Atlas / MCP servers / aptro / Zerodha

ZerodhaCAUTION

mcp/aptro/zerodha

Mcp server to connect with zerodha's kite trade apis

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
18 14r · 4w · 0d
Transport
—
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@aptro/zerodha-mcp)

This project integrates Zerodha's trading platform with Claude AI using the Multi-Cloud Plugin (MCP) framework, allowing you to interact with your Zerodha trading account directly through Claude.

Setup Instructions

Installing via Smithery

To install zerodha-mcp for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @aptro/zerodha-mcp --client claude

1. Create a Zerodha Developer Account

  1. Go to Kite Connect and sign up for a developer account
  2. Log in to your account at developers.kite.trade

2. Create a New App

  1. Navigate to the "Apps" section in your Kite Developer dashboard
  2. Click on "Create a new app"
  3. Fill in the required details:
  4. App Name: Choose a descriptive name (e.g., "Claude Zerodha Integration")
  5. App Category: Select "Personal" or appropriate category
  6. Redirect URL: Set to http://127.0.0.1:5000/zerodha/auth/redirect
  7. Description: Briefly describe your application's purpose
  8. Submit the form to create your app

3. Get API Credentials

After creating your app, you'll receive:

  • API Key (also called Consumer Key)
  • API Secret (also called Consumer Secret)

These credentials will be displayed on your app's details page.

4. Configure Environment Variables

  1. Create a .env file in the root directory of this project
  2. Add your API credentials to the file:
KITE_API_KEY=your_api_key_here
KITE_API_SECRET=your_api_secret_here

Replace your_api_key_here and your_api_secret_here with the actual credentials from step 3.

5. Install Dependencies

Make sure you have all required dependencies installed:

uv pip install kiteconnect fastapi uvicorn python-dotenv httpx

6. Install MCP config on y

Read from source at commit 65dd0cbfd46cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add zerodha-mcp --env KITE_API_KEY=${KITE_API_KEY} --env KITE_API_SECRET=${KITE_API_SECRET} -- uvx zerodha-mcp
claude-desktop
{
  "mcpServers": {
    "zerodha-mcp": {
      "command": "uvx",
      "args": [
        "zerodha-mcp"
      ],
      "env": {
        "KITE_API_KEY": "${KITE_API_KEY}",
        "KITE_API_SECRET": "${KITE_API_SECRET}"
      }
    }
  }
}
03

Exposed tools (18)

14 read · 4 write · 0 destructive.

ToolRiskDescription
cancel_mf_orderwrite
cancel_mf_sipread
check_and_authenticateread
get_historical_dataread
get_holdingsreadGet user
get_marginsreadGet account margins
get_mf_holdingsreadGet user
get_mf_instrumentsreadGet all available mutual fund instruments
get_mf_ordersreadGet all mutual fund orders
get_mf_sipsreadGet all mutual fund SIPs
get_positionsreadGet user
get_quoteread
get_request_tokenreadGet the current request token after login redirect
initiate_loginread
modify_mf_sipwrite
place_mf_orderwrite
place_mf_sipread
place_orderwrite
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
main.py:21
REDIRECT_URL = "http://127.0.0.1:5000/zerodha/auth/redirect"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
main.py:64
print("Starting FastAPI server on http://127.0.0.1:5000")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:28
- Redirect URL: Set to `http://127.0.0.1:5000/zerodha/auth/redirect`

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 65dd0cbfd46cfull audit observations/trust-audit/mcp-server/aptro__zerodha.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0865dd0cbfd46cCAUTIONB89first audit
06

Questions

What is the Zerodha MCP server?

Mcp server to connect with zerodha's kite trade apis

What tools does Zerodha expose?

18 in total: 14 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Zerodha safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Zerodha need?

It reads KITE_API_KEY and KITE_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (65dd0cbfd46c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement