PHP REST API and MCP for T-Invest
tbank_mcp_and_api
A PHP wrapper over the T-Invest API: REST endpoints and an MCP server sharing a 90-plus method catalog, trading disabled by default
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- With TBANK_ALLOW_TRADING enabled, the server can place and cancel orders on a real account
- The universal call gives access to any T-Invest API method, not just a safe subset
Install
Manual install
composer install && cp .env.example .envInstalling from source and configuring the environment before running.
This is third-party code. Review the repository files before installing.
What it does
The project provides both a regular REST API and an MCP server on the same PHP codebase over the official T-Invest API proxy: accounts, instruments, candles, the order book, portfolio, orders and sandbox, plus a universal call to any of the 90-plus T-Invest methods without waiting for a dedicated endpoint. MCP works both as stdio for Cursor and Claude and as Streamable HTTP with SSE. Trading is disabled until the TBANK_ALLOW_TRADING variable is explicitly set, Quotation and MoneyValue values are normalized into a single value field, an instrument can be resolved by ticker, FIGI, UID, ISIN or name, and a shared rate-limit queue keeps requests under T-Bank's quotas.
Who it is for. For PHP developers who need both a REST API and an MCP server for T-Invest on one stack, with an explicit trading kill switch.
Good fit when
- You need a PHP stack instead of Node.js or Python for T-Invest
- You need a universal call to any T-Invest method without waiting for a dedicated endpoint
- You need trading disabled by default, turned on only by an explicit variable
Not a fit when
- You have no PHP 8.3+ and Composer in your infrastructure
- You need a published Composer package: it only installs from source
Example request
Show me the T-Invest order book for SBER and the last hourly candlesLimitations
The project has a single author with no known releases and only installs from source via composer install. The README does not point to automated coverage beyond the phpunit require-dev dependency. Live trading requires deliberately setting TBANK_ALLOW_TRADING=true; it is disabled by default on purpose.
How to disable. Stop the PHP server process and remove it from your MCP client configuration.
MCP
- Transport
- stdio, http, sse
- Authentication
- API key
| Environment variables | |
|---|---|
| TBANK_INVEST_TOKEN required, secret | The T-Invest API token. |
| TBANK_INVEST_ENV required | The mode: sandbox or production. |
| TBANK_ALLOW_TRADING | Enables trading operations; false by default. |
Security check
- With TBANK_ALLOW_TRADING enabled, the server can place and cancel orders on a real account
- The universal call gives access to any T-Invest API method, not just a safe subset
README in short
The Russian README describes a PHP wrapper over the official T-Invest REST proxy: a 90-plus method catalog, high-level REST endpoints, MCP stdio and Streamable HTTP, sandbox and a live circuit with trading disabled by default. It gives a table of HTTP routes for process health, the method catalog, accounts, instruments, candles, the order book and the portfolio.
FAQ
Can it trade on a live account right away?
No, TBANK_ALLOW_TRADING=false by default and trading operations stay off until the variable is set explicitly.
Is there a method without a dedicated endpoint?
Yes, the universal call via /v1/tinvest/{service}/{method} or the matching MCP tool covers the whole 90-plus method T-Invest catalog.
Related
A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice
Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data
Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language
inn-check-ru: counterparty risk traffic light
inn-check-ru
An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict