
XRPLHub — XRPLScore & XRPL actions
io.github.Dcroyaltyv1.13.0Updated Sep 28, 2026
Free XRPL scores + tx previews; pay per unsigned txjson via x402 (USDC/RLUSD). You sign; no keys.
Installation
In SourceWeft
- Open XRPLHub — XRPLScore & XRPL actions in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"xrplhub": {
"type": "http",
"url": "https://www.xrplhub.io/api/mcp"
}
}
}README
XRPLHub.io — backend
The production app for xrplhub.io: Next.js (App Router, TypeScript) on Vercel, Neon Postgres through Prisma, XRP Ledger reads through a rotated pool of public nodes, and Xaman / Crossmark / GemWallet for signing. There is no AI or LLM anywhere in the shipped code.
What it does
XRPLHub is not a bank, credit bureau, consumer reporting agency or regulated entity, and nothing it returns is legal, financial or compliance advice.
Things that are deliberately true of this codebase
- The server decides every price.
src/lib/servicePrices.tsis the only price table. Nothing the client sends about amount or currency is read. - Payments are verified on the ledger, once.
src/lib/paymentGate.tschecks a validated, successful Payment to the treasury in XRP or RLUSD from the real issuer, covering the price; each payment hash is single-use in the database. - Invoices are matched without a scan window. Checkout invoices (
src/lib/rlusd.ts) are found by exact transaction hash when known, otherwise by walking the treasury's history back to the invoice's creation — dust traffic cannot push a real payment out of view. An invoice is only closed after the ledger was read completely. - A mistyped address is rejected, not screened. Every address goes through
src/lib/address.ts(base58check). - A cached score never reaches an attestation.
scripts/check-attestation-freshness.mjsruns innpm run buildand fails if any attestation module imports the cache or fetches a cache-backed score route. - Partial data never reads as whole. A failed ledger read is a 503 or a
degraded/complete:falseflag, never a clean-looking answer. - Every judgment carries a disclaimer in its response.
- The treasury is a single-key XRPL account. It has no signer list on the ledger; nothing here may claim multi-sig protection until it does.
Layout
Running it locally
npm run build runs the two build gates (attestation freshness, service parity), prisma generate, then next build
with TypeScript errors enforced.
Main environment variables (see .env.example; anything unset degrades loudly, not silently):
Operations
docs/AUTONOMY.md is the source of truth for what runs unattended (two Vercel crons, 06:00 and 07:00
UTC), what expires and when, the watchdog, and what to check first after a long absence. Deploys go out on every push to
main; redeploy with the Vercel build cache off.
Contact: [email protected]
Source: kreditkarma-backend/README.md at commit 9913ac1
Tools
0Version history
2- v1.13.0LatestSep 26, 2026
- v1.3.0Sep 16, 2026