
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@fts-studio/studio-mcp
Advanced tools
MCP server for FTS Studio API — search financial news & regulatory intelligence, retrieve full articles, generate cited AI summaries, and manage collections from Claude, ChatGPT, Cursor, and other MCP clients. Runs locally over stdio or remotely over Stre
MCP (Model Context Protocol) server for the FTS Studio API. Connects Claude Desktop, Cursor, and other MCP-compatible AI clients to financial news intelligence.
Create one at FTS Studio → Build → API Keys.
Add to your claude_desktop_config.json:
{
"mcpServers": {
"fts-studio": {
"command": "npx",
"args": ["@fts-studio/studio-mcp"],
"env": {
"FTS_API_KEY": "fts_live_your_key_here"
}
}
}
}
Config file locations:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.jsonAdd to your Cursor MCP settings:
{
"mcpServers": {
"fts-studio": {
"command": "npx",
"args": ["@fts-studio/studio-mcp"],
"env": {
"FTS_API_KEY": "fts_live_your_key_here"
}
}
}
}
Once configured, you can ask Claude or Cursor things like:
For hosted / directory connectors the server also runs over Streamable HTTP,
exposing POST/GET/DELETE /mcp with sessions tracked by Mcp-Session-Id. A
GET /healthz endpoint reports liveness.
MCP_TRANSPORT=http PORT=8787 npx @fts-studio/studio-mcp
# or: npx @fts-studio/studio-mcp --http
Point a remote MCP client at https://mcp.fintechstudios.com/mcp.
FTS_MCP_AUTH)apikey (default) — each request carries the FTS API key in the
Authorization: Bearer header; used directly for downstream calls. Good for
developer-mode / custom connectors.oauth — OAuth 2.1 Resource Server, required for the Anthropic Connectors
Directory and OpenAI Apps. The server publishes Protected Resource Metadata at
/.well-known/oauth-protected-resource, validates the bearer access token per
request (JWKS + issuer + audience), and returns 401 with a
WWW-Authenticate challenge on failure. The validated identity is exchanged
for a scoped fts_ key server-side (via FTS_MCP_EXCHANGE_URL), so the raw
API key never reaches the AI client.A Dockerfile is included; the image runs in HTTP mode on PORT (default 8787)
with TLS terminated by the platform/load balancer:
docker build -t fts-studio-mcp ./mcp-server
docker run -p 8787:8787 \
-e MCP_TRANSPORT=http \
-e FTS_API_BASE_URL=https://studio.fintechstudios.com \
-e FTS_MCP_AUTH=oauth \
-e FTS_MCP_OAUTH_ISSUER=https://auth.fintechstudios.com/ \
-e FTS_MCP_OAUTH_AUDIENCE=https://studio.fintechstudios.com/api \
-e FTS_MCP_RESOURCE=https://mcp.fintechstudios.com/mcp \
-e FTS_MCP_EXCHANGE_URL=https://studio.fintechstudios.com/api/v1/mcp/exchange \
-e FTS_MCP_EXCHANGE_SERVICE_TOKEN=<shared secret, same value set on the app> \
-e FTS_MCP_ALLOWED_HOSTS=mcp.fintechstudios.com \
fts-studio-mcp
All tools are read-only. Credit costs are indicative — call estimate_endpoint_costs
to price a call before making it.
| Tool | Credits | Description |
|---|---|---|
search | ~1 | Deep Research contract: find documents → {id, title, url} |
fetch | ~1 | Deep Research contract: full document text + citation by id |
search_news | ~1 | Richer news search (source, date, summary, citation) |
get_trending | ~1 | Trending market news stories |
get_trending_entities | ~1 | Trending companies/people/industries with scores |
summarize_news | ~5 | AI executive summary with inline citations |
list_collections | 0 | List your saved collections |
get_collection_articles | ~1 | Articles from a saved collection |
execute_collection | varies | Run a collection now for fresh articles |
estimate_endpoint_costs | 0 | Per-endpoint credit cost table |
get_usage | 0 | Recent credit usage and balance |
list_models | 0 | Models available for summaries/chat |
get_account | 0 | Account info, tier, and credit balance |
| Variable | Required | Description |
|---|---|---|
FTS_API_KEY | stdio only | Your API key (fts_live_... or fts_test_...) |
FTS_API_BASE_URL | No | API base URL (default https://studio.fintechstudios.com) |
MCP_TRANSPORT | No | Set to http for remote Streamable HTTP mode |
PORT | No | HTTP listen port (default 8787) |
FTS_MCP_TIMEOUT_MS | No | Per-request API timeout (default 30000) |
FTS_MCP_ALLOWED_HOSTS | No | Comma-separated Host allow-list (enables DNS-rebinding protection) |
FTS_MCP_ALLOWED_ORIGINS | No | Comma-separated Origin allow-list |
FTS_MCP_AUTH | No | apikey (default) or oauth |
FTS_MCP_OAUTH_ISSUER | oauth | Authorization Server issuer URL (e.g. your Auth0 tenant) |
FTS_MCP_OAUTH_AUDIENCE | oauth | Expected access-token audience |
FTS_MCP_RESOURCE | No | This server's resource URL (default https://mcp.fintechstudios.com/mcp) |
FTS_MCP_OAUTH_JWKS_URI | No | Override JWKS URI (default <issuer>/.well-known/jwks.json) |
FTS_MCP_OAUTH_SCOPES | No | Space-separated scopes_supported for metadata |
FTS_MCP_EXCHANGE_URL | No | FTS endpoint that swaps a validated identity for a scoped fts_ key |
FTS_MCP_EXCHANGE_SERVICE_TOKEN | No | Shared secret sent as X-MCP-Service-Token to the exchange endpoint |
MIT — see LICENSE.
FAQs
MCP server for FTS Studio API — search financial news & regulatory intelligence, retrieve full articles, generate cited AI summaries, and manage collections from Claude, ChatGPT, Cursor, and other MCP clients. Runs locally over stdio or remotely over Stre
We found that @fts-studio/studio-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.