xRocket Exchange MCP

xRocket Exchange MCP

Unofficial, safety-first MCP server for convenient xRocket market snapshots, with opt-in local account reads and guarded financial workflows.

Category
访问服务器

README

xRocket Exchange MCP

Set one daily value limit, connect an xRocket API token locally, and let an MCP-capable AI agent place and cancel spot orders autonomously inside that limit. Internal transfers and external withdrawals remain separate prepare/approve/execute operations.

The hosted endpoint is a zero-account market-data demo and onboarding path. Actual account reads and trading run locally with the user's xRocket token. This project is not affiliated with, endorsed by, or operated by xRocket.

Set up trading · Open xRocket · Try the market demo · Official API overview · Safety model · Coverage · Distribution

What is included

Layer Purpose Default
MCP server Semantic tools over the official REST API public, mainnet, read-only
Agent skill Teaches agents market analysis, bounded autonomous trading, explicit transfer/withdrawal approval, and reconciliation Read first; stay inside the configured policy
Codex plugin Installs the server and skill together from a repo-local marketplace Public tools only
Registry metadata server.json for io.github.nakazanie-ton/xrocket Published in the Official MCP Registry
Hosted endpoint Public mainnet tools over Streamable HTTP No install, token, or account access

The API surface was re-audited on 2026-08-24 and still covers all 50 Exchange documentation pages, all 26 OpenAPI operations, and all 7 WebSocket channels. The four linked legal PDFs were reviewed separately on 2026-08-07. The current OpenAPI document has canonical SHA-256 5de074def6ee9f59c7c1d1a2f8a06e1f5e2fafb446ebef58af7168e32813e2a3. See the source inventory.

Tool profiles

Profile Tools Token Financial writes
public 10 public market-data and onboarding tools Not used Impossible
private-read Public tools plus 6 account/history tools Required Impossible
full Public and private reads, 3 autonomous trading tools, and 4 transfer/withdrawal approval tools Required Still disabled until each feature gate is enabled

For normal questions, xrocket_market_snapshot resolves a symbol or base asset and returns rules, ticker, best bid/ask, recent trades, fees, and an Open xRocket next action in one call. Private mode adds xrocket_account_overview for funding balances, trading balances, and active orders without inventing portfolio valuation. Full mode adds autonomous market/limit orders and cancellation inside the local policy; transfers and withdrawals keep their approval receipts.

Quick start — trade through MCP

  1. Sign in to xRocket. In the bot, open Menu → Settings → Exchange settings → API token.

  2. Generate a testnet configuration with one daily value limit:

    npx -y xrocket-mcp@0.6.0 trading-config --limit 100 --asset USD
    
  3. Paste the printed JSON into your local MCP client and replace SET_YOUR_XROCKET_API_TOKEN_LOCALLY in that client's local secret or environment settings. Do not paste the token into chat, this website, an issue, or a committed file.

  4. Give the agent a strategy:

    Use xRocket on testnet. Trade GRAM-USDT with this strategy: [describe strategy]. Stay inside the configured daily trading limit. Do not transfer or withdraw funds.

  5. The agent can now place and cancel market or limit orders on any available spot pair until the daily limit or the built-in order-count limits are reached.

After testing, generate a live configuration with npx -y xrocket-mcp@0.6.0 trading-config --limit 100 --asset USD --mainnet. Transfers and withdrawals remain disabled.

The xRocket API token is a broad bearer credential without documented granular scopes. Local MCP feature gates reduce what this server exposes, but they do not narrow the upstream token itself. Use a trusted local client and protect its configuration like a password.

Market-data demo — no installation

Open the zero-install connection page or add this URL to any MCP client that supports Streamable HTTP:

https://xrocket-mcp-production.up.railway.app/mcp

Generic client configuration:

{
  "mcpServers": {
    "xrocket": {
      "url": "https://xrocket-mcp-production.up.railway.app/mcp"
    }
  }
}

The hosted service is structurally limited to the 10 public mainnet tools. It never reads tokens, account data, or financial-write settings. Its health endpoint is /health.

For balances, order history, or autonomous execution, use the local package above. The remote demo cannot be upgraded with a token.

Local package

Requirements: Node.js 20 or newer. No clone or configuration is needed for public market data:

npx -y xrocket-mcp@0.6.0 doctor
npx -y xrocket-mcp@0.6.0 config

The second command prints this copy-paste MCP client configuration:

{
  "mcpServers": {
    "xrocket": {
      "command": "npx",
      "args": ["-y", "xrocket-mcp@0.6.0"],
      "env": {
        "XROCKET_ENVIRONMENT": "mainnet",
        "XROCKET_ENABLE_TRADING": "false",
        "XROCKET_ENABLE_TRANSFERS": "false",
        "XROCKET_ENABLE_WITHDRAWALS": "false",
        "XROCKET_ALLOW_MAINNET_WRITES": "false"
      }
    }
  }
}

The Codex bundle is described by plugins/xrocket-exchange/.codex-plugin/plugin.json, and its safe defaults are already set in plugins/xrocket-exchange/.mcp.json. Register this repository's marketplace, then install the all-in-one plugin:

codex plugin marketplace add nakazanie-ton/myrocket --ref main
codex plugin add xrocket-exchange@xrocket-agents

For a local clone, replace the first command with codex plugin marketplace add /absolute/path/to/myrocket.

For source development:

git clone https://github.com/nakazanie-ton/myrocket.git
cd myrocket/plugins/xrocket-exchange
npm ci
npm test
npm run build

The current package is xrocket-mcp@0.6.0.

Enabling private reads

Create an xRocket API token in the signed-in bot and pass it only through the local process environment. With a token present, the profile defaults to private-read; an explicit profile is still respected:

export XROCKET_ENVIRONMENT=testnet
export XROCKET_API_TOKEN='replace-with-your-token'
node dist/cli.js

Never put the bearer token in a prompt, tool argument, committed MCP file, issue, or log. xRocket describes one broad bearer credential rather than fine-grained scopes, so treat it as full account access.

Enabling a write capability

full does not enable writes by itself. Enable only the capability you need:

export XROCKET_PROFILE=full
export XROCKET_ENVIRONMENT=testnet
export XROCKET_API_TOKEN='replace-with-your-token'
export XROCKET_ENABLE_TRADING=true
export XROCKET_TRADING_LIMIT='100 USD'
# XROCKET_ENABLE_TRANSFERS and XROCKET_ENABLE_WITHDRAWALS remain false
node dist/cli.js

Trading orders are autonomous:

  1. xrocket_agent_trade estimates the order, converts its quote value to the configured limit asset, checks the daily value, daily order-count, and active-order limits, reserves the amount durably, and submits once.
  2. xrocket_agent_cancel cancels an existing order directly. Cancellation does not need per-order approval.
  3. Unknown placement outcomes remain charged against the limit and are never retried automatically.
  4. All spot symbols are allowed by default. XROCKET_TRADING_SYMBOLS is an optional advanced allowlist, not an onboarding requirement.

Internal transfers and external withdrawals still use the exact prepare/approve/execute receipt flow. Their feature gates are off in the generated trading configuration.

Mainnet writes additionally require XROCKET_ENVIRONMENT=mainnet and XROCKET_ALLOW_MAINNET_WRITES=true. See configuration and safety details.

Important API boundaries

  • The Exchange API has no deposit-address or create-deposit endpoint. xrocket_onboarding_links provides the configured UI path; balances can be refreshed afterward.
  • Exchange POST /api/v1/accounts/transfers moves funds only between the same user's funding and trading accounts. It is not a user-to-user payment tool.
  • xRocket Pay is a different product, uses different authentication, and is outside this server.
  • The official API currently uses asset identifier TONCOIN in places where the UI may say TON.
  • The 0.6.0 server uses REST snapshots. WebSocket channels are audited but not exposed until the upstream documentation defines reliable replay, gap recovery, and orderbook delta deletion semantics.
  • Decimal financial values remain strings. Do not coerce them through binary floating point.

Development

cd plugins/xrocket-exchange
npm ci
npm test
npm run typecheck
npm run build
npm pack --dry-run

CI also checks the recorded documentation inventory and OpenAPI digest for drift. No live private credentials are used in tests.

Policy and support

This software can submit trades, transfers, and blockchain withdrawals when a local operator explicitly enables those capabilities. Review SECURITY.md, PRIVACY.md, TERMS.md, the project's legal and policy review, and xRocket's canonical terms and policies guide before use.

OpenAI's public plugin directory rules currently prohibit tools that execute investment trades, money transfers, or cryptocurrency transfers. The full profile is therefore not eligible for that public directory. Only the separately built hosted endpoint is a public-directory candidate; it contains no private or financial-write tool registrations.

Report defects through GitHub Issues. Report vulnerabilities privately as described in SECURITY.md.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选