High Risk →

compose_cancel

Compose a transaction to cancel an open DEX order

How to control compose_cancel ↓

What compose_cancel does on 21e14

AI agents invoke compose_cancel to trigger actions in 21e14. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call — builds kicked off, notifications sent, workflows started.

ParameterTypeRequiredDescription
address string Yes Source Bitcoin address (must be order creator)
inputs_set string Comma-separated UTXOs to use as inputs (txid:vout)
offer_hash string Yes Transaction hash of the order to cancel
sat_per_vbyte number Fee rate in satoshis per virtual byte (e.g. 1, 5.5, 0.15). Check get_fee_estimate for current market rates.

Parameters from the server's own tool schema.

High Risk

Why compose_cancel needs a policy

This tool composes a blockchain transaction to cancel an open DEX order on the Counterparty/Bitcoin protocol. While 'cancel' could seem destructive, composing a transaction is an Execute-level action — it constructs and prepares an on-chain operation. The actual irreversible effect (broadcasting) would occur via a separate broadcast step.

From the tool's definition Compose a transaction to cancel an open DEX order

Documented attack patterns abuse exactly the kind of access compose_cancel gives an agent:

How to control compose_cancel

PolicyLayer is an MCP gateway — it sits between your AI agents and 21e14, and nothing reaches the server without passing your rules. This is the rule we recommend for compose_cancel:

policy.json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "compose_cancel": {
      "limits": [
        {
          "counter": "compose_cancel_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}

compose_cancel stays usable, but rate-capped — a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.

  1. Create a free account and register 21e14 — nothing to install.
  2. Add this policy — paste it, or build it visually.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
RATE-LIMIT THIS TOOL →

Free to start. No card required.

Related tools and policies

Go deeper

Questions about compose_cancel

What does the compose_cancel tool do? +

Compose a transaction to cancel an open DEX order. It is categorised as a Execute tool in the 21e14 MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.

What parameters does compose_cancel accept? +

compose_cancel accepts 4 parameters: address, inputs_set, offer_hash, sat_per_vbyte. Required: address, offer_hash. The full parameter table on this page comes from the server's own tool schema.

How do I enforce a policy on compose_cancel? +

Register the 21e14 MCP server in PolicyLayer and add a rule for compose_cancel: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches 21e14. Nothing to install.

What risk level is compose_cancel? +

compose_cancel is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.

Can I rate-limit compose_cancel? +

Yes. Add a rate_limit block to the compose_cancel rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block compose_cancel completely? +

Set action: deny in the PolicyLayer policy for compose_cancel. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides compose_cancel? +

compose_cancel is provided by the 21e14 MCP server (@21e14/mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Enforce policy on every 21e14 tool call.

Start from 21e14, add the rest of your stack, and see everything your agents can call. Then put policy on all of it.

Free to start. No card required.

48 21e14 tools catalogued and risk-classified — across an index of 43,000+ MCP servers.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.