Atlas / MCP servers / rohitsingh-iitd / Robinhood

RobinhoodCAUTION

mcp/rohitsingh-iitd/robinhood

The Robinhood MCP Server provides a comprehensive interface to the Robinhood Crypto API. This server handles authentication, account management, market data retrieval, and trading operations through both REST API and WebSocket interfaces.

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
10 6r · 4w · 0d
Transport
—
License
MIT
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/rohitsingh-iitd-robinhood-mcp-server)

Overview

The Robinhood MCP Server provides a comprehensive interface to the Robinhood Crypto API. This server handles authentication, account management, market data retrieval, and trading operations through both REST API and WebSocket interfaces.

Table of Contents

  • Features
  • Prerequisites
  • Installation
  • Configuration
  • Running the Server
  • API Documentation
  • Testing
  • Development
  • Security
  • Troubleshooting
  • License
  • Disclaimer

Features

  • REST API for account management and trading operations
  • WebSocket support for real-time market data and order updates
  • Comprehensive error handling and logging
  • Rate limiting and security best practices
  • Easy configuration via environment variables

Prerequisites

  • Python 3.8 or higher
  • pip (Python package manager)
  • Robinhood API credentials

Installation

  1. Clone the repository:
git clone https://github.com/rohitsingh-iitd/robinhood-mcp-server
cd robinhood-mcp-server
  1. Set up a virtual environment (recommended):
# Create a virtual environment
python -m venv venv

# Activate the virtual environment
# On macOS/Linux:
source venv/bin/activate
# On Windows:
# .\venv\Scripts\activate
  1. Install dependencies:
pip install -r requirements.txt

Configuration

  1. Create a `.env` file in the project root with the following content:
# Required
ROBINHOOD_API_KEY=your_api_key_here
ROBINHOOD_PRIVATE_KEY=your_base64_encoded_private_key_here

# Optional (with defaults)
HOST=0.0.0.
Read from source at commit 7ca6b3c46e1bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add robinhood-mcp-server --env ROBINHOOD_API_KEY=${ROBINHOOD_API_KEY} --env ROBINHOOD_PRIVATE_KEY=${ROBINHOOD_PRIVATE_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "robinhood-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ROBINHOOD_API_KEY": "${ROBINHOOD_API_KEY}",
        "ROBINHOOD_PRIVATE_KEY": "${ROBINHOOD_PRIVATE_KEY}"
      }
    }
  }
}
03

Exposed tools (10)

6 read · 4 write · 0 destructive.

ToolRiskDescription
cancelOrderwriteCancels an open order
getAccountreadRetrieves the user
getBestPricereadGets the current best bid/ask prices for cryptocurrencies
getCryptoQuotereadGets the current quote for a cryptocurrency
getEstimatedPricereadCalculates estimated execution price for a potential trade
getHoldingsreadRetrieves the user
getOrderwriteGets details for a specific order
getOrderswriteRetrieves order history
getTradingPairsreadLists available cryptocurrency trading pairs
placeOrderwritePlaces a new order for a cryptocurrency
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server.js:735
console.log(`Server running on http://0.0.0.0:${address.port}${endpoint}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server.js:736
console.log(`Health check: http://0.0.0.0:${address.port}/health`);
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/account/account_wrapper.js:20
join(__dirname, '../../python_bridge.py'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/account/account_wrapper.js:54
path.join(__dirname, '../../python_bridge.py'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/auth_wrapper.js:25
join(__dirname, '../../python_bridge.py'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/market_data/market_data_wrapper.js:20
join(__dirname, '../../python_bridge.py'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/market_data/market_data_wrapper.js:55
path.join(__dirname, '../../python_bridge.py'),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/auth/auth.py:22
self.private_key_seed = base64.b64decode(PRIVATE_KEY) if PRIVATE_KEY else None
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@chatmcp/sdk
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
architecture.md:82
- Load API key and private key from environment variables
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7ca6b3c46e1bfull audit observations/trust-audit/mcp-server/rohitsingh-iitd__robinhood.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087ca6b3c46e1bCAUTIONB87first audit
06

Questions

What is the Robinhood MCP server?

The Robinhood MCP Server provides a comprehensive interface to the Robinhood Crypto API. This server handles authentication, account management, market data retrieval, and trading operations through both REST API and WebSocket interfaces.

What tools does Robinhood expose?

10 in total: 6 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Robinhood safe to connect to an agent?

With care. The audit graded it B (87/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Robinhood need?

It reads ROBINHOOD_API_KEY and ROBINHOOD_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (7ca6b3c46e1b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement