Zebpay Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Zebpay Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
AI Trading Made Simple
Production-ready TypeScript MCP (Model Context Protocol) server for Zebpay spot and futures APIs, using stdio transport only. Model Context Protocol (MCP) is a standard way for AI assistants to securely call tools and data sources. It is designed for MCP clients like Cursor, Claude Desktop, and MCP Inspector that connect through local process execution. The server provides both market-data and trading workflows with strict validation, safe error handling, and developer-friendly observability.
zebpay_public_getTickerzebpay_public_getOrderBookzebpay_spot_placeMarketOrderzebpay_spot_placeLimitOrderzebpay_spot_getBalancezebpay_futures_public_getMarketszebpay_futures_public_getOrderBookzebpay_futures_placeOrderzebpay_futures_getWalletBalancezebpay_futures_getPositions@modelcontextprotocol/sdkundicizodsrc/
├── index.ts # Stdio MCP server entrypoint
├── mcp/ # Tools, resources, prompts, MCP errors/logging
├── private/ # Authenticated Zebpay clients
├── public/ # Public market-data clients
├── security/ # Credentials + signing helpers
├── http/ # Shared outbound HTTP client to Zebpay APIs
├── validation/ # Schemas and validation helpers
├── utils/ # Caching, metrics, formatting, file logging
└── types/ # Shared response typeshttps://api.zebpay.com/Use the steps below to generate API credentials for this MCP server:
https://api.zebpay.com/zebpay-mcp-local)Then add them to your local .env file:
ZEBPAY_API_KEY=your_api_key
ZEBPAY_API_SECRET=your_api_secretSecurity notes:
git clone <your-repo-url>
cd zebpay-mcp-server
npm install
cp env.example .envUpdate .env (all values are read from environment; there are no fallback defaults in code):
ZEBPAY_API_KEY=your_api_key # Use the API key from the step above
ZEBPAY_API_SECRET=your_api_secret # Use the Secret key from the step above
ZEBPAY_SPOT_BASE_URL=https://sapi.zebpay.com/api/v2
ZEBPAY_FUTURES_BASE_URL=https://futuresbe.zebpay.com/api/v1
ZEBPAY_MARKET_BASE_URL=https://www.zebapi.com/api/v1/market
MCP_TRANSPORTS=stdio
LOG_LEVEL=info
HTTP_TIMEOUT_MS=15000
HTTP_RETRY_COUNT=2npm run build
npm startOptional logging to file:
npm run start:logExample MCP client config:
{
"mcpServers": {
"zebpay": {
"command": "node",
"args": [
"/absolute/path/to/zebpay-mcp-server/dist/index.js"
],
"env": {
"ZEBPAY_API_KEY": "YOUR_API_KEY_HERE",
"ZEBPAY_API_SECRET": "YOUR_API_SECRET_HERE",
"LOG_LEVEL": "info"
}
}
}
}<img src="https://cursor.com/deeplink/mcp-install-dark.svg" alt="Install in Cursor">
Also see: mcp-config.json.example.
| Variable | Required | Description | Example value |
|---|---|---|---|
ZEBPAY_API_KEY | Yes | Zebpay API key (required for private tools) | YOUR_API_KEY_HERE |
ZEBPAY_API_SECRET | Yes | Zebpay API secret (required for private tools) | YOUR_API_SECRET_HERE |
MCP_TRANSPORTS | Yes | Must be stdio | stdio |
ZEBPAY_SPOT_BASE_URL | Yes | Spot API base URL | https://www.zebapi.com/api/v2 |
ZEBPAY_FUTURES_BASE_URL | Yes | Futures API base URL | https://futures-api.zebpay.com/api/v1 |
ZEBPAY_MARKET_BASE_URL | Yes | Market API base URL | https://www.zebapi.com/api/v1/market |
LOG_LEVEL | Yes | debug, info, warn, error | info |
LOG_FILE | No | File path for logs | logs/mcp-server.log |
HTTP_TIMEOUT_MS | Yes | Outbound request timeout (ms) | 15000 |
HTTP_RETRY_COUNT | Yes | Retry count for outbound requests | 2 |
npm run build
npm test
npm run test:watch
npm run logs
npm run logs:watch
npm run logs:errors
npm run logs:stats
npm run logs:clearscripts/README.mddocs/LOGGING.mdlogs/ is ignored)Found a bug or want to request a feature?
<your-org> and <your-repo>:https://github.com/<your-org>/<your-repo>/issues/new?template=bug_report.mdhttps://github.com/<your-org>/<your-repo>/issues/new?template=feature_request.mdMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.