{"_id":"@shumi-ai/mcp","_rev":"10-be365188d77cb149918d1a49e187fcb2","name":"@shumi-ai/mcp","dist-tags":{"latest":"1.2.1"},"versions":{"0.1.2":{"name":"@shumi-ai/mcp","version":"0.1.2","keywords":["mcp","modelcontextprotocol","crypto","cryptocurrency","trading","market-data","funding-rates","sentiment","shumi","ai"],"author":{"name":"pxeodev"},"license":"MIT","_id":"@shumi-ai/mcp@0.1.2","maintainers":[{"name":"saschamayr","email":"mayr.sascha@gmail.com"}],"homepage":"https://shumi.ai","bugs":{"url":"https://github.com/mayrsascha/shumi-mcp/issues"},"bin":{"shumi-mcp":"bin/shumi-mcp.js"},"dist":{"shasum":"bd79d862f8efcdee8c58fcac483e076fd3efe2d6","tarball":"https://registry.npmjs.org/@shumi-ai/mcp/-/mcp-0.1.2.tgz","fileCount":14,"integrity":"sha512-lfV3s/tT0Vtp4ijyuENxAsyUtymM5zzPWRYKygXsSzH60VEdyOhYDr0vU0+Csss0xx+eflAEh+2XB4tK4NvpXw==","signatures":[{"sig":"MEYCIQCA8dJlZpZwWX20nj2+4T66Q9bYSZ8s65vTLsYMKbx8WwIhAL+zSl761EdTxR3+ZWxD7d4lUyOPeerAQwo0FC5CqPeU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@shumi-ai%2fmcp@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":60824},"main":"src/server.js","type":"module","engines":{"node":">=20"},"gitHead":"40e58f7c568e35fa89fbf644a36b41efbf053c5a","mcpName":"ai.shumi/mcp","scripts":{"test":"SHUMI_TELEMETRY=0 node --test","start":"node bin/shumi-mcp.js","verify":"node verify-live.mjs","inspect":"npx -y @modelcontextprotocol/inspector node bin/shumi-mcp.js","start:http":"node src/http-server.js","verify:remote":"node verify-live.mjs --remote"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:3423751a-4565-4b01-8d36-8a8404f6ebfc"}},"repository":{"url":"git+https://github.com/mayrsascha/shumi-mcp.git","type":"git"},"_npmVersion":"12.0.2","description":"Shumi crypto trade-intelligence MCP server — the market intelligence the shumi CLI provides, for any MCP client.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.25.0","posthog-node":"^5.38.6","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.2_1786549643545_0.9334869228826641","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@shumi-ai/mcp","version":"0.1.3","keywords":["mcp","modelcontextprotocol","crypto","cryptocurrency","trading","market-data","funding-rates","sentiment","shumi","ai"],"author":{"name":"pxeodev"},"license":"MIT","_id":"@shumi-ai/mcp@0.1.3","maintainers":[{"name":"saschamayr","email":"mayr.sascha@gmail.com"}],"homepage":"https://shumi.ai","bugs":{"url":"https://github.com/mayrsascha/shumi-mcp/issues"},"bin":{"shumi-mcp":"bin/shumi-mcp.js"},"dist":{"shasum":"59c683cad20e13ba9c7128dac94a21665429f18c","tarball":"https://registry.npmjs.org/@shumi-ai/mcp/-/mcp-0.1.3.tgz","fileCount":14,"integrity":"sha512-5ILx88kivuELddtKTq8EWDzPBu88twE70PjA0sqaT9YYdDQOrquCh4tjzQpjDajst+63BP69kA42PWblj+b/ig==","signatures":[{"sig":"MEYCIQDv3FFnyx3Ng3B9XHesD3hrPJ9QKdiOSE/jBnboMtM3uQIhAK5Gp1aplsixEslgBaOdTzhqUzaHo9EOw0ai9Dz2DNQb","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@shumi-ai%2fmcp@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":61508},"main":"src/server.js","type":"module","engines":{"node":">=20"},"gitHead":"d63b708fac5d23a6e0dfcf1e953d8d453f63e600","mcpName":"ai.shumi/mcp","scripts":{"test":"SHUMI_TELEMETRY=0 node --test","start":"node bin/shumi-mcp.js","verify":"node verify-live.mjs","inspect":"npx -y @modelcontextprotocol/inspector node bin/shumi-mcp.js","start:http":"node src/http-server.js","verify:remote":"node verify-live.mjs --remote"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:3423751a-4565-4b01-8d36-8a8404f6ebfc"}},"repository":{"url":"git+https://github.com/mayrsascha/shumi-mcp.git","type":"git"},"_npmVersion":"12.0.2","description":"Shumi crypto trade-intelligence MCP server — the market intelligence the shumi CLI provides, for any MCP client.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.25.0","posthog-node":"^5.38.6","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.3_1786551565202_0.9674038663707809","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@shumi-ai/mcp","version":"1.0.0","keywords":["mcp","modelcontextprotocol","crypto","cryptocurrency","trading","market-data","funding-rates","sentiment","shumi","ai"],"author":{"name":"pxeodev"},"license":"MIT","_id":"@shumi-ai/mcp@1.0.0","maintainers":[{"name":"saschamayr","email":"mayr.sascha@gmail.com"}],"homepage":"https://shumi.ai","bugs":{"url":"https://github.com/mayrsascha/shumi-mcp/issues"},"bin":{"shumi-mcp":"bin/shumi-mcp.js"},"dist":{"shasum":"4cec2772901f8a90b67e84a55244e5f6e0773613","tarball":"https://registry.npmjs.org/@shumi-ai/mcp/-/mcp-1.0.0.tgz","fileCount":15,"integrity":"sha512-gAfGHXm/a4ypT2WH8drUFCU5vN2eYkTGRlv5bc/pzP4/bT6g3eaplPXNQFZ9+vBVflBJ1tF9AlOxMixIj2CXJw==","signatures":[{"sig":"MEUCIDPvDv6dKfzsxrTlO06qK42n7zwN3H3XjJCdTjlWlmYNAiEA74/JP4vyQbf8f2+8JUrzavitWbb37cDg6koi03MsICs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@shumi-ai%2fmcp@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":70284},"main":"src/server.js","type":"module","engines":{"node":">=20"},"gitHead":"5f74274d2dc3ddae65b959e38cd4899aba1d27e6","mcpName":"ai.shumi/mcp","scripts":{"test":"SHUMI_TELEMETRY=0 node --test","start":"node bin/shumi-mcp.js","verify":"node verify-live.mjs","inspect":"npx -y @modelcontextprotocol/inspector node bin/shumi-mcp.js","start:http":"node src/http-server.js","verify:remote":"node verify-live.mjs --remote"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:3423751a-4565-4b01-8d36-8a8404f6ebfc"}},"repository":{"url":"git+https://github.com/mayrsascha/shumi-mcp.git","type":"git"},"_npmVersion":"12.0.2","description":"Shumi crypto trade-intelligence MCP server — the market intelligence the shumi CLI provides, for any MCP client.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^4.2.0","posthog-node":"^5.38.6","@modelcontextprotocol/node":"^2.0.0","@modelcontextprotocol/server":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@modelcontextprotocol/client":"^2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.0.0_1787174016102_0.48868448227857275","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@shumi-ai/mcp","version":"1.1.0","keywords":["mcp","modelcontextprotocol","crypto","cryptocurrency","trading","market-data","funding-rates","sentiment","shumi","ai"],"author":{"name":"pxeodev"},"license":"MIT","_id":"@shumi-ai/mcp@1.1.0","maintainers":[{"name":"saschamayr","email":"mayr.sascha@gmail.com"}],"homepage":"https://shumi.ai","bugs":{"url":"https://github.com/mayrsascha/shumi-mcp/issues"},"bin":{"shumi-mcp":"bin/shumi-mcp.js"},"dist":{"shasum":"edc6b3b3eefac53a3ebeb13a77057b2018c39dec","tarball":"https://registry.npmjs.org/@shumi-ai/mcp/-/mcp-1.1.0.tgz","fileCount":16,"integrity":"sha512-vHbsFprIMjSP3JYEQMBD6Kojj9l3T3SfWgydwg1GWHJ/XtBBiAtlQH6eQnxEAiMd8GWqsFr1ZIWBvIT3+f8LUw==","signatures":[{"sig":"MEQCIE/Vb3bySQsAJ/UYCJkxLdyRPqmAeTEwgnpYoDHp+6BAAiASulY/POS9YVdTfAGhqpFdwthyvnOZyM/7FihWTrvurg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@shumi-ai%2fmcp@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":79156},"main":"src/server.js","type":"module","engines":{"node":">=20"},"gitHead":"5110a3da2f9f0e9d992c8416bb1ecf6b6ff31ef1","mcpName":"ai.shumi/mcp","scripts":{"test":"SHUMI_TELEMETRY=0 node --test","start":"node bin/shumi-mcp.js","verify":"node verify-live.mjs","inspect":"npx -y @modelcontextprotocol/inspector node bin/shumi-mcp.js","start:http":"node src/http-server.js","verify:remote":"node verify-live.mjs --remote"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:3423751a-4565-4b01-8d36-8a8404f6ebfc"}},"repository":{"url":"git+https://github.com/mayrsascha/shumi-mcp.git","type":"git"},"_npmVersion":"12.0.2","description":"Shumi crypto trade-intelligence MCP server — the market intelligence the shumi CLI provides, for any MCP client.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^4.2.0","posthog-node":"^5.38.6","@modelcontextprotocol/node":"^2.0.0","@modelcontextprotocol/server":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@modelcontextprotocol/client":"^2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.1.0_1787176099834_0.9610713792471774","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@shumi-ai/mcp","version":"1.2.0","keywords":["mcp","modelcontextprotocol","crypto","cryptocurrency","trading","market-data","funding-rates","sentiment","shumi","ai"],"author":{"url":"https://shumi.ai","name":"Shumi"},"license":"MIT","_id":"@shumi-ai/mcp@1.2.0","maintainers":[{"name":"saschamayr","email":"hello@shumi.ai"}],"homepage":"https://shumi.ai","bugs":{"url":"https://github.com/shumi-ai/shumi-mcp/issues"},"bin":{"shumi-mcp":"bin/shumi-mcp.js"},"dist":{"shasum":"95674d12a92b3feb16a60dc1cc593af5aa556c0e","tarball":"https://registry.npmjs.org/@shumi-ai/mcp/-/mcp-1.2.0.tgz","fileCount":19,"integrity":"sha512-Y+YogUM0H3CymDtGhcFpK01v7PEfR0FTOy+IshWAQFIReVvR1nl6qCLdNLk/oZASeuujqreTvGK3NiZPFMU0DA==","signatures":[{"sig":"MEUCIQDdbfgo8YPmWGXt4CQboLbX9K90oxvbnbkWseiqu3gpiwIgcWGMWF4szRcRVO0TrnNqGZQkJq6+X68NC0sa0gt7pkE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIGhAtoDNMcMUjuC4gjRW4CWaJum5qxsnkvKqqggP3gPEAiBk5nkb8fkzeVn7UUZXkmVPpjK9mi66mv+4bgezs9I/dg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@shumi-ai%2fmcp@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":105119},"main":"src/server.js","type":"module","engines":{"node":">=20"},"gitHead":"059180486e4e0a6781eba89aa29a8db7bd87d08a","mcpName":"ai.shumi/mcp","scripts":{"test":"SHUMI_TELEMETRY=0 node --test","start":"node bin/shumi-mcp.js","verify":"node verify-live.mjs","inspect":"npx -y @modelcontextprotocol/inspector node bin/shumi-mcp.js","start:http":"node src/http-server.js","verify:remote":"node verify-live.mjs --remote"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e9d3980-1a31-4fb6-82b6-ed3d770c3b1f"}},"repository":{"url":"git+https://github.com/shumi-ai/shumi-mcp.git","type":"git"},"_npmVersion":"12.1.0","description":"Shumi crypto trade-intelligence MCP server — the market intelligence the shumi CLI provides, for any MCP client.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^4.2.0","posthog-node":"^5.38.6","@modelcontextprotocol/node":"^2.0.0","@modelcontextprotocol/server":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@modelcontextprotocol/client":"^2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.2.0_1790213645712_0.5770218755705541","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"_id":"@shumi-ai/mcp@1.2.1","bin":{"shumi-mcp":"bin/shumi-mcp.js"},"bugs":{"url":"https://github.com/shumi-ai/shumi-mcp/issues"},"dist":{"shasum":"3545cbc85565d89c8c458d52b6c621960f6114e2","tarball":"https://registry.npmjs.org/@shumi-ai/mcp/-/mcp-1.2.1.tgz","fileCount":19,"integrity":"sha512-sTu872O19UP2PvsKJhGBEO0ikDXYoHhAm6iiXvlLvSc/gmxw4/xkrJDF9gLzfD241Fdq7j2cRvWW5QWTvMSfBA==","signatures":[{"sig":"MEYCIQDdyCTIzIqh03akfmbLkJBoh7PtzlRyEYgh7eBPP8+/+gIhALOuqP+tHohBbckf/+yV6QroLDuNN4HklhBR+funruMa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDgv33Z/22dbT2E8zqvi0eVQJqbZFH/p872kcsxE2H2LgIgDUVjCnd5vsuseSIwasJAyLHmPHbnPFLq06EVtjmwuS4="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@shumi-ai%2fmcp@1.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":105171},"main":"src/server.js","name":"@shumi-ai/mcp","type":"module","author":{"url":"https://shumi.ai","name":"Shumi"},"engines":{"node":">=20"},"gitHead":"312d191c202478d055e3edfcccbb748dc1570119","license":"MIT","mcpName":"ai.shumi/mcp","scripts":{"test":"SHUMI_TELEMETRY=0 node --test","start":"node bin/shumi-mcp.js","verify":"node verify-live.mjs","inspect":"npx -y @modelcontextprotocol/inspector node bin/shumi-mcp.js","start:http":"node src/http-server.js","verify:remote":"node verify-live.mjs --remote"},"version":"1.2.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e9d3980-1a31-4fb6-82b6-ed3d770c3b1f"}},"homepage":"https://shumi.ai","keywords":["mcp","modelcontextprotocol","crypto","cryptocurrency","trading","market-data","funding-rates","sentiment","shumi","ai"],"repository":{"url":"git+https://github.com/shumi-ai/shumi-mcp.git","type":"git"},"_npmVersion":"12.1.0","description":"Shumi crypto trade-intelligence MCP server — the market intelligence the shumi CLI provides, for any MCP client.","directories":{},"maintainers":[{"name":"saschamayr","email":"hello@shumi.ai"}],"_nodeVersion":"22.23.2","dependencies":{"zod":"^4.2.0","posthog-node":"^5.38.6","@modelcontextprotocol/node":"^2.0.0","@modelcontextprotocol/server":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@modelcontextprotocol/client":"^2.0.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_1.2.1_1790259841556_0.732019134981267"}}},"time":{"created":"2026-08-12T09:48:44.959Z","modified":"2026-09-24T14:24:02.045Z","0.1.0":"2026-08-12T09:48:45.497Z","0.1.1":"2026-08-12T13:32:52.335Z","0.1.2":"2026-08-12T15:47:23.704Z","0.1.3":"2026-08-12T16:19:25.347Z","1.0.0":"2026-08-19T21:13:36.255Z","1.1.0":"2026-08-19T21:48:20.003Z","1.2.0":"2026-09-24T01:34:05.793Z","1.2.1":"2026-09-24T14:24:01.643Z"},"bugs":{"url":"https://github.com/shumi-ai/shumi-mcp/issues"},"author":{"url":"https://shumi.ai","name":"Shumi"},"license":"MIT","homepage":"https://shumi.ai","keywords":["mcp","modelcontextprotocol","crypto","cryptocurrency","trading","market-data","funding-rates","sentiment","shumi","ai"],"repository":{"url":"git+https://github.com/shumi-ai/shumi-mcp.git","type":"git"},"description":"Shumi crypto trade-intelligence MCP server — the market intelligence the shumi CLI provides, for any MCP client.","maintainers":[{"name":"saschamayr","email":"hello@shumi.ai"}],"readme":"# @shumi-ai/mcp\n\nShumi crypto trade-intelligence as an [MCP](https://modelcontextprotocol.io) server — the same\nmarket intelligence the [`shumi` CLI](https://www.npmjs.com/package/shumi) provides, for any MCP\nclient (Claude Desktop, Claude Code, Cursor, agents).\n\nIt's a thin wrapper over Shumi's data API: prices, trends, funding rates, sentiment, narratives,\nmarket regime, synthesized signals, pair / delta-neutral ideas, real-world assets, holder and\nwallet tracking, and transcript highlights. All tools are read-only.\n\n## Quick start\n\nYou need a Shumi API key (`shumi_sk_…`). Create one at <https://shumi.ai>.\n\n### Claude Desktop / Claude Code\n\nAdd to your MCP config (`claude_desktop_config.json`, or `claude mcp add` for Claude Code):\n\n```json\n{\n  \"mcpServers\": {\n    \"shumi\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@shumi-ai/mcp\"],\n      \"env\": {\n        \"SHUMI_TOKEN\": \"shumi_sk_your_key_here\"\n      }\n    }\n  }\n}\n```\n\nRestart the client. The `shumi` tools (e.g. `get_coin_risk`, `get_market_health`, `ask_shumi`)\nappear automatically.\n\n### Cursor\n\n`~/.cursor/mcp.json` uses the same `command` / `args` / `env` shape as above.\n\n### Plugin directories\n\nThis repo also ships `plugin.json` and `mcp.json` at its root, so it installs as an\n[Agent Plugin](https://agent-plugins.org) from Cursor's directory and any other client on that\nstandard.\n\nSet `SHUMI_TOKEN` in your environment before starting the client when you install this way. The\nAgent Plugins schema takes literal environment values only — it has no placeholder for a secret —\nso the manifest deliberately omits `env` rather than shipping a `${SHUMI_TOKEN}` string that would\nbe passed through verbatim and fail as an invalid key.\n\n## Tools\n\n**Typed (deterministic):** `get_coin_risk`, `lookup_coin`, `resolve_coin`, `get_coin_sentiment`,\n`get_coin_historical`, `get_market_health`, `get_market_crossing`, `get_global_market`,\n`get_prices`, `scan_trends`, `scan_coins`, `get_market_sentiment`, `list_narratives`,\n`get_narrative`, `list_categories`, `get_category`, `get_funding_momentum`, `get_funding_alerts`,\n`get_regime`, `get_signal`, `get_signal_quality`, `get_pair_suggestions`, `list_rwa_assets`,\n`get_rwa_asset`, `get_holders`, `get_wallets`, `get_futures_signals`, `get_basket`,\n`get_transcripts`.\n\n**Real-world assets** (`list_rwa_assets`, `get_rwa_asset`) cover stocks, ETFs, commodities,\nindices and FX trading as perps on Hyperliquid builder DEXes. They are not crypto tokens — the\ncoin tools will not find them.\n\n**Free-form:** `ask_shumi` (natural-language questions — Shumi classifies, fetches, and synthesizes)\nand `search_web`.\n\nList-returning tools accept `top` (keep first N items) and `fields` (comma-separated keys to keep)\nto save tokens.\n\n**Resources:** `shumi://capabilities` (the data surface) and `shumi://billing/tier` (your current\nentitlement).\n\n## Configuration\n\n| Env var | Default | Purpose |\n| --- | --- | --- |\n| `SHUMI_TOKEN` | — | API key (`shumi_sk_*`). **Required.** |\n| `SHUMI_API_URL` | production coinrotator-ai endpoint | Override the API base URL. |\n| `SHUMI_WALLET` | — | Wallet address to include in NLP query context. |\n\nGating (free / access / pro tiers and pay-per-call) is enforced server-side, exactly as for the CLI —\nout-of-quota responses come back as a structured error with an actionable hint.\n\n## Remote (HTTP)\n\nFor a hosted, multi-user deployment:\n\n```bash\nPORT=8787 SHUMI_MCP_ALLOWED_ORIGINS=https://yourapp.com npm run start:http\n```\n\nEach request authenticates with its own key header; that token is forwarded to the upstream API per\nrequest. Endpoint: `POST /mcp`, health: `GET /health`.\n\n### Connecting from Claude (`static_headers`)\n\nClaude supports a fixed credential entered as a request header, so no OAuth server is needed. In\n**Add custom connector → request headers**, an organisation administrator enters:\n\n| field | value |\n|---|---|\n| URL | `https://mcp.shumi.ai/mcp` |\n| Header name | `Authorization` |\n| Header value | `Bearer shumi_sk_…` |\n\n`x-api-key: shumi_sk_…` works too, and so does an `Authorization` value with the `Bearer ` prefix\nomitted — an admin types this once by hand, and a mistyped pair fails closed with no error they can\nsee, so all three shapes are accepted. `x-api-key` wins if both are present, on the grounds that an\nadmin who set it meant it.\n\n**Do not put the key in the URL.** The MCP authorization spec prohibits access tokens in the URI\nquery string and Anthropic documents a credential in a URL as a security vulnerability — URLs land in\nserver logs, proxies and browser history. The `?shumiToken=` / `?config=` query forms exist only\nbecause Smithery injects session config that way.\n\nOne thing to know before buying for a team: a `static_headers` credential is **shared by the\norganisation, not per user**. Everyone connecting through that connector shares one Shumi account,\none free-tier allowance and one quota. Per-user metering needs OAuth — see `docs/oauth-plan.md`.\n\nAn unauthenticated call is answered with **`200` and an in-band `AUTH_REQUIRED` error, not `401`**.\nThat is deliberate: Claude treats a `401` as the start of an OAuth flow, and a server with no\nauthorization server behind it would send the client into a handshake that cannot complete. The\n`401` path exists but is gated behind `SHUMI_MCP_AUTH_SERVER`, so it lights up only once there is an\nauthorization server to point at.\n\n**The server is stateless.** One endpoint serves both protocol revisions:\n\n- **`2026-07-28`** — no `initialize`, no `Mcp-Session-Id`. A request carries its own routing in\n  headers (`Mcp-Method`, plus `Mcp-Name` on `tools/call`) and its protocol envelope in `params._meta`,\n  so an intermediary can route and meter a call without parsing the body.\n- **`2025-11-25` and earlier** — still served. Old clients keep their `initialize` handshake, but each\n  exchange is answered by its own instance rather than a session.\n\nBecause nothing outlives a request, `GET` and `DELETE` (the 2025 session operations) return `405`,\nand the session tunables that used to live here — `SHUMI_MCP_SESSION_TTL_MS`, `SHUMI_MCP_MAX_SESSIONS`,\n`SHUMI_MCP_SESSION_SWEEP_MS` — are gone. They are safe to delete from any deployment; unset they do\nnothing. The idle-session reaper they configured existed to stop liveness probes from growing the\nheap, which cannot happen when no session is kept.\n\n## Develop\n\n```bash\nnpm install\nnpm test                # unit tests (no network)\nnpm run inspect         # open the MCP Inspector against the stdio server\nSHUMI_TOKEN=… npm start # run the stdio server\n```\n\n## Deliberately not exposed\n\nTwo CLI routes have no MCP tool, both on purpose:\n\n- **`walkforward`** — the route exists, but two of its three actions have nothing behind them\n  while Engine B is paused: positions is empty and outcomes holds a single row from 2026-05-28.\n  Shipping it would hand a caller an empty array with no reason attached. It goes in when the\n  engine resumes.\n- **`watch`** — server-sent events, which do not fit MCP tool semantics.\n\nEverything else in the CLI's typed surface has a tool.\n","readmeFilename":"README.md"}