Unofficial xRocket market data and opt-in local account and financial workflow tools
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Set one daily value limit, connect an xRocket API token locally, and let an MCP-capable AI agent place and cancel spot orders autonomously inside that limit. Internal transfers and external withdrawals remain separate prepare/approve/execute operations.
The hosted endpoint is a zero-account market-data demo and onboarding path. Actual account reads and trading run locally with the user's xRocket token. This project is not affiliated with, endorsed by, or operated by xRocket.
Set up trading Β· Open xRocket Β· Try the market demo Β· Official API overview Β· Safety model Β· Coverage Β· Distribution
| Layer | Purpose | Default |
|---|---|---|
| MCP server | Semantic tools over the official REST API | public, mainnet, read-only |
| Agent skill | Teaches agents market analysis, bounded autonomous trading, explicit transfer/withdrawal approval, and reconciliation | Read first; stay inside the configured policy |
| Portable Agent Plugin | Installs the public MCP endpoint and skill in GitHub Copilot CLI and other Agent Plugins-compatible hosts | Public tools only |
| Gemini CLI extension | Installs the public MCP endpoint directly from GitHub and is eligible for automatic Gallery indexing | Public tools only |
| Codex / Claude Code plugin | Installs the server and skill together from a repo marketplace | Public tools only |
| Registry metadata | server.json for io.github.nakazanie-ton/xrocket | Published in the Official MCP Registry |
| Hosted endpoint | Public mainnet tools over Streamable HTTP | No install, token, or account access |
The API surface was re-audited on 2026-08-24 and still covers all 50 Exchange documentation pages, all 26 OpenAPI operations, and all 7 WebSocket channels. The four linked legal PDFs were reviewed separately on 2026-08-07. The current OpenAPI document has canonical SHA-256 5de074def6ee9f59c7c1d1a2f8a06e1f5e2fafb446ebef58af7168e32813e2a3. See the source inventory.
| Profile | Tools | Token | Financial writes |
|---|---|---|---|
public | 10 public market-data and onboarding tools | Not used | Impossible |
private-read | Public tools plus 6 account/history tools | Required | Impossible |
full | Public and private reads, 3 autonomous trading tools, and 4 transfer/withdrawal approval tools | Required | Still disabled until each feature gate is enabled |
For normal questions, xrocket_market_snapshot resolves a symbol or base asset and returns rules, ticker, best bid/ask, recent trades, fees, and an Open xRocket next action in one call. Private mode adds xrocket_account_overview for funding balances, trading balances, and active orders without inventing portfolio valuation. Full mode adds autonomous market/limit orders and cancellation inside the local policy; transfers and withdrawals keep their approval receipts.
Sign in to xRocket. In the bot, open Menu β Settings β Exchange settings β API token.
Generate a testnet configuration with one daily value limit:
Paste the printed JSON into your local MCP client and replace SET_YOUR_XROCKET_API_TOKEN_LOCALLY in that client's local secret or environment settings. Do not paste the token into chat, this website, an issue, or a committed file.
Give the agent a strategy:
Use xRocket on testnet. Trade GRAM-USDT with this strategy: [describe strategy]. Stay inside the configured daily trading limit. Do not transfer or withdraw funds.
The agent can now place and cancel market or limit orders on any available spot pair until the daily limit or the built-in order-count limits are reached.
After testing, generate a live configuration with npx -y xrocket-mcp@0.6.0 trading-config --limit 100 --asset USD --mainnet. Transfers and withdrawals remain disabled.
The xRocket API token is a broad bearer credential without documented granular scopes. Local MCP feature gates reduce what this server exposes, but they do not narrow the upstream token itself. Use a trusted local client and protect its configuration like a password.
Open the zero-install connection page or add this URL to any MCP client that supports Streamable HTTP:
Generic client configuration:
The hosted service is structurally limited to the 10 public mainnet tools. It never reads tokens, account data, or financial-write settings. Its health endpoint is /health.
For balances, order history, or autonomous execution, use the local package above. The remote demo cannot be upgraded with a token.
Requirements: Node.js 20 or newer. No clone or configuration is needed for public market data:
The second command prints this copy-paste MCP client configuration:
The Codex bundle is described by plugins/xrocket-exchange/.codex-plugin/plugin.json, and its safe defaults are already set in plugins/xrocket-exchange/.mcp.json. Register this repository's marketplace, then install the all-in-one plugin:
GitHub Copilot CLI can install the portable Agent Plugin directly from its repository subdirectory:
This direct install uses the hosted public-only MCP endpoint. Local account access and trading still use the one-limit configuration generated in the quick start above.
Gemini CLI can install the root extension directly:
The Gemini extension also starts with the hosted public-only tools and returns the local trading setup when account access is requested.
For a local clone, replace the first command with codex plugin marketplace add /absolute/path/to/myrocket.
Claude Code uses the same public-first bundle through its native marketplace:
The installed plugin can inspect live markets immediately. When account access or trading is requested, its skill directs the user to sign in and generate the local configuration with one daily limit; no API token is requested in chat.
For source development:
The current package is xrocket-mcp@0.6.0.
Create an xRocket API token in the signed-in bot and pass it only through the local process environment. With a token present, the profile defaults to private-read; an explicit profile is still respected:
Never put the bearer token in a prompt, tool argument, committed MCP file, issue, or log. xRocket describes one broad bearer credential rather than fine-grained scopes, so treat it as full account access.
full does not enable writes by itself. Enable only the capability you need:
Trading orders are autonomous:
xrocket_agent_trade estimates the order, converts its quote value to the configured limit asset, checks the daily value, daily order-count, and active-order limits, reserves the amount durably, and submits once.xrocket_agent_cancel cancels an existing order directly. Cancellation does not need per-order approval.XROCKET_TRADING_SYMBOLS is an optional advanced allowlist, not an onboarding requirement.Internal transfers and external withdrawals still use the exact prepare/approve/execute receipt flow. Their feature gates are off in the generated trading configuration.
Mainnet writes additionally require XROCKET_ENVIRONMENT=mainnet and XROCKET_ALLOW_MAINNET_WRITES=true. See configuration and safety details.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/xrocket-exchange-mcp)<a href="https://allmcps.com/mcp/xrocket-exchange-mcp"><img src="https://allmcps.com/api/badge/xrocket-exchange-mcp?style=directory" alt="XRocket Exchange MCP on AllMCPs" /></a>