Appearance
Are you an LLM? You can read better optimized documentation at /mcp/security.md for this page in Markdown format
MCP Security, Privacy & Limits
Connecting an AI client to your trading account is a big step, so this page spells out exactly what that connection can and cannot do. The short version: the connector can read your TTMT data to answer your questions, and nothing more. It has no way to touch your money, your trades, or anyone else's account.
Read this before you connect. If you run into a problem while connecting, the MCP troubleshooting page walks through the common failures.
The read-only guarantee
The single most important thing to understand about the TTMT connector is that it is strictly read-only.
Read-only, always
The connector lets your AI assistant look at your trading data — trades, positions, performance, settings, channels, risk status. It can never place a trade, modify a trade, close a position, cancel an order, change a setting, or move funds. There is no "write" capability in the connector at all — not hidden, not optional, not coming later without you knowing. Even if you (or the AI) ask it to place a trade, it simply cannot.
This is not a policy you have to trust us to enforce by hand — it is how the connector is built. Every one of its tools only reads. There is no button, command, or trick that turns it into something that acts on your account. When you ask "If I got a XAUUSD BUY signal now, what would my order plan look like?", the connector calculates the answer on paper and shows it to you. No order is ever placed.
Your data stays yours. The connector only ever sees the data belonging to the account you signed in with. It cannot see another user's trades, signals, accounts, or settings — the same isolation that protects your data in the dashboard applies here.
How signing in works
You never paste a password, an API key, or any secret into your AI client to use the connector. Instead, you sign in the same way you sign in to the dashboard, and you approve exactly what the client is allowed to do.
Here is the whole flow, in plain terms:
- You add the connector URL in your AI client.
- Your client opens a TTMT sign-in page.
- You sign in with your normal TTMT account.
- You see a consent screen that names the app asking for access and the read-only permission it wants. You click Allow.
- That's it — your client is connected.
There is no separate MCP password to remember and no key to copy around. The sign-in is handled by the same secure standard (OAuth) that trusted "Sign in with…" buttons use across the web.
Every request is re-checked
Access is verified on every single request your AI client makes — there is no long-lived session sitting open in the background. If your access is ever turned off, the very next question your client asks will stop working. Nothing keeps running on stale permission.
The Developer API exposes related read-only data, but uses separately managed API keys and a separate access policy. MCP uses OAuth consent; you do not need to mint a Developer API key.
Revoking access whenever you want
You are always in control of the connection, and you can end it at any time.
You revoke access from your AI client's connector settings — for example, in Claude under Settings → Connectors, or from ChatGPT's connection settings, remove or disconnect the TTMT connector. Once you do, the connection is dead: the next request is rejected, and your client can no longer read your data until you connect and approve again.
TTMT never quietly reconnects a connector you removed. Disconnecting is your decision and it sticks.
The 60 requests/minute limit
To keep the service fast and fair for everyone, each user can make up to 60 requests per minute through the connector.
A single question you type usually turns into a small handful of requests behind the scenes (the AI gathers the data it needs to answer you), so this limit is generous for normal back-and-forth conversation. The limit is counted per user, shared across all your MCP clients — if you have the connector set up in two different apps at once, they draw from the same 60-per-minute budget.
A rate-limit can look like a sign-in problem
There is a known quirk worth knowing about. If you hit the 60-per-minute limit, your AI client may report it as a sign-in or authorization failure rather than a clear "you're going too fast, slow down" message. If your connector was working fine and suddenly complains about access right after a burst of rapid questions, you have almost certainly just hit the rate limit — wait a minute and try again. See MCP troubleshooting for how to tell this apart from a genuine access problem.
Daily limits by plan
The per-minute limit above keeps bursts fair. Separately, how much you can use the connector per day depends on your plan.
- Essential plan — a daily allowance of about 25 tool calls (roughly three questions), counted per day and reset at midnight UTC. A single question usually spends a few tool calls, so this suits light, occasional use.
- Pro and higher plans — unlimited MCP usage, with no daily cap.
The count isn't limited to tools you explicitly call. Reading the settings schema, one setting or one guide counts against the same allowance. The glossary, account resource, trade resource and channel resource are uncounted; calling their corresponding tools still counts.
When you reach the Essential daily allowance, counted calls return a message explaining the limit and reset. You can wait or review your upgrade options. With the experimental market extension enabled, show_analysis remains available for inspecting an existing result without another daily charge; it cannot start a new calculation. New history and replay calls, including follow-ups, count normally.
Rolling out
Like the rest of the connector, MCP access and these plan limits are enabled per account as the feature rolls out. You can change plans any time from your billing settings.
Account access
MCP and the Developer API do not share an identical access policy. An explicit account grant permits MCP access. Where subscription-based MCP access is enabled, active or grace-period service status also qualifies. Developer API access remains separately granted.
Availability
Valid sign-in alone is not sufficient. If consent or tool calls fail, message support to check account enablement, subscription status and the current rollout. Enabling the experimental market extension does not grant account access.
Access denial and the per-minute limit can both resemble an authentication failure. Check the URL, consent, client compatibility and timing before concluding that your password is wrong.
Experimental market-analysis privacy
Market analysis keeps LSE credentials on TTMT’s server. The external provider receives instrument and time-window requests, not your trade trace or account credentials. Your AI client receives the authorized analysis data you request; its own data-handling policy still applies.
Private analysis results have a maximum 30-minute lifetime and can disappear earlier on eviction or restart. Every inspection rechecks your access and the underlying records. The optional viewer has no direct LSE or dashboard-cookie access and cannot calculate new scenarios itself. Recorded trace fields are allowlisted; raw secrets and broker identifiers are not part of the replay viewer’s evidence. Expiry does not erase copies already returned to your AI client or downloaded by you.
Quick reference
| Question | Answer |
|---|---|
| Can it place, close, or modify a trade? | No — read-only, always. |
| Can it move funds? | No. |
| Can it see other users' data? | No — only the account you signed in with. |
| Do I paste a password or API key? | No — you sign in and approve a consent screen (OAuth). |
| Is there a long-lived session? | No — access is re-checked on every request. |
| How do I disconnect? | From your AI client's connector settings, any time. |
| Rate limit? | 60 requests per minute, per user, shared across all your clients. |
| Daily limit? | Essential plan: ~25 tool calls/day (about 3 questions), reset at midnight UTC. Pro and higher: unlimited. |
| What do I need to connect? | A TTMT account admitted by the current MCP access policy, OAuth consent and a compatible client. |
Related pages
- API Authentication — the Developer API’s separate key and access model.
- MCP Troubleshooting — fixing connection failures, including the rate-limit-looks-like-auth quirk.

