Skip to main content
AI Fin Hub

Directory

Finance MCP Directory + Security Grader

Security-graded catalog of finance MCP servers: Alpaca, Polygon, Databento, IBKR, Tradier, Tiingo, NautilusTrader. Scope, auth, grade.

Runs in your browser. Nothing you enter is uploaded, and no account or API key is needed.

Education, not investment advice. Past performance does not predict future results. How we check our numbers.

MCP servers tracked

7

2 graded A and 2 graded B on maintenance, schema, auth, idempotency and license. Catalog snapshot of 2026-04-20; check each repo before use.

7servers

sorted by grade

A

Alpaca MCP Server v2 ↗

Alpaca· Official

Official Alpaca MCP server. Shipped April 2026 with 61 actions across equities, options, and crypto. Read + execute across the Alpaca brokerage API.

Scope

full

Auth

api-key

Transport

stdio+http

Idempotent

yes

Schema qual

A

License

MIT

Last commit

2026-04-15

Capabilities: bars (daily / minute), quotes (live via SIP+IEX), options chains, crypto pairs, submit orders, portfolio positions, account state

Security notes

  • API key has broad trading authority — store securely
  • No scoping of key permissions in-server (rely on Alpaca dashboard key scopes)
  • Idempotency key supported on order submission
A

Polygon.io MCP Server ↗

Polygon.io· Official

Official Polygon.io MCP server. Read-only access to all Polygon equities, options, crypto, FX data endpoints.

Scope

read-only

Auth

api-key

Transport

stdio+http

Idempotent

no

Schema qual

A

License

Apache-2.0

Last commit

2026-04-10

Capabilities: stocks aggregates (daily / minute / sec / tick), options chains, crypto trades + quotes, forex rates, news API, reference data

Security notes

  • Read-only scope — no trade execution surface
  • API key required; safe to scope tightly
  • No idempotency concern (no writes)
B

IBKR CLI MCP ↗

Interactive Brokers· Community

Community MCP wrapper around Interactive Brokers' TWS / IB Gateway. Requires running Gateway locally; auth via IBKR account.

Scope

full

Auth

bearer-token

Transport

stdio

Idempotent

yes

Schema qual

B

License

Apache-2.0

Last commit

2026-04-02

Capabilities: live quotes (subject to IBKR data subscription), historical bars, options, submit orders, cancel orders, portfolio positions

Security notes

  • Requires TWS / Gateway running on the client machine
  • IBKR token stored client-side — do not commit to repos
  • Idempotency supported via client-supplied orderId
  • Community project — audit before production trading
B

Community MCP wrapper for NautilusTrader — a Rust-based algo trading platform. Exposes backtesting + live-trading adapters to LLM agents.

Scope

full

Auth

api-key

Transport

stdio

Idempotent

yes

Schema qual

B

License

LGPL-3.0

Last commit

2026-04-18

Capabilities: backtest harness control, strategy deployment, multi-venue adapters, risk engine

Security notes

  • LGPL license — review redistribution obligations if bundling
  • Idempotency enforced by Nautilus core
  • Local-only by default — exposes nothing to the network without configuration
C

Community-maintained Databento MCP server. Wraps historical + live data endpoints. Not endorsed by Databento; verify schemas against docs.

Scope

read-only

Auth

api-key

Transport

stdio

Idempotent

no

Schema qual

B

License

MIT

Last commit

2026-03-28

Capabilities: historical OHLCV, tick data (limited), futures, symbology lookups

Security notes

  • Unofficial — review schema fidelity before production use
  • Does not rate-limit; relies on Databento's server-side meter
  • Billing tracked via Databento meter — test runs cost money
C

Tiingo MCP (community) ↗

Tiingo· Community

Community Tiingo MCP. Read-only access to EOD equities, news API, fundamentals, crypto.

Scope

read-only

Auth

api-key

Transport

stdio

Idempotent

no

Schema qual

B

License

MIT

Last commit

2026-03-05

Capabilities: EOD equities, intraday (limited tiers), news, fundamentals, crypto

Security notes

  • Read-only — no execution risk
  • Does not expose API key in responses
D

Tradier MCP (community) ↗

Tradier· Community

Community Tradier brokerage MCP. Supports sandbox + live accounts, including options trading.

Scope

full

Auth

bearer-token

Transport

http-stream

Idempotent

no

Schema qual

C

License

MIT

Last commit

2026-02-14

Capabilities: stock + option quotes, option chains, submit orders, portfolio

Security notes

  • No idempotency key — duplicate-submission risk on retry
  • Sandbox + live on same server; verify account slug before every call
  • Community maintained, audit activity gaps

About this directory

Grade = points for official status (+2), a commit within 30 days of the snapshot (+2, or +1 within 90), schema quality (A +3 to F −1), auth (OAuth +2, API key or bearer token +1), idempotent order submission on servers that can trade (+2, or −1 without it) and a permissive license (+1). 9+ points = A, 7–8 = B, 5–6 = C, 3–4 = D. It is a hygiene screen, not a security audit: transport security and audit logging are not graded. Catalog snapshot of 2026-04-20.

How to use it

  1. Filter by scope: read-only servers only read data, while execution and full-scope servers can place orders and need much more scrutiny.
  2. Filter by grade (A only, B or better, C or better) or by source (official vs community), or search by vendor or capability. Results are sorted best grade first.
  3. Open a server's repository link and check that it is still maintained and that its auth method fits your deployment; the catalog is a 2026-04-20 snapshot.
  4. Read the facts and security notes: scope, auth, transport, idempotent order submission, schema quality, license and last commit.
  5. Test in paper mode first. Even an A-grade server can have edge-case bugs that surface only at integration time.

Questions people ask

How are MCP servers security-graded?

Each server gets points that add up to an A-F grade: official vendor server +2; last commit within 30 days of the snapshot +2 (within 90 days +1); tool-schema quality from +3 (A) to −1 (F); OAuth +2, API key or bearer token +1; for servers that can trade, idempotent order submission +2 or −1 without it; a permissive license (MIT, Apache-2.0, BSD-3-Clause) +1. 9 or more points is an A, 7-8 a B, 5-6 a C, 3-4 a D. Transport security and audit logging are listed in the notes where known but are not scored.

Why isn't every broker MCP server listed?

The catalog is a curated snapshot (2026-04-20) of publicly documented, maintained finance MCP servers: seven entries covering Alpaca, Polygon/Massive, Databento, Interactive Brokers, Tradier, Tiingo and NautilusTrader. Closed-beta and corporate-only servers are excluded, and newer servers released after the snapshot are not yet listed.

Are these MCP servers safe to use with real funds?

The grade is a hygiene screen, not a security audit or a recommendation. Even an A-grade server should not be wired to a live trading account untested: run it against paper trading first, scope the API key as tightly as the broker allows, log every request, and use idempotency keys on order submission. Read each entry's security notes for the known caveats.

What's the difference between scope: read-only vs scope: read-write?

Read-only servers expose market data and reference data with no way to change anything. Read-write servers can write non-trading state. Execution servers can place and cancel orders, and full-scope servers do both reading and trading. The directory marks every server's scope because anything that can trade needs much stricter key scoping, logging and rate limits.

How often is the directory updated?

Irregularly: the current catalog is a 2026-04-20 snapshot, and each entry shows the last commit date seen at that time. Recency points in the grade are measured against the snapshot date, so check the linked repository for current activity before relying on a server.

  • Comparators Market Data API Cost Calculator

    Compute annual cost of market data across Databento, Polygon, Alpaca, Tiingo, FMP, and Alpha Vantage for your exact universe, bar resolution, and real-time needs.

  • Generators Trading System Blueprinter

    Pick your data source, LLM, broker, storage, risk engine, and logger. Get a Mermaid architecture diagram and a copyable starter file tree — the full stack before you write code.

  • Playgrounds Prompt Injection Tester

    Red-team a finance agent against 23 documented prompt-injection attacks — direct override, role confusion, indirect injection via retrieved content.

  • 6 min read Twelve Data API Pricing 2026

    Twelve Data API pricing 2026: free Basic is 8 credits/min and 800/day; paid Grow is $79/mo ($66 annual), not the stale $29 some sites cite. Verified.

  • 10 min read The 2026 Engineer's Guide to AI in Markets

    An engineer's map of where LLMs, MCP servers, and market-data APIs fit into a 2026 trading stack — and where they still break. Direct, no hype, no grift.

  • 9 min read Market Data APIs Compared: Databento vs Polygon 2026

    Market data APIs compared: six retail providers on pricing, tier coverage, real-time access, options and futures coverage, and who wins for each profile.

All articles
  • Workflow Plan your agent stack

    Estimate first-year cost for an LLM agent — token budget, vendor selection, MCP servers.

Use it from code

The same calculation as a JavaScript module you can import. It runs where you import it, with no request, key or rate limit.

import { compute } from "https://aifinhub.io/engines/finance-mcp-directory.js";

Input and output contract and the guide for agents.