Orloj
FreeNot checkedExpose Sourcify-verified blockchain smart contract interfaces as MCP tools, with signing delegated to pluggable KMS backends.
About
Expose Sourcify-verified blockchain smart contract interfaces as MCP tools, with signing delegated to pluggable KMS backends.
README
Orloj (Czech for "astronomical clock") — a nod to Prague's iconic timepiece, built for ETHPrague Hackathon 2026 and continued at ETHGlobal Lisbon 2026.
Orloj is a registry that exposes smart-contract interfaces to AI agents as MCP (Model Context Protocol) servers. MCPs are generated dynamically from Sourcify-verified contract metadata, and signing is delegated to a pluggable KMS layer — pick 1Claw (HSM + TEE) or SpaceComputer Orbitport (orbital HSM + SpaceTEE) per vault. Each registered contract is served as its own MCP endpoint by a single hot-pluggable registry process, gated by per-agent bearer tokens — agents never touch keys, RPCs, or gas.
Highlights
- Sourcify ABI → typed MCP server, dynamically generated. Every function in a verified contract becomes an MCP tool with Solidity types parsed by alloy's
JsonAbiand encoded/decoded at runtime viaDynSolValue(tuples, dynamic + fixed-size arrays, all integer widths,bytesN), proxy ABIs resolved automatically via Sourcify'sproxyResolutionfield. Zero per-contract integration: the moment a contract is verified on Sourcify, it is callable by an agent. - Hardware-rooted, pluggable KMS — keys never leave the enclave. Each vault picks its signing backend: SpaceComputer Orbitport (orbital HSM + SpaceTEE; signing happens entirely inside the enclave on a 32-byte digest, with both
ETHEREUMandTRANSITschemes used in the same product surface for wallet signing and envelope-encrypted secret storage) or 1Claw (HSM + TEE intent signing). Both backends are wired into the samesignTransactionpath, so the agent surface is identical regardless of where the key lives. - Agents never hold a key, never see a transaction. The registry constructs every EIP-1559 tx with viem, hashes it, asks the chosen KMS to sign the digest, reassembles
(r, s, yParity), and broadcasts. A compromised registry host cannot forge transactions — it can only request signatures it is already authorized to request, on a digest, against a key it does not hold. - Per-agent bearer tokens with grant-based authorization. Each agent has a
mcpk_live_*token (constant-time-checked against Postgres) and a per-vault grant carryingpermissions, optionalsecret_path_pattern, and optionalexpires_at. The registry resolves the active grant on every MCP call and routes the signature to the matching KMS key. Revocation is a row update; keys never move. - Private personal agents, spawned on demand and wired straight into the Orloj MCPs. Opening a chat spawns that user's own ZeroClaw process with an isolated config dir and workspace. At spawn time the agent's selected MCPs are connected to the agent. Inference runs on 0G Compute through the 0G router using the
qwen3.7-maxmodel. - Immutable curated skills marketplace on 0G Storage. The curated agent skills in packages/skills-marketplace/ are published to 0G Storage and addressed by their Merkle root hash, with the upload registered on 0G Chain. Orloj agents load them dynamically: pick a skill from the marketplace and it is fetched by root hash into that agent's workspace, teaching a running personal agent a new capability without redeploying anything.
- Direct agent access to the Uniswap API — swap, quote, and manage liquidity. An extra special MCP at gives the agent multichain
quoteandswapfunctionality over the Uniswap API on any registered chain, plus Uniswap V3 liquidity management over the Uniswap Liquidity API. - Graph-powered LP manager — live subgraph data turned into liquidity decisions. An internal
orloj-lp-managerMCP (packages/lp-agent/) discovers the agent's own Uniswap V3 positions, queries the Uniswap V3 subgraph on The Graph for live pool, fee, and volume data, extracts deterministic range/activity features, and produces a strictly cited HOLD / REDUCE_LIQUIDITY / REBALANCE decision with a full audit trace.
Tracks Applied
ETH Prague 2026
- Ethereum Core — see ETHEREUM-CORE.md for our integration writeup
- Network Economy — see NETWORK-ECONOMY.md for our integration writeup
- Sourcify Bounty — see SOURCIFY.md for our integration writeup
- SpaceComputer Bounty — see SPACECOMPUTER.md for our integration writeup
- Best UX Flow
ETH Lisbon 2026
- 0G — 🚀 Keep Building on 0G — see 0G.md for our integration writeup
- Uniswap Foundation — 🤖 Best Uniswap API Integration — see UNISWAP.md for our integration writeup
- The Graph — 🏆 Best AI Use Case of The Graph (Continuity) — see THE-GRAPH.md for our integration writeup
The Problem It Solves
AI agents today can read about smart contracts, but can't safely use them. To call a contract, an agent has to:
- manage private keys,
- pick an RPC and handle network failures,
- estimate and pay gas,
- understand each contract's ABI and quirks.
Every one of those is a footgun — and a reason teams don't ship agentic on-chain workflows.
Orloj removes the entire surface. Each contract is published as an MCP server, so the agent sees only typed, verified interfaces it can call like any other tool. Account management, signing, and gas are abstracted away by the registry layer; the agent never holds a key and never sees a transaction. The result: agents that can act on-chain with the same ergonomics as calling a REST API.
Why This Matters for Agents
By abstracting key management and gas handling into the MCP boundary:
- Simplified mental model. Agents never need context about blockchain infrastructure, private key custody, or transaction mechanics — only contract interfaces. This shrinks cognitive load and reduces reasoning errors.
- Infrastructure-agnostic. Key rotation, HSM policies, network selection, and gas strategies are handled outside the agent's control loop. The agent stays focused on what to do, not how to pay for it.
- Lower model requirements. Even less powerful models (that support tool calling) can reliably execute on-chain operations. The agent doesn't need to reason about gas prices, nonce management, or transaction finality — it just calls a tool with clear inputs/outputs.
- Higher reliability. By removing accounts and signing from the agent's purview, you eliminate an entire class of bugs: fund loss, key leakage, stuck transactions, failed estimates. The registry layer enforces correctness.
- Focused reasoning. Agents can concentrate entirely on business logic — when to call what function and with what parameters — rather than worrying about the infrastructure layer.
How It Works
Orloj rests on two pillars:
1. Sourcify-driven MCP generation. We use the Sourcify verified-contracts dataset as our source of truth for ABIs. The registry fetches a contract's metadata, parses its ABI, and dynamically builds an MCP server where every contract function becomes an MCP tool — with typed inputs, descriptions, and structured outputs. No hand-written wrappers; the moment a contract is verified on Sourcify, it's callable by an agent.
2. Pluggable KMS-backed vaults. Each vault holds a wallet whose private key never leaves a hardened enclave. At creation time the user picks the KMS provider:
- 1Claw — HSM + TEE, intent-based signing. The agent issues a 1Claw intent and 1Claw signs inside the TEE.
- SpaceComputer Orbitport — secp256k1 keys provisioned inside orbital HSMs with SpaceTEE, "physically isolated, tamper-proof by any administrator or state actor." The registry constructs the unsigned tx, sends only the digest to Orbitport, assembles
(r,s,v)into a broadcast-ready transaction, and submits it via RPC. Secrets stored alongside the wallet are protected by a per-vault TRANSIT (AES-256-GCM) key inside the same HSM (envelope encryption — ciphertext lives in our DB, the key never leaves the enclave).
The provider is recorded per vault, so a single deployment can run both side-by-side. The agent surface stays the same regardless of backend: "describe what you want done."
SpaceComputer's Orbitport KMS is documented as experimental ("not for production"). Use Sepolia / testnets for the SpaceComputer-backed flows during the demo.

Challenges We Ran Into
(Placeholder — to be filled in towards the end of the project.)
Technologies Used
Registry server (packages/registry/)
- Rust (Cargo — not a pnpm workspace member)
- axum 0.7 — HTTP server
- rmcp 0.16 — MCP protocol, Streamable HTTP transport
- alloy 2.0 — ABI parsing (
JsonAbi), calldata encoding/decoding (DynSolValue), EIP-1559 tx construction - sqlx 0.8 — async Postgres; per-agent bearer tokens (
mcpk_live_*) verified with constant-time comparison
Frontend / control plane (packages/app/)
- Next.js 16, React 19, Tailwind CSS v4, TypeScript
- Better-Auth with magic-link (Resend) + SIWE, ENS lookups via viem
- Postgres (vault ownership, agent ownership, MCP API keys, Orbitport vault metadata + envelope-encrypted secrets)
Agent runtime (packages/zeroclaw-agents/)
- ZeroClaw — one private agent process per user, spawned over ACP from a template
config.tomlinto an isolated per-agent config dir + workspace - 0G Compute — decentralized inference for those agents: model
qwen3.7-maxvia the 0G router (https://router-api.0g.ai/v1)
On-chain & infra
- Sourcify — verified contract metadata / ABIs (source of truth for MCP generation)
- 1Claw — key vaults, intent-based signing, HSM-backed keys, TEE signing
- SpaceComputer Orbitport — orbital HSM-backed KMS (
@spacecomputer-io/orbitport-sdk-ts) for secp256k1 signing keys + AES-256-GCM envelope-encryption keys - 0G Storage — immutable hosting for the curated skills marketplace (packages/skills-marketplace/): skill bundles are uploaded to 0G Storage, addressed by Merkle root hash with the upload registered on 0G Chain, and fetched + hash-verified at runtime into an agent's workspace
- viem — local tx construction, digest hashing, signature recovery, broadcasting
Tooling
- Claude Code — development
- Claude Design — UI/design exploration
Run It Locally
The registry reads .env; the app reads .env.local. Copy the examples and fill in secrets before starting:
# from repo root
cp packages/registry/.env.example packages/registry/.env
cp packages/app/.env.example packages/app/.env.local
Fill in at least:
packages/registry/.env—DATABASE_URL(same Postgres as the app), and eitherONECLAW_API_KEY+ONECLAW_BASE_URLorORBITPORT_CLIENT_ID+ORBITPORT_CLIENT_SECRETdepending on which vault provider you'll sign with.packages/app/.env.local—DATABASE_URL,BETTER_AUTH_SECRET,BETTER_AUTH_URL(defaults tohttp://localhost:3000),RESEND_API_KEY+EMAIL_FROMfor magic-link sign-in,REGISTRY_URL=http://localhost:3001so the app can proxy to the registry, plus the same KMS credentials. Optional:ETH_RPC_URL,ETH_RPC_URL_SEPOLIA,ENS_CHAIN.
Then run:
# registry server (http://localhost:3001) — from packages/registry/
cargo run
# frontend (http://localhost:3000) — from repo root or packages/app/
pnpm install # app only; registry is Rust/Cargo
pnpm --filter app dev
Node 24.15.0 and pnpm 10.33.2 are pinned via .npmrc and packageManager — pnpm install will refuse on the wrong versions (applies to the app only).
Installing Orloj
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/gianfrancobazzani/orloj-registryFAQ
Is Orloj MCP free?
Yes, Orloj MCP is free — one-click install via Unyly at no cost.
Does Orloj need an API key?
No, Orloj runs without API keys or environment variables.
Is Orloj hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Orloj in Claude Desktop, Claude Code or Cursor?
Open Orloj on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectCompare Orloj with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
