Quote.Trade MCP Adapter
REMOTE · QUOTE.TRADE · SCANNED OCT 7
Quote.Trade MCP: login, deposit address, market data, orders, and withdraws.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (quote_trade_place_order). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3289 tokens (~131/item across 25 items; 25 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management88
- Stability check failed: schema churn in the 30 days we've observed: 2 tool removals, 0 breaking changes, 0 auth/transport breaks, 11 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety81
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 1 of 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "quote_trade_account" implies "withdraw" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
- An AI judge read all 26 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the Quote.Trade MCP Adapter server?
Quote.Trade MCP Adapter is a hosted endpoint at https://quote.trade/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · quote.trade
claude mcp add --transport http trade-quote-mcp 'https://quote.trade/mcp'
{
"mcpServers": {
"trade-quote-mcp": {
"url": "https://quote.trade/mcp"
}
}
} {
"servers": {
"trade-quote-mcp": {
"type": "http",
"url": "https://quote.trade/mcp"
}
}
} [mcp_servers.trade-quote-mcp] url = "https://quote.trade/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"trade-quote-mcp": {
"type": "remote",
"url": "https://quote.trade/mcp",
"enabled": true
}
}
} openclaw mcp add trade-quote-mcp --url 'https://quote.trade/mcp' --transport streamable-http
mcp_servers:
trade-quote-mcp:
url: "https://quote.trade/mcp" {
"McpServers": {
"trade-quote-mcp": {
"Transport": "http",
"Url": "https://quote.trade/mcp"
}
}
} assistant mcp add trade-quote-mcp -t streamable-http -u 'https://quote.trade/mcp'
{
"mcpServers": {
"trade-quote-mcp": {
"type": "http",
"url": "https://quote.trade/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “quote_trade_place_order” rewrote its description, which is the text the model reads security
- Tool “quote_trade_withdraw” rewrote its description, which is the text the model reads security
- Server version: 1.5.13 → 1.5.14 functional
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 17 Sept 26 −2
- Stability: pass → fail ▼ security
- Tool “quote_trade_liquidity_sample” was removed ▼ security
- Tool “quote_trade_private_events_sample” was removed ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- New tool “quote_trade_cancel_order”, which the server declares destructive security
- Tool “quote_trade_withdraw” rewrote its description, which is the text the model reads security
- Destructive annotations: 33% → 25% ▼ functional
- Schema quality: 150 → 130 ▲ functional
- Server version: 1.5.8 → 1.5.13 functional
- New tool “quote_trade_api_discovery” functional
- New tool “quote_trade_get_deposit_history” functional
- New tool “quote_trade_get_index_positions” functional
- New tool “quote_trade_get_order_history” functional
- New tool “quote_trade_get_order_status” functional
- New tool “quote_trade_get_orders” functional
- New tool “quote_trade_get_positions” functional
- New tool “quote_trade_get_risk” functional
- New tool “quote_trade_get_user_wallets” functional
- New tool “quote_trade_get_withdraw_requests” functional
- “quote_trade_depth” reworded the description of “limit” cosmetic
- 4 Sept 26 0
- Stability: 0.97 → pass security
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 14 Aug 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “quote_trade_exchange_info” rewrote its description, which is the text the model reads security
- Tool “quote_trade_get_challenge” rewrote its description, which is the text the model reads security
- Tool “quote_trade_instruments” rewrote its description, which is the text the model reads security
- Tool “quote_trade_logon” rewrote its description, which is the text the model reads security
- Tool “quote_trade_place_order” rewrote its description, which is the text the model reads security
- Tool “quote_trade_withdraw” rewrote its description, which is the text the model reads security
- Tool “quote_trade_withdraw_preview” rewrote its description, which is the text the model reads security
- Schema quality: 134 → 150 ▼ functional
- Server version: 1.5.6 → 1.5.8 functional
- “quote_trade_exchange_info” added an optional parameter “limit” cosmetic
- “quote_trade_exchange_info” added an optional parameter “skip” cosmetic
- “quote_trade_exchange_info” added an optional parameter “symbols” cosmetic
- “quote_trade_instruments” added an optional parameter “skip” cosmetic
- “quote_trade_instruments” reworded the description of “limit” cosmetic
- “quote_trade_withdraw” reworded the description of “symbol” cosmetic
- “quote_trade_withdraw_preview” reworded the description of “symbol” cosmetic
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 8 Oct 2026 · Probed https://quote.trade/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=quote.trade | CN=WE1,O=Google Trust Services,C=US | 12 Sept 2026 | 11 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 2f82d11b8e35731d13f9bc33e3b09afd |
| SANs: quote.trade, *.quote.trade | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of quote.trade. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| trade. | present | 64969 | 8 | Verified |
| quote.trade. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://quote.trade/mcp | Verified | 400 | |
| http (plaintext) | http://quote.trade/mcp | HTTPS enforced | 301 | https://quote.trade/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
quote_trade_account Quote.Trade account summary ~43
Withdraw step 1 / anytime account check. GET /api/account with per-request X-MBX-APIKEY. Inspect available balances before withdraw. No live trading action.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_api_discovery Quote.Trade direct API discovery ~44
Read once to learn efficient direct REST/WebSocket use: routes, signing, streaming, cumulative depth, and client execution controls. Public guidance only; no upstream calls.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| bases | object | yes | Configured REST, WebSocket, and MCP URLs. |
| depthSemantics | object | yes | Cumulative quantity and quote freshness. |
| discoveryUrl | string | yes | Public HTTP discovery URL. |
| documentation | object | yes | Canonical documentation links. |
| executionControls | array | yes | Controls required in direct API clients. |
| purpose | string | yes | How to use the guide. |
| releaseDate | string | yes | MCP implementation release date (YYYY-MM-DD). |
| rest | object | yes | Routes and route-specific signing guidance. |
| schemaVersion | string | yes | Discovery document schema version. |
| serverVersion | string | yes | MCP implementation version. |
| webSocket | object | yes | Subscriptions and reconnection guidance. |
| workflow | array | yes | Efficient agent integration workflow. |
No examples provided.
quote_trade_api_manifest Quote.Trade API/MCP manifest ~36
Explains that MCP is only a tool/schema adapter around the existing Quote.Trade APIs, and returns local servlet guardrail configuration.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| adapter | string | yes | MCP adapter name. |
| allowLeverage | boolean | – | Server-side leverage allowance. |
| allowedSymbols | array | yes | Trading symbol allowlist. Empty=deny-all; *=all instruments; else explicit symbols. |
| allowedSymbolsMode | string | yes | deny-all | all-quote-trade-instruments (*) | allowlist. |
| allowedWithdrawAssets | array | – | Withdraw asset allowlist, independent of allowedSymbols. Empty=deny-all withdrawals; *=all stablecoins; else explicit assets (USDC, USDT, XUSDC). |
| apiBase | string | – | Quote.Trade REST API base. |
| approvalFrictionOnly | boolean | yes | True when humanApproved/approvalText are friction only. |
| approvalTextRequired | string | – | Exact approval friction text for live orders. |
| canonicalBehavior | string | – | Adapter behavior summary. |
| credentialMapping | string | – | How to map a logon/register response, or a web-app API key, onto MCP client headers. |
| credentialScoping | string | – | Wallet login optional. Trade-only key: no withdraw. Full-access key (trade+withdraw): withdraw allowed. |
| credentialStatus | object | yes | – |
| dailyNotionalUsed | number | – | Compatibility field, always zero: MCP does not track a daily USD budget. |
| depositAssets | array | – | Supported deposit asset symbols (USDC, USDT, XUSDC). |
| depositsExposedThroughMcp | boolean | yes | True when deposit-address tools are registered in tools/list. |
| directApiDiscoveryUrl | string | – | Public GET guide for efficient direct REST/WebSocket use. |
| liquidityApiBase | string | – | Configured and validated at startup, but no MCP tool currently routes a request through it - every tool (withdraw included) calls apiBase. Reported here for operator visibility only. |
| liveTradingExecutable | boolean | yes | Server configuration permits orders: trading enabled and a nonempty symbol allowlist. No MCP USD cap; caller credentials and backend account checks are still required. |
| liveWithdrawExecutable | boolean | yes | Server configuration permits a supported withdrawal asset: trading enabled and USDC/USDT/XUSDC allowed. No MCP USD cap; caller withdrawal entitlement and backend balance checks are still required. |
| maxCallsPerMinute | integer | – | Per-caller MCP call rate limit. |
| maxDailyNotionalUsd | null | – | Null: no MCP cumulative daily USD cap on orders or withdrawals. |
| maxNotionalMode | string | yes | Always unlimited for MCP orders and withdrawals. Backend account controls still apply. |
| maxNotionalUsd | null | yes | Null: no MCP per-order or per-withdrawal USD notional cap. |
| mcpEndpointPath | string | – | Local MCP path. |
| mcpHostSeesApiSecret | boolean | – | True when private tools accept X-MBX-APISECRET at this MCP host. |
| mcpProtocolVersion | string | – | MCP protocol version. |
| mcpPublicUrl | string | – | Public MCP URL. |
| ordersExposedThroughMcp | boolean | yes | True when order tools are registered in tools/list. |
| releaseDate | string | yes | Adapter release date (YYYY-MM-DD). |
| servletOnly | boolean | – | True when this adapter is servlet-hosted only. |
| tools | array | yes | Registered tool names. |
| tradingEnabled | boolean | yes | Server-side live trading/withdraw enablement. |
| version | string | yes | Adapter version. |
| walletLoginOptional | boolean | – | True: agents can trade with a web-app API key without wallet logon. |
| withdrawApprovalTextRequired | string | – | Exact approval friction text for live withdraws. |
| withdrawAssets | array | – | Supported withdraw asset symbols (stablecoins only: USDC, USDT, XUSDC). |
| withdrawAssetsOnly | string | – | stablecoins-only |
| withdrawDestination | string | – | Always own-wallet-login-only; no toAddress is ever accepted. |
| withdrawalsExposedThroughMcp | boolean | yes | True when withdraw tools are registered in tools/list. |
| wsBase | string | – | Quote.Trade WebSocket base. |
No examples provided.
quote_trade_cancel_order Quote.Trade cancel a single live order ~274
Cancel one order by orderId. POST /api/cancelOrder. Identifies exactly one order via the matching engine's single-order cancel path - NOT a mass-cancel. There is no quote_trade_cancel_all: the upstream mass-cancel action's scope for edge-case parameters could not be verified from this codebase alone and is intentionally not exposed through MCP. Requires tradingEnabled, allowedSymbols (same allowlist as quote_trade_place_order), and a trade-scoped API key. No notional check applies: a cancellation has none. humanApproved/approvalText are agent friction only.
| Name | Type | Req | Description |
|---|---|---|---|
| account | integer | – | Quote.Trade account/user id. Optional (defaults to account init-param, QUOTE_TRADE_ACCOUNT, or 0). |
| approvalText | string | yes | Agent-supplied confirmation friction (not a security control). Must exactly equal: APPROVE QUOTE.TRADE CANCEL ORDER |
| humanApproved | boolean | yes | Agent-supplied confirmation friction (not a security control). Must be true; enableTrading remains authoritative. |
| orderId | integer | yes | The order id returned by quote_trade_place_order. |
| side | string | – | Optional BUY or SELL, matching the original order. Passed through if given. |
| symbol | string | yes | Instrument symbol the order was placed on, such as BTC. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_depth Quote.Trade order depth ~88
Trade step 3. GET /api/depth?symbol=SYMBOL&limit=N. Use depth quantity to choose a suitable limit price before placing an order.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Optional maximum levels per side. Positive values are enforced by MCP; omitted/nonpositive uses upstream depth. |
| symbol | string | yes | Instrument symbol from quote_trade_instruments, such as BTC or ETH. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_exchange_info Quote.Trade exchange info ~137
Call GET /api/exchangeInfo and return a paginated slice of trading symbols plus rate limits/server time. Upstream has no pagination, so this adapter filters/slices locally. Default limit=50, max=200. Prefer quote_trade_instruments for compact tradable-pair discovery.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max symbols to return. Default 50, max 200. |
| skip | integer | – | Number of matching symbols to skip before returning. Default 0. |
| symbols | string | – | Optional comma-separated symbol filter, e.g. BTC,ETH,SOL. When set, pagination applies to the filtered list. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_challenge Quote.Trade get wallet auth challenge ~119
Optional wallet login/register step 1 (not required for trading with an existing API key). POST /api/getChallenge with a wallet address (login). Returns challenge text and isNewUser. Step 2: sign the challenge with the wallet outside MCP. Step 3: quote_trade_logon. No API key required.
| Name | Type | Req | Description |
|---|---|---|---|
| login | string | yes | Wallet address used as login, e.g. 0x15b65a49faf9a4047e912d7de4a77fe24c7cf483. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_deposit_address Quote.Trade get deposit address ~104
Deposit step 1. GET /api/getDepositAddress?symbol=ASSET and return chain + contract/address. Supported assets: USDC and USDT (mainnet), XUSDC (USDC on XDC). Step 2 is transferring funds to that address outside MCP (no backend call).
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Deposit asset symbol: USDC or USDT (mainnet), or XUSDC (USDC on XDC network). |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_deposit_history Quote.Trade deposit history ~56
Anytime deposit check. POST /api/getDepositHistory with per-request X-MBX-APIKEY. Requires a trade-scoped API key (same scope as quote_trade_place_order). Read-only: no live trading action.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_index_positions Quote.Trade index/basket positions ~83
Anytime position check. POST /api/getIndexPositions with per-request X-MBX-APIKEY. Distinct from quote_trade_get_positions: index/basket instrument positions rather than regular instrument positions. Optional assetType filter. Read-only: no live trading action.
| Name | Type | Req | Description |
|---|---|---|---|
| assetType | string | – | Optional index/basket asset type filter. Omit for all. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_order_history Quote.Trade order history ~95
Anytime order check. POST /api/getOrderHistory with per-request X-MBX-APIKEY. Full order history, or one order's history with optional orderId. Requires a trade-scoped API key (same scope as quote_trade_place_order). Read-only: no live trading action.
| Name | Type | Req | Description |
|---|---|---|---|
| orderId | integer | – | Optional order id to narrow to one order's history. Omit for the full order history. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_order_status Quote.Trade single order status ~69
Anytime order check. POST /api/orderStatus with per-request X-MBX-APIKEY. Query the status of an order previously placed with quote_trade_place_order. Read-only: no live trading action.
| Name | Type | Req | Description |
|---|---|---|---|
| orderId | integer | yes | The order id returned by quote_trade_place_order. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_orders Quote.Trade current/open orders ~118
Anytime order check. POST /api/getOrders with per-request X-MBX-APIKEY. Read-only: no live trading action. Requires read entitlement on API keys that carry one.
| Name | Type | Req | Description |
|---|---|---|---|
| endTime | integer | – | Optional inclusive end of a time range, epoch milliseconds. |
| limit | integer | – | Optional maximum number of orders to return. |
| startTime | integer | – | Optional inclusive start of a time range, epoch milliseconds. |
| symbol | string | – | Optional instrument symbol filter, such as BTC. Omit for all symbols. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_positions Quote.Trade current positions ~61
Anytime position check. GET /api/positions with per-request X-MBX-APIKEY. Reconcile current positions when starting or reconnecting, per the direct-discovery guide (quote_trade_api_discovery / rest.privateReads). No live trading action.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_risk Quote.Trade account risk/margin summary ~54
Anytime risk check. POST /api/getRisk with per-request X-MBX-APIKEY. Margin/equity/unrealized-PnL summary for the authenticated account. Read-only: no live trading action.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_user_wallets Quote.Trade known deposit wallet addresses ~52
Anytime wallet check. POST /api/getUserWallets with per-request X-MBX-APIKEY. On-chain addresses previously seen depositing to the authenticated account. Read-only: no live trading action.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_get_withdraw_requests Quote.Trade withdraw request history ~71
Anytime withdrawal check. POST /api/getWithdrawRequests with per-request X-MBX-APIKEY. Inspect the status of withdrawals already submitted (including via quote_trade_withdraw). Requires a trade-scoped API key. Read-only: no live trading action, and this tool cannot cancel a withdrawal.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_instruments Quote.Trade instruments ~94
Trade step 1. GET /api/getInstrumentPairs — paginated tradable symbols/instruments. Default limit=50, max=200. Use skip to page. Pick a symbol from this response for ticker/depth/order calls.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max instruments to return. Default 50, max 200. |
| skip | integer | – | Number of instruments to skip before returning. Default 0. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_logon Quote.Trade wallet logon / register ~175
Optional wallet login/register step 3 (not required if the agent already has an API key). Pass challenge + wallet signature from steps 1–2. isNewUser=true -> POST /api/registerUser; else POST /api/logon. On success, map body.requestToken/requestSecret to X-MBX-APIKEY / X-MBX-APISECRET; use body.id as account. Wallet signing stays outside MCP.
| Name | Type | Req | Description |
|---|---|---|---|
| challenge | string | yes | Challenge text returned by quote_trade_get_challenge (Sign auth token: ...). |
| isNewUser | boolean | – | From quote_trade_get_challenge. true -> registerUser; false -> logon. If omitted, logon is tried first then registerUser on failure. |
| signature | string | yes | Wallet signature of the challenge text (0x-prefixed hex). |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| credentialMapping | object | – | Present on success only. Maps this response's requestToken/requestSecret/id to the MCP client headers and account field to use next. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| nextStep | string | – | Present on success only. What to configure before calling private tools. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_order_preview Quote.Trade order preview ~185
Optional before live trade. Normalize/validate a BUY/SELL order locally without sending it.
| Name | Type | Req | Description |
|---|---|---|---|
| account | integer | – | Quote.Trade account/user id. Optional for preview (defaults to account init-param, QUOTE_TRADE_ACCOUNT, or 0). Required for live place_order. |
| disableLeverage | integer | – | 1 disables leverage; 0 enables leverage/shorting only if server allowLeverage is true. |
| paymentCurrency | string | – | Payment currency such as USDT. |
| price | number | yes | Limit price chosen after quote_trade_depth. |
| quantity | number | yes | Order quantity. |
| side | string | yes | BUY or SELL. |
| symbol | string | yes | Instrument symbol from quote_trade_instruments, such as BTC. |
| timestamp | integer | – | Optional client timestamp in milliseconds. |
| type | string | – | LIMIT only in this adapter. |
| Name | Type | Req | Description |
|---|---|---|---|
| approvalFrictionOnly | boolean | yes | True when approval fields are friction only. |
| approvalTextRequired | string | – | Exact approval friction text. |
| credentialsPresent | boolean | yes | Whether per-request trading credentials are present. |
| destination | string | – | Withdraw previews only: always own-wallet-login-only (no toAddress accepted). |
| endpoint | string | yes | Target Quote.Trade order endpoint. |
| estimatedNotional | number | yes | Estimated notional in USD (orders: price×qty; withdraws: USD price×human quantity). |
| estimatedNotionalUsd | number | – | Withdraw USD notional. Present on withdraw previews when priced. |
| estimatedQuantity | number | – | Withdraw human quantity only (quantity / 10^quantity_scale). Present on withdraw previews. |
| notionalWarning | string | – | Withdraw previews only: present when a USD price could not be resolved. |
| priceSource | string | – | How priceUsd was obtained (stablecoin-peg|ticker|ticker-unavailable). |
| priceUsd | number | – | USD unit price used for withdraw notional. |
| requestBody | object | yes | Normalized order request body that would be posted. |
| safety | string | yes | Preview safety notes. |
| symbolAllowed | boolean | yes | Whether the order symbol or withdrawal asset passes its own allowlist (empty=deny-all; *=all supported). |
| tradingEnabled | boolean | yes | Server-side trading enablement. |
| willSend | boolean | yes | Whether this preview would send a live order. |
| withdrawAssetAllowed | boolean | – | Withdraw previews only: whether the asset passes allowedWithdrawAssets. |
| withinMaxNotional | boolean | yes | Always true for a valid preview: MCP imposes no USD notional cap. This does not establish balance, margin or authorization. |
No examples provided.
quote_trade_place_order Quote.Trade place live order ~300
Trade step 4. POST /api/order with a suitable price after instruments/ticker/depth. Requires tradingEnabled, allowedSymbols (* or explicit list; empty denies), and API credentials. No MCP USD notional cap applies. Sending X-MBX-APISECRET to this MCP host grants it full signing authority. humanApproved/approvalText are agent friction only.
| Name | Type | Req | Description |
|---|---|---|---|
| account | integer | yes | Quote.Trade account/user id. Optional for preview (defaults to account init-param, QUOTE_TRADE_ACCOUNT, or 0). Required for live place_order. |
| approvalText | string | yes | Agent-supplied confirmation friction (not a security control). Must exactly equal: APPROVE QUOTE.TRADE LIVE ORDER |
| disableLeverage | integer | – | 1 disables leverage; 0 enables leverage/shorting only if server allowLeverage is true. |
| humanApproved | boolean | yes | Agent-supplied confirmation friction (not a security control). Must be true; enableTrading remains authoritative. |
| paymentCurrency | string | – | Payment currency such as USDT. |
| price | number | yes | Limit price chosen after quote_trade_depth. |
| quantity | number | yes | Order quantity. |
| side | string | yes | BUY or SELL. |
| symbol | string | yes | Instrument symbol from quote_trade_instruments, such as BTC. |
| timestamp | integer | – | Optional client timestamp in milliseconds. |
| type | string | – | LIMIT only in this adapter. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_status Quote.Trade status ~29
Call GET /api/status and return system status, server time, contracts URL, and feature flags.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_ticker Quote.Trade ticker ~66
Trade step 2. GET /api/ticker?symbol=SYMBOL for a symbol from quote_trade_instruments. Returns last price, bid, ask, lastUpdateId.
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Instrument symbol from quote_trade_instruments, such as BTC or ETH. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_withdraw Quote.Trade live withdraw ~299
Withdraw step 3. POST /api/sendWithdrawWithVTokenRequest for stablecoins only (USDC|USDT|XUSDC) to the user's own login wallet (no toAddress). Not available for BTC/ETH/other assets. Requires a full-access API key with withdraw entitlement (trade-only keys are rejected by Quote.Trade), tradingEnabled, and allowedWithdrawAssets (independent of the trading allowedSymbols allowlist). No MCP USD notional cap applies. humanApproved/approvalText are agent friction only.
| Name | Type | Req | Description |
|---|---|---|---|
| account | integer | yes | Quote.Trade account/user id. Optional for preview (defaults to account init-param, QUOTE_TRADE_ACCOUNT, or 0). Required for live withdraw. |
| approvalText | string | yes | Agent-supplied confirmation friction (not a security control). Must exactly equal: APPROVE QUOTE.TRADE LIVE WITHDRAW |
| humanApproved | boolean | yes | Agent-supplied confirmation friction (not a security control). Must be true; enableTrading remains authoritative. |
| quantity | string | yes | Scaled integer quantity as string (API format). Example: "20000000" with quantity_scale=6 means 20 USDC. |
| quantity_scale | integer | yes | Decimal scale for quantity. Example: 6 for USDC. |
| symbol | string | yes | Stablecoin to withdraw: USDC, USDT, or XUSDC only (not BTC/ETH/other). |
| Name | Type | Req | Description |
|---|---|---|---|
| body | – | yes | Parsed JSON response body when valid JSON; otherwise the raw text. |
| endpoint | string | yes | Quote.Trade API endpoint path. |
| method | string | yes | HTTP method used against Quote.Trade. |
| raw | string | yes | Raw JSON response body. |
| status | integer | yes | HTTP status code. |
No examples provided.
quote_trade_withdraw_preview Quote.Trade withdraw preview ~195
Optional before live withdraw. Stablecoins only: USDC, USDT, or XUSDC (not BTC/ETH/other). Own login wallet only (no toAddress). estimatedNotional is USD at $1 peg. Trade-only API keys cannot withdraw — use a full-access key with withdraw entitlement.
| Name | Type | Req | Description |
|---|---|---|---|
| account | integer | – | Quote.Trade account/user id. Optional for preview (defaults to account init-param, QUOTE_TRADE_ACCOUNT, or 0). Required for live withdraw. |
| quantity | string | yes | Scaled integer quantity as string (API format). Example: "20000000" with quantity_scale=6 means 20 USDC. |
| quantity_scale | integer | yes | Decimal scale for quantity. Example: 6 for USDC. |
| symbol | string | yes | Stablecoin to withdraw: USDC, USDT, or XUSDC only (not BTC/ETH/other). |
| Name | Type | Req | Description |
|---|---|---|---|
| approvalFrictionOnly | boolean | yes | True when approval fields are friction only. |
| approvalTextRequired | string | – | Exact approval friction text. |
| credentialsPresent | boolean | yes | Whether per-request trading credentials are present. |
| destination | string | – | Withdraw previews only: always own-wallet-login-only (no toAddress accepted). |
| endpoint | string | yes | Target Quote.Trade order endpoint. |
| estimatedNotional | number | yes | Estimated notional in USD (orders: price×qty; withdraws: USD price×human quantity). |
| estimatedNotionalUsd | number | – | Withdraw USD notional. Present on withdraw previews when priced. |
| estimatedQuantity | number | – | Withdraw human quantity only (quantity / 10^quantity_scale). Present on withdraw previews. |
| notionalWarning | string | – | Withdraw previews only: present when a USD price could not be resolved. |
| priceSource | string | – | How priceUsd was obtained (stablecoin-peg|ticker|ticker-unavailable). |
| priceUsd | number | – | USD unit price used for withdraw notional. |
| requestBody | object | yes | Normalized order request body that would be posted. |
| safety | string | yes | Preview safety notes. |
| symbolAllowed | boolean | yes | Whether the order symbol or withdrawal asset passes its own allowlist (empty=deny-all; *=all supported). |
| tradingEnabled | boolean | yes | Server-side trading enablement. |
| willSend | boolean | yes | Whether this preview would send a live order. |
| withdrawAssetAllowed | boolean | – | Withdraw previews only: whether the asset passes allowedWithdrawAssets. |
| withinMaxNotional | boolean | yes | Always true for a valid preview: MCP imposes no USD notional cap. This does not establish balance, margin or authorization. |
No examples provided.
What is the Quote.Trade MCP Adapter server?
Quote.Trade MCP Adapter is listed in the public MCP registry as trade.quote/mcp. Quote.Trade MCP: login, deposit address, market data, orders, and withdraws. This page covers its hosted endpoint (https://quote.trade/mcp).
Is the Quote.Trade MCP Adapter server safe to use?
Quote.Trade MCP Adapter scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Quote.Trade MCP Adapter server expose?
Quote.Trade MCP Adapter exposes 25 tools: quote_trade_api_discovery, quote_trade_api_manifest, quote_trade_get_challenge, quote_trade_logon, quote_trade_get_deposit_address, and 20 more. Their descriptions and schemas cost roughly 2,847 tokens of context every time the server is loaded.
Does the Quote.Trade MCP Adapter server require authentication?
No. We connected to Quote.Trade MCP Adapter without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Quote.Trade MCP Adapter server still maintained?
Quote.Trade MCP Adapter is still listed as active in the MCP registry. We last reached this channel on 7 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.