# Connect Claude, Cursor and VS Code to MetaTrader 5 with MCP

> Give Claude, Claude Code, Cursor or VS Code access to your MT5 accounts through fxapis's hosted MCP server — with a scoped key, so the agent can only do what you allow.

Published 2026-10-08 by fxapis. Canonical: https://fxapis.com/blog/connect-ai-agents-to-metatrader-5-mcp

## In short

- fxapis runs a hosted MCP server at https://api.fxapis.com/mcp: an assistant connects with an fxapis API key and gets tools to read and trade your MT5 accounts.
- fxapis-mcp-examples has tested configs for Claude, Claude Code, Cursor, VS Code, the OpenAI API and the Anthropic API.
- The key's scopes are the real safety control: a read-only key cannot trade, and a reduce-only key can only close, cancel and move stops — enforced by the API, not the prompt.
- Connecting accounts and managing keys are deliberately not tools: a broker password should never pass through a model's context.

fxapis runs a hosted **Model Context Protocol (MCP) server** for its MetaTrader 5 API. Point an AI assistant at it with an fxapis API key, and it can list your accounts, read positions and history, bring accounts online, and — only if the key allows it — place, close and modify trades. [fxapis-mcp-examples](https://github.com/FXapis/fxapis-mcp-examples) has a tested config for each client; this post walks through setting one up safely.

## How it works

- **The server:** `https://api.fxapis.com/mcp`, over Streamable HTTP. It is stateless, so any client that supports remote MCP servers with a custom header can use it.
- **Authentication:** your fxapis API key, as `Authorization: Bearer fx_live_…`. OAuth sign-in is not available yet.
- **The same rules as the REST API.** Each tool calls the ordinary API with your key. Scopes, plan limits, idempotency and the workspace kill switch apply exactly as they do to your own code — the MCP server cannot do anything the key could not do directly.
- **Deliberately missing:** connecting an MT5 account and managing API keys. Connecting takes the broker password, and a broker credential should never pass through a language model's context. Do both in the [console](https://fxapis.com/dashboard).

## Create a key just for the agent

The key's scopes are the control that actually holds, whatever the model decides. Give the assistant the fewest it needs:

| The agent should… | Scopes |
|---|---|
| Report on accounts, positions and history | `accounts:read`, `trading:read`, `history:read` |
| …and bring accounts online or take them offline | add `accounts:write` |
| …and manage risk: close, move stops, cancel — never open | add `trading:reduce` |
| …and open new positions | add `trading:execute` |

A tool the key does not cover answers `MISSING_SCOPE`, and the agent is told to ask you rather than work around it. Revoke the key and the agent is cut off on its next call. [API keys vs broker logins](https://fxapis.com/blog/mt5-api-key-vs-broker-login) explains why the key, not the MT5 password, is what you hand out.

## Connect your client

**Claude Code**, from a terminal:

```bash
claude mcp add --transport http fxapis https://api.fxapis.com/mcp \
  --header "Authorization: Bearer $FXAPIS_KEY"
```

**Cursor**, in `~/.cursor/mcp.json` or the project's `.cursor/mcp.json`:

```json
{
  "mcpServers": {
    "fxapis": {
      "url": "https://api.fxapis.com/mcp",
      "headers": { "Authorization": "Bearer ${env:FXAPIS_KEY}" }
    }
  }
}
```

**VS Code** (GitHub Copilot agent mode), in `.vscode/mcp.json` — the key is asked for once and stored securely, never written to the file:

```json
{
  "inputs": [{ "type": "promptString", "id": "fxapis-key", "description": "fxapis API key", "password": true }],
  "servers": {
    "fxapis": {
      "type": "http",
      "url": "https://api.fxapis.com/mcp",
      "headers": { "Authorization": "Bearer ${input:fxapis-key}" }
    }
  }
}
```

The repository also has **Claude** (claude.ai and Claude Desktop), the **OpenAI** Responses API and the **Anthropic** Messages API, plus plain Python and Node scripts that call the tools with no model involved. To check a key from a terminal, list the tools with the MCP Inspector:

```bash
npx @modelcontextprotocol/inspector --cli https://api.fxapis.com/mcp --transport http \
  --header "Authorization: Bearer $FXAPIS_KEY" --method tools/list
```

## Keeping an agent safe around real money

An agent can misread a request, act on text planted in something it was asked to summarize, or loop. The protections, strongest first:

1. **The key's scopes**, enforced on every call.
2. **Demo accounts** while you learn how an agent behaves — fxapis has no simulated market.
3. **Your plan's limits**, which refuse opening orders past the allowance; closing is never refused for billing.
4. **Your client's approvals.** Trading tools are marked destructive, so Claude Code and Cursor ask before a trade. Do not choose "always allow" for trading tools on a live account.

Every order an agent places is recorded like any other, with the key that placed it.

## Things to try

- "Which of my MT5 accounts are online, and what positions are open on each?"
- "How much margin would 0.5 lots of XAUUSD need on account 2?"
- "Move the stop loss on my gold position to break-even." *(needs `trading:reduce`)*
- "Did anything go wrong with today's orders? Show me any that are still `unknown`."

## Where to go next

- The [MCP guide](https://docs.fxapis.com/guides/mcp) has the full tool list and the scope each tool needs.
- [The MCP server](https://fxapis.com/mcp) on the website, and [SDKs and examples](https://docs.fxapis.com/sdks) for building your own agent on the API directly.

## Questions

### Can ChatGPT connect to the fxapis MCP server?

Not yet. ChatGPT's developer-mode apps connect with OAuth or no authentication, and fxapis requires an API key. Agents built on the OpenAI API can use it today.

### Can an agent trade without my approval?

Only if its key allows trading and your client is set to run trading tools without asking. Trading tools are marked destructive, so clients such as Claude Code and Cursor ask first; give the agent a read-only or reduce-only key to make trading impossible.

### Does the MCP server cost extra?

No. Each tool call is one or two ordinary API calls on your plan, under the same limits as your own code.
