Unofficial, not affiliated with Papertrade. High leverage can lose your whole margin. Alerts are best effort.
Papertrade Alerts docs
App GitHub

Security and limits

What it never does#

It does not sign, send funds, swap, bridge, mint or pay. It has no private keys and no wallet connection. The MCP tools cannot move money.

Tokens and secrets#

SSRF guard#

Webhook destinations must be https:, carry no credentials, and resolve to a public host by name: loopback, private, link-local, CGNAT, benchmark, multicast and reserved IPv4, any IPv6 literal, single-label hosts and .local, .localhost, .internal, .lan, .home, .corp, .intranet are refused. Deliveries never follow redirects and time out. Use validate_destination to test a URL without a request.

Limits#

LimitValue
MCP requests per client IP120 per minute
MCP write tools per client IP12 per minute
Wallet previews per client IP8 per minute
MCP body, batch64 KB, 16 messages
New subscriptions per network10 per hour
Wallets, channels per subscription25, 6
Alerts per subscription60 per hour
Test messages5 per minute

CORS and origins#

/mcp and the discovery files send Access-Control-Allow-Origin: *. This is safe because nothing authenticates by cookie or by origin: the only credential is the bearer token you send explicitly.

Reporting a vulnerability#

See SECURITY.md in the repository.

Raw markdown: /docs/security.md. Apache-2.0. Unofficial, not affiliated with Papertrade.