ZerodhaCAUTION
Mcp server to connect with zerodha's kite trade apis
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@aptro/zerodha-mcp)
This project integrates Zerodha's trading platform with Claude AI using the Multi-Cloud Plugin (MCP) framework, allowing you to interact with your Zerodha trading account directly through Claude.
Setup Instructions
Installing via Smithery
To install zerodha-mcp for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install @aptro/zerodha-mcp --client claude
1. Create a Zerodha Developer Account
- Go to Kite Connect and sign up for a developer account
- Log in to your account at developers.kite.trade
2. Create a New App
- Navigate to the "Apps" section in your Kite Developer dashboard
- Click on "Create a new app"
- Fill in the required details:
- App Name: Choose a descriptive name (e.g., "Claude Zerodha Integration")
- App Category: Select "Personal" or appropriate category
- Redirect URL: Set to
http://127.0.0.1:5000/zerodha/auth/redirect - Description: Briefly describe your application's purpose
- Submit the form to create your app
3. Get API Credentials
After creating your app, you'll receive:
- API Key (also called Consumer Key)
- API Secret (also called Consumer Secret)
These credentials will be displayed on your app's details page.
4. Configure Environment Variables
- Create a
.envfile in the root directory of this project - Add your API credentials to the file:
KITE_API_KEY=your_api_key_here KITE_API_SECRET=your_api_secret_here
Replace your_api_key_here and your_api_secret_here with the actual credentials from step 3.
5. Install Dependencies
Make sure you have all required dependencies installed:
uv pip install kiteconnect fastapi uvicorn python-dotenv httpx
6. Install MCP config on y
65dd0cbfd46cOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add zerodha-mcp --env KITE_API_KEY=${KITE_API_KEY} --env KITE_API_SECRET=${KITE_API_SECRET} -- uvx zerodha-mcp{
"mcpServers": {
"zerodha-mcp": {
"command": "uvx",
"args": [
"zerodha-mcp"
],
"env": {
"KITE_API_KEY": "${KITE_API_KEY}",
"KITE_API_SECRET": "${KITE_API_SECRET}"
}
}
}
}Exposed tools (18)
14 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cancel_mf_order | write | |
cancel_mf_sip | read | |
check_and_authenticate | read | |
get_historical_data | read | |
get_holdings | read | Get user |
get_margins | read | Get account margins |
get_mf_holdings | read | Get user |
get_mf_instruments | read | Get all available mutual fund instruments |
get_mf_orders | read | Get all mutual fund orders |
get_mf_sips | read | Get all mutual fund SIPs |
get_positions | read | Get user |
get_quote | read | |
get_request_token | read | Get the current request token after login redirect |
initiate_login | read | |
modify_mf_sip | write | |
place_mf_order | write | |
place_mf_sip | read | |
place_order | write |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
REDIRECT_URL = "http://127.0.0.1:5000/zerodha/auth/redirect"
print("Starting FastAPI server on http://127.0.0.1:5000")- Redirect URL: Set to `http://127.0.0.1:5000/zerodha/auth/redirect`
Gates applied: no_behavioural_pass.
65dd0cbfd46cfull audit observations/trust-audit/mcp-server/aptro__zerodha.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 65dd0cbfd46c | CAUTION | B | 89 | first audit |
Questions
What is the Zerodha MCP server?
Mcp server to connect with zerodha's kite trade apis
What tools does Zerodha expose?
18 in total: 14 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Zerodha safe to connect to an agent?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Zerodha need?
It reads KITE_API_KEY and KITE_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (65dd0cbfd46c), read on 2026-10-08. The repository is watched and re-audited when it changes.