About this integration
MCP server for Webull OpenAPI: trading and market data access for AI assistants
- Transport
- stdio
- Authentication
- unknown
- Initial setup
- user-authorization
- Runtime
- unattended
- Evidence
- documented
- Version
- 1.2.4
- Package
- webull-openapi-mcp
- Last compatibility test
- Not independently tested
Connect your agent
webull-openapi-mcpPublisher documentation reviewed only; the package, Webull API, credentials, token flow, market-data subscriptions, and trading operations were not executed. Authentication combines App Key/App Secret credentials with conditional account 2FA, outside one native auth label. Trading can move real funds when production is explicitly selected; UAT is the documented default and toolset/size/symbol controls should be reviewed.
Capabilities: Query market, instrument, screener, and fundamental data, Inspect accounts, balances, positions, and orders, Manage watchlists, Preview, place, replace, and cancel supported orders
Connected profiles
Additional details
io.github.webull-inc/webull-openapi-mcp
Source ↗ · Checked 2026-09-171.2.4
Source ↗ · Checked 2026-09-17CC0-1.0; package licenses are separate
Source ↗ · Checked 2026-09-17pypi
Source ↗ · Checked 2026-09-17webull-openapi-mcp
Source ↗ · Checked 2026-09-201.2.4
Source ↗ · Checked 2026-09-20The documented serve command runs the local MCP process with credentials supplied by the client environment; after conditional 2FA, the token is documented as valid for 15 days with automatic refresh, subject to reauthentication on expiry.
Source ↗ · Checked 2026-09-20A Webull developer App Key and App Secret are required. Accounts requiring 2FA also need an interactive approval in the Webull mobile app, after which the server uses a stored auto-refreshing token until reauthentication is required.
Source ↗ · Checked 2026-09-20The MCP client configuration launches webull-openapi-mcp serve with uvx and injects region, environment, and credential settings into the local stdio process.
Source ↗ · Checked 2026-09-20Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.
Source ↗ · Checked 2026-09-20