How to connect an AI assistant to prediction-market data over MCP

Six MCP servers, three client config shapes, and the check to run before an assistant gets a tool that can cancel or place an order on your account.

Add a vendor's MCP server to your client: a remote URL as a custom connector in Claude Desktop, with claude mcp add in Claude Code, or as a url entry in Cursor's mcp.json; a local server as an npx command with your key in its environment. Start with a keyless read-only server, then ask the assistant to list its tools and compare that list with the vendor's documentation before connecting anything that touches an account.

The short way

Connect a server that cannot touch an account first, and learn your client on it. PolymarketScan's endpoint needs no key, no OAuth and no account, and every one of its tools is marked read-only. In Claude Code that is one line:

claude mcp add --transport http polymarketscan https://mcp.polymarketscan.org/mcp

Then open a session, run /mcp to see that it shows as connected, and ask the assistant which tools the server gave it. Compare that answer with the vendor's own list before you rely on it. On 4 October 2026 the two agreed — eleven tools, from search_markets to get_market_news — and the catalogue's own card, checked three days earlier, still said eighteen. That gap is the reason the step exists.

The same server in the other two clients:

  • Claude Desktop takes a remote server as a custom connector, not as a file: Settings, then Connectors, then Add custom connector, and paste the URL. Its configuration file, claude_desktop_config.json under ~/Library/Application Support/Claude/ on a Mac or %APPDATA%\Claude\ on Windows, is where local servers go.
  • Cursor reads .cursor/mcp.json in a project or ~/.cursor/mcp.json for every project. A remote server is a url entry:
{
  "mcpServers": {
    "adjacent": {
      "url": "https://mcp.adjacent.markets/mcp"
    }
  }
}

A local server is a command instead of a URL, and the key goes in its environment rather than in the conversation. CCXT's documented Claude Desktop and Cursor block is the shape for any of them:

{
  "mcpServers": {
    "ccxt": {
      "command": "npx",
      "args": ["-y", "ccxt-mcp"]
    }
  }
}

In Claude Code, the environment variable goes after the server name and the launch command after --, so that -y reaches npx rather than being read as Claude Code's own flag:

claude mcp add predictefy --env PREDICTEFY_API_KEY=YOUR_API_KEY -- npx -y @predictefy/mcp

What the options are

PolymarketScan is the easiest first connection: a Streamable HTTP endpoint with no key, eleven tools covering market search, odds, price history, movers, trending markets, large trades, buy and sell flow, leaderboards, trader profiles and positions, and news. Each tool carries a readOnlyHint annotation, and the readme says the tools cannot place, change or cancel orders. It is Polymarket data only, and the links in its results open PolymarketScan's own pages.

Adjacent answers its four tools — list, find, get and price — with no key at a 15-minute delay, and ids from the first two chain into the last two. Realtime data, news and historical lookups need an API key, which the documentation says to append to the URL as apiKey; realtime is on Adjacent's paid plans. Its published JSON block omits a type field; Cursor accepts that, Claude Code does not (see below).

Limitless runs its own server, and it is the one here where the account is the point. Every one of its fifteen tools needs an OAuth sign-in, market data included; the grant is a single trading scope that lasts 30 days, with one-hour access tokens and no withdrawal scope. place_orders builds a proposal for up to ten orders and returns a link: nothing is submitted until you open it on the exchange and approve, and a proposal expires after ten minutes.

Webull runs a hosted server behind Webull's own OAuth, where you choose which accounts and which capability groups — account information, order queries, market data, security master — the assistant may use. Its event-contract tools read categories, series, snapshots, depth, trades and bars, and place_event_instruction creates an order that still has to be confirmed in the Webull app or desktop platform.

CCXT ships ccxt-mcp, a local stdio server that does public market data out of the box, prediction events included. Private reads need an exchange account configured; trading, funds (withdrawals and transfers) and raw write endpoints are separate tiers enabled per account in that file, and an unenabled tier's tools do not appear in the list at all. Setting trading to true reaches sandbox and demo accounts only; live trading takes the string "live" and a per-order value cap.

Predictefy runs through npx with a key in PREDICTEFY_API_KEY. Its 1.0.0-beta.10 readme lists 47 tools by default — 38 read, intelligence and platform tools and 9 paper-trading tools — and ten execution and collateral tools that register only when MCP_ENABLE_TRADE is true or 1. Its submit tool is a dry run unless passed confirm: true. The vendor says to pin an exact version, which in a config file means @predictefy/mcp@1.0.0-beta.10 rather than the bare name.

Where this breaks

A tool that writes is a tool the model can call. The MCP specification says there should always be a human able to deny a tool call. A client that asks before each call can be told to stop asking, per tool or per server, and that is the setting that matters. Before allowing a server's tools without a prompt, read which of them change state. Limitless is the instructive case: orders need your browser, but cancel_order and cancel_all_orders execute immediately, so an assistant can pull your resting orders on its own. Webull's watchlist tools write too. On CCXT and Predictefy, the switch that adds live trading sits in a file or an environment variable rather than the chat, which is the right place for it — and the reason not to flip it while testing.

Annotations are claims, not controls. readOnlyHint is the server describing itself. The specification says a client must treat annotations as untrusted unless the server is trusted, so "read-only" is worth exactly as much as your confidence in whoever wrote the server.

The tool list moves under you. PolymarketScan went from eighteen tools to eleven in a version bump between 1 and 4 October 2026; Predictefy's card recorded 42 default tools, and the beta.10 readme published on 30 September lists 47. A server can announce changes with a listChanged notification, and Claude Code refetches on one, but a server is not required to send it, and a local npx server with no version pinned silently becomes a different server the next time it starts. Re-list the tools after any upgrade, and pin versions on anything with a write tier.

Config written for one client fails in another. Claude Code reads an entry with a url and no type as a stdio server and skips it with an error. Adjacent's published block and Webull's Kiro example are written that way, so in Claude Code's .mcp.json they need "type": "http" added. Claude Desktop's file takes local servers; a remote URL goes in as a connector instead.

A key in a URL is a key in a log. Adjacent's realtime tier puts the key in a query string, which ends up wherever URLs are recorded — proxy logs, client logs, a config file you commit. Claude Code's project-scoped .mcp.json is meant to be committed; keep keys in user scope or in environment variables rather than inside that file.

Rate limits arrive as tool errors. PolymarketScan rate-limits its free agent API to 60 requests a minute per IP, and Adjacent's MCP failures carry a stable RATE_LIMITED code. An assistant asked a broad question can fan out a dozen calls in one turn, and what it does with a refusal — retry, give up, or answer from what it already has — is the model's choice, not yours. Limitless caps order proposals at 50 per account per 10 minutes. Claude Code also warns when one tool result passes 10,000 tokens, which a long price history can do on its own.

Third-party servers are somebody's copy of the venue. PolymarketScan, Adjacent and Predictefy re-serve venue data with their own delay, coverage and failure modes. Adjacent's free tier returned only Kalshi markets when the card was checked. An answer is only as current as the server's cache, and the assistant will not say which server's number it is quoting unless you ask.

Market text is untrusted input. Market titles, descriptions and rules are written by whoever created the market, and on open-listing venues that can be anyone. They arrive in the model's context alongside your instructions. Limitless's own documentation says its market descriptions are the contract, not instructions to the assistant; CCXT keeps credentials out of every tool schema so that a prompt-injected page cannot supply or change one. Neither stops a description from asking the assistant to call a write tool, which is one more reason not to auto-approve one.

If you outgrow this

If the assistant is doing the same lookups every day, it is doing a script's job at a model's price: build a dashboard or stream the order book directly. If the conversation keeps ending in an order, placing an order from code covers signing and keys without a model in between, and where your key lives is the background on what any of these servers is holding. Every card that publishes a server is in the MCP collection.

The approaches, in order

Cards in the catalogue that do this, ordered editorially. Paid placement does not affect this order.

  1. 1.PolymarketScan

    Keyless remote server, 11 read-only Polymarket tools on 4 October 2026 — odds, price history, movers, large trades, trader profiles, news.

    Free Polymarket explorer and $5K+ whale radar with a free, keyless API and MCP server.

    Free · $10/mo add-onFree tier

  2. 2.Adjacent

    Keyless remote server with four tools (list, find, get, price) at a 15-minute delay; realtime needs a paid key passed as a query parameter.

    Prediction-market indices and reference rates, with Kalshi on the tier you can test.

    $50/moFree tier

  3. 3.Limitless API

    First-party remote server behind an OAuth sign-in; orders come back as a link you approve in the browser, but cancels execute at once.

    REST and WebSocket for markets, books, candles and trading on Base.

    Per-trade feeFree tier

  4. 4.Webull Prediction Markets

    Hosted server behind Webull OAuth with per-capability grants; an event order is an instruction you confirm in the Webull app.

    Kalshi's event contracts inside the Webull app, at a flat two cents a contract per side.

    Per-trade fee

  5. 5.CCXT

    Local stdio server, public market data by default; trading, withdrawals and raw writes are tiers switched on only in a config file.

    One client for seven prediction venues, inside a 104-exchange crypto library.

    FreeFree tierOpen source

  6. 6.Predictefy

    Local npx server on a Predictefy key; ten execution tools are not registered at all unless MCP_ENABLE_TRADE is set.

    Sixteen venues behind one verb family, priced in credits, with a key on every read.

    $49/moFree tier

FAQ

Do I need an API key to try one of these?

No. On 4 October 2026 two servers here answered a tools/list call with no key and no sign-in — PolymarketScan with 11 read-only tools, and Adjacent with four tools at a 15-minute delay. Limitless and Webull need an OAuth sign-in even for market data, and the local servers from CCXT and Predictefy read a key from their environment for anything beyond CCXT's public market data.

Is there an official MCP server from Polymarket or Kalshi?

Neither venue's own API card in this catalogue carries the MCP flag. The servers that reach Polymarket and Kalshi data here are third-party — PolymarketScan, Adjacent, Predictefy and others — so what they return is their copy of the venue's data, with their own delay, coverage and rate limits. Limitless is the venue on this page that runs its own.

Can a connected assistant trade for me?

On these six, not by default. PolymarketScan and Adjacent have no write tools. Limitless and Webull return an order you approve yourself in the browser or the app. CCXT and Predictefy do not register their trading tools until you switch them on outside the conversation. The exception to watch is Limitless's two cancel tools, which execute immediately.

Sources

  1. Connect Claude Code to tools via MCP — Anthropic, read
  2. Connect to local MCP servers (Claude Desktop configuration file) — Model Context Protocol, read
  3. Connect to remote MCP servers (custom connectors) — Model Context Protocol, read
  4. Model Context Protocol (MCP) — configuration locations and fields — Cursor, read
  5. Tools (specification, 2025-06-18) — annotations, listChanged, human in the loop — Model Context Protocol, read
  6. PolymarketScan MCP Server (readme, version 2.0.0) — PolymarketScan, read
  7. MCP server — Adjacent, read
  8. MCP Server — Limitless, read
  9. MCP (Cloud MCP, OAuth capability groups and tool list) — Webull, read
  10. ccxt-mcp 0.1.3 README (capability tiers) — CCXT, read
  11. @predictefy/mcp 1.0.0-beta.10 README — Predictefy, read

The catalogue next door

This page names a handful of cards. The rest of them are in Prediction Market Data APIs, each filled in against the same schema, with the fields to narrow it yourself.

Last updated . Corrected in place: this is a reference page, not a dated post.