Commertize Agents MCP Server
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Commertize Agents MCP Servershow me multifamily offerings in Texas under $5M"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Commertize Agents — MCP Server
The MCP server for Commertize Agents. It exposes Commertize's public marketplace data — offerings, news, sponsor listings, platform reference text — as typed tools any MCP-compatible agent can call directly, instead of scraping commertize.com.
Every tool registered by default is a read, and none needs a credential. Further
tools exist in this codebase and are NOT registered by default — get_disclosure_package,
the two sponsor-services writes (request_memo, file_sponsor_inquiry), and the
sandbox_* / x402_* groups — each behind its own explicit opt-in flag. See
What is actually live and Configuration.
Commertize is a digital capital markets platform for real-world assets. Sponsors list offerings on it, and investors complete identity verification on the platform before they can take part. This server is the read surface of that platform, nothing more.
Free. No API key. No account. Every default tool reads a route that is public and
unauthenticated on api.commertize.com. Nothing in this server is an offer, a
solicitation, or a recommendation, nothing here can transact, and the disclaimer travels
with every response.
What is actually live
Verified against api.commertize.com on 2026-09-10 by direct probe. A route that exists
answers 200/400/401 or a JSON 404; the plain-text 404 Not Found below is the
unmounted-route default.
Tool | Backing route | Production |
|
| 200 |
|
| 200 (unknown slug: JSON 404) |
| none — reads a local file | n/a |
|
| 404, not mounted — gated OFF |
|
| 404, not mounted — gated OFF |
|
| 404, not mounted — gated OFF |
The gated tools' code, schemas and tests are complete and unchanged; only their registration is switched off. The rule is the one this server already applied to the sandbox and paid-data groups: a tool that can only 404 teaches a machine reader that the platform is broken rather than that the capability is not offered.
Related MCP server: tengu-firm
Tools
Nine tools are registered by default, all reads. Every tool is listed below; the ones that are off by default are marked.
Marketplace & content (7):
Tool | Input | Returns |
|
| The public offering set: asset class, city/state, status, exemption type, sponsor, tokenomics, derived offering size, SPV leverage disclosure. |
|
| One offering's full public detail. |
|
| One publishable offering's SIGNED machine-readable disclosure package — terms, waterfall, covenants, risk factors, attestations, minimum investment, transfer-restriction profile and reason codes — every field with a provenance and an as-of, plus the Ed25519 signature, key id, verification endpoints and a PDF rendered from the same data. Assets under evaluation are never served. Off by default, like the offerings tools; the API endpoint is itself flag-gated ( |
|
| Published news and market commentary — headlines, summaries, categories, links. |
|
| One article's full body as plain text. |
| — | Curated "what is Commertize / what can an agent do here" reference text. Call this one first. |
Screening & comparison (4):
Tool | Input | Returns |
| free-text query + asset class / geography / status / exemption filters + numeric range filters (cap rate, cash-on-cash, IRR, equity multiple, hold period, lockup, offering size, minimum ticket, SPV leverage) | The filtered public set, sortable on any numeric field. Undisclosed values never silently match a range filter — they land in |
| 2–5 | Field-by-field comparison across offerings, with per-field disclosure/agreement counts — two undisclosed values are reported as two absences, never as agreement. |
| — | Every sponsor with a public offering: count, status/asset-class breakdown, states, summed target raise where disclosed. This is an inventory of platform listings, not a track record. |
|
| One sponsor's public listing record. Not a track record — prior deals, realized returns, AUM and verification status are not public data and are named as unavailable, not guessed at. |
Sponsor services — writes, OFF in the default build:
Neither tool below is registered unless its flag is set explicitly. The default public
build is the read-only tool set above; platform_info reports read_only: true.
Tool | Opt-in flag | Input | Returns |
|
|
| Files a request for a written feasibility read on an asset your principal controls. The memo goes to the address your credential was registered to and cannot be directed anywhere else — there is no recipient parameter. Returns the request id and the receipt time. Without a key the tool refuses and says so rather than silently filing nothing. |
|
| principal contact details + agent attribution | Files a sponsor inquiry about the principal's own asset. Returns the inquiry id and acceptance time; nothing else is promised. |
What makes this safe to hand to an arbitrary agent
Public data only. Every route backing these tools has no auth middleware — verified route-by-route against the backend source, not assumed.
No write tool by default. As this server ships, every registered tool is a read and
platform_inforeportsread_only: true— a value derived from the registered write list, not asserted. If a write gate is opened, the write tools file a request about the caller's OWN asset;request_memotakes no recipient address, so it cannot be used to mail a third party. Nothing in this server can subscribe, transfer, claim a distribution, or commit anyone to anything, and there are no credentials in the codebase — any agent key is read from the environment and only ever sent to Commertize's own API.Honest nulls. A missing value is
nulland named innot_disclosed. Never0, never a guess, never filled from a comparable.Provenance on every response.
as_of(fetch time, not call time),source_url, cache metadata, and a standing disclaimer ride along with every payload.Never fabricates on failure. An upstream outage returns a typed error, never an empty list dressed up as "no offerings."
Offering tools are off by default.
list_offeringsandget_offeringreturn data only whenCOMMERTIZE_MCP_ENABLE_OFFERINGS=1is explicitly set; a missing or malformed value keeps them off. When enabled, any offering structured under Rule 506(b), which does not permit general solicitation, carries an explicit non-solicitation note.
Install
Claude Code
claude mcp add commertize -- node /absolute/path/to/mcp-server/dist/index.js(Build from source first — see From source.)
Any client using an mcpServers config block
{
"mcpServers": {
"commertize": {
"command": "node",
"args": ["/absolute/path/to/mcp-server/dist/index.js"]
}
}
}From source
git clone https://github.com/Commertize-Inc/mcp-server.git
cd mcp-server
npm ci
npm run build
node dist/index.jsThe server speaks MCP over stdio; node dist/index.js is the command every client
config above points at (use the absolute path to dist/index.js).
Or point the official inspector at it directly:
npx @modelcontextprotocol/inspector node dist/index.jsStreamable HTTP transport (remote MCP)
The same server over the MCP Streamable HTTP transport, for clients that connect to a URL instead of spawning a process. It runs where you run it: start it yourself and point your client at the address you bind.
node dist/httpMain.js # 127.0.0.1:3920 by default# a client, once an instance is reachable at <url>:
claude mcp add --transport http commertize <url>/mcp --header "Authorization: Bearer <agent key>"What is different over HTTP, by design:
Every request needs a key.
Authorization: Bearer cfa_…, the agent-platform key format. The key is verified against the API named byCOMMERTIZE_API_BASE_URLatCOMMERTIZE_MCP_KEY_INTROSPECT_PATH(200 with the matchingkey_id= yes; 401/403 = no; anything else, or no answer, = 503 and the request is refused). There is no anonymous mode and no "skip verification" switch. The route itself requires a service secret (COMMERTIZE_MCP_INTROSPECT_SECRET, sent asx-commertize-introspect-secret); without one this server refuses every call with 503 and never calls upstream, and a route that refuses OUR secret is reported as "cannot verify", never as "bad key".Caching, both ways, bounded. A verified key is trusted for at most 15 s (
COMMERTIZE_MCP_KEY_VERIFY_CACHE_MS, hard ceiling 15 000 — an environment can lower it, not raise it) and never past theexpires_atthe route reported, so a revoked key works for at most 15 s. A refused key is remembered forCOMMERTIZE_MCP_KEY_NEGATIVE_CACHE_MS(30 s) so a flood of one bad key costs one upstream call per window; a revocation is honoured at the first re-check, at most 15 s away, and then remembered the same way.Per-IP verification brake. Requests whose key is not answered from cache count against the client's address (
x-vercel-forwarded-for, thenx-real-ip, then the socket; never the caller-settablex-forwarded-for):COMMERTIZE_MCP_HTTP_VERIFY_PER_IP_PER_MIN(20) per minute, then 429 before any upstream call. The route's own Postgres-counted ceilings (per IP, per key, global) are the ceiling that holds across serverless instances; this brake is the first, free one.The surface is an allowlist (
src/httpAllowlist.ts): the read tools plusfile_sponsor_inquiry.request_memo, the simulation venue and the paid-data rail are not registered over HTTP whatever their gates say, and atools/callnaming any of them — or any unknown name — is HTTP 403 with a loggedtool_refusedevent, before the MCP server sees it.Per-key ceilings:
COMMERTIZE_MCP_HTTP_RPMrequests per minute (60) andCOMMERTIZE_MCP_HTTP_INQUIRIES_PER_HOURinquiries per hour (2), each 429 withRetry-After. In-memory and per process: on a serverless platform every warm instance counts on its own. The API's own per-IP limits remain the floor.CORS is off. No
Access-Control-*header is ever sent;OPTIONSis 405. A key pasted into a web page cannot be used from a browser.Stateless. Each POST builds a fresh server and transport and tears them down. No sessions, no SSE streams:
GET /mcpis 405. Clients must sendAccept: application/json, text/event-stream(the SDK and Claude Code do).GET /healthanswers 200 with the version, transport andverifier_configured, needs no key, and names no upstream.Structured log, one JSON object per request on stderr: method, path, the key's public id, JSON-RPC methods, tool name, status, outcome, duration. Never the key, a header, or a body.
api/mcp.js, api/health.js and vercel.json are a serverless packaging of the same
handler, for self-hosting.
Configuration (all optional; sane defaults point at production)
Variable | Default | Purpose |
|
| Upstream API. |
|
| Fresh-response window. |
| unset (tools return no offering data) | Set to |
| unset ( | Set to |
| unset ( | Set to |
| unset ( | Agent credential from |
| unset ( | Set to |
|
| Bind address of |
|
| Path on |
| unset (every HTTP request is 503; no upstream call) | Service secret the introspection route requires. Never logged or served. |
|
| How long a verified key is trusted before re-checking; also bounded by the reported |
|
| How long a refused key is remembered without re-asking. |
|
| Per-client-IP ceiling on verification attempts (cache misses) per minute. |
|
| Per-key ceilings over HTTP. |
|
| Largest JSON-RPC body accepted over HTTP. |
| unset ( | Absolute path of |
| unset (not registered) | Opt-in for the |
Tests
npm testRuns the offline, screener, sandbox, x402, HTTP and banned-language suites. The
live-network suite is opt-in: COMMERTIZE_MCP_LIVE_TESTS=1 npm test, or
npm run test:live on its own.
License
Apache-2.0. This is the open half of Commertize's open-core split: the public edge
(this server, the agent skill, llms.txt) is open source; the venue itself — onboarding,
KYC, custody, settlement, everything that actually transacts — is not.
Links
Platform: https://commertize.com
Public API: https://api.commertize.com
Agent skill: https://github.com/Commertize-Inc/agent-skill
Nothing in this repository, or returned by any tool in it, is an offer, a solicitation, or a recommendation to buy or sell any security, or investment, legal, or tax advice.
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only market data for agents: prices, fundamentals, filings, options, credit, private markets.
Read-only MCP tools for AI agent discovery, structured resources, and NIULAI information.
Real SEC, 13F, insider, congress & macro data your AI agent can cite. Hosted MCP, 24 tools.
33 pay-per-call market and news data tools over MCP with free discovery and x402 payments.
Related MCP Servers
AlicenseNot gradedqualityDmaintenanceSafe, read-only market data for AI trading agents, offering 44 tools to query prediction markets, perpetuals, and cross-venue signals without the ability to execute trades.MIT- AlicenseNot gradedqualityBmaintenanceProvides AI agents access to 336 real-time and historical market, quant, SEC filing, insider trading, fundamentals, and macro data tools via MCP Streamable HTTP.MIT
- FlicenseNot gradedqualityBmaintenanceProvides protocol-neutral market intelligence for the AI agent economy, with read-only tools to search agents, retrieve details and histories, compare agents, list categories, view category rankings, and access methodology.-
- AlicenseNot gradedqualityAmaintenanceLets any MCP-speaking assistant look up SEC filings and fundamentals, 13F holdings, insider trades, BDC loan books, and U.S. government reference data from Treasury, FRED, FDIC, USAspending, USPTO and CFTC, with the source named on every answer. Most of its 29 tools run keyless against public sources, giving citations-backed answers without an account.289 PyPIMIT