v1.8.4
GitHub Release ↗ LatestNew: built-in read-only MCP server for AI clients.
- Read-only MCP (Model Context Protocol) server — Claude Code, Cursor and other AI clients can read Schwab account data, positions, orders, quotes, option chains and rebalance suggestions over HTTP (Streamable HTTP at
/mcp). There is no tool that places, changes or cancels an order, andcalculate_rebalanceonly computes suggestions. - Off by default —
Mcp:Enabledisfalse; the endpoint is not mapped (404) and no token is generated unless the user enables it. - Bearer-token authentication — a random 32-byte token is generated on first enable and stored at
{dataRoot}/config/mcp-token.txt(owner-only on macOS/Linux); requests must presentAuthorization: Bearer <token>. Comparison is constant-time and the token is never logged. - Origin / Host hardening — non-local
OriginorHostheaders are rejected (403) to block DNS rebinding and malicious web pages. - 10 tools:
get_account,get_balances,get_positions,get_orders,get_order,get_quote,get_quotes,get_price_history,get_option_chain,calculate_rebalance. Every tool and parameter has a runtime description for the AI client, and list results are size-capped. - Release-build safe — MCP responses are built from named fields, not anonymous types, which Obfuscar would otherwise break (HTTP 500). MCP types are excluded from obfuscation so tool names stay readable. Verified against the obfuscated release build.
- Privacy note — everything a tool returns is sent to the AI service your client uses.
新增:内置只读 MCP 服务,供 AI 客户端使用。
- 只读 MCP(Model Context Protocol)服务 —— Claude Code、Cursor 等 AI 客户端可通过 HTTP (Streamable HTTP,端点
/mcp)读取 Schwab 账户、持仓、订单、报价、期权链与再平衡建议。 不存在任何下单、改单或撤单的工具,calculate_rebalance仅计算建议。 - 默认关闭 ——
Mcp:Enabled为false;用户未启用时不映射端点(404)、不生成 token。 。 - Bearer token 认证 —— 首次启用时生成 32 字节随机 token,存于
{dataRoot}/config/mcp-token.txt(macOS/Linux 上仅属主可读写);请求须携带Authorization: Bearer <token>。 比较采用常量时间,token 绝不写入日志。 - Origin / Host 加固 —— 非本机的
Origin或Host头将被拒绝(403),防止 DNS 重绑定和恶意网页。 - 10 个工具:
get_account、get_balances、get_positions、get_orders、get_order、get_quote、get_quotes、get_price_history、get_option_chain、calculate_rebalance。每个工具和参数都带运行时描述, 列表结果有大小上限。 - 发布版安全 —— MCP 响应用具名字段而非匿名类型构造(否则会被 Obfuscar 破坏,返回 HTTP 500); MCP 类型已排除在混淆之外,工具名保持可读。已在混淆后的发布版上实测。
- 隐私提示 —— 工具返回的所有内容都会发送给您的客户端所使用的 AI 服务。