Model Context Protocol server providing trading, market data, account, and portfolio management tools for the Longbridge investment platform
The Longbridge MCP server exposes only a single tool (authenticate) with OAuth 2.1 functionality. The tool definition cannot be verified in the provided source code excerpt. The main.rs and Cargo.toml show HTTP transport via rmcp with Streamable HTTP support, but the actual tool schema, parameter definitions, and descriptions are not visible in the source provided. This is a critical gap: tool definitions must be directly inspectable in the codebase. Additionally, the tool marked as READ_ONLY (authenticate) suggests it is a read-only operation, but the MCP spec uses destructiveHint/idempotentHint/readOnlyHint annotations which are not evident. The server is production-grade infrastructure-wise (Rust, tokio, TLS support, prometheus metrics, structured logging) but tool quality cannot be assessed without visible schema definitions.
OAuth 2.1 authentication flow for MCP clients
Tool schema not visible in source code. The authenticate tool's input schema, parameter types, parameter descriptions, and output schema are not shown in the provided source. Cannot verify JSON Schema compliance, parameter constraints, or type information.
Tool description is vague and generic. 'OAuth 2.1 authentication flow for MCP clients' is only 48 characters. This description lacks WHEN to call it, WHAT the output contains, and WHY the agent would use it instead of alternatives. Does it return a session token? A refresh token? Does it require credentials as input?
No parameter descriptions visible. Even assuming the tool has parameters (API key, client ID, redirect URI), none are documented in the source excerpt.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 38 | <=2025-11-25 | v2 |
Tool annotation hints missing. The tool is marked READ_ONLY in the feature list, but the source does not show whether the tool definition includes readOnlyHint, destructiveHint, or idempotentHint annotations per the current MCP spec. Modern servers should declare these explicitly in the tool schema.
No error handling guidance visible. If authenticate fails (invalid credentials, expired token, network timeout), there is no evidence the tool returns actionable error messages telling the LLM what to do next (retry, ask user for credentials, etc.)
Single tool limits composition. With only authenticate available, the agent cannot compose meaningful workflows. An authentication tool alone does not enable the agent to list resources, call APIs, or perform downstream actions, a critical capability gap.