uk.quantdata/quantdata
REMOTE · API.QUANTDATA.UK · SCANNED SEP 26
Four market-statistics tools + a free qd_ key by email: 1 anonymous look, then 10 calls/UTC day.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 4 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability62
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2466 tokens (~493/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 5 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the uk.quantdata/quantdata MCP server?
uk.quantdata/quantdata is a hosted endpoint at https://api.quantdata.uk/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.quantdata.uk
claude mcp add --transport http uk-quantdata-quantdata 'https://api.quantdata.uk/mcp'
{
"mcpServers": {
"uk-quantdata-quantdata": {
"url": "https://api.quantdata.uk/mcp"
}
}
} {
"servers": {
"uk-quantdata-quantdata": {
"type": "http",
"url": "https://api.quantdata.uk/mcp"
}
}
} [mcp_servers.uk-quantdata-quantdata] url = "https://api.quantdata.uk/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"uk-quantdata-quantdata": {
"type": "remote",
"url": "https://api.quantdata.uk/mcp",
"enabled": true
}
}
} openclaw mcp add uk-quantdata-quantdata --url 'https://api.quantdata.uk/mcp' --transport streamable-http
mcp_servers:
uk-quantdata-quantdata:
url: "https://api.quantdata.uk/mcp" {
"McpServers": {
"uk-quantdata-quantdata": {
"Transport": "http",
"Url": "https://api.quantdata.uk/mcp"
}
}
} assistant mcp add uk-quantdata-quantdata -t streamable-http -u 'https://api.quantdata.uk/mcp'
{
"mcpServers": {
"uk-quantdata-quantdata": {
"type": "http",
"url": "https://api.quantdata.uk/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 8 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “quantdata_request_free_api_key” rewrote its description, which is the text the model reads security
- Destructive annotations: 100 → pass functional
- “quantdata_request_free_api_key” reworded the description of “email” cosmetic
- “quantdata_request_free_api_key” dropped the optional parameter “marketing_opt_in” cosmetic
- 6 Sept 26 +2
- Stability: fail → pass ▲ security
- 30 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 75 to 80.
- 29 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 72 to 75.
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 18 Aug 26 0
- Tool “quantdata_weis_wave” rewrote its description, which is the text the model reads security
- Server version: 3.2.0 → 3.4.0 functional
- “quantdata_brooks_events” reworded the description of “symbol” cosmetic
- “quantdata_weis_wave” reworded the description of “symbol” cosmetic
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 26 Sept 2026 · Probed https://api.quantdata.uk/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=quantdata.uk | CN=WE1,O=Google Trust Services,C=US | 22 Sept 2026 | 21 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | d65934c3032393e513b7de5da620d417 |
| SANs: quantdata.uk, *.quantdata.uk | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.quantdata.uk. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| uk. | present | 43876 | 8 | Verified |
| quantdata.uk. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.quantdata.uk/mcp | Verified | 200 | |
| http (plaintext) | http://api.quantdata.uk/mcp | HTTPS enforced | 301 | https://api.quantdata.uk/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
quantdata_brooks_events Rolling price-action events ~982
Classical Brooks price-action events detected in the current trading window — the day's first range breakout, breakout follow-through, closes in the top or bottom third of an established range, long-lived-range breakouts, climactic spikes — each paired with the outcome rate measured for that exact definition in that exact window (pre-registered, ES 5-minute bars 2010-2026). Range breakouts also carry a calibrated per-event estimate of the probability the breakout closes back through its level within 10 bars (validated zero-shot on NQ 2023+: AUC 0.646, calibration error 5.1%, n=2,637). Answers 'what just happened structurally, and how did events like it resolve historically'. Works around the clock on 24-hour instruments, including the Asia-close-to-US-open gap window. Some measured rates contradict the classical claims; quote the measured numbers, not the folklore. Every read also carries two blocks that answer different questions and must not be mixed: `day_type` is the five-class day-type distribution, from the model trained for the current window. In the regular day session it is mode=day_session, with published accuracy: 66% top-1 over a complete session and 53.5% at the 90-minute mark, against a 37% majority-class baseline. In the Asian window it is mode=asia_session — trained natively on Asian windows, pre-registered, confirmed zero-shot on NQ — whose accuracy figures live in the response's own `accuracy` field and use their own label taxonomy: never quote the day-session figures for an asia read or vice versa. The gap window has no validated model and returns available=false there. `shape` is plain arithmetic over the bars already printed (where price closed inside its own range, how much of the travel was one-way, deepest pullback) — no model, no accuracy claim, available in every window including the gap. Report day_type as a distribution with its baseline; report shape as measurement, never as a forecast. **`day_type.analysis` is the block to lead with (d…
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Ticker. US stocks and ETFs as-is (NVDA, SPY). US futures with =F (ES=F, GC=F). Hong Kong as digits.HK (3690.HK). China A-shares as 6 digits (600519). Crypto as PAIR-USD (BTC-USD). Spot FX with no sla… |
| window | string | – | Omit to follow whichever window has the freshest bars — usually what the user means by 'now'. 'rth' is the US day session; 'gap' is 16:00-21:30 Beijing, the stretch between the Asian close and the US… |
No output schema declared.
No examples provided.
quantdata_gamma Estimated dealer gamma exposure ~257
Estimated dealer gamma exposure (GEX) for a US listed stock or ETF: net and gross GEX, the zero gamma (flip) level and the heaviest strikes. Unlike max pain this is a Black-Scholes ESTIMATE — zero rate, zero dividend, implied volatility solved from end-of-day quotes, and the convention that dealers are long every call and short every put. Keep that framing when reporting it. A null flip is not an error: check flip_status — 'no_sign_change_within_10pct' means net gamma keeps one sign across the whole traded range, which is a state worth reporting. US listed stocks and ETFs only, with a liquid chain: cash-settled index options (SPX, NDX, RUT, VIX) return an error — use SPY, QQQ, IWM instead. Reads the prior session's settled open interest and cannot update intraday whatever the clock says, so report as_of and spot_date with the number.
| Name | Type | Req | Description |
|---|---|---|---|
| by_strike | boolean | – | Include the strike-level gamma profile. Large; only request it when the user wants strike detail. |
| symbol | string | yes | US listed stock or ETF ticker, e.g. NVDA or SPY. |
No output schema declared.
No examples provided.
quantdata_max_pain Options max pain by expiration ~223
Options max pain per expiration, computed from open interest alone: the strike at which option buyers lose the most in aggregate if the underlying settled there. Pure arithmetic — no pricing model, no volatility assumption, so anyone with the same chain gets the same number. Also returns put/call ratio and the heaviest call and put open-interest strikes. Returns every expiration inside 45 days rather than picking one, because the figure is per-expiration and the near- and far-dated values routinely disagree. US listed stocks and ETFs only: cash-settled index options (SPX, NDX, RUT, VIX) return an error — use SPY, QQQ, IWM. Open interest settles overnight, so this describes the prior session's positioning; report as_of and spot_date alongside the number.
| Name | Type | Req | Description |
|---|---|---|---|
| distribution | boolean | – | Include the full open-interest distribution by strike. Large; only request it when the user wants strike detail. |
| symbol | string | yes | US listed stock or ETF ticker, e.g. NVDA or SPY. |
No output schema declared.
No examples provided.
quantdata_request_free_api_key Request a free Quant Data API key ~165
Get a free qd_ API key for an email address. No account, card, payment or GUI is required. The key covers all four market-data tools, sharing 10 successful calls per UTC day, and expires after 30 days. Ask the user for their email address first, then call this tool: the key is returned here so you can use it immediately in the X-API-Key header, and a copy is emailed to that address. Do not invent an address — the owner is told an assistant requested it and can have it disabled. This tool never returns a key that already belonged to that address; it issues one for this purpose only.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | The user's own email address. Ask them for it; do not guess. |
No output schema declared.
No examples provided.
quantdata_weis_wave Volume-price wave structure ~461
Weis Wave volume-price structure: price grouped into waves with volume summed per wave, plus which of five classical volume-price events have fired. Each event carries the win rate measured for it on sixteen years of S&P 500 futures data, including the two that came out REVERSED against the tradition. Answers 'is there volume behind this move'. Quote the measured reference numbers rather than the folklore. Spot FX has no volume at all — use CME currency futures (6E=F) instead. GC=F carries exchange volume and is the gold instrument here. A spot-gold request (XAUUSD) answers with the XAUT-USD token reading plus a note — that is the Tether Gold token's order book, a different instrument. Use session='full' to match the published reference-rate window, or the default 'rth' for a regular-session-only read.
| Name | Type | Req | Description |
|---|---|---|---|
| session | string | – | Omit for the US regular session. Use 'full' when comparing returned Weis events with the published reference win rates: those rates were measured on the whole bar stream, including pre/post-market. '… |
| symbol | string | yes | Ticker. US stocks and ETFs as-is (NVDA, SPY). US futures with =F (ES=F, GC=F). Hong Kong as digits.HK (3690.HK). China A-shares as 6 digits (600519). Crypto as PAIR-USD (BTC-USD). Spot FX with no sla… |
No output schema declared.
No examples provided.
What is the uk.quantdata/quantdata MCP server?
uk.quantdata/quantdata is an MCP server listed in the public MCP registry as uk.quantdata/quantdata. Four market-statistics tools + a free qd_ key by email: 1 anonymous look, then 10 calls/UTC day. This page covers its hosted endpoint (https://api.quantdata.uk/mcp).
Is the uk.quantdata/quantdata MCP server safe to use?
uk.quantdata/quantdata scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the uk.quantdata/quantdata MCP server expose?
uk.quantdata/quantdata exposes 5 tools: quantdata_request_free_api_key, quantdata_brooks_events, quantdata_weis_wave, quantdata_max_pain, quantdata_gamma. Their descriptions and schemas cost roughly 2,088 tokens of context every time the server is loaded.
Does the uk.quantdata/quantdata MCP server require authentication?
No. We connected to uk.quantdata/quantdata without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the uk.quantdata/quantdata MCP server still maintained?
uk.quantdata/quantdata is still listed as active in the MCP registry. We last reached this channel on 26 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.