
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
finlight-mcp
Advanced tools
Real-time financial news for AI agents: search by ticker, source, and language, with sentiment and entities.
mcp-name: me.finlight/news
Real-time financial news for AI agents. Connect Claude, ChatGPT, Cursor, or any MCP client to finlight, a financial news API covering global markets, geopolitics, and company-level news with sentiment analysis and entity tagging.
Endpoint: https://mcp.finlight.me (remote, streamable HTTP)
Auth: OAuth 2.0 (you'll be prompted for your finlight API key during connection)
Registry: me.finlight/news
Ask your AI assistant things like:
| Tool | Description |
|---|---|
search_articles | Search financial news articles with filters for query, tickers, sources, countries, language, and date range. Returns articles with metadata, sentiment scores, and tagged company entities. |
get_article_by_link | Retrieve a specific article by its URL, including full enrichment (sentiment, confidence, tagged companies with tickers and ISINs). |
list_sources | List all available news sources with country of origin and content availability. |
You need a finlight API key. The free tier includes 5,000 requests per month: sign up at app.finlight.me.
https://mcp.finlight.meclaude mcp add --transport http finlight https://mcp.finlight.me
Add to your MCP settings (.cursor/mcp.json):
{
"mcpServers": {
"finlight": {
"url": "https://mcp.finlight.me"
}
}
}
Add https://mcp.finlight.me as a remote MCP server and complete the OAuth flow with your API key.
For MCP clients that only support stdio transport (or if you prefer a locally spawned process), use the npm wrapper:
npx finlight-mcp
This bridges stdio to the remote server via mcp-remote. Add it to any client config that takes a command + args:
{
"mcpServers": {
"finlight": {
"command": "npx",
"args": ["-y", "finlight-mcp"]
}
}
}
The OAuth flow is the same — a browser window will open for you to enter your API key on first use.
The server implements standard OAuth 2.0 with dynamic client registration and PKCE. During authorization you enter your finlight API key on a hosted page; the server never stores it. This means any MCP client that speaks OAuth works out of the box, no manual header configuration needed.
finlight aggregates and enriches financial news from curated, finance-relevant sources including major wire services, financial publishers, and regional sources (including Chinese-language financial media such as CLS, Caixin, Yicai, and East Money, with English canonical entity tagging). Articles include:
The MCP server uses the same data as the REST and WebSocket APIs.
MCP requests count toward your API quota. Free tier: 5,000 requests/month. See pricing for paid tiers with real-time access, higher limits, and additional features.
Issues and feature requests for the MCP server are welcome here on GitHub. For API questions, use Discord or the support channels above.
FAQs
Real-time financial news for AI agents: search by ticker, source, and language, with sentiment and entities.
The npm package finlight-mcp receives a total of 30 weekly downloads. As such, finlight-mcp popularity was classified as not popular.
We found that finlight-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.