AI agents can now place real orders on an exchange. The piece that makes it possible is called MCP. Here is what it is, how it works for trading, and the rules to set before you let any agent touch your account.
What MCP is
The Model Context Protocol (MCP) is an open standard that lets an AI model use outside tools in a uniform way. Anthropic introduced it in November 2024, OpenAI adopted it in March 2025, and in December 2025 it was handed over to the Agentic AI Foundation, under the Linux Foundation.
Before MCP, every AI application needed a custom integration for every service. With MCP, a service publishes one server that lists its tools, and any compatible AI client can use them. Think of it as a universal plug between AI models and the software around them.
What an MCP connector does for trading
For an exchange or a broker, the "tools" are the things you would otherwise do by hand: read your balance, fetch prices and candles, list your open positions, place or cancel an order, set a stop-loss.
Three parts work together:
- The AI agent decides which tool to call, and when.
- The MCP server translates each call into a request to the exchange's API.
- Your exchange account executes the order and keeps your funds.
The agent never logs in like a person. It can only do what the API key you gave it allows. That single fact is the basis of every safety rule below.
Some brokers publish official MCP servers (Alpaca does, for example). For many crypto exchanges, the servers available today are community projects. Check who maintains a server before you give it a key.
The real risk: an AI that improvises
An AI connected to an exchange can trade. The real question is what it trades. A general-purpose chatbot with order tools will open a position because the conversation felt bullish. That is not a system. It is a mood with API access.
The useful setup is the opposite. You write the rules, they get tested on market history, and the agent's only job is to check them and execute exactly. If no rule is met, there is no trade. Every order can be traced back to the rule that triggered it.
7 safety rules before you let an agent trade
- No withdrawal rights on the API key. Trading permission only. An agent never needs to move funds out.
- Lock the key to an IP address if your exchange allows it.
- Use a sub-account holding only the capital you have decided to expose.
- Enforce risk limits outside the AI: maximum position size, maximum daily loss, leverage cap. They must be enforced by code, not by the model's good intentions.
- Watch for prompt injection. Anything the agent reads (news, web pages, messages) can contain hidden instructions. An agent with order tools must never take orders from the content it reads.
- Log every order with its reason. If you cannot explain a trade, stop the agent.
- Start on a demo or testnet account when your exchange offers one.
Questions people ask
Does MCP trading mean the AI chooses the trades?
Not necessarily. MCP only gives the agent the ability to act. Whether it follows your rules or invents its own depends entirely on how the agent is built.
Is it safe?
As safe as the permissions you give it. With a key that cannot withdraw, a dedicated sub-account and hard risk limits, the worst case is bounded. Trading itself still carries a high risk of loss.
Do I need to code?
Connecting an MCP server yourself usually takes some technical setup. Tools built on top of MCP aim to hide that part.
Where Sunia fits
Sunia is built on the principle above. You describe your strategy in your own words, it becomes precise rules, those rules are backtested, then the agent trades them on your exchange or broker through an MCP connector, strictly by your rules, with every trade logged. Sunia never holds your funds, and your keys cannot withdraw.