Trading212CAUTION
The Trading212 MCP server is a Model Context Protocol server implementation that provides seamless data connectivity to the Trading212 trading platform enabling advanced interaction capabilities via the public beta API.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE) [](https://github.com/RohanAnandPandit/trading212-mcp-server/actions/workflows/tests.yml)
A Model Context Protocol server for the Trading 212 public API. It exposes account data, positions, orders, pies, instrument metadata, and account history. It also includes an account-currency-aware analysis prompt. It does not provide independent market feeds, investment recommendations, or real-time streaming.
Python 3.11–3.14 is supported. The current source package version is 0.2.0; see the changelog for upgrade details. The project uses the official MCP Python SDK 2.x.
Install and run
You can follow the setup below yourself or ask a coding agent such as Codex or Claude Code to do it. Paste this prompt into the agent's chat:
Read https://github.com/RohanAnandPandit/trading212-mcp-server/blob/main/README.md#setup and follow the setup process.
Setup
- Install prerequisites and dependencies. You need Git,
uv, and Python 3.11–3.14. Choose a stable installation folder, then run:
git clone https://github.com/RohanAnandPandit/trading212-mcp-server.git cd trading212-mcp-server uv sync --frozen
If you already have a checkout, reuse it without overwriting local changes. Alternatively, install the package from the checkout using pip install ., then run trading212-mcp-server. For a locked pip installation, use pip install --require-hashes -r requirements.txt followed by pip install --no-deps ..
- Configure credentials locally. Create an ignored
.envfile from
.env.example if one does not already exist:
cp .env.example .env
953ebe1cc6caOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add trading212-mcp-server --env TRADING212_API_KEY=${TRADING212_API_KEY} --env TRADING212_API_SECRET=${TRADING212_API_SECRET} -- uvx trading212-mcp-server{
"mcpServers": {
"trading212-mcp-server": {
"command": "uvx",
"args": [
"trading212-mcp-server"
],
"env": {
"TRADING212_API_KEY": "${TRADING212_API_KEY}",
"TRADING212_API_SECRET": "${TRADING212_API_SECRET}"
}
}
}
}Exposed tools (28)
18 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
cancel_order | write | |
create_pie | write | |
delete_pie | destructive | |
duplicate_pie | read | |
fetch_a_pie | read | |
fetch_account_cash | read | |
fetch_account_info | read | |
fetch_account_summary | read | |
fetch_all_open_positions | read | |
fetch_all_orders | read | |
fetch_exports_list | read | |
fetch_historical_order_data | write | |
fetch_open_position_by_ticker | read | |
fetch_order | write | |
fetch_paid_out_dividends | read | |
fetch_pies | read | |
fetch_position_by_ticker | read | |
fetch_positions | read | |
fetch_transaction_list | read | |
place_limit_order | write | |
place_market_order | write | |
place_stop_limit_order | write | |
place_stop_order | write | |
request_csv_export | read | |
search_exchange | read | |
search_instrument | read | |
search_specific_position_by_ticker | read | |
update_pie | write |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
allowed_origins=["http://127.0.0.1:8000", "http://localhost:8000"],
delete_pie
allowed_origins=["http://127.0.0.1:8000", "http://localhost:8000"],
base_url="http://127.0.0.1:8000",
Gates applied: no_behavioural_pass.
953ebe1cc6cafull audit observations/trust-audit/mcp-server/rohananandpandit__trading212.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 953ebe1cc6ca | CAUTION | B | 89 | first audit |
Questions
What is the Trading212 MCP server?
The Trading212 MCP server is a Model Context Protocol server implementation that provides seamless data connectivity to the Trading212 trading platform enabling advanced interaction capabilities via the public beta API.
What tools does Trading212 expose?
28 in total: 18 read-only, 9 that write, and 1 that can delete or overwrite (delete_pie). Every one is listed on this page with its risk.
Is Trading212 safe to connect to an agent?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Trading212 need?
It reads TRADING212_API_KEY and TRADING212_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Trading212 run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as trading212-mcp-server.
How current is this page?
The grade is for one exact copy of the source (953ebe1cc6ca), read on 2026-10-08. The repository is watched and re-audited when it changes.