Quote.Trade MCP Adapter
Quote.Trade MCP: login, deposit address, market data, orders, and withdraws.
- 1.5.8
- Version
- remote
- Transport
- 25
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 25 tools scanned
- metadata: scanned
No findings.
Tools (25)
quote_trade_api_discovery
Read once to learn efficient direct REST/WebSocket use: routes, signing, streaming, cumulative depth, and client execution controls. Public guidance only; no upstream calls.
quote_trade_api_manifest
Explains that MCP is only a tool/schema adapter around the existing Quote.Trade APIs, and returns local servlet guardrail configuration.
quote_trade_get_challenge
Optional wallet login/register step 1 (not required for trading with an existing API key). POST /api/getChallenge with a wallet address (login). Returns challenge text and isNewUser. Step 2: sign the challenge with the wallet outside MCP. Step 3: quote_trade_logon. No API key required.
quote_trade_logon
Optional wallet login/register step 3 (not required if the agent already has an API key). Pass challenge + wallet signature from steps 1–2. isNewUser=true -> POST /api/registerUser; else POST /api/logon. On success, map body.requestToken/requestSecret to X-MBX-APIKEY / X-MBX-APISECRET; use body.id as account. Wallet signing stays outside MCP.
quote_trade_get_deposit_address
Deposit step 1. GET /api/getDepositAddress?symbol=ASSET and return chain + contract/address. Supported assets: USDC and USDT (mainnet), XUSDC (USDC on XDC). Step 2 is transferring funds to that address outside MCP (no backend call).
quote_trade_status
Call GET /api/status and return system status, server time, contracts URL, and feature flags.
quote_trade_exchange_info
Call GET /api/exchangeInfo and return a paginated slice of trading symbols plus rate limits/server time. Upstream has no pagination, so this adapter filters/slices locally. Default limit=50, max=200. Prefer quote_trade_instruments for compact tradable-pair discovery.
quote_trade_instruments
Trade step 1. GET /api/getInstrumentPairs — paginated tradable symbols/instruments. Default limit=50, max=200. Use skip to page. Pick a symbol from this response for ticker/depth/order calls.
quote_trade_ticker
Trade step 2. GET /api/ticker?symbol=SYMBOL for a symbol from quote_trade_instruments. Returns last price, bid, ask, lastUpdateId.
quote_trade_depth
Trade step 3. GET /api/depth?symbol=SYMBOL&limit=N. Use depth quantity to choose a suitable limit price before placing an order.
quote_trade_account
Withdraw step 1 / anytime account check. GET /api/account with per-request X-MBX-APIKEY. Inspect available balances before withdraw. No live trading action.
quote_trade_get_positions
Anytime position check. GET /api/positions with per-request X-MBX-APIKEY. Reconcile current positions when starting or reconnecting, per the direct-discovery guide (quote_trade_api_discovery / rest.privateReads). No live trading action.
quote_trade_get_orders
Anytime order check. POST /api/getOrders with per-request X-MBX-APIKEY. Read-only: no live trading action. Requires read entitlement on API keys that carry one.
quote_trade_get_order_status
Anytime order check. POST /api/orderStatus with per-request X-MBX-APIKEY. Query the status of an order previously placed with quote_trade_place_order. Read-only: no live trading action.
quote_trade_get_risk
Anytime risk check. POST /api/getRisk with per-request X-MBX-APIKEY. Margin/equity/unrealized-PnL summary for the authenticated account. Read-only: no live trading action.
quote_trade_get_order_history
Anytime order check. POST /api/getOrderHistory with per-request X-MBX-APIKEY. Full order history, or one order's history with optional orderId. Requires a trade-scoped API key (same scope as quote_trade_place_order). Read-only: no live trading action.
quote_trade_get_deposit_history
Anytime deposit check. POST /api/getDepositHistory with per-request X-MBX-APIKEY. Requires a trade-scoped API key (same scope as quote_trade_place_order). Read-only: no live trading action.
quote_trade_get_withdraw_requests
Anytime withdrawal check. POST /api/getWithdrawRequests with per-request X-MBX-APIKEY. Inspect the status of withdrawals already submitted (including via quote_trade_withdraw). Requires a trade-scoped API key. Read-only: no live trading action, and this tool cannot cancel a withdrawal.
quote_trade_get_user_wallets
Anytime wallet check. POST /api/getUserWallets with per-request X-MBX-APIKEY. On-chain addresses previously seen depositing to the authenticated account. Read-only: no live trading action.
quote_trade_get_index_positions
Anytime position check. POST /api/getIndexPositions with per-request X-MBX-APIKEY. Distinct from quote_trade_get_positions: index/basket instrument positions rather than regular instrument positions. Optional assetType filter. Read-only: no live trading action.
quote_trade_order_preview
Optional before live trade. Normalize/validate a BUY/SELL order locally without sending it.
quote_trade_place_order
Trade step 4. POST /api/order with a suitable price after instruments/ticker/depth. Requires tradingEnabled, allowedSymbols (* or explicit list; empty denies), and API credentials. No MCP USD notional cap applies. Sending X-MBX-APISECRET to this MCP host grants it full signing authority. humanApproved/approvalText are agent friction only.
quote_trade_cancel_order
Cancel one order by orderId. POST /api/cancelOrder. Identifies exactly one order via the matching engine's single-order cancel path - NOT a mass-cancel. There is no quote_trade_cancel_all: the upstream mass-cancel action's scope for edge-case parameters could not be verified from this codebase alone and is intentionally not exposed through MCP. Requires tradingEnabled, allowedSymbols (same allowlist as quote_trade_place_order), and a trade-scoped API key. No notional check applies: a cancellation has none. humanApproved/approvalText are agent friction only.
quote_trade_withdraw_preview
Optional before live withdraw. Stablecoins only: USDC, USDT, or XUSDC (not BTC/ETH/other). Own login wallet only (no toAddress). estimatedNotional is USD at $1 peg. Trade-only API keys cannot withdraw — use a full-access key with withdraw entitlement.
quote_trade_withdraw
Withdraw step 3. POST /api/sendWithdrawWithVTokenRequest for stablecoins only (USDC|USDT|XUSDC) to the user's own login wallet (no toAddress). Not available for BTC/ETH/other assets. Requires a full-access API key with withdraw entitlement (trade-only keys are rejected by Quote.Trade), tradingEnabled, and allowedWithdrawAssets (independent of the trading allowedSymbols allowlist). No MCP USD notional cap applies. humanApproved/approvalText are agent friction only.