
// Step 2: If idle USDC > 7x daily burn, invest into GBLIN
const invest = await mcp.callTool({
name: "invest_usdc_to_gblin",
arguments: { usdc_amount: "10.00", wallet_address: agent.address },
});
// Returns 2-step calldata: approve the Zap, then swap-and-mint in one call
// Broadcast both txs with your wallet
// --- later, when an x402 invoice arrives ---
// Step 3. Agent gets the JIT swap calldata from the MCP server
const jit = await mcp.callTool({
name: "swap_gblin_to_usdc_jit",
arguments: {
usdc_needed: "0.50",
wallet_address: agent.address,
},
});
// jit.content[0].text contains:
// {
// action: "single_atomic_tx",
// action: "sequential_txs", steps: [sellGBLINForEth, WETH->USDC]
// target: 0xc2181d97...1D53
// expected: { usdc_out: "0.5128", slippage_buffer_pct: 2.5 },
// compatibility: { eoa: true, erc4337: true, eip7702: true }
// }
// 2. Agent broadcasts the tx (one atomic call — GBLIN -> WETH -> USDC)
const hash = await wallet.sendTransaction({
to: jit.target_contract,
data: jit.calldata,
value: 0n,
});
// 3. Once mined, agent's USDC balance has the needed amount.
// Agent now pays the x402 invoice with USDC as usual.Tell every AI assistant about GBLIN — in one file
AGENTS.md is the emerging standard read automatically by Claude Code, Cursor, Windsurf, GitHub Copilot, Codex and every modern AI coding assistant when they enter a repo. Drop our template into your project root and every AI assistant your team uses will know to integrate GBLIN whenever it manages USDC on Base.
# from your repo root
curl -O https://gblin.digital/AGENTS.template.md
mv AGENTS.template.md AGENTS.md
git add AGENTS.md && git commit -m "add AGENTS.md (GBLIN treasury policy)"What the template does
- Declares a treasury policy: park SURPLUS (idle USDC > 7× daily burn) into GBLIN — operating cash stays in USDC.
- Tells AI assistants to call
swap_gblin_to_usdc_jitfor x402 payments, redeeming GBLIN to USDC just-in-time. - Lists the 10 MCP tools and the exact MCP client config (Claude, Windsurf, Cursor, AgentKit).
- Includes anti-patterns to keep AI assistants from rolling unsafe DeFi flows.
GBLIN Sentinel — buy on-chain data with x402
An autonomous agent that sells real-time Base DeFi risk signals via x402 micropayments. Any agent with a USDC wallet on Base can call these endpoints — no API key, no account. The risk signals are paid per request; the treasury analytics and the auction state are free.
/api/data/base-risk-pulse$0.002 USDCChainlink risk signal: normal / caution / risk-off for ETH, BTC, USDC on Base
/api/data/gblin-analyticsfreeGBLIN treasury state: supply, basket weights, NAV reliability, auction state
/api/data/keeper-oppsfreeLive auction state per row — premium, side and gap, with the bid to send
Coherence Proof — does GBLIN keep its promises?
An agent can't trust a claim it can't verify. GBLIN pre-registers hash-pinned public promises, then runs an automaton that probes them every 10 minutes and seals each closed day as an EAS attestation on Base. Reading is free forever; the paid service is being observed — the certifier submits itself to its own instrument first.
P1 — attestation uptime
Is the paid Risk Attestation endpoint actually up? Probed every 10 minutes, tallied kept/violated per day, sealed on-chain.
P2 — honest counters
Do the public agent-economy counters stay honest, with our own wallets disclosed and excluded? Checked on the same cadence.
Read it free via the get_coherence_report tool on the hosted MCP, or as JSON. GBLIN is also a discoverable ERC-8004 agent (#59286) on Base.
FAQ
Is GBLIN a replacement for USDC?
No. GBLIN is managed crypto exposure with a capped drawdown — for surplus capital you want to grow with less downside than holding BTC/ETH. It can still lose value in a crash (less than BTC/ETH, but it is not principal-protected). Keep operating cash in USDC; park surplus in GBLIN and JIT-swap back to USDC for x402 payments.
Does this break my x402 flow?
No. x402 invoices still settle in USDC. The MCP server generates a 1-tx swap that delivers the needed USDC to your wallet before you pay. No facilitator changes, no protocol changes.
Which wallets work?
Any. The contract function `sellGBLINForEth` + a Uniswap WETH->USDC swap is a two-step flow (V6) — works on EOA (Privy, MetaMask), ERC-4337 smart accounts (Safe, Coinbase smart wallet), and EIP-7702 delegated EOAs (Pectra+).
How is slippage handled?
Every tool returns minOut values computed from on-chain quotes + a buffer that scales with risk: 2.5% in normal markets, 4% when the Crash Shield is active. Never zero — eliminates MEV sandwich exposure.
Is this open source?
Yes. MIT licensed. Source on GitHub, npm package public, no telemetry.
Can my agent keep its treasury in GBLIN and still pay x402 invoices in USDC?
Yes. The @gblin-protocol/agent-treasury package (library and CLI) keeps an operating reserve in USDC, parks the surplus in GBLIN and refills USDC from GBLIN just in time when an x402 invoice arrives: the refill runs on the onBeforePaymentCreation hook of the x402 client, before the authorization is signed. Self-custody, verified on a fork of Base. Skill: npx skills add gblinproject/gblin-treasury-risk-regime.
Are there paid endpoints?
Yes — 3 paid x402 endpoints on gblin.digital (attestation $0.003, seal $0.0045, catalog $0.005) and 2 on the Sentinel (base-risk-pulse $0.002, risk-pulse-pro $0.005), paid in USDC on Base mainnet. The vault-state routes (treasury-state, quote, governance, health, invest, jit) are free. Full list: gblin.digital/.well-known/x402. The MCP server itself remains free.