Command Palette

Search for a command to run...

Home / Servers

rh-mcp

by likefudan

rh-mcp

A default-deny Python Read Gateway for Robinhood's official MCP server (https://agent.robinhood.com/mcp/trading). It is intended to run inside a dedicated read-broker process and expose only tool schemas that have been discovered, reviewed, pinned, and marked read-allowed.

The public surfaces are:

  • LibraryRobinhoodReadGateway, returning versioned, SDK-neutral, bounded JSON result envelopes.
  • CLIrh-mcp, for authentication, readiness diagnostics, owner-assisted manifest discovery, and reviewed read capabilities.

There is deliberately no arbitrary call_tool or raw MCP session interface. OAuth credentials are capable of trading because Robinhood does not advertise separate read/write scopes; the committed manifest and fail-closed schema checks are therefore the security boundary. That boundary is "no trading", not "no writes" — the reviewed manifest denies all six order tools and both order simulators, and allows 11 non-trading mutations (watchlist and saved-scan management) alongside its reads. Each entry carries a reviewed mutates flag, so a consumer that gates writes never has to infer which capabilities are which. Consumers must independently pin the canonical full-manifest digest. The gateway refuses readiness when that expected digest does not exactly match and includes the active digest in readiness and every successful result envelope.

Investment strategy, domain normalization, risk limits, approvals, and live trading gates belong in the consuming application rather than this transport gateway.

Status

Usable, not yet released. All six build-order steps have landed and the first reviewed manifest is committed. DESIGN.md is the authoritative spec.

Owner-assisted discovery ran against the live Robinhood server on 2026-08-03. A human reviewed all 53 discovered tools: 45 allowed, 8 denied. The denied set is exactly the trading surface — the six order tools plus both order simulators. The allowed set is 34 reads plus 11 non-trading mutations (watchlist and saved-scan management), each carrying a reviewed mutates flag so a consumer gating writes never has to infer which is which.

The full-manifest digest a consumer pins:

sha256:a0a1718e7924f62d0c79f82ed8a3c0a325863e62bd6d897d26a93ae8de2f6c2c

Not released yet: the DESIGN.md §12 acceptance list remains — license, changelog, tagged artifact with checksums, published compatibility policy, and independent security review.

Canonicalization and digests

Digest comparisons are the whole boundary, so the canonical form is specified rather than left to an implementation. rh-canon-1 is written out in the module docstring of src/rh_mcp/canonical.py and pinned by golden vectors in tests/test_canonical.py. Object key order and insignificant whitespace do not change a digest; array order and semantically meaningful values do. The algorithm version is recorded inside every derived digest and inside the manifest, so changing it is an explicit migration rather than a silent revaluation of every pin.

Related servers

n8n

Updated today

by n8n-io

Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

199,260

mcp-server-git

OfficialUpdated today

by modelcontextprotocol

A Model Context Protocol server providing tools to read, search, and manipulate Git repositories programmatically via LLMs

89,176

mcp-server-fetch

OfficialUpdated today

by modelcontextprotocol

A Model Context Protocol server providing tools to fetch and convert web content for usage by LLMs

89,176

@modelcontextprotocol/server-everything

OfficialUpdated today

by modelcontextprotocol

MCP server that exercises all the features of the MCP protocol

89,176