Atlas / MCP servers / nirholas / Binance.US

Binance.USSAFE

mcp/nirholas/binance-us

A Model Context Protocol (MCP) server for Binance.US API. Provides standardized access to market data, spot trading, wallets, accounts, staking, OTC, sub-accounts, and institutional features. Built in TypeScript/Node.js. Handles authentication, rate limiting, and errors automatically. Ideal for AI a

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
93 57r · 36w · 0d
Transport
stdio
License
NOASSERTION
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for interacting with the Binance.US cryptocurrency exchange API.

Overview

This MCP server provides programmatic access to Binance.US exchange features including:

  • Market Data: Real-time prices, order books, trade history
  • Spot Trading: Place, cancel, and manage orders
  • Wallet Management: Deposits, withdrawals, balances
  • Account Information: Account details, trade history
  • Staking: Earn rewards on supported assets
  • OTC Trading: Over-the-counter trading
  • Sub-Accounts: Manage sub-accounts
  • Custodial Solution: For custody partners (requires special API key)
  • Credit Line: For institutional credit (requires special API key)

Binance.US vs Binance.com

This server is specifically designed for Binance.US, which differs from Binance.com in several important ways:

API Key Types

Binance.US offers three types of API keys:

1. Exchange API Keys

  • Standard API keys for most users
  • Access to market data, trading, wallet, and account endpoints
  • Create at: Binance.US > Profile > API Management

2. Custodial Solution API Keys

  • For users with a Custody Exchange Network agreement
  • Access to custodial-specific endpoints only
  • Requires agreement with a participating custody partner

3. Credit Line API Keys

  • For institutional users with a credit line agreement
  • Access to credit line-speci
Read from source at commit 716b8f987d22OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add binance-us-mcp-server --env BINANCE_US_API_KEY=${BINANCE_US_API_KEY} --env BINANCE_US_SECRET_KEY=${BINANCE_US_SECRET_KEY} -- npx -y @nirholas/[email protected]
03

Exposed tools (93)

57 read · 36 write · 0 destructive.

ToolRiskDescription
binance_us_account_inforeadGet current account information including balances and permissions. Returns all asset balances (free and locked), account permissions, and trading status.
binance_us_agg_tradeswriteGet compressed aggregate trades. Trades with same time, order, and price are aggregated.
binance_us_all_oco_ordersreadGet all OCO orders (history) on Binance.US. Returns up to 1000 orders.
binance_us_all_ordersreadGet all orders (active, canceled, or filled) for a symbol on Binance.US. Returns order history.
binance_us_asset_configreadGet details of all crypto assets including fees, withdrawal limits, and network status. Shows deposit/withdrawal enabled status per network.
binance_us_avg_pricereadGet current 5-minute rolling weighted average price.
binance_us_cancel_all_open_ordersreadCancel all active orders on a symbol on Binance.US. This includes OCO orders. Use with caution - this will cancel ALL open orders for the specified symbol.
binance_us_cancel_ocowriteCancel an entire OCO order on Binance.US. Cancelling any individual leg will cancel the entire OCO.
binance_us_cancel_orderwriteCancel an active order on Binance.US. Either orderId or origClientOrderId must be provided.
binance_us_cancel_replacewriteCancel an existing order and place a new order on the same symbol atomically. This is useful for modifying order parameters.
binance_us_cl_accountread
binance_us_cl_alert_historyread
binance_us_cl_liquidation_historyread
binance_us_cl_transferwrite
binance_us_cl_transfer_historywrite
binance_us_close_listen_keyreadClose a User Data Stream by invalidating the listen key. Use this when you
binance_us_create_listen_keywrite
binance_us_cust_available_balancereadGet available balance in the custodial sub-account for trading. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY Returns the balance available for placing new orders.
binance_us_cust_balanceread
binance_us_cust_cancel_ocowriteCancel an entire OCO (One-Cancels-the-Other) order list. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY This cancels both legs of the OCO order. Response includes orderListId, orders array, and orderReports with canceled order details.
binance_us_cust_cancel_orderwriteCancel an active custodial trade order. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY Either orderId or origClientOrderId must be provided. Response includes the canceled order details with status: CANCELED
binance_us_cust_cancel_orders_symbolreadCancel all active custodial orders for a specific trading pair. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY This includes OCO orders. Use with caution. Response is an array of all canceled orders.
binance_us_cust_get_orderwriteGet details of a specific custodial trade order. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY Response includes: symbol, orderId, price, origQty, executedQty, cummulativeQuoteQty, status, timeInForce, type, side, stopPrice, icebergQty, time, updateTime, isWorking, expressTradeFlag
binance_us_cust_new_orderwrite
binance_us_cust_oco_orderwrite
binance_us_cust_open_ordersread
binance_us_cust_order_historywriteGet historical custodial trade orders. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY If symbol is not sent, orders for all symbols will be returned. Response is an array of orders with full details including status, executedQty, and expressTradeFlag.
binance_us_cust_settlement_historyread
binance_us_cust_settlement_settingsread
binance_us_cust_supported_assetsread
binance_us_cust_trade_historyread
binance_us_cust_transferwrite
binance_us_cust_transfer_historywrite
binance_us_cust_undo_transferwriteUndo a previous transfer from your custodial partner. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY Use this to reverse a custodian transfer that hasn
binance_us_cust_wallet_transferwrite
binance_us_cust_wallet_transfer_historywrite
binance_us_custodial_balanceread
binance_us_custodial_custodian_transferwrite
binance_us_custodial_custodian_transfer_historywriteGet history of transfers from custodial partner, including ExpressTrade and Undo transfers. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY Returns transfer history with status, amounts, and timestamps.
binance_us_custodial_settlementreadRequest settlement of assets from custodial sub-account to custodial partner. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY ⚠️ This sends funds to your custodial partner! This settles (withdraws) assets from your Binance.US custodial sub-account to your custody partner
binance_us_custodial_settlement_historyreadGet history of settlements from custodial sub-account to custodial partner. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY Returns settlement history with status, amounts, and timestamps.
binance_us_custodial_supported_assetsread
binance_us_custodial_undo_transferwriteUndo a previous transfer from your custodial partner. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY ⚠️ Only certain transfers can be undone - check with your custodial partner. This reverses a previous custodian transfer by its transfer ID.
binance_us_custodial_wallet_transferwrite
binance_us_custodial_wallet_transfer_historywriteGet history of transfers from Binance.US exchange wallet to custodial sub-account. ⚠️ REQUIRES CUSTODIAL SOLUTION API KEY Returns transfer history with status, amounts, and timestamps.
binance_us_deposit_addressreadGet a deposit address for a specific crypto asset. Use this to receive funds into your Binance.US account.
binance_us_deposit_historyreadGet crypto deposit history. Filter by coin, status, or time range.
binance_us_exchange_inforeadGet current exchange trading rules and trading pair information from Binance.US. Can filter by specific symbol(s) or permissions.
binance_us_get_ocowriteQuery a specific OCO order on Binance.US. Either orderListId or origClientOrderId must be provided.
binance_us_get_orderwriteQuery the status of a specific order on Binance.US. Either orderId or origClientOrderId must be provided.
binance_us_historical_tradesreadGet older historical trades for a trading pair. Requires API key with MARKET_DATA permission.
binance_us_keepalive_listen_keyreadExtend the validity of a listen key by 60 minutes. ⚠️ IMPORTANT: - Call this every 30 minutes to prevent the stream from closing - If the key expires, you
binance_us_klinesreadGet Kline/candlestick data for a trading pair. Returns OHLCV data.
binance_us_my_tradesreadGet trade history for a specific trading pair. Returns executed trades including price, quantity, commission, and timestamps.
binance_us_new_ocowritePlace a new OCO (One-Cancels-the-Other) order on Binance.US. OCO orders combine a limit order with a stop-loss order. When one triggers, the other is automatically cancelled. Note: For SELL OCOs, limit price > stop price. For BUY OCOs, limit price < stop price.
binance_us_new_orderwritePlace a new trade order on Binance.US. Supports LIMIT, MARKET, STOP_LOSS, STOP_LOSS_LIMIT, TAKE_PROFIT, TAKE_PROFIT_LIMIT, and LIMIT_MAKER order types.
binance_us_ocbs_ordersread
binance_us_open_ocoreadGet all open OCO orders on Binance.US.
binance_us_open_ordersreadGet all open orders on Binance.US. Can be filtered by symbol. Warning: Querying without symbol is heavier on rate limits (weight 40 vs 3).
binance_us_order_bookwriteGet order book depth (bids and asks) for a trading pair on Binance.US. Returns price levels with quantities. Weight varies based on limit (1-100: weight 1, 101-500: weight 5, 501-1000: weight 10, 1001-5000: weight 50).
binance_us_otc_all_ordersread
binance_us_otc_coin_pairsread
binance_us_otc_get_orderwrite
binance_us_otc_place_orderwrite
binance_us_otc_quoteread
binance_us_pingreadTest connectivity to the Binance.US API. Returns empty object if successful.
binance_us_rate_limitswriteGet current trade order count rate limits for all time intervals. Shows how many orders you can place within each interval.
binance_us_recent_tradesreadGet recent trades for a trading pair on Binance.US. Returns trade ID, price, quantity, time, and maker/taker info.
binance_us_rolling_windowreadGet rolling window price change statistics with custom window sizes (1m to 7d).
binance_us_server_timereadGet the current server time from Binance.US exchange.
binance_us_staking_asset_inforead
binance_us_staking_balanceread
binance_us_staking_historyread
binance_us_staking_rewardsread
binance_us_staking_stakeread
binance_us_staking_unstakeread
binance_us_subaccount_assetsreadGet asset balances for a specific sub-account.
binance_us_subaccount_listreadGet a list of all sub-accounts. Filter by email or status (enabled/disabled).
binance_us_subaccount_statusreadGet status list of sub-accounts including activation status and enabled features.
binance_us_subaccount_summaryreadGet the total USD value of assets in the master account and all sub-accounts.
binance_us_subaccount_transferwriteExecute an asset transfer between master account and a sub-account. ⚠️ This moves funds between accounts!
binance_us_subaccount_transfer_historywriteGet transfer history between master and sub-accounts.
binance_us_system_statusreadCheck if Binance.US system is under maintenance. Status 0 = normal, 1 = system maintenance. Requires API key authentication.
binance_us_test_orderwriteTest a new order on Binance.US without actually placing it. Validates order parameters and signature without executing the trade.
binance_us_ticker_24hrreadGet 24-hour rolling window price change statistics.
binance_us_ticker_bookreadGet best bid/ask prices and quantities (top of book).
binance_us_ticker_pricereadGet latest price for symbol(s).
binance_us_trade_feereadGet your current maker & taker fee rates for spot trading based on your VIP level. BNB fee discount (25% off) is not factored in.
binance_us_trade_volumereadGet total trade volume for the past 30 days. Volume is calculated on a rolling basis every day at 0:00 AM (UTC).
binance_us_websocket_inforeadGet information about available WebSocket streams on Binance.US. Returns details about: - Market data streams (public) - User data streams (requires listen key) - Connection URLs and limits
binance_us_withdraw_cryptowriteSubmit a crypto withdrawal request. Requires withdrawal permission on API key. ⚠️ This action transfers funds OUT of your account - verify address carefully!
binance_us_withdraw_fiatwriteSubmit a USD withdrawal request via BITGO. ⚠️ This action transfers USD OUT of your account!
binance_us_withdraw_historyreadGet crypto withdrawal history. Filter by coin, status, or time range.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/account/index.ts:4
import { makeSignedRequest } from "../../config/binanceUsClient.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/credit-line/index.ts:7
import { makeSignedRequest } from "../../config/binanceUsClient.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/creditline/index.ts:7
import { makeSignedRequest } from "../../config/binanceUsClient.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/custodial-solution/index.ts:8
import { makeSignedRequest } from "../../config/binanceUsClient.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/custodial/index.ts:7
import { makeSignedRequest } from "../../config/binanceUsClient.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, zod, @types/node, tsx, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 716b8f987d22full audit observations/trust-audit/mcp-server/nirholas__binance-us.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09716b8f987d22SAFEB89first audit
06

Questions

What is the Binance.US MCP server?

A Model Context Protocol (MCP) server for Binance.US API. Provides standardized access to market data, spot trading, wallets, accounts, staking, OTC, sub-accounts, and institutional features. Built in TypeScript/Node.js. Handles authentication, rate limiting, and errors automatically. Ideal for AI a

What tools does Binance.US expose?

93 in total: 57 read-only, 36 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Binance.US safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Binance.US need?

It reads BINANCE_US_API_KEY, BINANCE_US_API_SECRET and BINANCE_US_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Binance.US run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @nirholas/binance-us-mcp-server at 1.0.2.

How current is this page?

The grade is for one exact copy of the source (716b8f987d22), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement