Atlas / MCP servers / qoyyuum / Metatrader 5

Metatrader 5CAUTION

mcp/qoyyuum/metatrader-5

A Model Context Protocol (MCP) server for interacting with the MetaTrader 5 trading platform. This server provides AI assistants with tools and resources to access market data, perform trading operations, and analyze trading history.

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
26 24r · 2w · 0d
Transport
stdio
License
—
Stars
228
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://deepwiki.com/Qoyyuum/mcp-metatrader5-server)

[](https://mseep.ai/app/qoyyuum-mcp-metatrader5-server)

[](https://codecov.io/github/Qoyyuum/mcp-metatrader5-server)

[](https://pypi.org/project/mcp-metatrader5-server/)

A Model Context Protocol (MCP) server for MetaTrader 5, allowing AI assistants to interact with the MetaTrader 5 platform for trading and market data analysis. Documentation

Features

  • Connect to MetaTrader 5 terminal
  • Access market data (symbols, rates, ticks)
  • Place and manage trades
  • Analyze trading history
  • Integrate with AI assistants through the Model Context Protocol

Installation

From PyPI

uvx --from mcp-metatrader5-server mt5mcp

From Source

git clone https://github.com/Qoyyuum/mcp-metatrader5-server.git
cd mcp-metatrader5-server
uv sync
uv run mt5mcp

Requirements

  • uv (recommended) or pip
  • Python 3.11 or higher
  • MetaTrader 5 terminal installed on Windows
  • MetaTrader 5 account (demo or real)

Usage

Quick Start

The server runs in stdio mode by default for MCP clients like Claude Desktop:

uv run mt5mcp

Development Mode (HTTP)

For testing with HTTP transport, create a .env file:

MT5_MCP_TRANSPORT=http
MT5_MCP_HOST=127.0.0.1
MT5_MCP_PORT=8000

Then run:

uv run mt5mcp

The server will start at http://127.0.0.1:8000

Installing for MCP Clients

Method 1: Using uvx (Simplest - No Installation Required) ⭐

Add this configuration to your MCP client's config file:

For Claude Desktop (claude_desktop_config.json)

Read from source at commit 172d3dc2313cOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-metatrader5-server --env MT5_PASSWORD=${MT5_PASSWORD} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- uvx mcp-metatrader5-server
claude-desktop
{
  "mcpServers": {
    "mcp-metatrader5-server": {
      "command": "uvx",
      "args": [
        "mcp-metatrader5-server"
      ],
      "env": {
        "MT5_PASSWORD": "${MT5_PASSWORD}",
        "OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
      }
    }
  }
}
03

Exposed tools (26)

24 read · 2 write · 0 destructive.

ToolRiskDescription
copy_rates_from_dateread
copy_rates_from_posread
copy_rates_rangeread
copy_ticks_from_dateread
copy_ticks_from_posread
copy_ticks_rangeread
get_account_inforead
get_last_errorread
get_symbol_inforead
get_symbol_info_tickread
get_symbolsread
get_symbols_by_groupread
get_terminal_inforead
get_versionread
history_deals_getread
history_orders_getread
initializeread
loginread
order_checkwrite
order_sendwrite
orders_getread
orders_get_by_ticketread
positions_getread
positions_get_by_ticketread
shutdownread
symbol_selectread
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (9)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.coverage
.coverage
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/pydantic_ai_integration.md:457
api_key="your-anthropic-api-key",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coverage
.coverage
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.readthedocs.yaml
.readthedocs.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:127
# Visit http://127.0.0.1:8000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:71
The server will start at http://127.0.0.1:8000
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
docs/requirements.txt
mkdocs, mkdocs-material, pymdown-extensions, mkdocs-autorefs
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/publishing.md:42
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha 172d3dc2313cfull audit observations/trust-audit/mcp-server/qoyyuum__metatrader-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06172d3dc2313cCAUTIONB88first audit
06

Questions

What is the Metatrader 5 MCP server?

A Model Context Protocol (MCP) server for interacting with the MetaTrader 5 trading platform. This server provides AI assistants with tools and resources to access market data, perform trading operations, and analyze trading history.

What tools does Metatrader 5 expose?

26 in total: 24 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Metatrader 5 safe to connect to an agent?

With care. The audit graded it B (88/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Metatrader 5 need?

It reads MT5_PASSWORD and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Metatrader 5 run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-metatrader5-server.

How current is this page?

The grade is for one exact copy of the source (172d3dc2313c), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement