com.longbridge/mcp — Model Context Protocol (MCP) Server
The com.longbridge/mcp server targets US/HK markets and exposes 163 tools for financial workflows, including quotes and options, order-related actions, and access to fundamentals, a screener, and IPO data. It also provides alerts plus DCA & grid functionality, enabling market monitoring and portfolio automation use cases.
🛠️ Key Features
US/HK markets scope
163 tools: quotes, options, orders
Fundamentals, screener, and IPO support
Alerts and DCA & grid capabilities
🚀 Use Cases
Retrieve US/HK market quotes and options data
Place or manage orders for trading workflows
Screen instruments and use fundamentals for analysis
Track IPO information and set alerts
Automate DCA and grid strategies
⚡ Developer Benefits
MCP alignment via a Model Context Protocol server
Structured tool coverage across trading and market data categories
Reusable topics for discovery: finance, longbridge, mcp, mcp-server, model-context-protocol, trading
⚠️ Limitations
Server details provided here only describe tool categories and market scope; specific tool names, interfaces, and authentication behavior are not included.
Official MCP server for the Longbridge brokerage. 164 tools across real-time quotes, options, order routing, fundamentals, analyst ratings, calendars, IPO, price alerts, DCA plans, grid trading, portfolio analytics and community sharelists — covering US and HK markets. Built with Rust using rmcp and axum.
Now live in ChatGPT and Claude
Longbridge is officially listed in the ChatGPT Apps directory and the Claude Connectors directory.
Talk to the markets in plain language — quotes, options, fundamentals, and your own portfolio —
with no config files to edit and no tokens to paste.
Add it in one place
Then just ask
ChatGPT
Settings → Apps & Connectors → add Longbridge
"How's NVDA trading today?" · "Show my HK positions"
"Compare AAPL and MSFT valuations" · "Any IPOs this week?"
Sign in once with your Longbridge account. Every request runs over the same hosted, OAuth 2.1–secured endpoint documented below — read-only market data plus full account, portfolio, and trading tools, all gated by your own credentials.
Highlights
164 tools, one endpoint — quotes, options, order routing, fundamentals, analyst research, screeners, IPO, alerts, DCA, grid trading and portfolio analytics across US and HK markets.
Stateless by design — every request forwards its Bearer token straight to the Longbridge SDK. No sessions, no database, nothing stored server-side.
OAuth 2.1, auto-discovered — RFC 9728 protected-resource and RFC 8414 authorization-server metadata; clients complete the flow with no token to paste.
Clean, typed responses — snake_case fields, RFC 3339 timestamps, human-readable symbols, and typed response schemas available as MCP resources.
Every tool accepts an optional _jq string in its arguments. The expression runs
on the complete returned JSON, after the normal response serialization. The _jq
name is reserved for response filtering to avoid conflicts with business parameters.
Usage guidance is sent once in the MCP initialize response's instructions;
each tool schema declares only the optional parameter name and type.
For example:
Use .data[:5] to take the first five entries of a data array,
.data | map(select(.price > 10)) to select rows, or {total: .total} to
project fields. Expressions use the embedded jaq
engine's jq-compatible syntax; no separate jq executable is needed.
Omit _jq (or pass null) to preserve the original response.
One output value is returned directly, multiple values as an array, and no
values as []. Scalars and arrays are JSON text; objects also appear in
structuredContent, containing only the filtered fields.
Plain text responses are available as JSON strings. Multiple content blocks
without structured content are available as an array.
Tool errors and permission/no-data explanations remain unfiltered.
Empty, invalid, or non-string expressions are rejected before the tool runs.
If filtering fails at runtime, the response explicitly says the tool already
executed. Do not automatically retry writes such as placing an order.
Environment access, filesystem imports, and logging filters are unavailable.
Output is limited to 10,000 values and 8 MiB; exceeding a limit returns an
error rather than a partial result.
Because filters can change the response shape, tools do not advertise a fixed
outputSchema. Original typed schemas remain available through resources/list
and resources/read at lb://tools/{tool-name}/output-schema for schema-backed tools.
Connect your own client
Longbridge runs a hosted endpoint at https://mcp.longbridge.com — point any MCP client at it and complete OAuth when prompted. Authorization is auto-discovered via RFC 9728; there is no token to paste.
Claude Code
bash
claude mcp add --transport http longbridge https://mcp.longbridge.com
Claude Desktop — add to claude_desktop_config.json, then restart:
Cursor · Cline · Windsurf · Zed · other clients — point them at https://mcp.longbridge.com with transport streamable-http.
More Claude Code commands
bash
# Local self-hosted instance (see Self-hosting below)
claude mcp add --transport http longbridge-local http://localhost:8000/mcp
claude mcp list # registered servers
claude mcp get longbridge # config + auth status
claude mcp remove longbridge # unregister
claude mcp logout longbridge # re-trigger OAuth after revocation
On first use, the client reads the WWW-Authenticate challenge, fetches /.well-known/oauth-protected-resource (RFC 9728), and opens your browser for the Longbridge OAuth flow. Tokens are cached per session and refreshed automatically.
The 164 tools
Twenty categories spanning market data, trading, research and account management.
Category
Count
Coverage
Quote
32
Real-time and historical quotes, candlesticks, depth, brokers, options, warrants, watchlists, capital flow, market temperature, short positions, option volume
Fundamental
33
Financial statements/reports, business segments, institutional views, industry peers/valuation, dividends, EPS forecasts, valuations & valuation comparison, company info/executives, shareholders, corporate actions, operating metrics
Set --base-url to your externally reachable URL on any public deployment — it is published in the OAuth metadata clients use to discover the authorization server. It defaults to http://localhost:{port}, which remote clients cannot use.
Or build from source: cargo build --release && ./target/release/longbridge-mcp.
Configuration & environment variables
Config lives at ~/.longbridge/mcp/config.json (override the directory with LONGBRIDGE_MCP_CONFIG_DIR). CLI flags take precedence. When tls_cert and tls_key are both set the server runs HTTPS, otherwise HTTP; base_url defaults to https://localhost:{port} with TLS or http://localhost:{port} without.
Option
Config Key
CLI Flag
Default
Description
Bind address
bind
--bind
127.0.0.1:8000
HTTP server listen address
Base URL
base_url
--base-url
auto
Public base URL for resource metadata
Log directory
log_dir
--log-dir
(stderr)
Directory for rolling log files
TLS certificate
tls_cert
--tls-cert
(none)
PEM certificate file for HTTPS
TLS private key
tls_key
--tls-key
(none)
PEM private key file for HTTPS
Canary upstream
canary
--canary
false
Talk to the Longbridge canary environment (*.longbridge.xyz). --canary=false forces production even when the config file enables it
The mainland-China environment (*.longbridge.cn) is not a flag: it is auto-selected when LONGBRIDGE_REGION=cn is set (the same variable the SDK uses), so a mainland cluster needs no dedicated setting.
Upstream endpoints are fixed by the selected environment:
Canary uses the -global gateway, not openapi.longbridge.xyz: only the former is CloudFront-fronted and performs x-dc-region data-center routing, which this server depends on to serve us_- and ap_-prefixed credentials from one process.
Canary and mainland pin every URL above at startup; production defers to the SDK's own resolution except that a us_ credential with no upstream override is pinned to the global .com gateway. See src/endpoints.rs for the exact selection rules.
Advanced environment variables — most deployments never touch these; they exist for SDK debugging and edge/global-entry deployments.
Variable
Default
Description
LONGBRIDGE_MCP_CONFIG_DIR
~/.longbridge/mcp
Config file directory
LONGBRIDGE_PUBLIC_HOSTS
(none)
Comma-separated hostnames accepted from the edge-injected X-Host header; matching requests echo that host in the 401 challenge / RFC 9728 metadata. Unset = X-Host ignored
LONGBRIDGE_GLOBAL_OAUTH_URL
(none)
Authorization-server URL advertised to requests arriving via an allowlisted X-Host (global single-domain entry). Unset = fall back to the mode's OpenAPI base URL
LONGBRIDGE_MCP_QUOTE_WS_IDLE_TTL_SECS
600
Idle seconds before a cached quote WebSocket context is evicted
LONGBRIDGE_MCP_QUOTE_WS_MAX_CONTEXTS
1024
Maximum cached quote WebSocket contexts per server process
LONGBRIDGE_MCP_LOG_PAYLOADS
(unset)
1 lifts the payload log caps (see below). Never set this in production
LONGBRIDGE_LOG_PATH
(none)
SDK internal log path. Leave unset in production — the SDK writes unfiltered request/response bodies there
Logging & customer data
MCP requests and responses carry customer data — cash balances, positions, order history — and upstream SDK frames carry access tokens. None of it belongs in a log file, so the server caps the log targets that would print it, independent of RUST_LOG:
Target
Cap
What it would otherwise print
longbridge_httpcli
warn
OpenAPI request and full response bodies (INFO)
longbridge_wscli
warn
Every WebSocket frame, auth token included (INFO)
longbridge::trade
warn
Order push events (INFO)
rmcp
info
Decoded MCP requests and full tool results (DEBUG), raw JSON-RPC frames (TRACE)
So raising verbosity is safe: RUST_LOG=debug (or trace) gives you the server's own logs without leaking customer data. Two switches defeat this, both off by default — LONGBRIDGE_MCP_LOG_PAYLOADS=1 (removes the caps; use only against a test account locally) and LONGBRIDGE_LOG_PATH (makes the SDK write unfiltered bodies to that directory; the server warns at startup when set).
HTTP endpoints, authentication & metrics
The server expects a Longbridge OAuth access token in Authorization: Bearer <token>. On missing or invalid auth it returns 401 with a WWW-Authenticate header pointing to the protected-resource metadata, which directs clients to the Longbridge OAuth authorization server.
Send x-papertrading: true (or 1) on a request to run it against the paper-trading environment. Upstream rejects a paper-trading request made with a real-money token, so the header is a safety guard rather than a routing switch: it can only narrow what a token may do. LONGBRIDGE_PAPERTRADING=true turns it on for the whole deployment instead.
Method
Path
Description
GET
/.well-known/oauth-protected-resource
Protected Resource Metadata (RFC 9728)
GET
/.well-known/oauth-authorization-server
Authorization Server Metadata (RFC 8414); advertises direct Longbridge authorize/register and proxied token/revoke endpoints
POST
/oauth2/token
OAuth token proxy; derives x-dc-region from the code/refresh token, defaulting to AP
POST
/oauth2/revoke
OAuth revocation proxy; derives x-dc-region from the token, defaulting to AP
Prometheus metrics: mcp_tool_calls_total (counter), mcp_tool_call_duration_seconds (histogram), and mcp_tool_call_errors_total (counter) — each labelled by tool_name.
Development
bash
cargo +nightly fmt# format
cargo clippy # lint
cargo test# test