Undertow

Read-only market-liquidity research with exit-cost context, market depth and sealed evidence records, without trade execution.

Documentation

Undertow MCP | Market liquidity and exit-cost tools

Endpoint: https://api.seiche.info/undertow/mcp (streamable HTTP, no install)

Try it live: liquilens-undertow.com/developers · API catalog: api.seiche.info/undertow

Undertow exposes estimated exit cost by position size and venue, the concentration of quoted depth, realized depth-collapse episodes, and liquidity tiers across market segments. This MCP 1.10.0 endpoint exposes 18 read-only tools, split into 10 public and 8 subscriber tools, plus 3 guided prompts. Its capability inventory is pinned to liquilens-undertow commit 9d1fedc28dca133fe6f9e018af1e381e247b8c9b, the hosted implementation at deploy/hetzner/undertow-mcp. The stdio discovery server in undertow_mm/mcp_server.py is a separate discovery surface; it is neither this registry listing nor the public stdio adapter provided here.

Add it

Claude Code:

claude mcp add --transport http undertow https://api.seiche.info/undertow/mcp

Claude.ai / ChatGPT / Cursor: add a custom connector or MCP server with the URL above. No key and no wallet for the free surface.

This repository contains the discovery manifest, documentation and an optional anonymous stdio adapter for the hosted service. The official registry serves io.github.beepboop2025/undertow version 1.10.0.

Local stdio and container installation

The direct hosted URL above remains the simplest connection. For clients that require stdio, clone this repository at a reviewed commit and use Python 3.12+ and uv:

uv sync --locked
uv run --locked undertow-mcp

A Claude Desktop configuration can use uv as its command and ["run", "--directory", "/absolute/path/to/undertow-mcp", "--locked", "undertow-mcp"] as its arguments. The stdio adapter exposes only the 10 anonymous tools and three prompts; subscriber access uses the direct hosted URL instead.

For Docker and Glama's container build:

docker build -t undertow-mcp .
docker run --rm -i undertow-mcp

The root Dockerfile runs as an unprivileged user and starts stdio directly. No API key, bearer token, wallet, port, volume or environment setting is needed. Outbound HTTPS access to the fixed api.seiche.info endpoint is required. Redirects, environment proxies and arbitrary upstream URLs are disabled. Requests are capped at 64 KiB, responses at 2 MiB, and each upstream operation at 10 seconds including queue wait. No automatic retries or response cache can hide outages or spend a quota twice. Upstream version/catalog drift fails closed. Tool results, native isError values and rights refusals are preserved.

A Glama maintainer can configure the root Dockerfile, complete its build test, and publish a Glama release from the listing's admin page. A GitHub commit or release does not create a Glama release. This repository does not claim a grade until Glama has actually rescanned and inspected it. See Glama's release guide.

Hosted protocol compatibility

  • 2026-07-28: stateless requests use server/discover, per-request _meta, MCP-Protocol-Version, and mirrored Mcp-Method / Mcp-Name routing headers.
  • 2025-11-25, 2025-06-18, and 2025-03-26: retained legacy initialization, tools, prompts, notifications, batching, and ping behavior.
  • Discovery identifies all ten public and eight subscriber tools. Anonymous tools/list returns only the public inventory; entitlement is checked fresh on every subscriber request.
  • resources/list and resources/templates/list return explicit empty catalogs. resources/read returns a not-found error and never invents a resource.

Example

In the snapshot generated at 2026-08-08T15:01:22Z, selling $1,000,000 of BTC at the selected $1,000,000 published size rung cost 2.386 bp on Binance and 13.623 bp on Bitfinex: about $238.60 against $1,362.30. Gemini was the dearest observed venue in that same snapshot at 25.852 bp, or about $2,585.20.

Venue rankings can change during the day, and those differences are not visible in a single consolidated price. Undertow publishes the observation time and venue inputs with the estimate.

Tools

ToolWhat it servesSurface
agent_access_statusYour current tier, daily meter, grants, and the exact route to Agent or Desk accessfree
board_fullEvery measure with its stress percentile or ACCRUING label, limits and analyst notesubscriber
corporate_transmissionWhether funding stress is reaching nonfinancial firmssubscriber
depth_episodesRealized depth-collapse episodes with onset, trough, drawdown and recovery, against thresholds declared before any episode accruedfree
divergence_statusCompact comparison of corporate and household transmission regimessubscriber
exit_costPer-venue sell cost in basis points at the nearest published size rung, cheapest and dearest venue with approximate dollar cost, and the venue spreadfree
exit_desk_fullBTC and ETH at every published rung, plus the venue-failure withdrawal scenariosubscriber
exit_schedulePosition-sized hour-by-hour liquidation schedule beside immediate and TWAP baselinessubscriber
household_creditWhether funding stress is reaching household balance sheetssubscriber
latest_articleThe exact reviewed daily market-liquidity editorial with its evidence clock and publication authorityfree
liquidity_tiersA liquidity tier per market segment (UST, IG, HY, equities, ETF, FX, China basin, crypto) with the funding-stress overlayfree
sealed_recordThe sealed forward-calls record, hash-chained and signed before outcomes, misses keptfree
tide_clockClock-phase liquidity map and exit-cost-by-phase for BTC or ETH perpetualssubscriber
trade_safety_exit_contextExact-rung BTC/USD sell context with request, PIT, rights, clock and depth checks; unavailable inputs remain unavailable, never order clearancefree
unwind_stressFull institutional unwind and forced-sale stress packsubscriber
unwind_watchBanded public watch over institutional unwind time and forced-sale pressure, with exact sensitive quantities withheldfree
venue_concentrationThe BTC depth backbone: top venue share of aggregate depth, HHI, effective venue count, per-venue depth in USDfree
venue_price_reconciliationA consensus mark weighted by resting depth over squared half-spread, plus the gap between the deepest venue and consensusfree

Prompts

PromptGuided playbook
can_this_book_exitCompare watched-book door width, unwind horizon, margin clock, venue concentration, and realized depth collapses
exit_cost_checkPrice a position-sized exit across venues and identify the observed depth limitations
market_liquidity_briefingRead the market-level liquidity board, funding overlay, concentration, and current exit-cost evidence together

Commodity futures are intentionally absent from that table. Undertow has no licensed point-in-time depth by contract month, venue and session, so executable commodity exit cost is CANNOT_ASSESS_EXECUTABLE_EXIT_COST; open interest or daily volume is never substituted. For aggregate WTI/Henry Hub cash pressure, Cushing and benchmark structure, call Seiche's public oil_funding_context or use /oil in @seiche_desk_bot.

Limitations

  • PARTIAL is not calm. A segment reads PARTIAL when fewer than two of its measures have earned a scoring history. Four of nine segments read PARTIAL on 2026-07-30, and the board says so instead of guessing.
  • Exit costs are estimates, interpolated from published quote depth at the 1% and 2% bands. Never a book walk. The snapshot refreshes roughly hourly, so it is a snapshot and not a real-time feed.
  • Crypto measures are still accruing, so the board has not earned a crypto stress percentile and you should never quote one from it.
  • The sealed record includes misses. Calls are hash-chained and signed before their outcomes are knowable, then scored against the point-in-time board.
  • Commodity execution is a declared coverage gap. Ballast is useful upstream context from Seiche, not a depth ladder and not an Undertow exit-cost estimate.

Research and market data, not investment advice.

Subscriber tier

The Agent and Desk tiers unlock the eight subscriber tools. Send /agent to the Telegram bot to mint a bearer token:

{
  "mcpServers": {
    "undertow": {
      "url": "https://api.seiche.info/undertow/mcp",
      "headers": { "Authorization": "Bearer YOUR_TOKEN" }
    }
  }
}

The token proves identity only. Entitlement is re-read from live membership on every call, so access stops when the subscription does rather than when the token expires. Subscriber tools are invisible to an anonymous tools/list, and agent_access_status tells you where you stand.

Only tools/call is metered, reported on X-MCP-Usage-Used, X-MCP-Usage-Limit and X-MCP-Usage-Remaining. GET /undertow/mcp/usage is the self-meter. Hitting a quota returns a normal JSON-RPC result carrying isError and an upgrade pointer, never a dropped connection.

About this repository

This repo is the listing: a README and the two manifests that let directories describe the server accurately. The server itself is hosted at the endpoint above; its source is deploy/hetzner/undertow-mcp in the Undertow product repository and the registry target remains hosted 1.10.0. The adapter forwards the native public schemas and results without computing market values or granting subscriber access. Its own version is 0.1.0; the upstream contract is 1.10.0.

Verification and deployment boundary

The verification workflow validates the exact 40-character releaseCommit in contract.json against the immutable source receipt in source-receipt.json. The receipt binds that commit and contract to SHA-256 digests of the hosted implementation and registry manifest without granting this public repository access to the private product repository. A maintainer creates or updates the receipt only after running the local pinned-core verifier against a clean checkout; that verifier derives the public/subscriber split, prompt inventory, protocol versions, server identity and registry manifest directly from the source and checks both artifact digests. A branch name or current product-repository HEAD is never accepted as release provenance.

A separate scheduled and manually dispatchable smoke makes anonymous, read-only calls to the listed endpoint. It initializes the legacy protocol, exercises modern discovery, checks the public tools, subscriber advertisement, prompts and explicit empty resource catalogs, then calls agent_access_status. It does not use a bearer token or exercise a subscriber tool. Run the same checks locally with:

uv run --locked python -m unittest discover -s tests -v
python3 scripts/verify_core_pin.py --receipt
python3 scripts/verify_core_pin.py --core /path/to/exact/core/checkout
python3 scripts/smoke_live_mcp.py

The source pin is a reviewed contract boundary, not an HTTP deployment receipt. Undertow's release controller records the deployed SHA and append-only receipts on the host, while the public MCP response currently reports its semantic version and capability catalog but no exact Git commit. Therefore a green live smoke proves the published behavior, not that the host runs this exact SHA. Do not repin this listing from a matching version or catalog alone; require the host's exact successful deployment receipt (or an equivalent authenticated SHA attestation) first.

Siblings from the same lab

  • Seiche: US dollar funding stress.
  • LiquiLens: bank, NBFC and lender failure risk, and whether that stress is reaching firms and households.
  • groundcheck: claim grounding and citation verification for general text.
  • Palimpsest: live internet-censorship signals.

Human front door: liquilens-undertow.com and the Telegram desk.

License

The original public integration code and documentation in this repository are MIT licensed. See NOTICE.md for scope: this grant does not cover the private Undertow service or third-party market data. Native access controls, evidence limitations and source-rights holds still apply.