# openapi-mcp [Health: Active]

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/keumbang/goldpopcon-openapi-mcp  
**GitHub Stars:** 0  
**npm Downloads (last month):** 173  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/openapi-mcp

## Description
금방 Open API MCP 서버 — 스펙 조회·JWT 서명 코드 생성·로컬 서명/검증

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "openapi-mcp": {
    "command": "npx",
    "args": ["-y","@keumbang/goldpopcon-openapi-mcp"],
    "env": {
      "GOLDPOPCON_OPENAPI_SPEC": "",
      "GOLDPOPCON_MCP_ALLOW_LIVE": "",
      "GOLDPOPCON_ACCESS_KEY": "",
      "GOLDPOPCON_SECRET_KEY": ""
    }
  }
}
```

**Requires environment variables:** `GOLDPOPCON_OPENAPI_SPEC`, `GOLDPOPCON_MCP_ALLOW_LIVE`, `GOLDPOPCON_ACCESS_KEY`, `GOLDPOPCON_SECRET_KEY` — the values above are empty placeholders; fill in real credentials before running (see the repository for what each one is for).

## Documentation

## What openapi-mcp MCP server does

The openapi-mcp MCP server helps coding assistants work with the Goldpopcon Open API for gold and silver trading. It exposes the API specification, endpoint details, signing guidance, error information, and request-generation utilities through MCP tools. The server is intended for clients such as Claude Code, Claude Desktop, Codex CLI, Gemini CLI, Cursor, and VS Code.

Its bundled specification supports documentation lookup without requiring a live API connection. The available resources are `goldpopcon://openapi.yaml`, which contains the full specification, and `goldpopcon://overview`, which describes signing, limits, and errors.

## How it works

The server loads `spec/openapi.yaml` by default. `list_endpoints` returns operation names with permission scopes, idempotency details, and rate-limit buckets. `get_endpoint` provides one operation’s parameters, request body, successful response examples, and response codes. `list_error_codes` adds retry guidance and documents cases such as insufficient balance returning `400 P0001`.

JWT-related tools cover the signing rules used by Goldpopcon. `signing_guide` explains the method-dependent `query_hash` input, time claims, nonce, and idempotency. `generate_signed_request` creates complete Python, JavaScript, Go, or cURL examples. `sign_request` calculates a JWT locally from supplied keys and returns the token, query hash, and a usable cURL command. `verify_signature` checks an existing token using the same ordering as the API, which can help investigate HTTP 401 responses.

The optional `call_api` tool is registered only when `GOLDPOPCON_MCP_ALLOW_LIVE=true`. It is restricted to production, permits only selected read operations, and forces GET requests. Its supported operations are `getPrices`, `getBalances`, `getPriceHistory`, `getOrderPreview`, and `getTradeHistory`.

## Setup and configuration

Install from npm with `npx -y @keumbang/goldpopcon-openapi-mcp`, or clone the repository and run `npm install`, `npm run build`, and `npm test`. MCP clients can launch the package through a standard stdio configuration using `npx`, or run the built `dist/index.js` directly from a local clone.

`GOLDPOPCON_OPENAPI_SPEC` changes the specification file path. To enable live read-only calls, set `GOLDPOPCON_MCP_ALLOW_LIVE=true`. `GOLDPOPCON_ACCESS_KEY` and `GOLDPOPCON_SECRET_KEY` provide credentials to `call_api` when tool arguments are omitted. The README recommends environment variables for repeated automation so secret keys are not placed in model inputs or client transcripts.

API keys are issued in the Goldpopcon mobile app. The secret key is shown only during issuance and should be stored securely.

## Limitations and notes

The openapi-mcp MCP server does not execute live write operations. `buy`, `sell`, `payout`, and `virtual-accounts` cannot be used through `call_api`; use `generate_signed_request` to produce code that the developer runs in their own environment. Live calls are also limited to production and read-only GET requests.

Secrets supplied to `sign_request`, `verify_signature`, and `call_api` are used for local signing or requests; the README states that the secret itself is not sent over the network. However, passing a secret as a tool argument can expose it in model context, transcripts, or client logs, so environment-based credentials are preferred for automated reads.

The bundled specification is a copy of an OpenAPI file maintained in a separate backend repository. Updating it requires setting the `SPEC_SRC` path and running the synchronization command; the variable is required for that workflow. Rate limits differ by request group, including 600 requests per minute for quote operations and 60 for trade operations.

_Full upstream README: https://allmcps.com/mcp/openapi-mcp/readme_

