Parlay
REMOTE · MCP.PARLAY.RUN · SCANNED SEP 22
Read-only MCP server for live Polymarket, Kalshi, Limitless odds; Manifold sentiment.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security78
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 401, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability62
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1047 tokens (~174/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage73
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 20% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Parlay MCP server?
Parlay is a hosted endpoint at https://mcp.parlay.run/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.parlay.run
claude mcp add --transport http run-parlay-parlay 'https://mcp.parlay.run/mcp'
{
"mcpServers": {
"run-parlay-parlay": {
"url": "https://mcp.parlay.run/mcp"
}
}
} {
"servers": {
"run-parlay-parlay": {
"type": "http",
"url": "https://mcp.parlay.run/mcp"
}
}
} [mcp_servers.run-parlay-parlay] url = "https://mcp.parlay.run/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"run-parlay-parlay": {
"type": "remote",
"url": "https://mcp.parlay.run/mcp",
"enabled": true
}
}
} openclaw mcp add run-parlay-parlay --url 'https://mcp.parlay.run/mcp' --transport streamable-http
mcp_servers:
run-parlay-parlay:
url: "https://mcp.parlay.run/mcp" {
"McpServers": {
"run-parlay-parlay": {
"Transport": "http",
"Url": "https://mcp.parlay.run/mcp"
}
}
} assistant mcp add run-parlay-parlay -t streamable-http -u 'https://mcp.parlay.run/mcp'
{
"mcpServers": {
"run-parlay-parlay": {
"type": "http",
"url": "https://mcp.parlay.run/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://mcp.parlay.run/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=parlay.run | CN=WE1,O=Google Trust Services,C=US | 26 Aug 2026 | 24 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | da6031350474207f0eaededf995e3791 |
| SANs: parlay.run, mcp.parlay.run, *.mcp.parlay.run | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.parlay.run. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| run. | present | 37315 | 8 | Verified |
| parlay.run. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="OAuth", resource_metadata="https://mcp.parlay.run/.well-known/oauth-protected-resource/mcp", error="invalid_token", error_description="Missing or invalid access token"
Bearer realm="OAuth", resource_metadata="https://mcp.parlay.run/.well-known/oauth-protected-resource/mcp", error="invalid_token", error_description="Missing or invalid access token" Protected resource metadata
| Document | https://mcp.parlay.run/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.parlay.run/mcp |
| Authorisation server | https://mcp.parlay.run |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.parlay.run/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.parlay.run/mcp | Inconclusive | 401 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
compare_markets Compare markets across venues ~122
Compare the same event contract across Polymarket, Kalshi, and Limitless side-by-side: probability, liquidity, settlement rules, and venue type. Use when the user wants to know "what's the spread between Polymarket and Kalshi on X" or "which venue has better liquidity for Y". Returns match confidence buckets (high/medium/low) and explains any mismatches. Real-money venues only — Manifold is excluded because play-money pricing isn't comparable to real-money.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| query | string | yes | – |
No output schema declared.
No examples provided.
discover_markets Discover trending markets ~126
Browse trending, high-volume, fast-moving, or high-disagreement prediction markets across Polymarket, Kalshi, Limitless, and Manifold. Use when the user wants to explore what's happening — "what's hot on Polymarket today", "show me biggest political markets", "what events are ending soon" — rather than search a specific topic. Filter by category and sort by volume, newest, or ending soon.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | – |
| limit | number | – | – |
| real_money_only | boolean | – | – |
| sort_by | string | – | – |
No output schema declared.
No examples provided.
inspect_platform Inspect platform ~106
Inspect a single named venue. Returns available capabilities, market data for the query, and metadata quality flags. Use when the user explicitly names a venue — "show me Polymarket markets on AI", "what's on Kalshi for Q4 inflation", "Manifold markets about geopolitics". For cross-venue queries use `search_markets` or `compare_markets`.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| platform | string | yes | – |
| query | string | yes | – |
No output schema declared.
No examples provided.
market_brief Generate market brief ~189
Generate a synthesized brief for a topic, combining real-money signals from Polymarket, Kalshi, and Limitless with Manifold community sentiment. Use for analytical queries like "what do markets think about the 2028 election", "odds on a Fed rate cut", or "how is crypto priced for year-end". Returns top markets by volume, cross-venue divergences, venue coverage, and risk flags. For raw market lists use `search_markets`.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| min_volume | number | – | Minimum 24h USD volume per market. Real-money markets with missing volume data are kept but tagged with risk_flag 'volume_unconfirmed'. Sentiment markets (Manifold) are exempt — their volume is denom… |
| real_money_only | boolean | – | – |
| topic | string | yes | – |
No output schema declared.
No examples provided.
scan_discrepancies Scan cross-venue discrepancies ~369
Surface cross-venue price discrepancies between Polymarket, Kalshi, and Limitless as a discovery feed for price discovery and divergence detection. Default threshold is 0.5% spread, below typical round-trip fees — most results are informational, not tradable arbitrage. Raise `min_spread` to 0.03+ for after-fee opportunities. The optional `query` parameter post-filters results by topic keywords on event titles — it does not perform a topic search; for topic-driven retrieval use `discover_markets` or `search_markets`. Pairs with missing volume data on at least one venue are flagged 'volume_unconfirmed'. All results are indicative only — not trade recommendations. Real-money venues only. Orderbook depth is not confirmed in Phase 1.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| min_spread | number | – | Minimum price gap to report (0.005 = 0.5%, 0.03 = 3 percentage points). Default 0.005 surfaces price discovery signals, most of which are below typical 4% round-trip fees and therefore informational… |
| min_volume | number | – | Minimum 24h USD volume on the thinner side of each pair. Pairs where at least one venue has missing volume data are kept but tagged with risk_flag 'volume_unconfirmed'. Set to 0 to disable. |
| query | string | – | Optional post-filter on event titles by topic keywords (e.g. 'crypto', 'election', 'fed'). This filters the discovery feed locally — it is not a topic search and may return zero results when today's… |
No output schema declared.
No examples provided.
search_markets Search prediction markets ~135
Search live prediction markets and event contracts across Polymarket, Kalshi, Limitless (real-money) and Manifold (sentiment). Use for queries on election odds, political markets, Fed rate decisions, crypto prices, sports outcomes, geopolitics, and other binary markets with crowd-sourced probabilities. Returns unified results with title, current probability, volume, liquidity, expiration, source venue, and risk flags. For topic synthesis use `market_brief`; for browsing trending markets use `discover_markets`.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| query | string | yes | – |
| real_money_only | boolean | – | – |
No output schema declared.
No examples provided.
What is the Parlay MCP server?
Parlay is an MCP server listed in the public MCP registry as run.parlay/parlay. Read-only MCP server for live Polymarket, Kalshi, Limitless odds; Manifold sentiment. This page covers its hosted endpoint (https://mcp.parlay.run/mcp).
Is the Parlay MCP server safe to use?
Parlay scores 82 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Parlay MCP server expose?
Parlay exposes 6 tools: search_markets, discover_markets, compare_markets, scan_discrepancies, market_brief, inspect_platform. Their descriptions and schemas cost roughly 1,047 tokens of context every time the server is loaded.
Does the Parlay MCP server require authentication?
Yes. Parlay asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Parlay MCP server still maintained?
Parlay is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.