Skip to main content
Glama

MCP Server CCXT

by carlosatta

MCP Server CCXT

āš ļø Work in Progress: This project is currently under active development. Features and APIs may change without notice. Use in production environments at your own risk.

MCP (Model Context Protocol) server that exposes CCXT cryptocurrency exchange APIs via Server-Sent Events (SSE). This server provides 24 comprehensive tools for interacting with multiple cryptocurrency exchanges.

šŸ”’ Security First

IMPORTANT: This server includes multiple layers of security to prevent accidental or malicious trading operations:

  • šŸ›”ļø SAFE_MODE: Disable all trading operations, only read-only access

  • ā±ļø Rate Limiting: Prevent burst of orders (max 10 orders/minute per session)

  • šŸ“ Enhanced Logging: Full audit trail of all trading operations

  • šŸ” Tool Classification: Clear separation between safe vs dangerous tools

  • 🚨 Security Checks: Multiple validation layers before executing trades

See

Quick Start - Safe Mode

For maximum security (recommended for production):

# .env SAFE_MODE=true # Disables ALL trading operations

With SAFE_MODE enabled:

  • āœ… Can read: balances, markets, prices, orders, history

  • āŒ Cannot: place orders, cancel orders, transfer funds

Features

  • 🌐 Web-based MCP server using SSE transport

  • šŸ’± Multiple exchange support: Binance, Coinbase, Kraken, Bitfinex, Bybit

  • šŸ”§ 24 comprehensive tools (13 public + 11 private)

  • šŸ” Environment-based credentials management

  • šŸ›”ļø Advanced security features (SAFE_MODE, rate limiting, audit logs)

  • šŸ“Š Public APIs: Market data, tickers, orderbooks, OHLCV, trades, funding rates

  • šŸ’° Private APIs: Account balance, order management, futures trading, fund transfers

  • šŸ”„ Session-based transport with UUID tracking

  • šŸ“ Detailed logging for debugging

Installation

npm install

Configuration

Create a .env file in the root directory:

# ========================================== # Security Configuration # ========================================== # SAFE_MODE: Disable ALL trading operations # Recommended: true for production SAFE_MODE=false # ========================================== # Server Configuration # ========================================== HOST=0.0.0.0 PORT=3000 LOG_LEVEL=info DEFAULT_EXCHANGE=coinbase # ========================================== # Exchange API Credentials # ========================================== # Only needed for private tools (balance, orders, etc) # Leave empty to use public tools only BINANCE_API_KEY=your_binance_api_key BINANCE_SECRET=your_binance_secret COINBASE_API_KEY=your_coinbase_api_key COINBASE_SECRET=your_coinbase_secret KRAKEN_API_KEY=your_kraken_api_key KRAKEN_SECRET=your_kraken_secret # Add credentials for other exchanges as needed

Security Recommendations:

  1. Always enable SAFE_MODE unless trading is explicitly required

  2. Use separate API keys for read-only vs trading operations

  3. Enable IP restrictions on exchange API keys

  4. Never commit .env file to version control

  5. See SECURITY.md for complete security guide

Running the Server

npm start

The server will start on http://0.0.0.0:3000 (or your configured HOST/PORT).

Available Endpoints

  • SSE Stream: GET http://localhost:3000/sse - Establishes SSE connection

  • Messages: POST http://localhost:3000/message?sessionId=<uuid> - Handles MCP messages

  • Health Check: GET http://localhost:3000/health - Server health status

  • Info: GET http://localhost:3000/ - Server information

  • Stats: GET http://localhost:3000/stats - Server statistics

Available Tools

Public Tools (13 tools - No authentication required)

  1. list_exchanges - List all available exchanges

  2. get_ticker - Get current ticker for a trading pair

  3. batch_get_tickers - Get multiple tickers at once

  4. get_orderbook - Get market order book

  5. get_ohlcv - Get candlestick data

  6. get_trades - Get recent trades

  7. get_markets - List all available markets

  8. get_exchange_info - Get exchange information

  9. get_leverage_tiers - Get futures leverage tiers

  10. get_funding_rates - Get perpetual futures funding rates

  11. get_positions - Get open positions (public data)

  12. get_open_orders - Get open orders (public data)

  13. get_order_history - Get order history (public data)

Private Tools (10 tools - Require API credentials)

  1. account_balance - Get account balance

  2. place_market_order - Place market order āš ļø

  3. place_limit_order - Place limit order āš ļø

  4. cancel_order - Cancel specific order

  5. cancel_all_orders - Cancel all orders

  6. set_leverage - Set futures leverage

  7. set_margin_mode - Set margin mode (isolated/cross)

  8. place_futures_market_order - Place futures market order āš ļø

  9. place_futures_limit_order - Place futures limit order āš ļø

  10. transfer_funds - Transfer funds between accounts

āš ļø Warning: Trading tools execute real operations with real money!

Testing

Basic Test

npm test

Extended Test

node test-extended.js

Tool Examples

Get Ticker

{ "name": "get_ticker", "arguments": { "symbol": "BTC/USDT", "exchange": "binance" } }

Batch Get Tickers

{ "name": "batch_get_tickers", "arguments": { "symbols": ["BTC/USDT", "ETH/USDT", "BNB/USDT"] } }

List Exchanges

{ "name": "list_exchanges", "arguments": { "certified": false } }

Get Account Balance (requires credentials)

{ "name": "account_balance", "arguments": { "exchange": "binance" } }

Place Limit Order (requires credentials) āš ļø

{ "name": "place_limit_order", "arguments": { "symbol": "BTC/USDT", "side": "buy", "amount": 0.001, "price": 50000 } }

Architecture

mcp-server-ccxt/ ā”œā”€ā”€ index.js # Main server ā”œā”€ā”€ src/ │ ā”œā”€ā”€ mcpServer.js # MCP server │ ā”œā”€ā”€ config/ │ │ └── config.js # Configuration │ ā”œā”€ā”€ tools/ │ │ ā”œā”€ā”€ publicTools.js # 13 public tools │ │ └── privateTools.js # 10 private tools │ └── utils/ │ └── exchangeManager.js # Exchange manager ā”œā”€ā”€ test-mcp-client.js # Basic tests ā”œā”€ā”€ test-extended.js # Extended tests └── .env # Environment variables

MCP Integration

Using with n8n

  1. Install MCP connector in n8n

  2. Configure server URL: http://your-server:3000

  3. Use tools in workflows

Custom Integration

import { Client } from "@modelcontextprotocol/sdk/client/index.js"; import { SSEClientTransport } from "@modelcontextprotocol/sdk/client/sse.js"; const client = new Client({ name: "my-client", version: "1.0.0", }, { capabilities: {} }); const transport = new SSEClientTransport( new URL("http://localhost:3000/sse") ); await client.connect(transport); const result = await client.callTool({ name: "get_ticker", arguments: { symbol: "BTC/USDT" }, }); console.log(result.content[0].text);

Security

āš ļø Important Security Notes:

  1. Never commit to version control

  2. Trading tools execute real trades with real money

  3. Use HTTPS in production

  4. Restrict access with firewall rules

  5. Be aware of rate limits on exchanges

Supported Exchanges

  • Coinbase (default)

  • Binance

  • Kraken

  • Bitfinex

  • Bybit

CCXT supports 100+ exchanges. Add credentials in .env to enable more.

Troubleshooting

Server won't start

  • Check port 3000 is not in use

  • Verify .env file exists

  • Check logs for errors

Tools not showing

  • Restart server after code changes

  • Check tool definitions

  • Review server logs

Authentication errors

  • Verify API keys in .env

  • Check exchange name (lowercase)

  • Ensure proper API permissions

License

MIT

Contributing

Contributions welcome! Please:

  1. Fork the repository

  2. Create feature branch

  3. Add tests

  4. Submit pull request

-
security - not tested
F
license - not found
-
quality - not tested

remote-capable server

The server can be hosted and run remotely because it primarily relies on remote services or has no dependency on the local environment.

Provides access to cryptocurrency exchange APIs through CCXT, enabling market data retrieval, account balance checks, and trading operations across multiple exchanges like Binance, Coinbase, and Kraken with built-in security features.

  1. šŸ”’ Security First
    1. Quick Start - Safe Mode
  2. Features
    1. Installation
      1. Configuration
        1. Running the Server
          1. Available Endpoints
        2. Available Tools
          1. Public Tools (13 tools - No authentication required)
          2. Private Tools (10 tools - Require API credentials)
        3. Testing
          1. Basic Test
          2. Extended Test
        4. Tool Examples
          1. Get Ticker
          2. Batch Get Tickers
          3. List Exchanges
          4. Get Account Balance (requires credentials)
          5. Place Limit Order (requires credentials) āš ļø
        5. Architecture
          1. MCP Integration
            1. Using with n8n
            2. Custom Integration
          2. Security
            1. Supported Exchanges
              1. Troubleshooting
                1. Server won't start
                2. Tools not showing
                3. Authentication errors
              2. License
                1. Contributing

                  MCP directory API

                  We provide all the information about MCP servers via our MCP API.

                  curl -X GET 'https://glama.ai/api/mcp/v1/servers/carlosatta/mcp-server-ccxt'

                  If you have feedback or need assistance with the MCP directory API, please join our Discord server