Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.tickerbot/mcp-server

REMOTE · API.TICKERBOT.IO · 2 COMPONENTS · SCANNED OCT 5

The stock market, in SQL — scan, replay, or subscribe across ~12k US tickers and top 100 cryptos.

−1 this week 81 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security89
Transport & Reachability100
Schema Quality & AI Usability62
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 12250 tokens (~382/item across 32 items; 32 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management70
  • Stability check failed: schema churn in the 30 days we've observed: 9 tool removals, 3 breaking changes, 0 auth/transport breaks, 6 additions. See how to fix → Fail
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (91% of tools); any adoption earns full credit.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "tickerbot_delete_custom_signal" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the io.github.tickerbot/mcp-server server?

io.github.tickerbot/mcp-server is a hosted endpoint at https://api.tickerbot.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · api.tickerbot.io

# add to Claude Code
claude mcp add --transport http tickerbot-mcp-server 'https://api.tickerbot.io/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "tickerbot-mcp-server": {
      "url": "https://api.tickerbot.io/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "tickerbot-mcp-server": {
      "type": "http",
      "url": "https://api.tickerbot.io/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.tickerbot-mcp-server]
url = "https://api.tickerbot.io/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "tickerbot-mcp-server": {
      "type": "remote",
      "url": "https://api.tickerbot.io/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add tickerbot-mcp-server --url 'https://api.tickerbot.io/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  tickerbot-mcp-server:
    url: "https://api.tickerbot.io/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "tickerbot-mcp-server": {
      "Transport": "http",
      "Url": "https://api.tickerbot.io/mcp"
    }
  }
}
# add to Vellum
assistant mcp add tickerbot-mcp-server -t streamable-http -u 'https://api.tickerbot.io/mcp'
// mcp.json
{
  "mcpServers": {
    "tickerbot-mcp-server": {
      "type": "http",
      "url": "https://api.tickerbot.io/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Oct 26 0
    • “tickerbot_get_signal” reworded the description of “interval” cosmetic
    • “tickerbot_get_ticker” reworded the description of “asof” cosmetic
    • “tickerbot_get_ticker” reworded the description of “interval” cosmetic
    • “tickerbot_list_events” reworded the description of “interval” cosmetic
    • “tickerbot_list_events” reworded the description of “join” cosmetic
    • “tickerbot_scan” reworded the description of “asof” cosmetic
    • “tickerbot_scan” reworded the description of “interval” cosmetic
    • “tickerbot_scan” reworded the description of “universe” cosmetic
    • “tickerbot_get_series” reworded the description of “asof” cosmetic
    • “tickerbot_get_signal” reworded the description of “asof” cosmetic
    • “tickerbot_get_bars” reworded the description of “asof” cosmetic
    • “tickerbot_get_series” reworded the description of “interval” cosmetic

    12 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.

  • 2 Oct 26 0
    • “tickerbot_scan” reworded the description of “universe” cosmetic

    1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.

  • 30 Sept 26 −1
    • “tickerbot_scan” reworded the description of “universe” cosmetic
    • “tickerbot_list_events” reworded the description of “kind” cosmetic

    2 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.

  • 29 Sept 26 0
    • Tool “tickerbot_get_ticker_coverage” rewrote its description, which is the text the model reads security
  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • “tickerbot_create_custom_signal” reworded the description of “expr” cosmetic
    • “tickerbot_update_custom_signal” reworded the description of “expr” cosmetic

    2 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.

  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 0
    • Tool “tickerbot_get_signal” rewrote its description, which is the text the model reads security
    • “tickerbot_get_signal” reworded the description of “signal” cosmetic
    • “tickerbot_get_signal” reworded the description of “condition” cosmetic
    • “tickerbot_subscribe_signal” reworded the description of “condition” cosmetic
    • “tickerbot_scan” reworded the description of “universe” cosmetic
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 8 Oct 2026 · Probed https://api.tickerbot.io/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=api.tickerbot.io CN=YE2,O=Let's Encrypt,C=US 12 Sept 2026 11 Dec 2026 ECDSA 256 ECDSA-SHA384 6a9b724237f1a73a10a834d941a40fa0d66
SANs: api.tickerbot.io
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of api.tickerbot.io. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
io. present 57355 8 Verified
tickerbot.io. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On connection
HTTP status 401

WWW-Authenticate challenge Bearer realm="mcp", resource_metadata="https://api.tickerbot.io/.well-known/oauth-protected-resource"

Bearer realm="mcp", resource_metadata="https://api.tickerbot.io/.well-known/oauth-protected-resource"
Header Value
www-authenticate Bearer realm="mcp", resource_metadata="https://api.tickerbot.io/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://api.tickerbot.io/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://api.tickerbot.io/mcp
Authorisation server https://api.tickerbot.io

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.tickerbot.io/mcp Auth required 401
http (plaintext) http://api.tickerbot.io/mcp HTTPS enforced 301 https://api.tickerbot.io/mcp
MCP tools · 32 exposed · ~12,250 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
tickerbot_subscribe_ticker ~692

Push one ticker: we POST your endpoint whenever it matches the condition you give. Webhooks need a paid plan (Free has no webhook slots). Omit `target_url` for in-app delivery.

NameTypeReqDescription
cadencestring–How often to evaluate. `realtime` (the default) is evaluated on every data refresh (~1×/min); `hourly` and `nyse_open` throttle to a batch schedule. `1m` is a deprecated alias for `realtime`.
channelstring–Delivery channel. `webhook` (POST to `target_url`), `discord` (post an embed to `discord_url`), `in_app` (dashboard only), or `mobile_push` (notify a phone signed in to the Tickerbot mobile app; requ…
columnsstring–Comma-separated extra signals to include in each fired payload match row, beyond the standard set (`ticker`, `name`, `asset_type`, `price`, `change_1d_pct`, `market_cap`). Each must be a real signal;…
conditionstring–Original name for `q` — accepted as well. The same WHERE-clause fragment; send either spelling.
device_idstring–Device to notify, from `POST /v2/devices/register`. Required when `channel` is `mobile_push`; unknown ids are a 404 `device_not_found`.
dirstring–Sort direction for `order`.
discord_urlstring–Discord incoming-webhook URL (`https://discord.com/api/webhooks/…`). Required when `channel` is `discord`. Stored as a posting credential: the create response echoes it back under `channel_config`, b…
namestring–Human-readable label (up to 80 chars). Defaults to `<TICKER>: <query>`.
orderstring–Signal the fired payload's match lists are sorted by before the 100-row cap is applied, so a truncated list is the deterministic top 100 rather than an arbitrary sample. Must be a real signal (valida…
qstringyesWHERE-clause fragment using signal names from the schema — the same grammar as /v2/scan. (`condition` accepted as an alias.)
target_urlstring–https:// URL to POST when the condition fires. Omit for in-app delivery (visible in the dashboard).
tickerstringyesCase-insensitive. Equities are bare symbols (`AAPL`); every other class carries a prefix — rates (`R:SOFR`), crypto (`X:BTCUSD`), fx (`X:EURUSD`). Bare `BTC`/`ETH` are US-listed ETFs, not spot crypto…
NameTypeReqDescription
_metaobject–Returned on create only, and only when the rule or `columns` named a column under its pre-2026-09-07 spelling: `deprecated_columns` lists each one (`requested`, `use`, `note`). The stored rule carrie…
as_ofstringyesServer time this response was assembled (ISO 8601).
cadencestringyesHow often the trigger is evaluated — `realtime`, `hourly`, or `nyse_open`.
channelstringyesWhere deliveries go: `webhook`, `discord`, `in_app`, or `mobile_push`.
channel_configobjectyesReturned on create only: the channel-specific delivery settings as stored (e.g. the Discord URL, the device id).
created_atnumberyesCreation timestamp.
deliverystringyesLegacy alias of `channel`, kept aligned for older readers.
dirstringyesSort direction for that list; `null` means the default (`desc`).
event_kindsarray–Event-trigger webhooks only: the kinds subscribed (`split`, `dividend`, `insider`, `analyst`, `earnings`).
event_qstring–Event-trigger webhooks only: the payload filter, or `null`.
event_tickersarray–Event-trigger webhooks only: the symbols the trigger is scoped to, or `null` for the universe / whole market.
fieldsstringyesExtra signals carried on each fired match row; `null` means the standard set.
idstringyesThe webhook id — `wh_…`, the handle for every other call on this record.
last_errorstring–The last evaluation error; `null` on a healthy hook. The answer to "why is my webhook not firing?".
last_eval_error_atnumber–When the last evaluation error happened; `null` on a healthy hook.
last_evaluated_atnumberyesWhen it was last evaluated; `null` until the first run.
last_firednumberyesWhen a delivery last went out; `null` if it never has.
last_match_setarrayyesTickers matching at the last evaluation — the set the next run is diffed against, which is what makes firing edge-triggered.
last_predicate_valuestringyesThe trigger's value at the last evaluation; `null` until it has run.
namestringyesYour label for the subscription.
next_eval_atnumberyesWhen the evaluator will next consider this subscription.
orderstringyesSort signal for the payload row list; `null` means the evaluator default (`market_cap`).
qstringyesThe stored predicate. Custom signals appear expanded: the SQL is frozen at creation.
rule_idstringyesLegacy link to a v1 alert rule; `null` on everything created through v2.
signing_secretstringyesReturned on create only — shown once, never again. HMAC key for verifying the `X-Tickerbot-Signature` header on deliveries.
sourcestringyesWhich API version created the record; `v2` for anything you create today.
statusstringyes`active` or `disabled`. Auto-disable follows repeated delivery failure.
subscription_originobjectyesWhich door created it — `type` (`ticker`/`signal`/`scan`/`event`), its `ref`, and the `condition` in display form.
target_urlstringyesYour HTTPS endpoint; `null` on every channel except `webhook`.
test_urlstring–Returned on create only: the `POST /v2/webhooks/{id}/test` URL for this record.
trigger_kindstring–Event-trigger webhooks only: `event`.
universe_idstringyesUniverse the trigger is scoped to, or `null` for the whole market.
updated_atnumberyesLast modification timestamp.

No examples provided.

tickerbot_test_webhook ~60

Send a real-shape test POST to your endpoint, instantly. One-shot: a failed test never retries and never auto-disables the webhook. 400 when the webhook has no target_url.

NameTypeReqDescription
idstringyesWebhook id.
NameTypeReqDescription
as_ofstringyesServer time this response was assembled (ISO 8601).
created_atstringyesWhen the ping was sent (ISO 8601).
deliveredbooleanyesWhether your endpoint accepted the ping (2xx within the timeout).
elapsed_msnumberyesRound-trip time of the ping.
errorstringyesWhy delivery failed, in words; `null` on success.
http_statusnumberyesThe status your endpoint returned; `null` when it could not be reached.
idstringyesDelivery id of the test — `dl_…`, the same shape as a real delivery on the deliveries route.
statusstringyesThe delivery record's status: `delivered` or `permanent_failure` (a test is never retried).
testbooleanyes`true` — this delivery was a synthetic ping, not a trigger firing.
webhook_idstringyesThe webhook that was tested.

No examples provided.

tickerbot_update_custom_signal ~263

Update a custom signal you own — its expression, description, or name.

NameTypeReqDescription
descriptionstring–New description. Not derived from `expr` — change both if the prose describes a threshold you are moving.
exprstring–New SQL expression. Re-validated and re-inlined against your other custom signals. Same strict grammar as create — no `LIKE`/`ILIKE`, `CASE`, `::` casts, or functions beyond `abs`/`coalesce`/`round`/…
new_namestring–New slug — renames the signal and changes its API handle everywhere (same validation as create). Refused while other custom signals reference the current name. `name` is accepted as an alias (new_nam…
signalstringyesCustom signal slug (the signal name). A built-in name answers 404 — built-ins are read-only.
NameTypeReqDescription
_metaobject–Only when `expr` named a column under its pre-2026-09-07 spelling: `deprecated_columns` lists each one (`requested`, `use`, `note`). The stored `expr` carries the current name.
as_ofstringyesServer time this response was assembled (ISO 8601).
signalobjectyesThe stored signal: `name`, `kind` (`custom`), `description`, `expr` (your predicate as stored), `created_at`, `updated_at`.

No examples provided.

tickerbot_update_universe ~158

Update one of your universes: its name, description, or members. `tickers` replaces the whole list; `add`/`remove` adjust it. System universes cannot be edited.

NameTypeReqDescription
addarray–Add these tickers (deduplicated).
descriptionstring–New notes. Max 500 characters.
idstringyesUniverse slug.
namestring–New label. Non-empty, max 80 characters.
removearray–Remove these tickers.
tickersarray–Replace the full ticker list (up to 10,000; validated against the active universe). Does not combine with `add`/`remove` (400).
NameTypeReqDescription
as_ofstringyesServer time this response was assembled (ISO 8601).
created_atnumberyesCreation timestamp.
descriptionstringyesFree-form notes; `""` when unset.
effective_atnumber–System universes only; absent on yours.
idstringyesThe slug — the universe's handle in `?universe=`.
namestringyesDisplay label.
next_rebalance_atnumber–System universes only; absent on yours.
rebalance_methodstring–System universes only; absent on yours.
sizenumberyesMember count.
systembooleanyes`false` — this is your universe.
tickersarrayyesMembers, after this call.
updated_atnumberyesLast modification timestamp.

No examples provided.

tickerbot_update_webhook ~238

Edit a webhook in place — send only the fields you want to change. The trigger and channel are immutable — delete and re-create to change what fires or where it delivers. Unknown fields are a 400.

NameTypeReqDescription
cadencestring–Evaluation cadence. A user preference — never gated. Event triggers deliver on ingest — only `realtime` is accepted on them (400 otherwise).
enabledboolean–`false` disables the webhook (status → `disabled`). `true` is a no-op unless disabled, in which case use `POST /v2/webhooks/{id}/enable` instead.
idstringyesWebhook id.
namestring–New display name. Non-empty, max 80 characters.
target_urlstring–New https:// delivery URL (webhook channel only — a Discord/mobile subscription 400s here). `null` or empty switches to in-app delivery; `status` is untouched — a disabled webhook stays disabled unti…
NameTypeReqDescription
as_ofstringyesServer time this response was assembled (ISO 8601).
cadencestringyesHow often the trigger is evaluated — `realtime`, `hourly`, or `nyse_open`.
channelstringyesWhere deliveries go: `webhook`, `discord`, `in_app`, or `mobile_push`.
created_atnumberyesCreation timestamp.
deliverystringyesLegacy alias of `channel`, kept aligned for older readers.
dirstringyesSort direction for that list; `null` means the default (`desc`).
event_kindsarray–Event-trigger webhooks only: the kinds subscribed (`split`, `dividend`, `insider`, `analyst`, `earnings`).
event_qstring–Event-trigger webhooks only: the payload filter, or `null`.
event_tickersarray–Event-trigger webhooks only: the symbols the trigger is scoped to, or `null` for the universe / whole market.
fieldsstringyesExtra signals carried on each fired match row; `null` means the standard set.
idstringyesThe webhook id — `wh_…`, the handle for every other call on this record.
last_errorstring–The last evaluation error; `null` on a healthy hook. The answer to "why is my webhook not firing?".
last_eval_error_atnumber–When the last evaluation error happened; `null` on a healthy hook.
last_evaluated_atnumberyesWhen it was last evaluated; `null` until the first run.
last_firednumberyesWhen a delivery last went out; `null` if it never has.
last_match_setarrayyesTickers matching at the last evaluation — the set the next run is diffed against, which is what makes firing edge-triggered.
last_predicate_valuestringyesThe trigger's value at the last evaluation; `null` until it has run.
namestringyesYour label for the subscription.
next_eval_atnumberyesWhen the evaluator will next consider this subscription.
orderstringyesSort signal for the payload row list; `null` means the evaluator default (`market_cap`).
qstringyesThe stored predicate. Custom signals appear expanded: the SQL is frozen at creation.
rule_idstringyesLegacy link to a v1 alert rule; `null` on everything created through v2.
sourcestringyesWhich API version created the record; `v2` for anything you create today.
statusstringyes`active` or `disabled`. Auto-disable follows repeated delivery failure.
subscription_originobjectyesWhich door created it — `type` (`ticker`/`signal`/`scan`/`event`), its `ref`, and the `condition` in display form.
target_urlstringyesYour HTTPS endpoint; `null` on every channel except `webhook`.
trigger_kindstring–Event-trigger webhooks only: `event`.
universe_idstringyesUniverse the trigger is scoped to, or `null` for the whole market.
updated_atnumberyesLast modification timestamp.

No examples provided.

Common questions

What is the io.github.tickerbot/mcp-server server?

io.github.tickerbot/mcp-server is listed in the public MCP registry as io.github.tickerbot/mcp-server. The stock market, in SQL, scan, replay, or subscribe across ~12k US tickers and top 100 cryptos. This page covers its hosted endpoint (https://api.tickerbot.io/mcp).

Is the io.github.tickerbot/mcp-server server safe to use?

io.github.tickerbot/mcp-server scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.tickerbot/mcp-server server expose?

io.github.tickerbot/mcp-server exposes 32 tools: tickerbot_list_tickers, tickerbot_get_ticker, tickerbot_subscribe_ticker, tickerbot_get_ticker_coverage, tickerbot_list_signals, and 27 more. Their descriptions and schemas cost roughly 12,250 tokens of context every time the server is loaded.

Does the io.github.tickerbot/mcp-server server require authentication?

Yes. io.github.tickerbot/mcp-server asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the io.github.tickerbot/mcp-server server still maintained?

io.github.tickerbot/mcp-server is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.