AlgoVesta MCP Server
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@AlgoVesta MCP Serverwhat's my current paper balance and any open positions?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
AlgoVesta MCP Server
Trade 16 crypto exchanges and MetaTrader 5 from your AI assistant — over one MCP connection.
Documentation · Tool reference · Safety model · Tool schemas (JSON) · Product overview
AlgoVesta runs a hosted Model Context Protocol server that reaches 16 crypto exchanges and MetaTrader 5 through a single HTTPS endpoint. Claude, ChatGPT, Cursor, Claude Code, Gemini CLI or any other MCP-capable client can read balances, open and close positions, move stop-loss and take-profit, and audit its own actions.
Your risk rules are compiled to JSON and evaluated on the server, after the request leaves the model — outside the reach of anything the model can be persuaded to say. Every new key starts on a $5,000 paper balance, and every action returns an ed25519-signed, hash-chained receipt.
Hosted and closed-source. This repository is the public documentation, tool reference and client configuration set. There is nothing to install, build or self-host — you connect to the hosted endpoint.
Contents — At a glance · How it works · Quick start · Connect your client · Supported AI clients · In use · Tools · Safety model · Venues · Performance and limits · Endpoints · FAQ
At a glance
Transport | Remote MCP over Streamable HTTP |
Authentication | Secret link, or OAuth 2.1 with mandatory PKCE ( |
Tools | 20 — 13 read-only, 3 write, 4 destructive (reference) |
Venues | 16 crypto exchanges · MetaTrader 5 · built-in paper engine |
Default scope |
|
Live scope | Issued only after a second factor, enforced server-side |
Risk policy | Compiled to JSON, evaluated deterministically on the server |
Audit | ed25519-signed, hash-chained receipt per action, independently verifiable |
Install | None. Hosted endpoint. |
Registry |
|
Related MCP server: bybit-trading-mcp
How it works
flowchart LR
A["AI client<br/>Claude, ChatGPT, Cursor, and more"]
B["AlgoVesta MCP server<br/>scope, rate limit, idempotency"]
C{"Policy wall<br/>evaluated server-side"}
R["Refusal<br/>plus audit entry"]
D["Execution"]
E["16 crypto exchanges"]
F["MetaTrader 5<br/>managed terminals"]
G["Paper engine<br/>5,000 USD virtual"]
H["ed25519-signed receipt"]
A -->|MCP over HTTPS| B
B --> C
C -->|violates a rule| R
C -->|allowed| D
D --> E
D --> F
D --> G
D --> HThe model is the caller, never the authority. It decides what to ask for; the server decides what happens. Your exchange API keys never leave AlgoVesta and are created without withdrawal permission — the assistant only ever holds a scoped, revocable MCP link.
Quick start
Create an AlgoVesta account and open the MCP Connection tab in the panel.
Generate a key. New keys default to the
paperscope; the full link is shown once.Paste the link into your AI client as a custom MCP server.
https://api.algovesta.com/u/avmcp_<your-key>/mcpThat URL is a credential. Treat it like a password. If it leaks, revoke it in the panel — revocation takes effect immediately for new connections and drops open event streams within seconds.
Clients that prefer a full authorization flow can use OAuth 2.1 instead, at https://api.algovesta.com/mcp. PKCE (S256) is mandatory and Dynamic Client Registration is supported, so most clients configure themselves. See docs/AUTHENTICATION.md.
Connect your client
Six walkthroughs below; anything else uses the same URL in whatever field it calls a remote MCP server.
Claude — web, desktop, iOS, Android
Settings -> Connectors -> Add custom connector, paste the URL, then allow the tools when Claude asks. Walkthrough
Claude Code
claude mcp add --transport http algovesta https://api.algovesta.com/u/avmcp_<your-key>/mcpChatGPT
Settings -> Connectors -> Advanced -> Developer mode -> Create, transport Streamable HTTP. Custom connectors are a paid-plan feature on OpenAI's side. Walkthrough
Cursor
~/.cursor/mcp.json, or .cursor/mcp.json inside a project — file
{
"mcpServers": {
"algovesta": { "url": "https://api.algovesta.com/u/avmcp_<your-key>/mcp" }
}
}VS Code — GitHub Copilot
.vscode/mcp.json — file
{
"servers": {
"algovesta": {
"type": "http",
"url": "https://api.algovesta.com/u/avmcp_<your-key>/mcp"
}
}
}Gemini CLI
~/.gemini/settings.json — file. CLI only; the Gemini web app does not accept custom MCP servers.
{
"mcpServers": {
"algovesta": { "httpUrl": "https://api.algovesta.com/u/avmcp_<your-key>/mcp" }
}
}Anything else
The three config shapes you will meet, plus a curl connection check: examples/other-clients.md
Supported AI clients
This is a standard remote MCP server over Streamable HTTP, so anything that speaks remote MCP can connect. The clients below document that support themselves — each row links to the client's own configuration docs, which is where the exact field name lives.
Client | MCP documentation |
Claude — web, desktop, iOS, Android | |
ChatGPT — Developer mode connectors | |
Microsoft Copilot Studio agents | |
Goose (Block) | |
LibreChat | |
Open WebUI | |
Cherry Studio | |
Raycast |
Client | MCP documentation |
Claude Code | |
OpenAI Codex CLI | |
Gemini CLI | |
Cursor | |
VS Code — GitHub Copilot | |
Windsurf | |
Zed | |
Cline | |
Roo Code | |
Kilo Code | |
Continue | |
JetBrains AI Assistant | |
Warp | |
Amazon Q Developer | |
Kiro (AWS) | |
Sourcegraph Amp | |
Trae | |
PostHog Code | |
Archestra.AI |
Client | MCP documentation |
OpenAI Agents SDK | |
fast-agent | |
n8n — MCP Client Tool node | |
Postman | |
MCP Inspector | |
MCPJam |
Scope of that claim. We have verified Claude end to end against this server. The others are listed because they document remote MCP support — not because we individually tested each one. Client support also moves fast, and a given client may gate connectors behind a paid plan (ChatGPT does) or behind its CLI only (the Gemini web app does not accept custom MCP servers). If a listed client misbehaves with us, or one is missing, open an issue.
What it looks like in use
You never call a tool by name. You ask in plain language; the assistant picks the tool.
You say | The assistant reaches for |
"What's in my accounts right now, and how has this month gone?" |
|
"Where is BTC trading on the exchanges I've connected?" |
|
"If I opened 0.05 BTC long on Binance with a 2% stop, what would it cost and would my rules allow it?" |
|
"OK, open it — stop 2% below, target 4% above." |
|
"Move the stop on my ETH position up to break-even." |
|
"Close half of the SOL long." |
|
"Never risk more than 1% per trade, max 3 positions, stop me after a 5% daily drawdown." |
|
"Show me the receipt for that last order and verify it." |
|
"Run my last 90 days of signals again with a 1% risk cap." |
|
And what it will refuse. "Turn on auto-trading for that strategy" — refused; auto_trade is not a writable field in any scope. "Trade on Kraken for me" when Kraken is not connected — VENUE_NOT_CONNECTED, not a guess. "Open it without a stop" — refused, with no saved default to fall back on.
On a paper key every one of those runs against the $5,000 virtual balance with the identical toolset, so the whole workflow can be rehearsed before real money is reachable.
Tools
20 tools. Scope read works on any key; paper / live gates the rest.
Tool | Scope | Kind | Purpose |
| read | read-only | Every connected account in one call |
| read | read-only | Live price with freshness reported |
| read | read-only | Closed trades and performance across crypto, MT5 and paper |
| read | read-only | Ranks your connected exchanges on measured price and spread |
| read | read-only | Dry-run including the policy verdict |
| paper / live | destructive | Opens a position (live crypto: market orders only) |
| read | read-only | Turns plain-language rules into a policy preview |
| read | read-only | Pending limit orders (paper book) |
| paper / live | destructive | Cancels a pending order |
| paper / live | destructive | Closes fully or partially (MT5: full close only) |
| paper / live | write | Moves stop-loss and take-profit |
| read | read-only | Your TradingView strategies and whether real money is on |
| paper / live | write | New strategy, always created with real money OFF |
| paper / live | write | Changes strategy settings (never |
| read | read-only | Checks signature and hash chain |
| read | read-only | Backtests a Telegram channel against your rules |
| read | read-only | Replays your own past signals with different settings (queued job) |
| read | read-only | Applies a risk policy to the trades you actually closed (queued job) |
| read | read-only | Recomputes a TradingView trade export with real fees and slippage (queued job) |
| read | read-only | Progress and result of a queued job |
Two of them deserve a note, because what they refuse to do is the point:
compare_venuesdoes not route your order. It reports the live price and, on venues that publish one, the bid/ask spread. It does not know your fee tier, the order book depth or the slippage you would pay — and it says so in every response. A venue that publishes no bid/ask is listed separately rather than ranked as if its spread were zero. You still name the exchange yourself inplace_order.create_strategy/update_strategycannot turn real money on. A new strategy is always created withauto_tradeoff, andauto_tradeis not in the writable field set — an assistant cannot set it, whatever it is asked or persuaded to do. A single order is one action you can see; a strategy keeps trading after the conversation ends, so arming one stays a human decision made in the panel.ip_allowlistis refused for the same reason: it is the second factor that verifies where signals come from.
Full reference with descriptions and JSON Schemas: docs/TOOLS.md · machine-readable: tools.json
Safety model
The AI is the caller — never the authority. Full model: docs/SAFETY.md.
Control | What it means |
Paper by default | Every new key starts in |
Server-side policy wall | Max risk per trade, order-size cap, daily-loss cap, position count, leverage cap, venue/symbol/side restrictions — compiled to JSON and evaluated deterministically after the request leaves the model. A prompt injection can change what the model sends; it cannot change how the server evaluates it. |
Stop-loss is mandatory | No stop-loss and no saved default means the order is refused. The stop cannot be removed later either. On forex/MT5, a take-profit is mandatory too. |
Idempotency | Every order-shaped tool — including the read-only |
Signed receipts | Every action returns an ed25519-signed, hash-chained receipt, verifiable against the public key endpoint. |
Kill switch and per-key revocation | Freeze everything at once, or revoke one client without touching the others. |
Structural tenant isolation | Tools have no identity parameter at all. The account is derived from the authenticated connection, so there is no argument a confused model or an attacker could supply to reach another account. |
No withdrawal path | Exchange API keys are created without withdrawal permission and stay inside AlgoVesta, AES-256 encrypted. The AI only ever holds a scoped, revocable MCP link. |
Venues
Crypto (16) — Binance · Bybit · OKX · KuCoin · Gate.io · Bitget · Kraken · Coinbase · BingX · Hyperliquid · Backpack · HTX · BloFin · Phemex · WOO X · CoinEx
Forex, metals, indices — MetaTrader 5, zero installation: AlgoVesta runs the MT5 terminals on its own managed servers, connected to your broker 24/7.
Simulation — built-in paper engine, $5,000 virtual.
Six exchanges — Binance, Bybit, OKX, Gate.io, KuCoin and Bitget — have been verified end to end with real money on both futures and spot, with stop-loss and take-profit confirmed on the exchange itself. Each exchange has its own quirks, and the differences are deliberate rather than gaps: Bybit and Bitget do not accept a second take-profit leg on spot; OKX spot is routed through the raw API to keep a cash account from silently becoming a margin account; Binance spot enforces a minimum notional before buying; KuCoin market buys are placed in cost mode. A venue becomes available to the AI only after you connect it — asking for one you have not connected returns VENUE_NOT_CONNECTED rather than a guess.
Performance and limits
Limit | Value |
All tool calls, per key | 60 / minute |
| 10 / minute |
| 5 / hour (results cached 24 h) |
Measured, not marketing — all figures measured in August 2026:
Stage | Measured |
Request intake and parsing | 17–67 ms (median 38, n=6) |
End to end on MetaTrader 5 | about 1 second (849 ms on a live demo order) |
End to end on a crypto exchange | about 3 seconds (2,785 ms on a live order) |
Paper engine | median 318 ms (n=18, min 284, max 769) |
Time spent inside your AI client — the model thinking, and you confirming — is not included and usually dominates. This server is not a low-latency execution venue and is not sold as one.
Endpoints
Purpose | URL |
MCP — secret link |
|
MCP — OAuth 2.1 |
|
Live events (SSE) |
|
OAuth metadata |
|
Receipt public key | |
Tool schemas |
Published in the official MCP Registry as com.algovesta/trading; server.json in this repository is that manifest.
FAQ
Yes — once you give it a key with the live scope, and that scope is only issued after a second factor. Until then the same assistant runs against a $5,000 paper balance with identical tools, so you can rehearse the entire workflow before any real money is reachable.
No, and you should never do that with any tool. Your API keys stay inside AlgoVesta, encrypted, created without withdrawal permission. The assistant only ever holds an MCP link — scoped, rate-limited, policy-checked, individually revocable, and useless for moving funds off an exchange.
It can change what the model asks for. It does not change how the server answers: your rules are evaluated after the request leaves the model, by code the prompt never reaches, and a violation is rejected and written to the audit log. The limits of that guarantee are worth stating plainly — it covers rule evaluation, scope and account isolation, not the wording of what the assistant tells you afterwards.
Nothing happens twice. Every write tool requires an idempotency key, and a repeat of the same key returns the stored response instead of acting again.
The kill switch in the panel (POST /api/mcp/freeze) stops everything at once; every tool then returns user_frozen. To cut off a single client, revoke just that key.
Support
Account and trading questions: support · support@algovesta.com Vulnerability reports: SECURITY.md Client that will not connect, or one missing from the list above: open an issue
Compliance
AlgoVesta does not generate signals, does not hold, receive or move client funds, and does not provide investment advice. Trading carries risk; automation does not remove it. Every new key starts on paper.
License
Copyright (c) 2026 AlgoVesta. Documentation and configuration examples in this repository are licensed under CC BY 4.0. The AlgoVesta MCP server itself is proprietary and hosted; this repository contains no server source code.
This server cannot be deployed
Maintenance
Related MCP Connectors
Trade across 22+ exchanges and brokers from any MCP-capable AI agent, no install required.
No-KYC managed MCP for AI agents: sandboxed TypeScript trading SDK, isolated sub-accounts, futures.
Unified financial infrastructure connecting AI agents directly to trade live/demo brokerage accounts, Web3 non-custodial wallets, real-time market data across equities, ETFs, crypto, forex, options, DeFi swaps, and prediction markets, institutional research feeds, and algorithmic strategy backtesters.
Crypto trading intelligence MCP — 34+ endpoints, x402 pay-per-use, AI agent strategy & execution
Related MCP Servers
AlicenseNot gradedqualityAmaintenanceMCP server connecting AI assistants to OKX exchange, enabling trading, market data, account management, and more via 150+ tools across 11 modules.439MIT- FlicenseNot gradedqualityDmaintenanceEnables AI tools to execute trades and fetch market data across six crypto exchanges via natural language or API, with dual Telegram and MCP interfaces.2-
- FlicenseNot gradedqualityBmaintenanceSecure broker gateway and stateful trading SaaS that bridges LLM AI agents with brokerage accounts via MCP, encrypting credentials and supporting connectors for Bybit, MetaTrader 5, TradingView, and more.-
- AlicenseBqualityDmaintenanceEnables AI agents to trade crypto with paper money, access market data, view leaderboards, and manage trading bots via an MCP-compatible interface.16MIT