Stratify
REMOTE · STRATIFY-MCP.AEON-LABS.SITE · 2 COMPONENTS · SCANNED SEP 21
Backtest NIFTY option strategies on real 1-minute data, with an honest out-of-sample panel.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security97
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability85
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2921 tokens (~108/item across 27 items; 10 tools + 17 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage87
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 60% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 10 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities73
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
- Supports UI / widget rendering.Pass
How do I install the Stratify MCP server?
Stratify is a hosted endpoint at https://stratify-mcp.aeon-labs.site/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · stratify-mcp.aeon-labs.site
claude mcp add --transport http site-aeon-labs-stratify 'https://stratify-mcp.aeon-labs.site/mcp'
{
"mcpServers": {
"site-aeon-labs-stratify": {
"url": "https://stratify-mcp.aeon-labs.site/mcp"
}
}
} {
"servers": {
"site-aeon-labs-stratify": {
"type": "http",
"url": "https://stratify-mcp.aeon-labs.site/mcp"
}
}
} [mcp_servers.site-aeon-labs-stratify] url = "https://stratify-mcp.aeon-labs.site/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"site-aeon-labs-stratify": {
"type": "remote",
"url": "https://stratify-mcp.aeon-labs.site/mcp",
"enabled": true
}
}
} openclaw mcp add site-aeon-labs-stratify --url 'https://stratify-mcp.aeon-labs.site/mcp' --transport streamable-http
mcp_servers:
site-aeon-labs-stratify:
url: "https://stratify-mcp.aeon-labs.site/mcp" {
"McpServers": {
"site-aeon-labs-stratify": {
"Transport": "http",
"Url": "https://stratify-mcp.aeon-labs.site/mcp"
}
}
} assistant mcp add site-aeon-labs-stratify -t streamable-http -u 'https://stratify-mcp.aeon-labs.site/mcp'
{
"mcpServers": {
"site-aeon-labs-stratify": {
"type": "http",
"url": "https://stratify-mcp.aeon-labs.site/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 16 Sept 26 80
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://stratify-mcp.aeon-labs.site/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=stratify.aeon-labs.site | CN=YE1,O=Let's Encrypt,C=US | 25 Aug 2026 | 23 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 6cf3442e90fb8b52e56a17e195251a2853c |
| SANs: stratify-mcp.aeon-labs.site, stratify.aeon-labs.site | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of stratify-mcp.aeon-labs.site. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| site. | present | 31826 | 13 | Verified |
| aeon-labs.site. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer error="invalid_token", error_description="Authentication required", resource_metadata="https://stratify-mcp.aeon-labs.site/.well-known/oauth-protected-resource/mcp", scope="mcp"
Bearer error="invalid_token", error_description="Authentication required", resource_metadata="https://stratify-mcp.aeon-labs.site/.well-known/oauth-protected-resource/mcp", scope="mcp" | Header | Value |
|---|---|
| strict-transport-security | max-age=15768000 |
| x-content-type-options | nosniff |
| referrer-policy | no-referrer |
Protected resource metadata
| Document | https://stratify-mcp.aeon-labs.site/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://stratify-mcp.aeon-labs.site/mcp |
| Authorisation server | https://stratify.aeon-labs.site |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://stratify-mcp.aeon-labs.site/mcp | Verified | 200 | |
| http (plaintext) | http://stratify-mcp.aeon-labs.site/mcp | HTTPS enforced | 301 | https://stratify-mcp.aeon-labs.site/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
build_report ~483
Turn a stored backtest into a finished, self-contained Stratify report — one HTML document with the honesty panel, equity and drawdown curves, walk-forward folds, the gross-to-net breakdown, a month grid and the trade table. PUBLISH THE RETURNED HTML VERBATIM AS AN ARTIFACT (Claude), a canvas document (ChatGPT, Gemini), or write it to a .html file (CLI clients). Do not rewrite it, summarise it into your own chart code, or regenerate the figures — the numbers in it came from the backtest, and anything you redraw from a table is a second source that can disagree with the first. It needs no network, no libraries and no build step, and it renders on light and dark. Use it when someone asks for a report, a summary they can keep, something to share, or an artifact.
| Name | Type | Req | Description |
|---|---|---|---|
| backtest_id | string | yes | From a previous run_backtest. |
| capital | integer | – | format 'full' only. Starting capital in rupees. It sets the report's OPENING view — the reader can change it in the page without a new report. Default 1,000,000. |
| deploy_pct | number | – | format 'full' only. Percent of capital used as margin on any one trade. Default 10. |
| format | string | – | 'artifact' (default) returns the whole document to publish. 'link' returns only the hosted URL — far cheaper in tokens, and the right choice when the user just wants to look at it rather than keep it… |
| risk_pct | number | – | format 'full' only. Size by RISK instead of margin: the percent of capital the trade is allowed to lose in its worst case (2 means 'risk 2% per trade'). Only works where the position has a bounded wo… |
No output schema declared.
No examples provided.
describe_coverage ~43
What data is available: symbols, date range, resolution, structures, gates, biases, the cost model, and every known gap. Call this before building a spec.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
explain_methodology ~61
How a result is produced and how to judge it: entry pricing, settlement, margin, slippage, the honesty rubric, and what each check can and cannot prove. Read this before trusting any backtest, including ours.
| Name | Type | Req | Description |
|---|---|---|---|
| topic | string | – | – |
No output schema declared.
No examples provided.
fetch ~29
Fetch a document or backtest result by id, as returned by search.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_backtest ~51
Retrieve a previous backtest result by its id — honesty panel, equity curve and per-trade detail, exactly as first computed.
| Name | Type | Req | Description |
|---|---|---|---|
| backtest_id | string | yes | – |
| detail | string | – | – |
No output schema declared.
No examples provided.
list_strategies ~122
Strategies from THIS account's history that held up under out-of-sample and walk-forward checks, not merely ones that made money. Ranked by worst walk-forward fold — consistency, not size. Call it to answer 'what has worked for me so far?' without re-running anything.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| order | string | – | 'consistency' (default) sorts by worst walk-forward fold, then median fold. 'pnl' sorts by total P&L and is the ranking most likely to put an overfit at the top. |
No output schema declared.
No examples provided.
my_feedback ~35
Reports this account has filed, and where each one stands. Use it to answer 'did that bug I reported ever get fixed?'.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
run_backtest ~327
Backtest an Indian index option strategy on real 1-minute NIFTY options data. Returns P&L after real charges and slippage, return-on-margin, and an honesty panel: out-of-sample split, walk-forward folds, bootstrap interval, and a deflated Sharpe that accounts for how many variants you have already tried. Refuses windows too narrow to be meaningful, and reports no ratios below 30 trades. Two spec forms: a PRESET (structure + params) for the common shapes, or an OPEN STRATEGY (legs + rules) for anything else — any number of legs at any strikes on any expiry, strikes chosen by percent, points, premium or delta, entry at any minute, and rules that CHANGE the position while it is live (roll a tested leg, close one side, add a hedge, trail a stop) plus book-level rules like standing down after three losers. Nothing here is restricted by tier; a paid tier only widens the date window.
| Name | Type | Req | Description |
|---|---|---|---|
| detail | string | – | How much per-trade data to return. 'standard' (default) is the equity curve, breakdowns and the first 25 trades with their leg prices. 'full' returns up to 300 trades — ask for it when the caller wan… |
| lots | integer | – | – |
| spec | – | yes | Either a preset spec (structure + params) or an open strategy (legs + rules). Use the open form for anything the presets cannot say. |
No output schema declared.
No examples provided.
search ~36
Search what this service covers — symbols, dates, structures, signals, methodology. Returns ids usable with fetch.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | – |
No output schema declared.
No examples provided.
submit_feedback ~191
Report a bug, request a feature, flag a data gap, or say what worked. Use this whenever the user expresses a problem with this service or wishes it did something it does not — do not just apologise to them, file it. If a backtest was involved, pass its backtest_id: that attaches the exact spec and the recent call trail so the issue can be reproduced without a reply. Tell the user you filed it and give them the returned id.
| Name | Type | Req | Description |
|---|---|---|---|
| backtest_id | string | – | The result this is about, if any. |
| body | string | yes | What was expected, what happened, and any spec involved. Write it from the user's report, not from your own summary of it. |
| category | string | – | Omit it and it will be inferred from the text. |
| severity | string | – | – |
| title | string | yes | One line naming the problem or request. |
No output schema declared.
No examples provided.
What is the Stratify MCP server?
Stratify is an MCP server listed in the public MCP registry as site.aeon-labs/stratify. Backtest NIFTY option strategies on real 1-minute data, with an honest out-of-sample panel. This page covers its hosted endpoint (https://stratify-mcp.aeon-labs.site/mcp).
Is the Stratify MCP server safe to use?
Stratify scores 82 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Stratify MCP server expose?
Stratify exposes 10 tools: run_backtest, describe_coverage, explain_methodology, get_backtest, list_strategies, and 5 more. Their descriptions and schemas cost roughly 1,378 tokens of context every time the server is loaded.
Does the Stratify MCP server require authentication?
Yes. Stratify asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Stratify MCP server still maintained?
Stratify is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.