magicblock_swap
Build an unsigned swap transaction from a quote. 'public' mode passes through Jupiter. 'private' mode routes output through a scheduled private transfer: requires destination, minDelayMs (string ms), maxDelayMs (string ms, <= 600000), and split (1-14). The API appends a schedule_private_transfer ...
This record as markdown: /tools/oobe-protocol-labs-sap-mcp-server/magicblock-swap.md
What magicblock_swap does on Sap
AI agents use magicblock_swap to commit financial operations through Sap, usually the final step of a payment, billing, or trading workflow. A call moves real money.
| Parameter | Type | Required | Description |
|---|---|---|---|
split | number | — | Private only. Number of queue entries to split across (1-14) |
validator | string | — | Optional validator pubkey for the transfer-queue PDA |
maxDelayMs | string | — | Private only. Latest (ms) the queued transfer may settle (<= 600000) |
minDelayMs | string | — | Private only. Earliest (ms) the queued transfer may settle |
visibility | string | — | 'public' = transparent Jupiter pass-through, 'private' = output routed through scheduled private transfer |
clientRefId | string | — | Private only. Optional u64 client correlation ID |
destination | string | — | Final private-transfer recipient (required when visibility='private') |
quoteResponse | object | Yes | Quote response object from magicblock_swapQuote (pass as-is) |
userPublicKey | string | Yes | Wallet that will sign the swap transaction |
wrapAndUnwrapSol | boolean | — | Auto wrap/unwrap native SOL when needed (default true) |
asLegacyTransaction | boolean | — | Build a legacy transaction (not allowed when visibility=private, default false) |
Parameters from the server's own tool schema.
Why magicblock_swap is rated Critical
Executes token swaps and financial transfers on-chain with potential irreversible financial consequences.
From the tool's definition swap transaction, routes output, private transfer, fee
Risk signalsAccepts file system path (destination) · High parameter count (11 properties)
Attacks that exploit this kind of access
The rule that runs magicblock_swap safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Sap, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For magicblock_swap, this is the rule to start with:
Any call to magicblock_swap is blocked until a human approves it. The rest of the server keeps working.
The button opens the PolicyLayer dashboard: create your workspace, connect Sap, apply this rule, and every magicblock_swap call is checked against it from then on.
Questions about magicblock_swap
Build an unsigned swap transaction from a quote. 'public' mode passes through Jupiter. 'private' mode routes output through a scheduled private transfer: requires destination, minDelayMs (string ms), maxDelayMs (string ms, <= 600000), and split (1-14). The API appends a schedule_private_transfer instruction that registers a one-shot Hydra crank for delivery. Legacy transactions are not allowed in private mode. Agents must continue with sap_preview_transaction, sap_sign_transaction, and sap_submit_signed_transaction; never write temporary signing scripts or read keypair JSON. Value-action fee applies. SAP MCP execution guidance: Intent: Solana value-action or trading workflow. Pricing: paid value-action; preview cost and transaction effects before user confirmation. Routing: paid hosted call; call sap_estimate_tool_cost first, then use sap_payments_call_paid_tool if the runtime cannot handle x402 natively. Signer boundary: hosted reads/builders never receive keypair bytes; value-moving results must be finalized locally when signing is required. It is categorised as a Financial tool in the Sap MCP Server, which means it involves financial transactions. Block by default and require explicit approval.
magicblock_swap accepts 11 parameters: split, validator, maxDelayMs, minDelayMs, visibility, clientRefId, destination, quoteResponse, userPublicKey, wrapAndUnwrapSol, asLegacyTransaction. Required: quoteResponse, userPublicKey. The full parameter table on this page comes from the server's own tool schema.
Register the Sap MCP server in PolicyLayer and add a rule for magicblock_swap: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Sap. Nothing to install.
magicblock_swap is a Financial tool with critical risk. Critical-risk tools should be blocked by default and only enabled with explicit human approval.
Yes. Add a rate_limit block to the magicblock_swap rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for magicblock_swap. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
magicblock_swap is provided by the Sap MCP server (https://mcp.sap.oobeprotocol.ai/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Sap, and thousands of servers like it.
Across the catalogue