avaConnect

8 mainnet settlements on 4 chains

Give your AI agent a wallet it cannot drain.

Ava is the execution layer for Claude Code, Cursor, Codex and any MCP agent. You sign a spending cap once. The agent lends, swaps and bridges inside it, and every run ends in a receipt re-read from the chain.

npx @getava-xyz/connect
Connect your agent
or tell your agent:
set up https://www.getava.xyz/SKILL.md
  • Keys in a Turnkey enclave
  • Refuses outside the mandate
  • Receipts anyone can verify
claude code · ava mcp
you

Supply 1 USDC to Aave on Monad. Cap it at 5 USDC.

▸ava_create_mandate

asset: USDC

chain: monad

notionalCap: 5.00

status: active

▸ava_lend_execute

amount: 1.00

previewHash: 4b37e63f…87e16

status: filled

txHash: 0x1b23c35d…8af7 · block 93,291,520

proof: chain-confirmed

you

Now supply 50 USDC.

▸ava_lend_executerefused

code: MANDATE_NOTIONAL_EXCEEDED

Notional 50 exceeds the mandate limit of 5 USDC.

Refusal and fill both from production runs.Verify this receipt
8
mainnet settlements
4
chains with confirmed fills
25
protocols with an adapter
0
keys the agent ever holds

Runs inside the agent you already use

No new app, no browser extension, no seed phrase to paste. Ava is an MCP server. The agent points at one URL and gets a wallet, a mandate, and a receipt.

DeFi, handed to autonomous agents

The gap is the product.

Every other answer to “can an agent move money” closes this distance and calls it progress. Ava keeps it open and makes crossing it cost a signature. The mandate is the reach; the receipt is what proves the agent stayed inside it.

Two marble hands reaching toward each other, fingertips not touching. Both are cut from the same stone; the right one also carries the construction lines a sculptor scribes before carving. The space between the fingertips is empty.
Nothing crosses until you sign

The agent reaching

  • Claude
  • Cursor
  • Codex
  • Grok

What it reaches for

  • Aave
  • Morpho
  • Compound
  • Jupiter

25 protocols across 12 chains, each at the standing it earned

Every row is read from the same capability registry the executor consults before a signer exists, so nothing here can claim more than the code allows. A venue moves up a column by settling a transaction, not by being described differently.

Settled on mainnet3

A real transaction went through this venue and confirmed. Every hash is re-read from that chain's own node before this page is allowed to build.

Live route, no fill yet7

Executor, public route and registry authority all exist end to end. Nothing has settled through it, so it does not get a hash and does not get called proven.

  • Aave v3lend

    • Arbitrum
    • Base
    • Optimism
  • Compound v3lend

    • Arbitrum
    • Base
  • 0xswap

    • Base
  • Jupiterswap

    • Solana
  • Suilendlend

    • Sui
  • Uniswap v3swap

    • Base
  • Venuslend

    • BNB Chain
Prepare-only19

The adapter builds real unsigned calldata against addresses verified on mainnet, and the registry refuses to submit it. Useful today for planning and simulation.

  • KyberSwapswap

    • Arbitrum
    • Avalanche
    • Base
    • BNB Chain
    • Ethereum
    • Optimism
    • Polygon
  • LI.FIbridge

    • Arbitrum
    • Avalanche
    • Base
    • Ethereum
    • Gnosis
    • Optimism
    • Polygon
  • 0xswap

    • Arbitrum
    • Avalanche
    • BNB Chain
    • Ethereum
    • Optimism
    • Polygon
  • CoW Protocolswap

    • Arbitrum
    • Base
    • Ethereum
    • Gnosis
  • Acrossbridge

    • Arbitrum
    • Base
    • Optimism
  • Uniswap v3swap

    • Arbitrum
    • Avalanche
    • Monad
  • Hyperliquidperps

    • Arbitrum
    • Hyperliquid
  • Aerodromeswap

    • Base
  • Cetusswap

    • Sui
  • Curvancelend

    • Monad
  • DeepBookswap

    • Sui
  • Euler v2lend

    • Monad
  • Kuruswap

    • Monad
  • Lidostake

    • Ethereum
  • Pendleswap

    • Monad
  • Perplperps

    • Monad
  • Rocket Poolstake

    • Ethereum
  • shMON · gMON · aprMONstake

    • Monad
  • Uniswap v4swap

    • Monad

The last column is the one no competitor publishes. Seven Monad adapters build verified calldata and are still unreachable, because a package existing is not the same as a route existing, and the registry is the only thing allowed to say which. Registering one is what moves it.

One command. Any agent.

The connect command mints a session, writes the MCP config for your client, and drops a real token in place. Two minutes to a bounded wallet.

npx @getava-xyz/connect
set up https://www.getava.xyz/SKILL.md

Shell command, or a sentence you say to the agent. Both end in the same config.

~/.claude.json

{
  "mcpServers": {
    "ava": {
      "type": "http",
      "url": "https://www.getava.xyz/mcp",
      "headers": {
        "Authorization": "Bearer <token>"
      }
    }
  }
}

The connect command writes this file for you, with a real token in place of <token>.