J-Quants MCP
PYPI · JQUANTS-MCP · SCANNED SEP 20
MCP server for retrieving Japanese stock market data via J-Quants API v2
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
- 0 of 33 dependencies flagged as unhealthy. View diagnostics → Pass
Provenance & Transparency48
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 29 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability66
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 12249 tokens (~222/item across 55 items; 55 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management97
- Stability observed for 29 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (96% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 55 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the J-Quants MCP server?
J-Quants MCP runs locally as a PyPI package, launched with uvx jquants-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · jquants-mcp
claude mcp add shigechika-jquants-mcp -- uvx jquants-mcp
{
"mcpServers": {
"shigechika-jquants-mcp": {
"command": "uvx",
"args": [
"jquants-mcp"
]
}
}
} {
"servers": {
"shigechika-jquants-mcp": {
"command": "uvx",
"args": [
"jquants-mcp"
]
}
}
} codex mcp add shigechika-jquants-mcp -- uvx jquants-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"shigechika-jquants-mcp": {
"type": "local",
"command": [
"uvx",
"jquants-mcp"
],
"enabled": true
}
}
} openclaw mcp add shigechika-jquants-mcp --command uvx --arg jquants-mcp
mcp_servers:
shigechika-jquants-mcp:
command: "uvx"
args: ["jquants-mcp"] {
"McpServers": {
"shigechika-jquants-mcp": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"jquants-mcp"
]
}
}
} assistant mcp add shigechika-jquants-mcp -t stdio -c uvx -a jquants-mcp
{
"mcpServers": {
"shigechika-jquants-mcp": {
"command": "uvx",
"args": [
"jquants-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +12
- Malware scan: unverified → pass ▲ security
- Stability: pass → 0.80 functional
- 14 Sept 26 −15
- Malware scan: pass → unverified ▼ security
- Stability: 0.97 → pass security
- 13 Sept 26 0
- Stability: pass → 0.97 functional
- 10 Sept 26 0
- Package version: 1.2.0 → 1.3.0 functional
- 7 Sept 26 0
- Stability: 0.97 → pass security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed pypi/jquants-mcp@1.3.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | pypi |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 33 packages
| Packages resolved | 33 |
|---|---|
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_valuation_ranking ~347
Rank listed stocks by PER or PBR valuation multiple (バリュエーションランキング). All plans. Use for 割安株, PER/PBRランキング, 低PER, 低PBR, バリュー株スクリーニング, cheapest stocks by PER/PBR. Default = 20 cheapest by PER (ascending). PER excludes net-loss stocks (EPS≤0); PBR excludes negative-book (BPS≤0). For sector medians use get_sector_briefing; for one stock use get_stock_briefing; for dividend yield use get_dividend_yield_ranking. [Supported plans] Free / Light / Standard / Premium (cache-only, no API call) Args: metric: Ranking metric — "per" (default) or "pbr". Both ratios are returned per item. n: Stocks to return (1–100, default 20). ascending: True (default) = cheapest first; False = most expensive first. min_value: Minimum metric value filter (default null). max_value: Maximum metric value filter (default null). market: "prime" / "standard" / "growth" / "tokyo_pro" (default all). sector: S33 sector code filter (default all). disc_months: Max FY-disclosure age in months (default 18) — drops stale financials.
| Name | Type | Req | Description |
|---|---|---|---|
| ascending | boolean | – | – |
| disc_months | integer | – | – |
| market | – | – | – |
| max_value | – | – | – |
| metric | string | – | – |
| min_value | – | – | – |
| n | integer | – | – |
| sector | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
get_value_stock_screen ~641
Screen value stocks near their 52-week low with high forward dividend yield and a profit-increase forecast (年安・割安・高配当・好決算スクリーニング). All plans. Use for 年安 割安 高配当 好決算, 年安圏の割安高配当株, バリュー株総合スクリーニング, value stocks near 52-week low, undervalued high-dividend profit-growth screen. ALL criteria must hold: close within near_low_pct % of the split-adjusted 52-week low (or a fresh 52w low touched that day), PER < max_per AND PBR < max_pbr (latest FY EPS/BPS, split-adjusted), forward dividend yield >= min_yield % (NxFDivAnn > FDivAnn priority, same as get_dividend_yield_ranking), and — by default — a forward net-profit forecast above the latest FY actual (NxFNp/FNP > NP = 増益予想). REITs are excluded (different accounting semantics; use get_dividend_yield_ranking for REIT yields). For a single criterion use get_valuation_ranking / get_dividend_yield_ranking / detect_52w_high_low. Included in get_market_briefing as the value_screen section. Each item also carries margin_ratio (信用倍率 = LongVol/ShrtVol, latest weekly margin interest) and margin_date — null on Free/Light plans or when the stock has no margin data. [Supported plans] Free / Light / Standard / Premium (cache-only, no API call) Args: n: Stocks to return (1–100, default 20). near_low_pct: Max % distance of close above the 52-week low (0–100, default 5.0). max_per: PER upper bound, exclusive (default 15.0). Net-loss stocks (EPS<=0) never match. max_pbr: PBR upper bound, exclusive (default 1.0). Negative-book stocks (BPS<=0) never match. min_yield: Minimum forward dividend yield % (default 3.5). require_profit_increase: Require forward net profit > latest FY actual, both disclosed (default True). disc_months: Max disclosure age in months for financials and dividend forecasts (default 18). market: "prime" / "standard" / "growth" / "tokyo_pro" (default all). sector: S33 sector code filter (default all). date: Trading date (YYYY-MM-DD or YYYYMMDD, default latest cached).
| Name | Type | Req | Description |
|---|---|---|---|
| date | – | – | – |
| disc_months | integer | – | – |
| market | – | – | – |
| max_pbr | number | – | – |
| max_per | number | – | – |
| min_yield | number | – | – |
| n | integer | – | – |
| near_low_pct | number | – | – |
| require_profit_increase | boolean | – | – |
| sector | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
health_check ~363
Check server health, API key configuration, and cache readiness. Offloaded to a worker thread (see ``_health_check_impl``): the body can trigger the slow lazy cache initialization (connect + migrations), and the official mcp SDK — unlike the standalone fastmcp package this server used to run on — invokes sync tool bodies directly on the event loop rather than in a worker thread, so an explicit ``asyncio.to_thread`` offload is required here to keep that work off the loop. Sharing the SQLite connection with the loop from that thread is what caused #537; the store's write lock, not this offload, is what makes it safe. Call this at session start to confirm cache.db has finished loading before issuing detect_* or cache_status — the first call after server start may take 10–60 seconds while the cache initialises lazily. After a tool-call timeout, use this to distinguish a transient cache-loading delay from a permanent failure. Returns server version, API key status, active plan, ``status`` (healthy / degraded), ``cache_integrity`` and ``cache_ready``. ``status`` is degraded only when the integrity check reports a failure; there is no error state, since this call does no I/O that can fail. ``cache_integrity`` (ok / pending / not-checked / failed: <detail> / error: <detail>) is the integrity check's own result. The last two carry a detail string appended to the prefix, so test them with ``startswith``, not ``==``. ``cache_ready`` is a boolean shorthand: true only when cache_integrity is exactly "ok". In multi-user mode, returns the authenticated user's plan.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
register_api_key ~221
Register or update your J-Quants API key (multi-user mode). ⚠️ SECURITY WARNING: The API key is transmitted in plaintext via the MCP protocol and may be logged by the MCP client or LLM provider. Treat the key as exposed to every hop in that chain, and rotate it from the J-Quants console if that is not acceptable. Stores your J-Quants API key encrypted in the server's user database, associated with your OAuth identity. The server probes plan-specific J-Quants endpoints to auto-detect the plan (free / light / standard / premium) and stores it alongside the key. Subsequent tool calls will automatically use this key and the detected plan's rate limits and date-range restrictions. This tool requires OAuth 2.1 authentication and server-side encryption (MCP_ENCRYPTION_KEY) to be configured. Args: api_key: Your J-Quants API key (refresh token from the J-Quants portal).
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
search_equities ~210
Search for listed stocks by company name (reverse lookup: 会社名 → コード). Use when the user knows a company name but not the stock code — e.g. "住友商事 のコードは?" or "トヨタ関連銘柄を調べて". Performs a case-insensitive partial match against both the Japanese name (CoName) and English name (CoNameEn) fields in the equities master cache. Reads entirely from the local ``equities_master`` Tier 1 cache (no API call). Returns an empty list when the cache has never been populated. [Supported plans] Free / Light / Standard / Premium [Source] equities_master Tier 1 cache (no API call) Args: name: Partial or full company name to search for (e.g. "住友商事", "トヨタ", "Sumitomo"). Case-insensitive; matches anywhere in the name.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
What is the J-Quants MCP server?
J-Quants MCP is listed in the public MCP registry as io.github.shigechika/jquants-mcp. MCP server for retrieving Japanese stock market data via J-Quants API v2. This page covers its PyPI package (jquants-mcp).
Is the J-Quants MCP server safe to use?
J-Quants MCP scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the J-Quants MCP server expose?
J-Quants MCP exposes 55 tools: health_check, cache_status, cache_clear, register_api_key, delete_api_key, and 50 more. Their descriptions and schemas cost roughly 12,249 tokens of context every time the server is loaded.
Is the J-Quants MCP server still maintained?
J-Quants MCP is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the J-Quants MCP server under?
J-Quants MCP declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.