Atlas / MCP servers / rohananandpandit / Trading212

Trading212CAUTION

mcp/rohananandpandit/trading212

The Trading212 MCP server is a Model Context Protocol server implementation that provides seamless data connectivity to the Trading212 trading platform enabling advanced interaction capabilities via the public beta API.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
28 18r · 9w · 1d
Transport
stdio · streamable-http
License
MIT
Stars
62
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE) [](https://github.com/RohanAnandPandit/trading212-mcp-server/actions/workflows/tests.yml)

A Model Context Protocol server for the Trading 212 public API. It exposes account data, positions, orders, pies, instrument metadata, and account history. It also includes an account-currency-aware analysis prompt. It does not provide independent market feeds, investment recommendations, or real-time streaming.

Python 3.11–3.14 is supported. The current source package version is 0.2.0; see the changelog for upgrade details. The project uses the official MCP Python SDK 2.x.

Install and run

You can follow the setup below yourself or ask a coding agent such as Codex or Claude Code to do it. Paste this prompt into the agent's chat:

Read https://github.com/RohanAnandPandit/trading212-mcp-server/blob/main/README.md#setup
and follow the setup process.

Setup

  1. Install prerequisites and dependencies. You need Git,

uv, and Python 3.11–3.14. Choose a stable installation folder, then run:

git clone https://github.com/RohanAnandPandit/trading212-mcp-server.git
cd trading212-mcp-server
uv sync --frozen

If you already have a checkout, reuse it without overwriting local changes. Alternatively, install the package from the checkout using pip install ., then run trading212-mcp-server. For a locked pip installation, use pip install --require-hashes -r requirements.txt followed by pip install --no-deps ..

  1. Configure credentials locally. Create an ignored .env file from

.env.example if one does not already exist:

cp .env.example .env
Read from source at commit 953ebe1cc6caOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add trading212-mcp-server --env TRADING212_API_KEY=${TRADING212_API_KEY} --env TRADING212_API_SECRET=${TRADING212_API_SECRET} -- uvx trading212-mcp-server
claude-desktop
{
  "mcpServers": {
    "trading212-mcp-server": {
      "command": "uvx",
      "args": [
        "trading212-mcp-server"
      ],
      "env": {
        "TRADING212_API_KEY": "${TRADING212_API_KEY}",
        "TRADING212_API_SECRET": "${TRADING212_API_SECRET}"
      }
    }
  }
}
03

Exposed tools (28)

18 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cancel_orderwrite
create_piewrite
delete_piedestructive
duplicate_pieread
fetch_a_pieread
fetch_account_cashread
fetch_account_inforead
fetch_account_summaryread
fetch_all_open_positionsread
fetch_all_ordersread
fetch_exports_listread
fetch_historical_order_datawrite
fetch_open_position_by_tickerread
fetch_orderwrite
fetch_paid_out_dividendsread
fetch_piesread
fetch_position_by_tickerread
fetch_positionsread
fetch_transaction_listread
place_limit_orderwrite
place_market_orderwrite
place_stop_limit_orderwrite
place_stop_orderwrite
request_csv_exportread
search_exchangeread
search_instrumentread
search_specific_position_by_tickerread
update_piewrite
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/trading212_mcp/server.py:122
allowed_origins=["http://127.0.0.1:8000", "http://localhost:8000"],
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_pie
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_startup.py:116
allowed_origins=["http://127.0.0.1:8000", "http://localhost:8000"],
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_startup.py:124
base_url="http://127.0.0.1:8000",

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 953ebe1cc6cafull audit observations/trust-audit/mcp-server/rohananandpandit__trading212.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08953ebe1cc6caCAUTIONB89first audit
06

Questions

What is the Trading212 MCP server?

The Trading212 MCP server is a Model Context Protocol server implementation that provides seamless data connectivity to the Trading212 trading platform enabling advanced interaction capabilities via the public beta API.

What tools does Trading212 expose?

28 in total: 18 read-only, 9 that write, and 1 that can delete or overwrite (delete_pie). Every one is listed on this page with its risk.

Is Trading212 safe to connect to an agent?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Trading212 need?

It reads TRADING212_API_KEY and TRADING212_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Trading212 run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as trading212-mcp-server.

How current is this page?

The grade is for one exact copy of the source (953ebe1cc6ca), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement