New:Microsoft Teams Notifications Are Now Available in Socket.Learn more
Get Started

@luxalgo/broker-mcp

Package Overview
Dependencies
Maintainers
3
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install
Package was removed
Sorry, it seems this package was removed from the registry

@luxalgo/broker-mcp

Local MCP server giving AI agents read-only access to your real brokerage accounts — your keys, your machine, never a server in between.

latest
Source
npmnpm
Version
0.1.0
Version published
Weekly downloads
0
Maintainers
3
Weekly downloads
 
Created
Source

@luxalgo/broker-mcp

npm CI License: MIT

Give your AI agent read access to your real brokerage accounts — with keys that never leave your machine.

A local MCP server wrapping @luxalgo/broker-sdk. Connect Claude (or any MCP client) to Alpaca, Binance, Kraken, Bybit, Hyperliquid, Interactive Brokers and more, then just ask:

"How's my portfolio doing?" · "What's my win rate this month?" · "What did I trade last week?"

No hosted service, no telemetry, no per-connection fees. The server runs on your machine, your keys live in your own MCP config, and the underlying SDK has no trading endpoints at all — the agent can look, not touch.

Setup

Add the server to your MCP client config with the credential env vars for the brokers you use. Claude Desktop (claude_desktop_config.json) or Claude Code (.mcp.json):

{
  "mcpServers": {
    "brokers": {
      "command": "npx",
      "args": ["-y", "@luxalgo/broker-mcp"],
      "env": {
        "BROKERS_ALPACA_API_KEY": "…",
        "BROKERS_ALPACA_API_SECRET": "…",
        "BROKERS_KRAKEN_API_KEY": "…",
        "BROKERS_KRAKEN_API_SECRET": "…",
        "BROKERS_HYPERLIQUID_WALLET_ADDRESS": "0x…"
      }
    }
  }
}

Every broker whose variables are all set is connected automatically. Create every key with read-only scope — that is all this server ever needs; the list_brokers tool includes the one-line read-only setup guide per broker.

Environment variables

Names derive mechanically from each broker's credential fields: BROKERS_<BROKER>_<FIELD>.

BrokerVariables
AlpacaBROKERS_ALPACA_API_KEY, BROKERS_ALPACA_API_SECRET
Coinbase (BYO app)BROKERS_COINBASE_CLIENT_ID, BROKERS_COINBASE_CLIENT_SECRET, BROKERS_COINBASE_REFRESH_TOKEN
BinanceBROKERS_BINANCE_API_KEY, BROKERS_BINANCE_API_SECRET
BybitBROKERS_BYBIT_API_KEY, BROKERS_BYBIT_API_SECRET
Crypto.comBROKERS_CRYPTO_COM_API_KEY, BROKERS_CRYPTO_COM_API_SECRET
E*TRADE (BYO app)BROKERS_ETRADE_CONSUMER_KEY, BROKERS_ETRADE_CONSUMER_SECRET, BROKERS_ETRADE_ACCESS_TOKEN, BROKERS_ETRADE_ACCESS_TOKEN_SECRET
HyperliquidBROKERS_HYPERLIQUID_WALLET_ADDRESS
Interactive Brokers (Flex)BROKERS_IBKR_FLEX_FLEX_TOKEN, BROKERS_IBKR_FLEX_FLEX_QUERY_ID
KrakenBROKERS_KRAKEN_API_KEY, BROKERS_KRAKEN_API_SECRET
OKXBROKERS_OKX_API_KEY, BROKERS_OKX_API_SECRET, BROKERS_OKX_PASSPHRASE
Public.comBROKERS_PUBLIC_API_KEY
QuestradeBROKERS_QUESTRADE_REFRESH_TOKEN
TopstepBROKERS_TOPSTEP_USER_NAME, BROKERS_TOPSTEP_API_KEY
TradierBROKERS_TRADIER_ACCESS_TOKEN
Trading212BROKERS_TRADING212_API_KEY
WebullBROKERS_WEBULL_API_KEY, BROKERS_WEBULL_API_SECRET

Questrade caveat: its refresh tokens are single-use and rotate on every fetch. The server keeps the rotated token in memory while it runs, but after a restart the token in your config is already consumed — you'll need to paste a fresh one. Static env config and rotating tokens are a poor fit; a better answer is on the roadmap.

Tools

ToolWhat the agent gets
list_brokersEvery supported broker, its env vars (set/unset — never values), configured state, read-only key guide
list_accountsAll connected accounts: broker, currency, equity, cash
get_positionsOpen positions with market values (negative quantity = short); filter by broker
get_tradesTrade history, newest first; filter by broker/symbol
get_statsTotal equity, equity by broker, top positions, FIFO win rate, avg win/loss, realized PnL per symbol
refreshBypass the 5-minute cache and re-fetch everything now

Snapshots are cached in memory for 5 minutes; per-broker failures are reported alongside results, never silently dropped.

Security posture

  • Read-only by construction. The SDK underneath implements no order, transfer, or withdrawal endpoint for any broker.
  • Keys stay in your MCP config. The server reads them from its environment, reports only whether each variable is set, and never writes secrets anywhere.
  • Local only. Talks to your brokers directly over HTTPS and to your MCP client over stdio. No LuxAlgo server involved, no telemetry.
  • Still: scope every key read-only at the broker, and treat your MCP config file like the secret store it is.

Development

pnpm install && pnpm check && pnpm build

The SDK dependency installs from the public npm registry like any other package.

Disclaimer

This software reports what your broker reports. It is not investment advice. Verify important numbers against your broker's own statements.

License

MIT © LuxAlgo

Keywords

mcp

FAQs

Package last updated on 25 Aug 2026

Related posts