Model Context Protocol
Moontower MCP Server
Moontower exposes a Model Context Protocol (MCP) server at /mcp so Claude Code and other MCP clients can call the API as typed tools.
Server URL
https://api.moontower.ai/mcp
Authentication
Use the same API key as the REST API. Pass it in the X-API-Key header.
Do not commit API keys to .mcp.json, shell history, or project docs. Prefer an environment variable:
export MOONTOWER_API_KEY="mtw_..."
Claude Code Setup
Add the hosted MCP server:
claude mcp add --transport http moontower https://api.moontower.ai/mcp \
--header "X-API-Key: $MOONTOWER_API_KEY"
You can also configure .mcp.json:
{
"mcpServers": {
"moontower": {
"type": "http",
"url": "https://api.moontower.ai/mcp",
"headers": {
"X-API-Key": "${MOONTOWER_API_KEY}"
}
}
}
}
Verify the connection:
claude mcp get moontower
claude mcp list
Inside Claude Code:
/mcp
claude mcp get should show https://api.moontower.ai/mcp and an X-API-Key header. If the header is missing or the key is the literal string ${MOONTOWER_API_KEY}, the variable never expanded.
Troubleshooting
Failed to connect — HTTP 404 / Invalid OAuth error response
Claude Code reports this when the initialize request is rejected and then it falls back to OAuth discovery (/.well-known/*, POST /register). Those paths are not implemented. The 404 is the discovery fallback, not a missing MCP server.
Typical cause: the API key never reached us. Auth responses from get_api_key_user / _lookup_auth:
- 401
{"detail":"API key required"}— noX-API-Keyheader - 401
{"detail":"Invalid API key format"}— header present, value does not start withmtw_ - 401
{"detail":"Invalid API key"}— unknown hash, or key already deactivated - 401
{"detail":"API key has expired"}— key found butexpires_atis in the past (then deactivated) - 403
{"detail":"User account is not active"}— key is valid; userstatusis notACTIVE - 404
{"detail":"Not Found"}on/.well-known/*or/register— expected. Auth failed first; Claude Code then probed OAuth
Check:
echo "$MOONTOWER_API_KEY"is a realmtw_...key in the same shell that launched Claude Code..mcp.jsonuses"${MOONTOWER_API_KEY}"(Claude Code expands this). A raw$MOONTOWER_API_KEYor an unexpanded${...}will not authenticate.claude mcp get moontowershows the header with the resolved key, not the placeholder.
Direct probe (bypasses Claude Code):
curl -sS -D- -X POST https://api.moontower.ai/mcp \
-H "X-API-Key: $MOONTOWER_API_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"probe","version":"0"}}}'
A valid key returns an MCP initialize result. A missing/bad key returns one of the JSON bodies above with server: cloudflare and no cf-mitigated header — that means you reached the origin, so the problem is the credential, not Cloudflare.
Cloudflare Error 1010 (browser signature banned)
Error 1010 is Cloudflare Browser Integrity Check, not application auth. It blocks some TLS/header fingerprints. MCP is machine-to-machine; a 1010 on /mcp is a WAF false positive.
Use https://api.moontower.ai/mcp only. moontower.ai/mcp and app.moontower.ai/mcp are the product site (Vercel), not the API.
If you hit 1010, send us:
- the Ray ID from the Cloudflare page
claude --version- whether you are on a VPN / corporate proxy
- whether a plain
curlprobe (above) also 1010s, or only Claude Code
A curl / claude mcp list that returns one of the origin JSON details above has already passed Cloudflare. Browser-impersonation workarounds (curl_cffi, spoofed JA3) are not required for a clean Claude Code install talking to this endpoint.
If 1010 also hits /v1/* from python-requests / httpx, it is the same zone-wide check, not MCP-specific.
Available Tools
The MCP server exposes the public FastAPI endpoints as typed tools:
get_pricesget_implied_volatilityget_realized_volatilityget_constant_maturity_implied_volatilityget_iv_rankget_realized_vs_implied_volatilityget_volatility_skewget_option_chainget_early_exercise_analysisget_options_pair_hedgeget_hedge_ratiosget_earnings_datesget_cockpit_statisticsget_ticker_directoryget_trade_ideas
Example Claude Prompts
Use Moontower to get the latest price and 30-day IV data for SPY and QQQ.
Find high-liquidity trade ideas for SPY, QQQ, and IWM, excluding earnings in the next 4 weeks.
Compare realized volatility vs implied volatility for AAPL over the last week.
Use Moontower early exercise analysis for a TSLA 250 put expiring 2026-08-21. Is early exercise optimal?
Compute options pair hedge ratios: short QQQ 900 call vs long SPY 1010 call, both Dec 2028.
What hedge ratio do I need to hedge $1M of QQQ with SPY using Moontower hedge ratios?
Implementation Notes
The MCP server is generated from the FastAPI app with fastapi-mcp, so tool schemas and descriptions stay aligned with the OpenAPI definitions. Only public endpoint tags are exposed: Market Data, Options Data, Trade Ideas, and Reference Data.