The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Longbridge MCP listing page.
Official MCP server for the Longbridge brokerage. 163 tools across real-time quotes, options, order routing, fundamentals, analyst ratings, calendars, IPO, price alerts, DCA plans, grid trading, portfolio analytics and community sharelists — covering US and HK markets. Built with Rust using rmcp and axum.
Longbridge is officially listed in the ChatGPT Apps directory and the Claude Connectors directory.
Talk to the markets in plain language — quotes, options, fundamentals, and your own portfolio —
with no config files to edit and no tokens to paste.
| Add it in one place | Then just ask | |
|---|---|---|
| ChatGPT | Settings → Apps & Connectors → add Longbridge | "How's NVDA trading today?" · "Show my HK positions" |
| Claude | Settings → Connectors → add Longbridge (web · desktop · mobile) | "Compare AAPL and MSFT valuations" · "Any IPOs this week?" |
Sign in once with your Longbridge account. Every request runs over the same hosted, OAuth 2.1–secured endpoint documented below — read-only market data plus full account, portfolio, and trading tools, all gated by your own credentials.
Built in Rust with rmcp and axum.
Every tool accepts an optional _jq string in its arguments. The expression runs
on the complete returned JSON, after the normal response serialization. The _jq
name is reserved for response filtering to avoid conflicts with business parameters.
Usage guidance is sent once in the MCP initialize response's instructions;
each tool schema declares only the optional parameter name and type.
For example:
Use .data[:5] to take the first five entries of a data array,
.data | map(select(.price > 10)) to select rows, or {total: .total} to
project fields. Expressions use the embedded jaq
engine's jq-compatible syntax; no separate jq executable is needed.
_jq (or pass null) to preserve the original response.[]. Scalars and arrays are JSON text; objects also appear in
structuredContent, containing only the filtered fields.Because filters can change the response shape, tools do not advertise a fixed
outputSchema. Original typed schemas remain available through resources/list
and resources/read at lb://tools/{tool-name}/output-schema for schema-backed tools.
Longbridge runs a hosted endpoint at https://mcp.longbridge.com — point any MCP client at it and complete OAuth when prompted. Authorization is auto-discovered via RFC 9728; there is no token to paste.
Claude Code
Claude Desktop — add to claude_desktop_config.json, then restart:
Cursor · Cline · Windsurf · Zed · other clients — point them at https://mcp.longbridge.com with transport streamable-http.
On first use, the client reads the WWW-Authenticate challenge, fetches /.well-known/oauth-protected-resource (RFC 9728), and opens your browser for the Longbridge OAuth flow. Tokens are cached per session and refreshed automatically.
Twenty categories spanning market data, trading, research and account management.
| Category | Count | Coverage |
|---|---|---|
| Quote | 32 | Real-time and historical quotes, candlesticks, depth, brokers, options, warrants, watchlists, capital flow, market temperature, short positions, option volume |
| Fundamental | 33 | Financial statements/reports, business segments, institutional views, industry peers/valuation, dividends, EPS forecasts, valuations & valuation comparison, company info/executives, shareholders, corporate actions, operating metrics |
| Trade | 14 | Order submission/cancellation/replacement, positions, balance, executions, cash flow, margin |
| Market | 15 | Market status, industry/top-mover rank, broker holdings, A/H premium, trade statistics, anomalies, short trades/margin, index constituents |
| DCA | 9 | Dollar-cost averaging plan create/update/pause/resume/stop, execution history, statistics, support check |
| Grid | 11 | Grid trading order submit/replace/cancel/suspend/restart, list/detail/trigger-history reads, per-symbol setup info, one-time strategy consent |
| Sharelist | 8 | Community sharelist CRUD, member add/remove/sort, popular lists |
| IPO | 7 | IPO subscriptions, calendar, listed stocks, order detail, profit/loss analysis |
| Content | 7 | News list/detail, discussion topic CRUD and replies |
| Alert | 5 | Price alert CRUD (add, delete, enable, disable, list) |
| Screener | 5 | Stock screener search, indicators, strategy recommendation/management |
| Portfolio | 4 | Exchange rates, profit/loss analysis (summary, detail, realized) |
| ATM | 3 | Bank cards, withdrawal records, deposit records |
| Macrodata | 2 | Macroeconomic indicator list and detail |
| Search | 2 | News search, community topic search |
| Statement | 2 | Account statement listing and export |
| Calendar | 1 | Finance calendar (earnings, dividends, IPOs, macro data, closures) |
| Quant | 1 | Run a quant indicator script against historical K-line data |
| Authenticate | 1 | OAuth code exchange for clients that can't complete a browser redirect |
| Utility | 1 | Current UTC time |
Prefer your own instance? Run the published image:
Set
--base-urlto your externally reachable URL on any public deployment — it is published in the OAuth metadata clients use to discover the authorization server. It defaults tohttp://localhost:{port}, which remote clients cannot use.
Or build from source: cargo build --release && ./target/release/longbridge-mcp.
Config lives at ~/.longbridge/mcp/config.json (override the directory with LONGBRIDGE_MCP_CONFIG_DIR). CLI flags take precedence. When tls_cert and tls_key are both set the server runs HTTPS, otherwise HTTP; base_url defaults to https://localhost:{port} with TLS or http://localhost:{port} without.
| Option | Config Key | CLI Flag | Default | Description |
|---|---|---|---|---|
| Bind address | bind | --bind | 127.0.0.1:8000 | HTTP server listen address |
| Base URL | base_url | --base-url | auto | Public base URL for resource metadata |
| Log directory | log_dir | --log-dir | (stderr) | Directory for rolling log files |
| TLS certificate | tls_cert | --tls-cert | (none) | PEM certificate file for HTTPS |
| TLS private key | tls_key | --tls-key | (none) | PEM private key file for HTTPS |
| Canary upstream | canary | --canary | false | Talk to the Longbridge canary environment (*.longbridge.xyz) instead of production. --canary=false forces production even when the config file enables it |
Upstream endpoints are fixed by the mode, not by the environment:
| Production (default) | Canary (--canary) | |
|---|---|---|
| OpenAPI | https://openapi.longbridge.com | https://openapi-global.longbridge.xyz |
| Quote WebSocket | wss://openapi-quote.longbridge.com/v2 | wss://openapi-global-quote.longbridge.xyz/v2 |
| Trade WebSocket | wss://openapi-trade.longbridge.com/v2 | wss://openapi-global-trade.longbridge.xyz/v2 |
| OAuth / connect page | openapi.longbridge.com / open.longbridge.com | openapi-global.longbridge.xyz / open.longbridge.xyz |
Canary uses the -global gateway, not openapi.longbridge.xyz: only the former is CloudFront-fronted and performs x-dc-region data-center routing, which this server depends on to serve us_- and ap_-prefixed credentials from one process.
All three are set explicitly on the SDK, so LONGBRIDGE_HTTP_URL, LONGBRIDGE_QUOTE_WS_URL, LONGBRIDGE_TRADE_WS_URL, their LONGPORT_* aliases, LONGBRIDGE_REGION, and a .env file are all inert — as is the SDK's geolocation probe, which means the openapi.longbridge.cn access point is never selected. Which data center serves a request is unaffected: that is decided by the x-dc-region header the SDK derives from the credential's us_ / ap_ prefix.
Advanced environment variables — most deployments never touch these; they exist for SDK debugging and edge/global-entry deployments.
| Variable | Default | Description |
|---|---|---|
LONGBRIDGE_MCP_CONFIG_DIR | ~/.longbridge/mcp | Config file directory |
LONGBRIDGE_PUBLIC_HOSTS | (none) | Comma-separated hostnames accepted from the edge-injected X-Host header; matching requests echo that host in the 401 challenge / RFC 9728 metadata. Unset = X-Host ignored |
LONGBRIDGE_GLOBAL_OAUTH_URL | (none) | Authorization-server URL advertised to requests arriving via an allowlisted X-Host (global single-domain entry). Unset = fall back to the mode's OpenAPI base URL |
LONGBRIDGE_MCP_QUOTE_WS_IDLE_TTL_SECS | 600 | Idle seconds before a cached quote WebSocket context is evicted |
LONGBRIDGE_MCP_QUOTE_WS_MAX_CONTEXTS | 1024 | Maximum cached quote WebSocket contexts per server process |
LONGBRIDGE_MCP_LOG_PAYLOADS | (unset) | 1 lifts the payload log caps (see below). Never set this in production |
LONGBRIDGE_LOG_PATH | (none) | SDK internal log path. Leave unset in production — the SDK writes unfiltered request/response bodies there |
MCP requests and responses carry customer data — cash balances, positions, order history — and upstream SDK frames carry access tokens. None of it belongs in a log file, so the server caps the log targets that would print it, independent of RUST_LOG:
| Target | Cap | What it would otherwise print |
|---|---|---|
longbridge_httpcli | warn | OpenAPI request and full response bodies (INFO) |
longbridge_wscli | warn | Every WebSocket frame, auth token included (INFO) |
longbridge::trade | warn | Order push events (INFO) |
rmcp | info | Decoded MCP requests and full tool results (DEBUG), raw JSON-RPC frames (TRACE) |
So raising verbosity is safe: RUST_LOG=debug (or trace) gives you the server's own logs without leaking customer data. Two switches defeat this, both off by default — LONGBRIDGE_MCP_LOG_PAYLOADS=1 (removes the caps; use only against a test account locally) and LONGBRIDGE_LOG_PATH (makes the SDK write unfiltered bodies to that directory; the server warns at startup when set).
The server expects a Longbridge OAuth access token in Authorization: Bearer <token>. On missing or invalid auth it returns 401 with a WWW-Authenticate header pointing to the protected-resource metadata, which directs clients to the Longbridge OAuth authorization server.
| Method | Path | Description |
|---|---|---|
| GET | /.well-known/oauth-protected-resource | Protected Resource Metadata (RFC 9728) |
| GET | /.well-known/oauth-authorization-server | Authorization Server Metadata (RFC 8414); advertises direct Longbridge authorize/register and proxied token/revoke endpoints |
| POST | /oauth2/token | OAuth token proxy; derives x-dc-region from the code/refresh token, defaulting to AP |
| POST | /oauth2/revoke | OAuth revocation proxy; derives x-dc-region from the token, defaulting to AP |
| GET | /metrics | Prometheus metrics |
| POST/GET/DELETE | /mcp | MCP Streamable HTTP endpoint (requires Bearer token) |
Prometheus metrics: mcp_tool_calls_total (counter), mcp_tool_call_duration_seconds (histogram), and mcp_tool_call_errors_total (counter) — each labelled by tool_name.
Released under the MIT License.