Connects MCP clients to Goldpopcon’s Open API for spec lookup, JWT request signing, verification, and optional read-only calls.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag — we're steadily working through the catalog.
💡 Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Openapi MCP.
The openapi-mcp MCP server helps coding assistants work with the Goldpopcon Open API for gold and silver trading. It exposes the API specification, endpoint details, signing guidance, error information, and request-generation utilities through MCP tools. The server is intended for clients such as Claude Code, Claude Desktop, Codex CLI, Gemini CLI, Cursor, and VS Code.
Its bundled specification supports documentation lookup without requiring a live API connection. The available resources are goldpopcon://openapi.yaml, which contains the full specification, and goldpopcon://overview, which describes signing, limits, and errors.
The server loads spec/openapi.yaml by default. list_endpoints returns operation names with permission scopes, idempotency details, and rate-limit buckets. get_endpoint provides one operation’s parameters, request body, successful response examples, and response codes. list_error_codes adds retry guidance and documents cases such as insufficient balance returning 400 P0001.
JWT-related tools cover the signing rules used by Goldpopcon. signing_guide explains the method-dependent query_hash input, time claims, nonce, and idempotency. generate_signed_request creates complete Python, JavaScript, Go, or cURL examples. sign_request calculates a JWT locally from supplied keys and returns the token, query hash, and a usable cURL command. verify_signature checks an existing token using the same ordering as the API, which can help investigate HTTP 401 responses.
The optional call_api tool is registered only when GOLDPOPCON_MCP_ALLOW_LIVE=true. It is restricted to production, permits only selected read operations, and forces GET requests. Its supported operations are getPrices, getBalances, getPriceHistory, getOrderPreview, and getTradeHistory.
Install from npm with npx -y @keumbang/goldpopcon-openapi-mcp, or clone the repository and run npm install, npm run build, and npm test. MCP clients can launch the package through a standard stdio configuration using npx, or run the built dist/index.js directly from a local clone.
GOLDPOPCON_OPENAPI_SPEC changes the specification file path. To enable live read-only calls, set GOLDPOPCON_MCP_ALLOW_LIVE=true. GOLDPOPCON_ACCESS_KEY and GOLDPOPCON_SECRET_KEY provide credentials to call_api when tool arguments are omitted. The README recommends environment variables for repeated automation so secret keys are not placed in model inputs or client transcripts.
API keys are issued in the Goldpopcon mobile app. The secret key is shown only during issuance and should be stored securely.
The openapi-mcp MCP server does not execute live write operations. buy, sell, payout, and virtual-accounts cannot be used through call_api; use generate_signed_request to produce code that the developer runs in their own environment. Live calls are also limited to production and read-only GET requests.
Secrets supplied to sign_request, verify_signature, and call_api are used for local signing or requests; the README states that the secret itself is not sent over the network. However, passing a secret as a tool argument can expose it in model context, transcripts, or client logs, so environment-based credentials are preferred for automated reads.
The bundled specification is a copy of an OpenAPI file maintained in a separate backend repository. Updating it requires setting the SPEC_SRC path and running the synchronization command; the variable is required for that workflow. Rate limits differ by request group, including 600 requests per minute for quote operations and 60 for trade operations.
Factual signals from GitHub, npm, and our automated checks — not a rating.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/openapi-mcp)<a href="https://allmcps.com/mcp/openapi-mcp"><img src="https://allmcps.com/api/badge/openapi-mcp?style=directory" alt="Openapi MCP on AllMCPs" /></a>