ZerodhaSAFE
Zerodha MCP Server & Client - AI Agent (w/Agno & w/Google ADK)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Python-based trading assistant that connects to a Zerodha MCP server to help users manage their trading account.
Features
- Account Management: Manage Zerodha trading account, orders, and positions
- Interactive Chat Interface: Natural language interface for trading operations
- MCP Integration: Built on the Model Context Protocol for standardized communication
- Zerodha API Integration: Uses Zerodha's API to interact with the trading platform
- Agno Agent: Uses Agno Agent to interact with the trading platform
- Google ADK Agent: Uses Google ADK Agent to interact with the trading platform
Tech Stack
- Protocol: Model Context Protocol (MCP)
- Agent Framework:
- Agno
- Google ADK
Tools
- Place Orders: Place orders in the trading platform
- Modify Orders: Modify orders in the trading platform
- Cancel Orders: Cancel orders in the trading platform
- Get Orders: Get orders in the trading platform
- Get Order History: Get order history in the trading platform
- Get Order Trades: Get order trades in the trading platform
- Get Margins: Get margins in the trading platform
- Get Holdings: Get holdings in the trading platform
- Get Positions: Get positions in the trading platform
- Get User Profile: Get user profile in the trading platform
Prerequisites
- Python
- Zerodha trading account with Personal API access from here
- Zerodha API key and secret
- OpenAI API key (for Agno Agent)
- Gemini API key or Application Default Credentials (for Google ADK Agent)
Installation
- Clone the repository:
git clone https://github.com/mtwn105/zerodha-mcp-server-client.git cd zerodha-
523490168d80OBSERVED · 2026-10-08Exposed tools (12)
7 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cancel_order | write | Cancel an order. |
get_access_token | read | Get the access token for the user. |
get_holdings | read | Get the user |
get_login_url | read | Get the login URL for the user. Use this to get the login URL for the user and then redirect the user to the login URL to get the request token. |
get_margins | read | Get the user |
get_order_history | write | Get history of an order. |
get_order_trades | write | Get trades generated by an order. |
get_orders | read | Get all orders placed for the day. |
get_positions | read | Get the user |
get_user_profile | read | Get the authenticated user |
modify_order | write | Modify an existing order. |
place_order | write | Place a new order on Zerodha. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
agno, mcp, python-dotenv, kiteconnect, starlette, uvicorn, rich, google-adk
Gates applied: no_behavioural_pass.
523490168d80full audit observations/trust-audit/mcp-server/mtwn105__zerodha-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 523490168d80 | SAFE | B | 89 | first audit |
Questions
What is the Zerodha MCP server?
Zerodha MCP Server & Client - AI Agent (w/Agno & w/Google ADK)
What tools does Zerodha expose?
12 in total: 7 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Zerodha safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Zerodha need?
It reads ZERODHA_API_KEY and ZERODHA_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (523490168d80), read on 2026-10-08. The repository is watched and re-audited when it changes.