Questrade MCP Server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Questrade MCP ServerShow me my portfolio overview"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Questrade MCP Server
An MCP server for the Questrade trading API. Use it from MCP-compatible clients (Claude, ChatGPT, Cursor, and others) to inspect portfolio data, quotes, market history, orders, and account activity.
This server is designed around outcome-oriented tools: each tool performs the necessary Questrade API orchestration internally so agents can get complete results with fewer round-trips.
Table of Contents
Related MCP server: Interactive Brokers MCP Server
Quick Start
Prerequisites
Node.js 22+
A Questrade account with API access enabled
1) Clone, Install, Build
git clone https://github.com/DrWheelicus/questrade-mcp-server.git
cd questrade-mcp-server
npm install
npm run build2) Get a Questrade Refresh Token
Open the Questrade API Hub
Register a personal app (or reuse an existing one)
Enter a name for the device and a description
Click Create
Select New device
Select Generate new token
Copy the refresh token and paste it into the .env file
The refresh token is a secret and should not be shared. If you lose it, you will need to generate a new one. (Steps 5-7)
3) Add Server to Your MCP Client
Use a config like this (replace with your local absolute path):
{
"mcpServers": {
"questrade": {
"command": "node",
"args": ["/absolute/path/to/Questrade/dist/index.js"],
"env": {
"QUESTRADE_REFRESH_TOKEN": "<your-token>"
}
}
}
}Common locations:
Claude Desktop:
~/Library/Application Support/Claude/claude_desktop_config.json(macOS) or%APPDATA%\Claude\claude_desktop_config.json(Windows)Claude Code: project
.mcp.jsonor~/.claude/mcp.jsonCursor: Settings -> MCP Servers
On some Windows MSIX installs, Claude Desktop may read a virtualized config path instead:%LOCALAPPDATA%\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude\claude_desktop_config.json.
4) Verify
Restart your MCP client and ask:
Show me my portfolio
MCP Features
Tools: purpose-built portfolio and market data operations
Transport support:
stdiofor local clients, Streamable HTTP for remote clientsValidation: tool inputs validated with Zod schemas
Token lifecycle management: encrypted persistence and automatic refresh
This server currently exposes MCP tools (not prompts/resources).
Tools
Tool | Description |
| Full portfolio overview across accounts with positions and balances |
| Positions held in a specific account |
| Cash balances and buying power for an account |
| Search by ticker/name and return symbol details plus live quote |
| Batch Level 1 quotes by ticker names or symbol IDs |
| Historical OHLCV candles at intervals from 1 minute to yearly |
| Order history with state and date filters |
| Combined activities and executions timeline |
Configuration
All runtime configuration is environment-driven:
Variable | Required | Default | Description |
| Yes (first run) | - | OAuth refresh token from Questrade |
| No |
|
|
| No |
|
|
| No |
| Port for HTTP transport |
| No | machine-derived | Override encryption key for token storage |
| No |
|
|
The CLI flag --transport overrides QUESTRADE_MCP_TRANSPORT.
HTTP Mode (Remote Clients)
QUESTRADE_REFRESH_TOKEN=<your-token> node dist/index.js --transport=httpServer endpoint:
http://localhost:3100/mcp
Token Management
Questrade uses single-use refresh tokens. This server:
Exchanges the initial refresh token on first startup
Encrypts and stores token material with AES-256-GCM
Renews access proactively before expiry
Retries once on
401responses after refreshing
Token storage paths:
Platform | Path |
Windows |
|
macOS |
|
Linux |
|
After first successful startup, QUESTRADE_REFRESH_TOKEN is only needed again if the cached token expires.
Real-Time Data Notes
Questrade requires a paid market data subscription for real-time quotes.
Without one, getQuotes returns snap quotes with daily exchange limits and may
fall back to delayed data. Use isDelayed in quote responses to detect this.
Development Setup
npm install
npm run dev
npm run build
npm run lint
npm run typecheck
npm testMCP Inspector
npx @modelcontextprotocol/inspector node dist/index.jsProject Structure
.
├── src/
│ ├── index.ts # Server entrypoint and transport selection
│ ├── server.ts # MCP server and tool registration
│ ├── config.ts # Env/config parsing
│ ├── log.ts # Logger setup
│ ├── auth/ # Token persistence and refresh
│ ├── client/ # Questrade API client and rate limiting
│ ├── tools/ # MCP tool implementations
│ ├── transports/ # stdio and HTTP transport handlers
│ └── types/ # Shared API/domain types
├── tests/ # Unit/integration tests
├── .github/workflows/ # CI/CD workflows
└── DockerfileDocker
Build and run HTTP transport:
docker build -t questrade-mcp .
docker run -p 3100:3100 -e QUESTRADE_REFRESH_TOKEN=<your-token> questrade-mcpCI/CD
CI on push/PR to
main: type check, lint, build, tests,npm audit, dependency reviewCD on tags matching
v*.*.*: multi-arch Docker image to GHCR and GitHub Release
Security
Token material encrypted at rest (AES-256-GCM)
Refresh tokens rotated by design (Questrade behavior)
Token values redacted from logs
Read-only server scope (no trade placement tools)
Input validation on all tool parameters (Zod)
HTTP transport uses per-client session isolation
Docker image runs as non-root user
Contributing
See CONTRIBUTING.md for contributor setup, quality checks, and PR process.
GitHub issue and PR templates are provided in .github/ to keep reports and reviews consistent.
Security Policy
See SECURITY.md for how to report vulnerabilities privately.
Release Process
See RELEASE.md for the tag-based release checklist and verification steps.
License
Proprietary - All Rights Reserved.
No permission is granted to copy, modify, redistribute, sublicense, or use this code except with explicit written permission from the copyright holder.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/DrWheelicus/questrade-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server