Model Context Protocol (MCP) server for Toss Securities Open API
18 tools with complete JSON Schema definitions, strong naming conventions (verb_noun prefix), and reasonable descriptions. Most tools have type-constrained parameters with enums (currency, orderType, side, interval). However, descriptions are terse (many under 100 chars, some under 50), missing context on when to use tools and dependencies. Parameter descriptions are minimal or absent for some tools. Output schemas not documented. Error handling present but not guide-based. Security-sensitive tools (create/modify/cancel order) have guardrails in code but not described in tool metadata.
Cancel an existing order with guardrails enforcement (confirmation and account lock only).
Create a new securities order with guardrails enforcement (confirmation, daily limits, account lock, symbol allowlist, sell/market order restrictions).
List Toss Securities accounts available to the configured Open API credentials.
Get available buying power for an account. currency is required: KRW for Korean stocks, USD for US stocks.
Get 1-minute or daily OHLCV candles for one KRX or US stock symbol.
Get trading commission information for an account.
Output schemas not documented. Tool descriptions state what is returned (e.g. 'Get account holdings') but do not specify the response structure (fields, types, presence of IDs for chaining). This forces LLMs to infer structure from trial and error.
Most read-only tool descriptions are terse (under 80 chars). 'Get orderbook data for one KRX or US stock symbol.' lacks context on when to use (market analysis? pre-trade analysis?) and what the response contains (bid/ask levels? volume?). Descriptions should be 50-200 chars with actionable context.
Parameter descriptions missing or minimal for optional parameters. 'accountSeq' repeated across 8 tools with identical description ('Account sequence number (optional when TOSSINVEST_ACCOUNT is configured)') but no guidance on when to provide it vs relying on env config. Requires agent to understand environment coupling.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2025-06-18+ | v2 |
Get KRW/USD or USD/KRW exchange rate. dateTime is optional ISO 8601.
Get account holdings. accountSeq is optional when TOSSINVEST_ACCOUNT is configured.
Get Korean market calendar and session hours. date is optional YYYY-MM-DD.
Get orderbook data for one KRX or US stock symbol.
Get upper and lower price limits for one KRX or US stock symbol.
Get current prices for up to 200 comma-separated KRX or US stock symbols.
Get sellable quantity for one symbol in an account.
Get buy warning flags for one KRX or US stock symbol.
Get stock master data for up to 200 comma-separated KRX or US stock symbols.
Get recent trades for one KRX or US stock symbol. count defaults to the Toss API default and is capped at 50.
Get US market calendar and session hours. date is optional YYYY-MM-DD in US local date.
Modify an existing order with guardrails enforcement. Enforces KR/US quantity rules and LIMIT/MARKET price rules, subject to the same categorical create guardrails (daily limits, sell/market restrictions, symbol allowlist).
Guardrails enforcement (daily limits, sell/market restrictions, symbol allowlist) documented in code (guard/index.ts) but not exposed in tool descriptions or as separate dedicated guardrail-check tools. Agents cannot see or verify what restrictions apply before attempting an order.
Confirmation parameter 'confirmOrderAction' required when TOSSINVEST_REQUIRE_ORDER_CONFIRMATION=true, but this requirement is not documented in the tool description, only in the parameter description. Agents must discover this by reading parameter metadata, not the tool summary.
No error recovery guidance. Code throws errors like 'Order blocked: sell orders are disabled. Set TOSSINVEST_ALLOW_SELL_ORDERS=true to allow them.' but this is server configuration, not actionable for an LLM calling the tool. LLM cannot self-correct; it can only report the error to the user.