# How to connect an AI assistant to prediction-market data over MCP

Six MCP servers, three client config shapes, and the check to run before an assistant gets a tool that can cancel or place an order on your account.

*https://predictionmarkets.tools/how-to/connect-an-ai-assistant-over-mcp · next to Prediction Market Data APIs*

**Answer:** Add a vendor's MCP server to your client: a remote URL as a custom connector in Claude Desktop, with claude mcp add in Claude Code, or as a url entry in Cursor's mcp.json; a local server as an npx command with your key in its environment. Start with a keyless read-only server, then ask the assistant to list its tools and compare that list with the vendor's documentation before connecting anything that touches an account.

## The approaches, in order

1. [PolymarketScan](https://predictionmarkets.tools/tools/polymarketscan.md) — Keyless remote server, 11 read-only Polymarket tools on 4 October 2026 — odds, price history, movers, large trades, trader profiles, news.
2. [Adjacent](https://predictionmarkets.tools/tools/adjacent.md) — Keyless remote server with four tools (list, find, get, price) at a 15-minute delay; realtime needs a paid key passed as a query parameter.
3. [Limitless API](https://predictionmarkets.tools/tools/limitless-api.md) — First-party remote server behind an OAuth sign-in; orders come back as a link you approve in the browser, but cancels execute at once.
4. [Webull Prediction Markets](https://predictionmarkets.tools/tools/webull-prediction-markets.md) — Hosted server behind Webull OAuth with per-capability grants; an event order is an instruction you confirm in the Webull app.
5. [CCXT](https://predictionmarkets.tools/tools/ccxt.md) — Local stdio server, public market data by default; trading, withdrawals and raw writes are tiers switched on only in a config file.
6. [Predictefy](https://predictionmarkets.tools/tools/predictefy.md) — Local npx server on a Predictefy key; ten execution tools are not registered at all unless MCP_ENABLE_TRADE is set.

*Ordered editorially. Paid placement does not affect this order.*

## The short way

Connect a server that cannot touch an account first, and learn your client on it. PolymarketScan's
endpoint needs no key, no OAuth and no account, and every one of its tools is marked read-only. In
Claude Code that is one line:

```bash
claude mcp add --transport http polymarketscan https://mcp.polymarketscan.org/mcp
```

Then open a session, run `/mcp` to see that it shows as connected, and ask the assistant which
tools the server gave it. Compare that answer with the vendor's own list before you rely on it.
On 4 October 2026 the two agreed — eleven tools, from `search_markets` to `get_market_news` — and
the catalogue's own card, checked three days earlier, still said eighteen. That gap is the reason
the step exists.

The same server in the other two clients:

- **Claude Desktop** takes a remote server as a custom connector, not as a file: Settings, then
  Connectors, then Add custom connector, and paste the URL. Its configuration file,
  `claude_desktop_config.json` under `~/Library/Application Support/Claude/` on a Mac or
  `%APPDATA%\Claude\` on Windows, is where local servers go.
- **Cursor** reads `.cursor/mcp.json` in a project or `~/.cursor/mcp.json` for every project. A
  remote server is a `url` entry:

```json
{
  "mcpServers": {
    "adjacent": {
      "url": "https://mcp.adjacent.markets/mcp"
    }
  }
}
```

A local server is a command instead of a URL, and the key goes in its environment rather than in
the conversation. CCXT's documented Claude Desktop and Cursor block is the shape for any of them:

```json
{
  "mcpServers": {
    "ccxt": {
      "command": "npx",
      "args": ["-y", "ccxt-mcp"]
    }
  }
}
```

In Claude Code, the environment variable goes after the server name and the launch command after
`--`, so that `-y` reaches `npx` rather than being read as Claude Code's own flag:

```bash
claude mcp add predictefy --env PREDICTEFY_API_KEY=YOUR_API_KEY -- npx -y @predictefy/mcp
```

## What the options are

[PolymarketScan](https://predictionmarkets.tools/tools/polymarketscan) is the easiest first connection: a Streamable HTTP endpoint
with no key, eleven tools covering market search, odds, price history, movers, trending markets,
large trades, buy and sell flow, leaderboards, trader profiles and positions, and news. Each tool
carries a `readOnlyHint` annotation, and the readme says the tools cannot place, change or cancel
orders. It is Polymarket data only, and the links in its results open PolymarketScan's own pages.

[Adjacent](https://predictionmarkets.tools/tools/adjacent) answers its four tools — `list`, `find`, `get` and `price` — with no key
at a 15-minute delay, and ids from the first two chain into the last two. Realtime data, news and
historical lookups need an API key, which the documentation says to append to the URL as `apiKey`;
realtime is on Adjacent's paid plans.
Its published JSON block omits a `type` field; Cursor accepts that, Claude Code does not (see below).

[Limitless](https://predictionmarkets.tools/tools/limitless-api) runs its own server, and it is the one here where the account is
the point. Every one of its fifteen tools needs an OAuth sign-in, market data included; the grant is
a single `trading` scope that lasts 30 days, with one-hour access tokens and no withdrawal scope.
`place_orders` builds a proposal for up to ten orders and returns a link: nothing is submitted until
you open it on the exchange and approve, and a proposal expires after ten minutes.

[Webull](https://predictionmarkets.tools/tools/webull-prediction-markets) runs a hosted server behind Webull's own OAuth, where you
choose which accounts and which capability groups — account information, order queries, market
data, security master — the assistant may use. Its event-contract tools read categories, series,
snapshots, depth, trades and bars, and `place_event_instruction` creates an order that still has to
be confirmed in the Webull app or desktop platform.

[CCXT](https://predictionmarkets.tools/tools/ccxt) ships `ccxt-mcp`, a local stdio server that does public market data out of the
box, prediction events included. Private reads need an exchange account configured; `trading`,
`funds` (withdrawals and transfers) and raw write endpoints are separate tiers enabled per account
in that file, and an unenabled tier's tools do not appear in the list at all. Setting `trading` to
`true` reaches sandbox and demo accounts only; live trading takes the string `"live"` and a
per-order value cap.

[Predictefy](https://predictionmarkets.tools/tools/predictefy) runs through `npx` with a key in `PREDICTEFY_API_KEY`. Its 1.0.0-beta.10
readme lists 47 tools by default — 38 read, intelligence and platform tools and 9 paper-trading
tools — and ten execution and collateral tools that register only when `MCP_ENABLE_TRADE` is `true`
or `1`. Its submit tool is a dry run unless passed `confirm: true`. The vendor says to pin an exact
version, which in a config file means `@predictefy/mcp@1.0.0-beta.10` rather than the bare name.

## Where this breaks

**A tool that writes is a tool the model can call.** The MCP specification says there should always
be a human able to deny a tool call. A client that asks before each call can be told to stop
asking, per tool or per server, and that is the setting that matters. Before allowing a server's tools without a prompt, read which of them change
state. Limitless is the instructive case: orders need your browser, but `cancel_order` and
`cancel_all_orders` execute immediately, so an assistant can pull your resting orders on its own.
Webull's watchlist tools write too. On CCXT and Predictefy, the switch that adds live trading sits
in a file or an environment variable rather than the chat, which is the right place for it — and
the reason not to flip it while testing.

**Annotations are claims, not controls.** `readOnlyHint` is the server describing itself. The
specification says a client must treat annotations as untrusted unless the server is trusted, so
"read-only" is worth exactly as much as your confidence in whoever wrote the server.

**The tool list moves under you.** PolymarketScan went from eighteen tools to eleven in a version
bump between 1 and 4 October 2026; Predictefy's card recorded 42 default tools, and the
beta.10 readme published on 30 September lists 47. A server can announce changes with a `listChanged` notification, and Claude
Code refetches on one, but a server is not required to send it, and a local `npx` server with no
version pinned silently becomes a different server the next time it starts. Re-list the tools after
any upgrade, and pin versions on anything with a write tier.

**Config written for one client fails in another.** Claude Code reads an entry with a `url` and no
`type` as a stdio server and skips it with an error. Adjacent's published block and Webull's Kiro example
are written that way, so in Claude Code's `.mcp.json` they need `"type": "http"` added. Claude
Desktop's file takes local servers; a remote URL goes in as a connector instead.

**A key in a URL is a key in a log.** Adjacent's realtime tier puts the key in a query string, which
ends up wherever URLs are recorded — proxy logs, client logs, a config file you commit. Claude Code's
project-scoped `.mcp.json` is meant to be committed; keep keys in user scope or in environment
variables rather than inside that file.

**Rate limits arrive as tool errors.** PolymarketScan rate-limits its free agent API to 60 requests a
minute per IP, and Adjacent's MCP failures carry a stable `RATE_LIMITED` code. An assistant asked a
broad question can fan out a dozen calls in one turn, and what it does with a refusal — retry, give
up, or answer from what it already has — is the model's choice, not yours. Limitless caps order
proposals at 50 per account per 10 minutes. Claude Code also warns when one tool result passes
10,000 tokens, which a long price history can do on its own.

**Third-party servers are somebody's copy of the venue.** PolymarketScan, Adjacent and Predictefy
re-serve venue data with their own delay, coverage and failure modes. Adjacent's free tier returned
only Kalshi markets when the card was checked. An answer is only as current as the server's cache,
and the assistant will not say which server's number it is quoting unless you ask.

**Market text is untrusted input.** Market titles, descriptions and rules are written by whoever
created the market, and on open-listing venues that can be anyone. They arrive in the model's
context alongside your instructions. Limitless's own documentation says its market descriptions
are the contract, not instructions to the assistant; CCXT keeps credentials out of every tool
schema so that a prompt-injected page cannot supply or change one. Neither stops a description
from asking the assistant to call a write tool, which is one more reason not to auto-approve one.

## If you outgrow this

If the assistant is doing the same lookups every day, it is doing a script's job at a model's
price: [build a dashboard](https://predictionmarkets.tools/how-to/build-a-dashboard-on-polymarket-data) or
[stream the order book](https://predictionmarkets.tools/how-to/stream-an-order-book) directly. If the conversation keeps ending in
an order, [placing an order from code](https://predictionmarkets.tools/how-to/place-an-order-from-code) covers signing and keys
without a model in between, and [where your key lives](https://predictionmarkets.tools/guides/where-your-key-lives) is the
background on what any of these servers is holding. Every card that publishes a server is in
[the MCP collection](https://predictionmarkets.tools/collections/mcp-servers).

## FAQ

### Do I need an API key to try one of these?

No. On 4 October 2026 two servers here answered a tools/list call with no key and no sign-in — PolymarketScan with 11 read-only tools, and Adjacent with four tools at a 15-minute delay. Limitless and Webull need an OAuth sign-in even for market data, and the local servers from CCXT and Predictefy read a key from their environment for anything beyond CCXT's public market data.

### Is there an official MCP server from Polymarket or Kalshi?

Neither venue's own API card in this catalogue carries the MCP flag. The servers that reach Polymarket and Kalshi data here are third-party — PolymarketScan, Adjacent, Predictefy and others — so what they return is their copy of the venue's data, with their own delay, coverage and rate limits. Limitless is the venue on this page that runs its own.

### Can a connected assistant trade for me?

On these six, not by default. PolymarketScan and Adjacent have no write tools. Limitless and Webull return an order you approve yourself in the browser or the app. CCXT and Predictefy do not register their trading tools until you switch them on outside the conversation. The exception to watch is Limitless's two cancel tools, which execute immediately.

## Sources

1. [Connect Claude Code to tools via MCP](https://code.claude.com/docs/en/mcp) — Anthropic, read 2026-10-04
2. [Connect to local MCP servers (Claude Desktop configuration file)](https://modelcontextprotocol.io/docs/develop/connect-local-servers) — Model Context Protocol, read 2026-10-04
3. [Connect to remote MCP servers (custom connectors)](https://modelcontextprotocol.io/docs/develop/connect-remote-servers) — Model Context Protocol, read 2026-10-04
4. [Model Context Protocol (MCP) — configuration locations and fields](https://cursor.com/docs/context/mcp) — Cursor, read 2026-10-04
5. [Tools (specification, 2025-06-18) — annotations, listChanged, human in the loop](https://modelcontextprotocol.io/specification/2025-06-18/server/tools) — Model Context Protocol, read 2026-10-04
6. [PolymarketScan MCP Server (readme, version 2.0.0)](https://polymarketscan.org/mcp-readme.md) — PolymarketScan, read 2026-10-04
7. [MCP server](https://docs.adjacent.markets/explore/mcp) — Adjacent, read 2026-10-04
8. [MCP Server](https://docs.limitless.exchange/developers/mcp-server) — Limitless, read 2026-10-04
9. [MCP (Cloud MCP, OAuth capability groups and tool list)](https://developer.webull.com/apis/docs/AI-friendly-Resources/mcp) — Webull, read 2026-10-04
10. [ccxt-mcp 0.1.3 README (capability tiers)](https://www.npmjs.com/package/ccxt-mcp) — CCXT, read 2026-10-04
11. [@predictefy/mcp 1.0.0-beta.10 README](https://www.npmjs.com/package/@predictefy/mcp) — Predictefy, read 2026-10-04

*Last updated 2026-10-04. A reference page, corrected in place — not a dated post.*
