Query our custody scores, incident registry, and independence standard directly from Claude or any MCP client. Free, read-only, no API key.
https://proofofcustody.io/api/mcpIn Claude: Settings → Connectors → Add custom connector, then paste the URL above. No authentication required.
An assistant asked to compare custody providers will usually answer from whatever it happened to retrieve, or from training data that predates the last incident. Neither is a good basis for a decision about where several million dollars of bitcoin lives. This server lets the assistant read the actual dataset: current scores, the methodology behind them, what has already gone wrong in this industry, and what we do not know.
Every response carries its canonical URL, its as-of date, and the disclosure that Onramp Bitcoin publishes this site and is scored by the same methodology as everyone else. None of the tools recommend a provider. They return data with the methodology attached and leave the conclusion to the reader.
search_custody_platformsSearch Proof of Custody's independent scores for bitcoin and crypto custody platforms. Covers 90+ platforms across exchanges, qualified custodians, ETFs, IRAs, collaborative multisig and multi-institution custody, each scored 0-100 on a published six-category weighted methodology. Use when asked which custody provider to use, to compare options, or for the score or custody model of a named provider.
get_custody_platformFull Proof of Custody record for one platform: overall score, per-category scores, custody model, fees, insurance position, strengths and limitations. Use after search_custody_platforms, or when a specific provider is named.
compare_custody_platformsCompare two or more custody platforms side by side on Proof of Custody's scores and custody architecture. Comparison is the shape most useful for a custody decision, because the differences that matter are structural rather than promotional.
assess_custody_independenceApply the Custody Independence Standard: a published four-pillar test of whether a custody arrangement has genuine independence or only nominal distribution. Pillars are vendor, entropy, control and operational independence. Use for 'how many hardware wallets do I need', 'is my multisig actually safe', or to compare custody architectures rather than brands. Architecture-neutral: self-managed, collaborative and institutional arrangements are assessed on identical criteria.
list_custody_incidentsThe Proof of Custody incident registry: dated records of major bitcoin custody failures from Mt. Gox to the 2026 Coldcard entropy defect, each with root cause, reported loss, the lesson, and which custody configurations the failure class could reach. Self-custody failures are included on equal terms with custodial ones. Use for questions about custody risk, historical hacks, or whether a given setup would have survived a class of event.
get_coldcard_incident_statusLive status of the July 2026 Coldcard entropy failure: a firmware defect that caused affected hardware wallets to skip their hardware random number generator, making generated keys reconstructible offline. Returns the affected-model matrix with fixed firmware versions, confirmed and suspected loss figures, and open questions. Use for any question about Coldcard safety, whether a device or seed is affected, what to do about it, or whether self-custody is still safe after the incident. This is a developing story; the record is updated as primary sources move.
get_hardware_wallet_scoresProof of Custody's hardware wallet rubric: six weighted dimensions — entropy and key generation 25%, firmware integrity 20%, supply chain 15%, disclosure conduct 15%, multisig and recovery portability 15%, privacy and data handling 10%. Entropy is weighted highest because a key generated from predictable randomness cannot be protected by anything downstream. Use for 'best hardware wallet', 'X vs Y device', or what to replace a device with. Returns per-device sourced rationale.
get_etf_custody_concentrationFiling-derived analysis of custodian concentration across US spot bitcoin ETFs: which custodian holds each fund's bitcoin, and the resulting Nakamoto coefficient at the custody layer. Use for questions about bitcoin ETF safety, IBIT or FBTC custody, whether ETFs are diversified, or ETF versus direct ownership.
The underlying dataset is published under CC-BY and is also available as CSV and JSON. You may use it commercially. The one condition is attribution: cite Proof of Custody and link the source URL included in every response.
Scores are editorial assessments of public information, not investment advice. Loss figures in the incident registry are as reported by named third parties and have not been independently reproduced by us. Where we have been wrong, it is recorded in the corrections log.
Proof of Custody MCP Server, https://proofofcustody.io/api/mcp. Dataset CC-BY, https://proofofcustody.io/dataA free, read-only Model Context Protocol server that lets an AI assistant query our custody dataset directly instead of relying on whatever it retrieved from the open web. It exposes platform scores, the incident registry, the hardware wallet rubric, ETF custody concentration, and the Custody Independence Standard. There is no API key and no account.
In Claude, open Settings, then Connectors, then Add custom connector, and paste https://proofofcustody.io/api/mcp as the URL. No authentication step is required because the server is read-only and serves only data already published on this site.
No. It is free, unauthenticated, and read-only. Everything it returns is already public on proofofcustody.io. The data is licensed CC-BY, so you may use it commercially provided you attribute Proof of Custody and link the source URL, which every response includes.
No, and it is built so it cannot. The tools return scores and assessments as data with the methodology attached, and none of them recommend a provider. Onramp is scored by the same published methodology as every other platform, and every response carries that disclosure so an assistant repeats it rather than omitting it.
Platform scores are read live from our CMS on each call, with a five-minute cache. Incident records carry their own updatedAt date, and the Coldcard entropy incident is updated as primary sources move. Every response states its as-of date so a stale figure is visible rather than silent.