Skip to content
Join the waitlistWaitlist

MCP for Claude and Cursor

Give an AI agent guarded trading tools through Guard's MCP server. The exact config for Claude Desktop, Claude Code, Cursor, the OpenAI Agents SDK and LangGraph, and why ChatGPT is not supported.

A prompt is not a limit. A model can misread a number, repeat itself, or be talked out of an instruction. Guard’s MCP server gives an agent tools that cannot break your limits, because every order still passes the same nine rules as any bot’s, in Guard, on your machine.

ToolWhat it does
account_overviewequity, positions with the stops that protect them, open orders, Guard’s state
limitsyour nine rules and the risk state (active, halted for the day, stopped, kill switch)
preview_order“what would you allow for this trade?”: the size from the stop, a resize and the rule that bound it, or the veto, without sending
place_orderan entry with its stop (or Guard’s default stop), through the nine rules; returns Guard’s verdict and the venue’s reply
move_stopmove a stop; only tighter is accepted
close_positionreduce or close; never blocked
cancel_ordercancel one order; Guard keeps a position’s last stop
recent_decisionsGuard’s latest verdicts and why
kill_switchpull the kill switch; needs confirm: true

There is no tool to raise a limit, change the stop policy, change leverage, resume after a halt, release the kill switch, move funds or send a raw request. Those need you, at the machine running Guard.

Prices and sizes are decimal strings ("58800", "0.01"); a size can be "max", and a stop can be "guard_policy". Every refusal comes back with a code and a plain reason, and says whether anything was sent.

Example. You ask the agent to “go long BTC, stop 2% below”. It calls preview_order and gets back: “resize: 0.02553 BTC, bound by the loss at the stop (2% of equity)”. It can report that to you; it cannot change it.

  1. Guard is running (zunder-guard run, with --network testnet for a testnet setup).

  2. The agent gets its own client key, not your bot’s. Make one with Guard; it is written to a new file only you can read (mode 0600) and never shown:

    Terminal window
    mkdir -p ~/.config/zunder-guard
    zunder-guard client add --out ~/.config/zunder-guard/mcp-client.key

    Then restart Guard: a running Guard accepts a new client after a restart. The key is never a command-line argument or an environment variable. Without one, the server is read-only.

  3. The kill switch needs nothing more: with a client key, kill_switch sends Guard’s signed kill request.

The MCP server is part of Guard’s own program: zunder-guard mcp. The configs below start it without a shell, so write absolute paths (no ~). If your client cannot find zunder-guard, give the full path that command -v zunder-guard prints (for example /opt/homebrew/bin/zunder-guard with Homebrew on an Apple silicon Mac).

Flag of zunder-guard mcpDefault
--networkpaperpaper, testnet or mainnet: orders are refused unless Guard runs the same
--key-filethe client key file (mode 0600 or 0400)
--key-stdinthe client key on the first line of standard input
--guard-urlhttp://127.0.0.1:8547Guard’s address; this machine only
--confirm-accountmainnet only, and required there: the account Guard trades
--kill-fileGuard’s kill file, only for an older Guard without the signed kill request; not needed otherwise

The same local Guard process serves each client. Select the configuration for the client you use.

Edit claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/claude_desktop_config.json; Windows: %APPDATA%\Claude\claude_desktop_config.json), then restart Claude Desktop.

{
"mcpServers": {
"zunder-guard": {
"command": "zunder-guard",
"args": ["mcp", "--network", "testnet", "--key-file", "/Users/you/.config/zunder-guard/mcp-client.key"]
}
}
}

ChatGPT’s connectors reach MCP servers over the internet (SSE or streamable HTTP); a local server started from a command does not work there. Guard runs on your machine and listens on localhost only. So ChatGPT is not supported.

We do not recommend exposing Guard to the internet with a tunnel to make it work. A connection through the relay is being considered; it is not planned yet.

What the MCP server needs, and what it cannot do

Section titled “What the MCP server needs, and what it cannot do”

zunder-guard mcp talks only to your running Guard on your machine. It holds no API wallet key: that stays in Guard. Its client key only identifies the agent to Guard; the venue would refuse it.

It can sign three kinds of request (an order, a cancel, a change to an order), and Guard judges each one again. It refuses to send anything when Guard runs another network than the one you named, when its key is not one of Guard’s clients or is known to Hyperliquid, or when the address does not answer like a Guard. A client key must be a fresh key: never approve it as an API wallet. Text that comes back from Guard or the venue is passed to the model as quoted data, never as instructions, and tool calls are rate-limited (order requests: 4 at once, then 10 a minute). The kill switch is never rate-limited.

This page as plain Markdown, for people and LLMs: /docs/integrations/mcp.md