io.github.tickerbot/mcp-server
REMOTE · API.TICKERBOT.IO · 2 COMPONENTS · SCANNED OCT 5
The stock market, in SQL — scan, replay, or subscribe across ~12k US tickers and top 100 cryptos.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability62
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 12250 tokens (~382/item across 32 items; 32 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management70
- Stability check failed: schema churn in the 30 days we've observed: 9 tool removals, 3 breaking changes, 0 auth/transport breaks, 6 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (91% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "tickerbot_delete_custom_signal" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.github.tickerbot/mcp-server server?
io.github.tickerbot/mcp-server is a hosted endpoint at https://api.tickerbot.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.tickerbot.io
claude mcp add --transport http tickerbot-mcp-server 'https://api.tickerbot.io/mcp'
{
"mcpServers": {
"tickerbot-mcp-server": {
"url": "https://api.tickerbot.io/mcp"
}
}
} {
"servers": {
"tickerbot-mcp-server": {
"type": "http",
"url": "https://api.tickerbot.io/mcp"
}
}
} [mcp_servers.tickerbot-mcp-server] url = "https://api.tickerbot.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"tickerbot-mcp-server": {
"type": "remote",
"url": "https://api.tickerbot.io/mcp",
"enabled": true
}
}
} openclaw mcp add tickerbot-mcp-server --url 'https://api.tickerbot.io/mcp' --transport streamable-http
mcp_servers:
tickerbot-mcp-server:
url: "https://api.tickerbot.io/mcp" {
"McpServers": {
"tickerbot-mcp-server": {
"Transport": "http",
"Url": "https://api.tickerbot.io/mcp"
}
}
} assistant mcp add tickerbot-mcp-server -t streamable-http -u 'https://api.tickerbot.io/mcp'
{
"mcpServers": {
"tickerbot-mcp-server": {
"type": "http",
"url": "https://api.tickerbot.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 0
- “tickerbot_get_signal” reworded the description of “interval” cosmetic
- “tickerbot_get_ticker” reworded the description of “asof” cosmetic
- “tickerbot_get_ticker” reworded the description of “interval” cosmetic
- “tickerbot_list_events” reworded the description of “interval” cosmetic
- “tickerbot_list_events” reworded the description of “join” cosmetic
- “tickerbot_scan” reworded the description of “asof” cosmetic
- “tickerbot_scan” reworded the description of “interval” cosmetic
- “tickerbot_scan” reworded the description of “universe” cosmetic
- “tickerbot_get_series” reworded the description of “asof” cosmetic
- “tickerbot_get_signal” reworded the description of “asof” cosmetic
- “tickerbot_get_bars” reworded the description of “asof” cosmetic
- “tickerbot_get_series” reworded the description of “interval” cosmetic
12 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.
- 2 Oct 26 0
- “tickerbot_scan” reworded the description of “universe” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 30 Sept 26 −1
- “tickerbot_scan” reworded the description of “universe” cosmetic
- “tickerbot_list_events” reworded the description of “kind” cosmetic
2 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.
- 29 Sept 26 0
- Tool “tickerbot_get_ticker_coverage” rewrote its description, which is the text the model reads security
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- “tickerbot_create_custom_signal” reworded the description of “expr” cosmetic
- “tickerbot_update_custom_signal” reworded the description of “expr” cosmetic
2 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- Tool “tickerbot_get_signal” rewrote its description, which is the text the model reads security
- “tickerbot_get_signal” reworded the description of “signal” cosmetic
- “tickerbot_get_signal” reworded the description of “condition” cosmetic
- “tickerbot_subscribe_signal” reworded the description of “condition” cosmetic
- “tickerbot_scan” reworded the description of “universe” cosmetic
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 8 Oct 2026 · Probed https://api.tickerbot.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.tickerbot.io | CN=YE2,O=Let's Encrypt,C=US | 12 Sept 2026 | 11 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6a9b724237f1a73a10a834d941a40fa0d66 |
| SANs: api.tickerbot.io | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.tickerbot.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| tickerbot.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer realm="mcp", resource_metadata="https://api.tickerbot.io/.well-known/oauth-protected-resource"
Bearer realm="mcp", resource_metadata="https://api.tickerbot.io/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| www-authenticate | Bearer realm="mcp", resource_metadata="https://api.tickerbot.io/.well-known/oauth-protected-resource" |
Protected resource metadata
| Document | https://api.tickerbot.io/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://api.tickerbot.io/mcp |
| Authorisation server | https://api.tickerbot.io |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.tickerbot.io/mcp | Auth required | 401 | |
| http (plaintext) | http://api.tickerbot.io/mcp | HTTPS enforced | 301 | https://api.tickerbot.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
tickerbot_subscribe_ticker ~692
Push one ticker: we POST your endpoint whenever it matches the condition you give. Webhooks need a paid plan (Free has no webhook slots). Omit `target_url` for in-app delivery.
| Name | Type | Req | Description |
|---|---|---|---|
| cadence | string | – | How often to evaluate. `realtime` (the default) is evaluated on every data refresh (~1×/min); `hourly` and `nyse_open` throttle to a batch schedule. `1m` is a deprecated alias for `realtime`. |
| channel | string | – | Delivery channel. `webhook` (POST to `target_url`), `discord` (post an embed to `discord_url`), `in_app` (dashboard only), or `mobile_push` (notify a phone signed in to the Tickerbot mobile app; requ… |
| columns | string | – | Comma-separated extra signals to include in each fired payload match row, beyond the standard set (`ticker`, `name`, `asset_type`, `price`, `change_1d_pct`, `market_cap`). Each must be a real signal;… |
| condition | string | – | Original name for `q` — accepted as well. The same WHERE-clause fragment; send either spelling. |
| device_id | string | – | Device to notify, from `POST /v2/devices/register`. Required when `channel` is `mobile_push`; unknown ids are a 404 `device_not_found`. |
| dir | string | – | Sort direction for `order`. |
| discord_url | string | – | Discord incoming-webhook URL (`https://discord.com/api/webhooks/…`). Required when `channel` is `discord`. Stored as a posting credential: the create response echoes it back under `channel_config`, b… |
| name | string | – | Human-readable label (up to 80 chars). Defaults to `<TICKER>: <query>`. |
| order | string | – | Signal the fired payload's match lists are sorted by before the 100-row cap is applied, so a truncated list is the deterministic top 100 rather than an arbitrary sample. Must be a real signal (valida… |
| q | string | yes | WHERE-clause fragment using signal names from the schema — the same grammar as /v2/scan. (`condition` accepted as an alias.) |
| target_url | string | – | https:// URL to POST when the condition fires. Omit for in-app delivery (visible in the dashboard). |
| ticker | string | yes | Case-insensitive. Equities are bare symbols (`AAPL`); every other class carries a prefix — rates (`R:SOFR`), crypto (`X:BTCUSD`), fx (`X:EURUSD`). Bare `BTC`/`ETH` are US-listed ETFs, not spot crypto… |
| Name | Type | Req | Description |
|---|---|---|---|
| _meta | object | – | Returned on create only, and only when the rule or `columns` named a column under its pre-2026-09-07 spelling: `deprecated_columns` lists each one (`requested`, `use`, `note`). The stored rule carrie… |
| as_of | string | yes | Server time this response was assembled (ISO 8601). |
| cadence | string | yes | How often the trigger is evaluated — `realtime`, `hourly`, or `nyse_open`. |
| channel | string | yes | Where deliveries go: `webhook`, `discord`, `in_app`, or `mobile_push`. |
| channel_config | object | yes | Returned on create only: the channel-specific delivery settings as stored (e.g. the Discord URL, the device id). |
| created_at | number | yes | Creation timestamp. |
| delivery | string | yes | Legacy alias of `channel`, kept aligned for older readers. |
| dir | string | yes | Sort direction for that list; `null` means the default (`desc`). |
| event_kinds | array | – | Event-trigger webhooks only: the kinds subscribed (`split`, `dividend`, `insider`, `analyst`, `earnings`). |
| event_q | string | – | Event-trigger webhooks only: the payload filter, or `null`. |
| event_tickers | array | – | Event-trigger webhooks only: the symbols the trigger is scoped to, or `null` for the universe / whole market. |
| fields | string | yes | Extra signals carried on each fired match row; `null` means the standard set. |
| id | string | yes | The webhook id — `wh_…`, the handle for every other call on this record. |
| last_error | string | – | The last evaluation error; `null` on a healthy hook. The answer to "why is my webhook not firing?". |
| last_eval_error_at | number | – | When the last evaluation error happened; `null` on a healthy hook. |
| last_evaluated_at | number | yes | When it was last evaluated; `null` until the first run. |
| last_fired | number | yes | When a delivery last went out; `null` if it never has. |
| last_match_set | array | yes | Tickers matching at the last evaluation — the set the next run is diffed against, which is what makes firing edge-triggered. |
| last_predicate_value | string | yes | The trigger's value at the last evaluation; `null` until it has run. |
| name | string | yes | Your label for the subscription. |
| next_eval_at | number | yes | When the evaluator will next consider this subscription. |
| order | string | yes | Sort signal for the payload row list; `null` means the evaluator default (`market_cap`). |
| q | string | yes | The stored predicate. Custom signals appear expanded: the SQL is frozen at creation. |
| rule_id | string | yes | Legacy link to a v1 alert rule; `null` on everything created through v2. |
| signing_secret | string | yes | Returned on create only — shown once, never again. HMAC key for verifying the `X-Tickerbot-Signature` header on deliveries. |
| source | string | yes | Which API version created the record; `v2` for anything you create today. |
| status | string | yes | `active` or `disabled`. Auto-disable follows repeated delivery failure. |
| subscription_origin | object | yes | Which door created it — `type` (`ticker`/`signal`/`scan`/`event`), its `ref`, and the `condition` in display form. |
| target_url | string | yes | Your HTTPS endpoint; `null` on every channel except `webhook`. |
| test_url | string | – | Returned on create only: the `POST /v2/webhooks/{id}/test` URL for this record. |
| trigger_kind | string | – | Event-trigger webhooks only: `event`. |
| universe_id | string | yes | Universe the trigger is scoped to, or `null` for the whole market. |
| updated_at | number | yes | Last modification timestamp. |
No examples provided.
tickerbot_test_webhook ~60
Send a real-shape test POST to your endpoint, instantly. One-shot: a failed test never retries and never auto-disables the webhook. 400 when the webhook has no target_url.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Webhook id. |
| Name | Type | Req | Description |
|---|---|---|---|
| as_of | string | yes | Server time this response was assembled (ISO 8601). |
| created_at | string | yes | When the ping was sent (ISO 8601). |
| delivered | boolean | yes | Whether your endpoint accepted the ping (2xx within the timeout). |
| elapsed_ms | number | yes | Round-trip time of the ping. |
| error | string | yes | Why delivery failed, in words; `null` on success. |
| http_status | number | yes | The status your endpoint returned; `null` when it could not be reached. |
| id | string | yes | Delivery id of the test — `dl_…`, the same shape as a real delivery on the deliveries route. |
| status | string | yes | The delivery record's status: `delivered` or `permanent_failure` (a test is never retried). |
| test | boolean | yes | `true` — this delivery was a synthetic ping, not a trigger firing. |
| webhook_id | string | yes | The webhook that was tested. |
No examples provided.
tickerbot_update_custom_signal ~263
Update a custom signal you own — its expression, description, or name.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | New description. Not derived from `expr` — change both if the prose describes a threshold you are moving. |
| expr | string | – | New SQL expression. Re-validated and re-inlined against your other custom signals. Same strict grammar as create — no `LIKE`/`ILIKE`, `CASE`, `::` casts, or functions beyond `abs`/`coalesce`/`round`/… |
| new_name | string | – | New slug — renames the signal and changes its API handle everywhere (same validation as create). Refused while other custom signals reference the current name. `name` is accepted as an alias (new_nam… |
| signal | string | yes | Custom signal slug (the signal name). A built-in name answers 404 — built-ins are read-only. |
| Name | Type | Req | Description |
|---|---|---|---|
| _meta | object | – | Only when `expr` named a column under its pre-2026-09-07 spelling: `deprecated_columns` lists each one (`requested`, `use`, `note`). The stored `expr` carries the current name. |
| as_of | string | yes | Server time this response was assembled (ISO 8601). |
| signal | object | yes | The stored signal: `name`, `kind` (`custom`), `description`, `expr` (your predicate as stored), `created_at`, `updated_at`. |
No examples provided.
tickerbot_update_universe ~158
Update one of your universes: its name, description, or members. `tickers` replaces the whole list; `add`/`remove` adjust it. System universes cannot be edited.
| Name | Type | Req | Description |
|---|---|---|---|
| add | array | – | Add these tickers (deduplicated). |
| description | string | – | New notes. Max 500 characters. |
| id | string | yes | Universe slug. |
| name | string | – | New label. Non-empty, max 80 characters. |
| remove | array | – | Remove these tickers. |
| tickers | array | – | Replace the full ticker list (up to 10,000; validated against the active universe). Does not combine with `add`/`remove` (400). |
| Name | Type | Req | Description |
|---|---|---|---|
| as_of | string | yes | Server time this response was assembled (ISO 8601). |
| created_at | number | yes | Creation timestamp. |
| description | string | yes | Free-form notes; `""` when unset. |
| effective_at | number | – | System universes only; absent on yours. |
| id | string | yes | The slug — the universe's handle in `?universe=`. |
| name | string | yes | Display label. |
| next_rebalance_at | number | – | System universes only; absent on yours. |
| rebalance_method | string | – | System universes only; absent on yours. |
| size | number | yes | Member count. |
| system | boolean | yes | `false` — this is your universe. |
| tickers | array | yes | Members, after this call. |
| updated_at | number | yes | Last modification timestamp. |
No examples provided.
tickerbot_update_webhook ~238
Edit a webhook in place — send only the fields you want to change. The trigger and channel are immutable — delete and re-create to change what fires or where it delivers. Unknown fields are a 400.
| Name | Type | Req | Description |
|---|---|---|---|
| cadence | string | – | Evaluation cadence. A user preference — never gated. Event triggers deliver on ingest — only `realtime` is accepted on them (400 otherwise). |
| enabled | boolean | – | `false` disables the webhook (status → `disabled`). `true` is a no-op unless disabled, in which case use `POST /v2/webhooks/{id}/enable` instead. |
| id | string | yes | Webhook id. |
| name | string | – | New display name. Non-empty, max 80 characters. |
| target_url | string | – | New https:// delivery URL (webhook channel only — a Discord/mobile subscription 400s here). `null` or empty switches to in-app delivery; `status` is untouched — a disabled webhook stays disabled unti… |
| Name | Type | Req | Description |
|---|---|---|---|
| as_of | string | yes | Server time this response was assembled (ISO 8601). |
| cadence | string | yes | How often the trigger is evaluated — `realtime`, `hourly`, or `nyse_open`. |
| channel | string | yes | Where deliveries go: `webhook`, `discord`, `in_app`, or `mobile_push`. |
| created_at | number | yes | Creation timestamp. |
| delivery | string | yes | Legacy alias of `channel`, kept aligned for older readers. |
| dir | string | yes | Sort direction for that list; `null` means the default (`desc`). |
| event_kinds | array | – | Event-trigger webhooks only: the kinds subscribed (`split`, `dividend`, `insider`, `analyst`, `earnings`). |
| event_q | string | – | Event-trigger webhooks only: the payload filter, or `null`. |
| event_tickers | array | – | Event-trigger webhooks only: the symbols the trigger is scoped to, or `null` for the universe / whole market. |
| fields | string | yes | Extra signals carried on each fired match row; `null` means the standard set. |
| id | string | yes | The webhook id — `wh_…`, the handle for every other call on this record. |
| last_error | string | – | The last evaluation error; `null` on a healthy hook. The answer to "why is my webhook not firing?". |
| last_eval_error_at | number | – | When the last evaluation error happened; `null` on a healthy hook. |
| last_evaluated_at | number | yes | When it was last evaluated; `null` until the first run. |
| last_fired | number | yes | When a delivery last went out; `null` if it never has. |
| last_match_set | array | yes | Tickers matching at the last evaluation — the set the next run is diffed against, which is what makes firing edge-triggered. |
| last_predicate_value | string | yes | The trigger's value at the last evaluation; `null` until it has run. |
| name | string | yes | Your label for the subscription. |
| next_eval_at | number | yes | When the evaluator will next consider this subscription. |
| order | string | yes | Sort signal for the payload row list; `null` means the evaluator default (`market_cap`). |
| q | string | yes | The stored predicate. Custom signals appear expanded: the SQL is frozen at creation. |
| rule_id | string | yes | Legacy link to a v1 alert rule; `null` on everything created through v2. |
| source | string | yes | Which API version created the record; `v2` for anything you create today. |
| status | string | yes | `active` or `disabled`. Auto-disable follows repeated delivery failure. |
| subscription_origin | object | yes | Which door created it — `type` (`ticker`/`signal`/`scan`/`event`), its `ref`, and the `condition` in display form. |
| target_url | string | yes | Your HTTPS endpoint; `null` on every channel except `webhook`. |
| trigger_kind | string | – | Event-trigger webhooks only: `event`. |
| universe_id | string | yes | Universe the trigger is scoped to, or `null` for the whole market. |
| updated_at | number | yes | Last modification timestamp. |
No examples provided.
What is the io.github.tickerbot/mcp-server server?
io.github.tickerbot/mcp-server is listed in the public MCP registry as io.github.tickerbot/mcp-server. The stock market, in SQL, scan, replay, or subscribe across ~12k US tickers and top 100 cryptos. This page covers its hosted endpoint (https://api.tickerbot.io/mcp).
Is the io.github.tickerbot/mcp-server server safe to use?
io.github.tickerbot/mcp-server scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.tickerbot/mcp-server server expose?
io.github.tickerbot/mcp-server exposes 32 tools: tickerbot_list_tickers, tickerbot_get_ticker, tickerbot_subscribe_ticker, tickerbot_get_ticker_coverage, tickerbot_list_signals, and 27 more. Their descriptions and schemas cost roughly 12,250 tokens of context every time the server is loaded.
Does the io.github.tickerbot/mcp-server server require authentication?
Yes. io.github.tickerbot/mcp-server asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the io.github.tickerbot/mcp-server server still maintained?
io.github.tickerbot/mcp-server is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.