RobinhoodCAUTION
The Robinhood MCP Server provides a comprehensive interface to the Robinhood Crypto API. This server handles authentication, account management, market data retrieval, and trading operations through both REST API and WebSocket interfaces.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/rohitsingh-iitd-robinhood-mcp-server)
Overview
The Robinhood MCP Server provides a comprehensive interface to the Robinhood Crypto API. This server handles authentication, account management, market data retrieval, and trading operations through both REST API and WebSocket interfaces.
Table of Contents
- Features
- Prerequisites
- Installation
- Configuration
- Running the Server
- API Documentation
- Testing
- Development
- Security
- Troubleshooting
- License
- Disclaimer
Features
- REST API for account management and trading operations
- WebSocket support for real-time market data and order updates
- Comprehensive error handling and logging
- Rate limiting and security best practices
- Easy configuration via environment variables
Prerequisites
- Python 3.8 or higher
- pip (Python package manager)
- Robinhood API credentials
Installation
- Clone the repository:
git clone https://github.com/rohitsingh-iitd/robinhood-mcp-server cd robinhood-mcp-server
- Set up a virtual environment (recommended):
# Create a virtual environment python -m venv venv # Activate the virtual environment # On macOS/Linux: source venv/bin/activate # On Windows: # .\venv\Scripts\activate
- Install dependencies:
pip install -r requirements.txt
Configuration
- Create a `.env` file in the project root with the following content:
# Required ROBINHOOD_API_KEY=your_api_key_here ROBINHOOD_PRIVATE_KEY=your_base64_encoded_private_key_here # Optional (with defaults) HOST=0.0.0.
7ca6b3c46e1bOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add robinhood-mcp-server --env ROBINHOOD_API_KEY=${ROBINHOOD_API_KEY} --env ROBINHOOD_PRIVATE_KEY=${ROBINHOOD_PRIVATE_KEY} -- npx -y [email protected]{
"mcpServers": {
"robinhood-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ROBINHOOD_API_KEY": "${ROBINHOOD_API_KEY}",
"ROBINHOOD_PRIVATE_KEY": "${ROBINHOOD_PRIVATE_KEY}"
}
}
}
}Exposed tools (10)
6 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cancelOrder | write | Cancels an open order |
getAccount | read | Retrieves the user |
getBestPrice | read | Gets the current best bid/ask prices for cryptocurrencies |
getCryptoQuote | read | Gets the current quote for a cryptocurrency |
getEstimatedPrice | read | Calculates estimated execution price for a potential trade |
getHoldings | read | Retrieves the user |
getOrder | write | Gets details for a specific order |
getOrders | write | Retrieves order history |
getTradingPairs | read | Lists available cryptocurrency trading pairs |
placeOrder | write | Places a new order for a cryptocurrency |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
.DS_Store
console.log(`Server running on http://0.0.0.0:${address.port}${endpoint}`);console.log(`Health check: http://0.0.0.0:${address.port}/health`);.DS_Store
join(__dirname, '../../python_bridge.py'),
path.join(__dirname, '../../python_bridge.py'),
join(__dirname, '../../python_bridge.py'),
join(__dirname, '../../python_bridge.py'),
path.join(__dirname, '../../python_bridge.py'),
self.private_key_seed = base64.b64decode(PRIVATE_KEY) if PRIVATE_KEY else None
@chatmcp/sdk
- Load API key and private key from environment variables
Gates applied: no_behavioural_pass.
7ca6b3c46e1bfull audit observations/trust-audit/mcp-server/rohitsingh-iitd__robinhood.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7ca6b3c46e1b | CAUTION | B | 87 | first audit |
Questions
What is the Robinhood MCP server?
The Robinhood MCP Server provides a comprehensive interface to the Robinhood Crypto API. This server handles authentication, account management, market data retrieval, and trading operations through both REST API and WebSocket interfaces.
What tools does Robinhood expose?
10 in total: 6 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Robinhood safe to connect to an agent?
With care. The audit graded it B (87/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Robinhood need?
It reads ROBINHOOD_API_KEY and ROBINHOOD_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (7ca6b3c46e1b), read on 2026-10-08. The repository is watched and re-audited when it changes.