Hosted MCP setup should use type http plus browser sign-in, with JWT and RapidAPI local OpenAPI as fallbacks. Co-authored-by: Cursor <cursoragent@cursor.com>
4.6 KiB
Security Policy
API Key Management
This skill requires API keys to access TradingView data through the Console API (api.tradingviewapi.com) or RapidAPI. Please follow these security best practices:
⚠️ Critical Security Rules
-
Never commit API keys to version control
- Do not include real API keys in configuration files that are tracked by git
- Use environment variables or secure configuration management tools
- Add configuration files with keys to
.gitignore
-
Keep your API keys private
- Do not share your API keys in public forums, chat rooms, or documentation
- Do not include API keys in screenshots or screen recordings
- Treat API keys like passwords
-
Rotate keys regularly
- If you suspect your API key has been compromised, regenerate it immediately
- Consider rotating keys periodically as a security best practice
-
Use minimal permissions
- Only use API keys with the minimum required permissions
- Monitor your API usage for unexpected activity
Data Privacy
What data is sent to external APIs
When using this skill, the following data may be sent to external services:
- TradingView API: Stock symbols, market queries, and analysis requests
- Console / RapidAPI: Authentication headers and API requests
What data is NOT sent
- Your local files and code (unless explicitly referenced in queries)
- Personal information beyond what's required for API authentication
- Conversation history (unless you explicitly include it in queries)
External Dependencies
This skill relies on the following external services:
- TradingView Data API (https://api.tradingviewapi.com) - Recommended Console host
- TradingView MCP (https://mcp.tradingviewapi.com) - MCP endpoint
- RapidAPI (https://rapidapi.com) - Alternate API gateway
These services have their own security policies and terms of service. Please review:
Reporting Security Issues
If you discover a security vulnerability in this skill, please report it by:
- Do NOT open a public GitHub issue
- Contact the maintainer directly through GitHub private message
- Provide detailed information about the vulnerability
- Allow reasonable time for the issue to be addressed before public disclosure
Security Best Practices for Users
Configuration File Security
When configuring the MCP server, prefer Console OAuth so the config file has no JWT. If you must store a JWT, keep the file private:
# Set appropriate file permissions (Unix/Linux/macOS)
chmod 600 ~/.cursor/mcp.json
OAuth (recommended — no token in the file):
{
"mcpServers": {
"tradingview": {
"type": "http",
"url": "https://mcp.tradingviewapi.com/mcp"
}
}
}
JWT fallback (do not commit the token):
{
"mcpServers": {
"tradingview": {
"type": "http",
"url": "https://mcp.tradingviewapi.com/mcp",
"headers": {
"Authorization": "Bearer ${TRADINGVIEW_MCP_TOKEN}",
"Accept": "application/json, text/event-stream"
}
}
}
}
Then set the environment variable:
export TRADINGVIEW_MCP_TOKEN="your-actual-token-here"
Older clients may use "type": "streamable-http" instead of "http". RapidAPI subscribers who are not using Console OAuth can mint a JWT via POST /api/mcp/generate, or run a local OpenAPI MCP (npx -y @ivotoby/openapi-mcp-server) with ${RAPIDAPI_KEY}.
Monitoring API Usage
Regularly check your Console or RapidAPI dashboard to:
- Monitor API call volume
- Detect unusual activity
- Stay within rate limits
- Review billing (if applicable)
Rate Limiting and Abuse Prevention
- The free tier has rate limits to prevent abuse
- Excessive requests may result in temporary blocks
- Use caching when possible to reduce API calls
- Implement exponential backoff for retries
Disclaimer
This skill is provided "as is" without warranty of any kind. Users are responsible for:
- Securing their own API keys
- Complying with terms of service of external APIs
- Understanding the risks of using third-party services
- Any investment decisions made using this tool
Investment Risk Warning: This tool is for educational and research purposes only. It does not constitute financial advice. All investment decisions are made at your own risk.
License
This security policy is part of the TradingView Quantitative Skills project and is licensed under the MIT License.