Skip to main content

MCP server for trade.xyz — analysis and trading of the xyz HIP-3 markets (xyz:AAPL, xyz:GOLD, ...) on Hyperliquid, with in-code guardrails. Fork of hyperliquid-mcp.

Project description

mcpxyz — MCP server for trade.xyz (HIP-3 on Hyperliquid)

An MCP server that lets an AI assistant (Claude Desktop, Claude Code, …) analyse and trade the xyz markets — tokenized equities, commodities and indices like xyz:AAPL, xyz:GOLD, xyz:NVDA, xyz:XYZ100 — exposed by trade.xyz.

trade.xyz has no proprietary API: it is a UI over the xyz HIP-3 perp dex deployed on Hyperliquid. Everything here goes through the standard Hyperliquid API, with markets namespaced xyz:.

⚠️ Not financial advice. Trading involves risk of loss. Use at your own risk.

Safety model

This server signs financial transactions, so guardrails are enforced in code (not via the prompt):

  • Read-only by default — no order is signed unless READ_ONLY=false and a key is set.
  • Delegated API wallet only — use a Hyperliquid API wallet (no withdrawal rights). The withdraw tool has been removed entirely.
  • Asset whitelist — writes are limited to ALLOWED_ASSETS (empty ⇒ all writes blocked).
  • Per-order capsMAX_ORDER_SIZE, MAX_ORDER_NOTIONAL_USD, MAX_LEVERAGE.
  • Two-step ordersplace_order returns a preview + token; nothing is signed until you call confirm_order.
  • Kill switchcancel_all_orders is always available and never whitelisted.

See SECURITY.md for the full policy and key-handling guidance.

Tools

Market data (read-only): get_markets_overview (all markets in one call — price, 24h change, funding, OI, volume; sortable for top movers), get_market_data, get_candle_data, get_l2_orderbook, get_funding_rates, calculate_min_order_size.

Account: get_positions (xyz isolated margin account), get_spot_user_state, get_user_fees, update_leverage, transfer (move collateral between core / spot / xyz).

Orders: place_order (preview) → confirm_order, cancel_order, cancel_all_orders, bulk_cancel_orders, modify_order, get_open_orders, get_order_status, get_user_fills, get_user_fills_by_time.

Assets are accepted namespaced (xyz:AAPL) or bare (AAPL, apple) — they are normalized automatically.

Install

# from PyPI (recommended)
uvx mcpxyz

# or from source
uvx --from git+https://github.com/akugone/mcp-xyz mcpxyz

Get a delegated API wallet

  1. In the Hyperliquid / trade.xyz UI, create an API wallet (a.k.a. agent wallet). It can trade but cannot withdraw funds.
  2. Copy its private key. This is what you put in HYPERLIQUID_PRIVATE_KEYnever your main account key.

Claude Desktop config

Configuration lives in claude_desktop_config.json (there is no .env to fill as an end user). Generate a ready-to-paste snippet with:

mcpxyz init            # analysis only (read-only)
mcpxyz init --trading  # with a trading env block to fill in

Then merge the xyz entry into the mcpServers object and fully restart Claude Desktop. The two cases:

Analysis only — zero config, no key:

{
  "mcpServers": {
    "xyz": { "command": "uvx", "args": ["mcpxyz"] }
  }
}

Reads (prices, funding, candles, orderbook) work immediately. No key ⇒ fully read-only, no order can be placed.

Trading — add your own delegated API wallet key:

{
  "mcpServers": {
    "xyz": {
      "command": "uvx",
      "args": ["mcpxyz"],
      "env": {
        "HYPERLIQUID_PRIVATE_KEY": "0x<your_delegated_api_wallet_key>",
        "HYPERLIQUID_USER_ADDRESS": "0x<your_main_account_address>",
        "READ_ONLY": "false",
        "ALLOWED_ASSETS": "xyz:*",
        "MAX_ORDER_NOTIONAL_USD": "100"
      }
    }
  }
}

ALLOWED_ASSETS: "xyz:*" allows trading every xyz market. To restrict trading to specific markets, list them instead, e.g. "xyz:AAPL,xyz:GOLD".

Your key stays on your machine — it is only read from this env block (or, for local development, a gitignored .env) and never sent anywhere.

Environment variables

Variable Default Description
HYPERLIQUID_PRIVATE_KEY Delegated API wallet key. Empty ⇒ read-only.
HYPERLIQUID_USER_ADDRESS wallet addr Address to query positions/fills for.
HYPERLIQUID_TESTNET false Use testnet instead of mainnet.
READ_ONLY true Must be false (and a key set) to sign anything.
XYZ_DEX xyz HIP-3 perp dex namespace.
ALLOWED_ASSETS Comma-separated whitelist for writes (e.g. xyz:AAPL,xyz:GOLD). xyz:* allows all xyz markets. Empty ⇒ writes blocked. Reads are never restricted.
MAX_ORDER_SIZE Max size per order.
MAX_ORDER_NOTIONAL_USD Max notional (USD) per order.
MAX_LEVERAGE Max leverage for update_leverage.
HYPERLIQUID_MCP_SHOW_LOGS false Keep false in production.

Usage flow

  1. Explore read-only: get_market_data xyz:AAPL → candles → L2 → funding.
  2. Check get_positions.
  3. place_order (limit, away from the price) → review the preview → confirm_order.
  4. cancel_order / cancel_all_orders.

Validation & tests

  • uv run pytest — offline unit tests (guardrails, models, tool registration, order flow).
  • Write-path validation on testnet: see docs/VALIDATION.md and scripts/validate_testnet.py.

Transports

mcpxyz                       # stdio (default)
mcpxyz --transport http --port 3000
mcpxyz --transport sse  --port 3000

Credits & license

Fork of midodimori/hyperliquid-mcp (MIT). Adapted for the trade.xyz HIP-3 markets with in-code guardrails. Licensed under MIT.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mcpxyz-0.2.1.tar.gz (211.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mcpxyz-0.2.1-py3-none-any.whl (35.0 kB view details)

Uploaded Python 3

File details

Details for the file mcpxyz-0.2.1.tar.gz.

File metadata

  • Download URL: mcpxyz-0.2.1.tar.gz
  • Upload date:
  • Size: 211.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for mcpxyz-0.2.1.tar.gz
Algorithm Hash digest
SHA256 8e7f9f1a1b6becdf97c64066cfaa83a6c24ad0b1e477849cb9ede97fd24c536c
MD5 aca0d65ae1e071b2ef470310a209f6d6
BLAKE2b-256 dd86d8bb75e124407966ffe5657633e6115055ff4d2b40eb9d42273ceb12bafc

See more details on using hashes here.

File details

Details for the file mcpxyz-0.2.1-py3-none-any.whl.

File metadata

  • Download URL: mcpxyz-0.2.1-py3-none-any.whl
  • Upload date:
  • Size: 35.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for mcpxyz-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 42a60e228acc55247e59d926fbd6b0773b5cf8bf4601b2fa0e44816afdfd56dc
MD5 e15bfccfd1a30ab6801d89ecc0fc46f4
BLAKE2b-256 163ec6b66aa79c495a4c7f2a263f884736cdeb9a68c8f16e11a8e9c09e6a6163

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page