[ mcp ]
Ask your agent how it's doing — from your own chat
Protocol Bank ships a Model Context Protocol server. Claude Desktop, Claude Code, or any MCP host can read your agent and control it in plain language — no browser required.
[ what you can say ]
> "How is my trading agent doing?"
> "What positions is the agent holding right now?"
> "Why did it open the SOL short?"
> "Pause the agent — I don't like this market."
[ connect in 2 minutes ]
- 1. Clone this repository (the server runs from it) and pnpm install.
- 2. Sign in with your wallet on the site and take your session token for MCP_AUTH_TOKEN.
- 3. Add the server to your host's config.
{
"mcpServers": {
"protocol-bank": {
"command": "npx",
"args": ["tsx", "/path/to/protocol-bank/lib/mcp/stdio-server.ts"],
"env": {
"MCP_AUTH_TOKEN": "<your SIWE session JWT>",
"MCP_WALLET_ADDRESS": "0x…"
}
}
}
}Without credentials the server still runs in guest mode: read-only access to the demo account and the public track record.
[ tools ]
get_trading_overviewAgent status, equity, trading wallet, max loss, today's PnL.(optional auth)
get_positionsOpen positions: side, entry/mark, size, unrealized PnL.(optional auth)
get_activityScans, opens/closes with PnL, and risk-guard events.(optional auth)
get_track_recordPublic anonymized live-account performance.(none auth)
control_trading_agentpause / resume / stop, and approve-or-reject a pending trade.(required auth)
[ safety ]
- Your chat model can never touch funds. It talks to an agent wallet that holds trading-only rights on Hyperliquid — withdrawal is not in its vocabulary.
- Every request is scoped to your wallet. The server authenticates with your session; it cannot read another account.
- Risk limits stay in the engine. Sizing, stop-loss and daily circuit breakers are enforced server-side no matter what the model asks for.
- Revoke anytime. One click on Hyperliquid removes the agent's access; the MCP server then has nothing to control.

