{"id":28610180,"url":"https://github.com/anirbanbasu/frankfurtermcp","last_synced_at":"2026-08-27T23:10:55.659Z","repository":{"id":297869904,"uuid":"997812241","full_name":"anirbanbasu/frankfurtermcp","owner":"anirbanbasu","description":"A MCP server for the Frankfurter API for currency exchange rates.","archived":false,"fork":false,"pushed_at":"2026-06-19T04:28:48.000Z","size":7704,"stargazers_count":6,"open_issues_count":5,"forks_count":10,"subscribers_count":0,"default_branch":"master","last_synced_at":"2026-06-19T05:24:14.476Z","etag":null,"topics":["currency-converter","currency-exchange-rates","currency-mcp","fastmcp","finance","frankfurter-api","mcp","mcp-server","model-context-protocol","model-context-protocol-server"],"latest_commit_sha":null,"homepage":"https://pypi.org/project/frankfurtermcp/","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/anirbanbasu.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":"AUTHORS.md","dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-06-07T08:31:11.000Z","updated_at":"2026-06-19T04:26:43.000Z","dependencies_parsed_at":"2025-11-28T13:05:07.779Z","dependency_job_id":null,"html_url":"https://github.com/anirbanbasu/frankfurtermcp","commit_stats":null,"previous_names":["anirbanbasu/frankfurtermcp"],"tags_count":31,"template":false,"template_full_name":null,"purl":"pkg:github/anirbanbasu/frankfurtermcp","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anirbanbasu%2Ffrankfurtermcp","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anirbanbasu%2Ffrankfurtermcp/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anirbanbasu%2Ffrankfurtermcp/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anirbanbasu%2Ffrankfurtermcp/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/anirbanbasu","download_url":"https://codeload.github.com/anirbanbasu/frankfurtermcp/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anirbanbasu%2Ffrankfurtermcp/sbom","scorecard":{"id":1244795,"data":{"date":"2026-03-12T13:29:29Z","repo":{"name":"github.com/anirbanbasu/frankfurtermcp","commit":"a42b04caa30c32aa508c0ec7ded248a14a3c03fa"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":7.3,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":7,"reason":"5 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 7","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained"}},{"name":"Code-Review","score":1,"reason":"Found 4/29 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Info: jobLevel 'packages' permission set to 'read': .github/workflows/codeql.yml:39","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:42","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:43","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:15","Info: topLevel 'contents' permission set to 'read': .github/workflows/pypi-publish.yml:8","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:21","Info: topLevel 'contents' permission set to 'read': .github/workflows/uv-pytest-coverage.yml:12","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":7,"reason":"dependency not pinned by hash detected -- score normalized to 7","details":["Warn: containerImage not pinned by hash: local.dockerfile:2: pin your Docker image by updating ghcr.io/astral-sh/uv:python3.12-trixie-slim to ghcr.io/astral-sh/uv:python3.12-trixie-slim@sha256:cab406ea74885312aa1f55a97bc7ed0fd46366643c0e17ffd002a03d7eb9e45f","Warn: containerImage not pinned by hash: local.dockerfile:25: pin your Docker image by updating python:3.12-slim-trixie to python:3.12-slim-trixie@sha256:ccc7089399c8bb65dd1fb3ed6d55efa538a3f5e7fca3f5988ac3b5b87e593bf0","Info:   8 out of   8 GitHub-owned GitHubAction dependencies pinned","Info:   7 out of   7 third-party GitHubAction dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 1 commits out of 17 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":6,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'master'","Info: 'force pushes' disabled on branch 'master'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'master'","Info: 'stale review dismissal' is required to merge on branch 'master'","Warn: required approving review count is 1 on branch 'master'","Warn: codeowners review is not required on branch 'master'","Info: 'last push approval' is required to merge on branch 'master'","Warn: no status checks found to merge onto branch 'master'","Info: PRs are required in order to make changes on branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases"}},{"name":"Contributors","score":0,"reason":"project has 0 contributing companies or organizations -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors"}},{"name":"CI-Tests","score":10,"reason":"17 out of 17 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests"}}]},"last_synced_at":"2026-03-12T17:48:34.602Z","repository_id":297869904,"created_at":"2026-03-12T17:48:34.603Z","updated_at":"2026-03-12T17:48:34.603Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36947767,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-08-27T02:00:07.166Z","response_time":96,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["currency-converter","currency-exchange-rates","currency-mcp","fastmcp","finance","frankfurter-api","mcp","mcp-server","model-context-protocol","model-context-protocol-server"],"created_at":"2025-06-11T22:41:26.208Z","updated_at":"2026-08-27T23:10:55.648Z","avatar_url":"https://github.com/anirbanbasu.png","language":"Python","funding_links":[],"categories":["📦 Other","Community Servers","Finance \u0026 Fintech","MCP Servers \u0026 Protocol"],"sub_categories":["How to Submit"],"readme":"[![Python 3.12+](https://img.shields.io/badge/python-3.12+-blue?logo=python\u0026logoColor=3776ab\u0026labelColor=e4e4e4)](https://www.python.org/downloads/release/python-3120/) [![pytest](https://github.com/anirbanbasu/frankfurtermcp/actions/workflows/uv-pytest-coverage.yml/badge.svg)](https://github.com/anirbanbasu/frankfurtermcp/actions/workflows/uv-pytest-coverage.yml) ![GitHub commits since latest release](https://img.shields.io/github/commits-since/anirbanbasu/frankfurtermcp/latest)\n [![PyPI](https://img.shields.io/pypi/v/frankfurtermcp?label=pypi%20package)](https://pypi.org/project/frankfurtermcp/#history)\n[![PyPI - Downloads](https://img.shields.io/pypi/dm/frankfurtermcp?label=pypi%20downloads)](https://pypi.org/project/frankfurtermcp/) [![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/anirbanbasu/frankfurtermcp/badge)](https://scorecard.dev/viewer/?uri=github.com/anirbanbasu/frankfurtermcp)\n\n# Frankfurter MCP\n\n[Frankfurter](https://frankfurter.dev/) is a useful API for latest currency exchange rates, historical data, or time series published by sources such as the European Central Bank. Should you have to access the Frankfurter API as tools for language model agents exposed over the Model Context Protocol (MCP), Frankfurter MCP is what you need.\n\n# Installation\n\n_If your objective is to use the tools available on this MCP server, please refer to the usage \u003e client sub-section below_.\n\nThe directory where you clone this repository will be referred to as the _working directory_ or _WD_ hereinafter.\n\nInstall [just](https://just.systems/man/en/) to manage project tasks.\n\nInstall [uv](https://docs.astral.sh/uv/getting-started/installation/). To install the project with its minimal dependencies in a virtual environment, run the `just install` in the _WD_. To install all non-essential dependencies (_which are required for developing and testing_), run `just install-all` instead.\n\n## Environment variables\n\nFollowing is a list of environment variables that can be used to configure the application. A template of environment variables is provided in the file `.env.template`. _Note that the default values listed in the table below are not always the same as those in the `.env.template` file_.\n\nThe following environment variables can be specified, prefixed with `FASTMCP_`: `HOST`, `PORT`, `DEBUG` and `LOG_LEVEL`.\n\nThe underlying HTTP client also respects some environment variables, as documented in [the HTTPX library](https://www.python-httpx.org/environment_variables/). In addition, `SSL_CERT_FILE` and `SSL_CERT_DIR` can be configured to use self-signed certificates of hosted API endpoint or intermediate HTTP(S) proxy server(s).\n\nFrankfurter MCP will cache calls to the Frankfurter API to improve performance. The cache happens with two different strategies. For API calls whose responses do not change for certain parameters, e.g., historical rate lookup, a least recently used (LRU) cache is used. For API calls whose responses do change, e.g., latest rate lookup, a time-to-live (TTL) cache is used with a default time-to-live set to 15 minutes. The cache parameters can be adjusted using the environment variables, see below.\n\n| Variable |  [Default value] and description   |\n|--------------|----------------|\n| `LOG_LEVEL` | [INFO] The level for logging. Changing this level also affects the log output of other dependent libraries that may use the same environment variable. See valid values at [Python logging documentation](https://docs.python.org/3/library/logging.html#logging-levels). |\n| `HTTPX_TIMEOUT` | [5.0] The time for the underlying HTTP client to wait, in seconds, for a response from the Frankfurter API. The acceptable range of values is between 5.0 and 60.0. |\n| `HTTPX_VERIFY_SSL` | [True] This variable can be set to False to turn off SSL certificate verification, if, for instance, you are using a proxy server with a self-signed certificate. However, setting this to False _is advised against_: instead, use the `SSL_CERT_FILE` and `SSL_CERT_DIR` variables to properly configure self-signed certificates. |\n| `FAST_MCP_HOST` | [localhost] This variable specifies which host the MCP server must bind to unless the server transport (see below) is set to `stdio`. _Note that running the server to bind to any IP by specifying `0.0.0.0` poses a security threat. Such a setting should only be used in demo environments._|\n| `FAST_MCP_PORT` | [8000] This variable specifies which port the MCP server must listen on unless the server transport (see below) is set to `stdio`. |\n| `CORS_MIDDLEWARE_ALLOW_ORIGINS` | [\"localhost\", \"127.0.0.1\"] This variable specifies [Cross-Origin Resource Sharing (CORS)](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS) allowed origins for the MCP server unless the server transport (see below) is set to `stdio`. You **must** set it to \"*\" explicitly (and you will get a warning by doing so) if you want to test this server over an HTTP transport using [the MCP inspector described below](https://github.com/anirbanbasu/frankfurtermcp?tab=readme-ov-file#the-official-mcp-visual-inspector). |\n| `MCP_SERVER_TRANSPORT` | [stdio] The acceptable options are `stdio`, `sse` or `streamable-http`. However, in the `.env.template`, the default value is set to `stdio`. |\n| `MCP_SERVER_INCLUDE_METADATA_IN_RESPONSE` | [True] This specifies if additional metadata will be included with the MCP  response from each tool call. The additional metadata, for example, will include the API URL of the Frankfurter server, amongst others, that is used to obtain the responses. |\n| `FRANKFURTER_API_URL` | [https://api.frankfurter.dev/v1] If you are [self-hosting the Frankfurter API](https://hub.docker.com/r/lineofflight/frankfurter), you should change this to the API endpoint address of your deployment. |\n| `LRU_CACHE_MAX_SIZE` | [1024] The maximum size of the least recently used (LRU) cache for API calls. The acceptable range of values is between 128 and 65536. |\n| `TTL_CACHE_MAX_SIZE` | [256] The maximum size of the time-to-live (TTL) cache for API calls. The acceptable range of values is between 64 and 16384. |\n| `TTL_CACHE_TTL_SECONDS` | [900] The time limit, in seconds, of the time-to-live (TTL) cache for API calls. The acceptable range of values is between 60 and 3600. |\n| `UVICORN_LIMIT_CONCURRENCY` | [100] The maximum number of concurrent connections the server will accept. This helps prevent resource exhaustion from too many simultaneous connections. Only applies when using HTTP transports (`sse` or `streamable-http`). The acceptable range of values is between 10 and 10000. |\n| `UVICORN_TIMEOUT_KEEP_ALIVE` | [60] The timeout in seconds for keeping idle connections alive. Idle connections will be closed after this period to free up resources. Only applies when using HTTP transports (`sse` or `streamable-http`). The acceptable range of values is between 60 and 300. |\n| `UVICORN_TIMEOUT_GRACEFUL_SHUTDOWN` | [5] The timeout in seconds for graceful shutdown. The server will wait this long for active connections to complete before forcefully shutting down. Only applies when using HTTP transports (`sse` or `streamable-http`). The acceptable range of values is between 5 and 60. |\n| `RATE_LIMIT_MAX_REQUESTS_PER_SECOND` | [10.0] The maximum number of requests allowed per second using a token bucket algorithm. This implements rate limiting to prevent API abuse and ensure fair resource allocation. The acceptable range of values is between 1.0 and 10000.0. |\n| `RATE_LIMIT_BURST_CAPACITY` | [20] The burst capacity for the rate limiter, allowing short bursts of requests above the per-second limit. This provides flexibility for legitimate usage patterns while still protecting against sustained high request rates. The acceptable range of values is between 2x and 5x the `RATE_LIMIT_MAX_REQUESTS_PER_SECOND` value. |\n| `REQUEST_SIZE_LIMIT_BYTES` | [102400] The maximum size in bytes for HTTP request bodies (default 100KB). Requests exceeding this limit will be rejected with a 413 status code. This prevents memory exhaustion attacks from large payloads. Only applies when using HTTP transports (`sse` or `streamable-http`). The acceptable range of values is between 10240 (10KB) and 524288 (512KB). |\n| `DOCKER_TMPFS_SIZE_MB` | [100] The size in megabytes for the temporary filesystem (`/tmp`) when running in Docker with read-only root filesystem. This temporary storage is used for runtime file operations. Increase this value if the application requires more temporary storage for caching or processing large datasets. Only relevant when deploying with Docker Compose. |\n\n# Usage\n\nThe following sub-sections illustrate how to run the Frankfurter MCP as a server and how to access it from MCP clients.\n\n## Server\nWhile running the server, you have the choice to use `stdio` transport or HTTP options (`sse` or the newer `streamable-http`).\n\nUsing default settings and `MCP_SERVER_TRANSPORT` set to `sse` or `streamable-http`, the MCP endpoint will be available over HTTP at [http://localhost:8000/sse](http://localhost:8000/sse) for the Server Sent Events (SSE) transport, or [http://localhost:8000/mcp](http://localhost:8000/mcp) for the streamable HTTP transport.\n\nIf you want to run Frankfurter MCP with `stdio` transport and the default parameters, execute the commands below without using the `.env.template` file.\n\n### Server with `uv`\n\n_Optional_: Copy the `.env.template` file to a `.env` file in the _WD_, to modify the aforementioned environment variables, if you want to use anything other than the default settings. Or, on your shell, you can export the environment variables that you wish to modify.\n\nRun the following in the _WD_ to start the MCP server.\n\n```bash\nuv run frankfurtermcp\n```\n\n### Server with `pip` from PyPI package\n\nAdd this package from PyPI using `pip` in a virtual environment (possibly managed by `uv`, `pyenv` or `conda`) and then start the server by running the following.\n\n_Optional_: Add a `.env` file with the contents of the `.env.template` file if you wish to modify the default values of the aforementioned environment variables. Or, on your shell, you can export the environment variables that you wish to modify.\n\n```bash\npip install frankfurtermcp\npython -m frankfurtermcp.server\n```\n\n### Server using Docker\n\nThere is a Dockerfile provided in this repository, `local.dockerfile`, for containerising the Frankfurter MCP server. First, make a copy of the `.env.template` to a `.env` file. Then, modify the following variables in the `.env` file as needed.\n\n - `FASTMCP_HOST`: Set to `0.0.0.0` to allow external access to the container. _This is only for local testing and is not recommended for production deployments_.\n - `CORS_MIDDLEWARE_ALLOW_ORIGINS`: Set to `*` to allow external access to the MCP server from any origin. _This is needed if you want to test the server using the MCP Inspector over HTTP transport and is not recommended for production deployments_.\n\nTo build the image, create the container and start it using Docker Compose, run the following in _WD_.\n\nIf you change the port to anything other than 8000 in `.env`, _do remember to change the port number in `docker-compose.yml`_.\n\n**Note**: The minimum Docker Compose version needed is 2.24.0. You can check your version by running `docker compose version`. If you have an older version, please update Docker Desktop to get the latest Docker Compose. In addition, the backend must be BuildKit capable.\n\n```bash\ndocker compose up --build\n```\n\nTo run in detached mode (background), add the `-d` flag:\n\n```bash\ndocker compose up -d --build\n```\n\nTo stop the container:\n\n```bash\ndocker compose down\n```\n\nTo run the container and use the local Frankfurter API server, run the following command. Attach the `-d` flag to run in detached mode. Check the `local_api.env.template` file to specify the optional environment variables used by the local API server.\n\n**Note**: Upon starting the first time, the local Frankfurter API may need some time to fetch updated exchange rates. For subsequent runs, the local Frankfurter API will use cached data and should be faster to start although it will still fetch the latest rates.\n\n\n```bash\nFRANKFURTER_API_URL=http://frankfurter_api:8080/v1 docker compose --profile local_api up --build frankfurtermcp frankfurter_api\n```\n\nTo stop the container group created with the `local_api` profile, run the following command.\n\n```bash\ndocker compose --profile local_api down\n```\n\nThe `docker-compose.yml` file includes security hardening with read-only filesystem (where relevant), dropped capabilities and resource limits.\n\n**Note**: The local API server is built using the latest code from the [Frankfurter GitHub repository](https://github.com/lineofflight/frankfurter), hence this may be unstable. If you want to use a specific commit, change the `context` field for `build` under `frankfurter_api_base` in the `docker-compose.yml` file to point to the specific commit hash, e.g., `https://github.com/lineofflight/frankfurter.git#0b6dbd80716f5abe27e8759fc548b74d35fa82b9` to use commit `0b6dbd80716f5abe27e8759fc548b74d35fa82b9`.\n\nUpon successful build and container start, the MCP server will be available over HTTP at [http://localhost:8000/sse](http://localhost:8000/sse) for the Server Sent Events (SSE) transport, or [http://localhost:8000/mcp](http://localhost:8000/mcp) for the streamable HTTP transport. If you are also starting the local Frankfurter API server, the API endpoint will be available at [http://localhost:8080/v1](http://localhost:8080/v1).\n\n### Cloud hosted servers\n\nThe currently available cloud hosted options are as follows.\n\n - FastMCP Cloud: https://frankfurtermcp.fastmcp.app/mcp\n - Glama.AI: https://glama.ai/mcp/servers/@anirbanbasu/frankfurtermcp\n\n\n## Client access\n\nThis sub-section explains ways for a client to connect and test the FrankfurterMCP server.\n\n### The official MCP visual inspector\n\nThe [MCP Inspector](https://github.com/modelcontextprotocol/inspector) is an _official_ Model Context Protocol tool that can be used by developers to test and debug MCP servers. This is the most comprehensive way to explore the MCP server.\n\nTo use it, you must have Node.js installed. The best way to install and manage `node` as well as packages such as the MCP Inspector is to use the [Node Version Manager (or, `nvm`)](https://github.com/nvm-sh/nvm). Once you have `nvm` installed, you can install and use the latest Long Term Release version of `node` by executing the following.\n\n```bash\nnvm install --lts\nnvm use --lts\n```\n\nFollowing that (install and) run the MCP Inspector by executing the following in the _WD_.\n\n```bash\nnpx @modelcontextprotocol/inspector uv run frankfurtermcp\n```\n\nThis will create a local URL at port 6274 with an authentication token, which you can copy and browse to on your browser. Once on the MCP Inspector UI, press _Connect_ to connect to the MCP server. Thereafter, you can explore the tools available on the server.\n\n### Claude Desktop, Visual Studio, and so on\n\nThe server entry to run with `stdio` transport that you can use with systems such as Claude Desktop, Visual Studio Code, and so on is as follows.\n\n```json\n{\n    \"command\": \"uv\",\n    \"args\": [\n        \"run\",\n        \"frankfurtermcp\"\n    ]\n}\n```\n\nOr, using `uvx`:\n\n```json\n{\n    \"command\": \"uvx\",\n    \"args\": [\n        \"frankfurtermcp\"\n    ]\n}\n```\n\nInstead of having `frankfurtermcp` as the last item in the list of `args`, you may need to specify the full path to the script, e.g., _WD_`/.venv/bin/frankfurtermcp`. Likewise, instead of using `uv`, you could also have the following JSON configuration with the path properly substituted for `python3.12`, for instance such as _WD_`/.venv/bin/python3.12`.\n\n```json\n{\n    \"command\": \"python3.12\",\n    \"args\": [\n        \"-m\",\n        \"frankfurtermcp.server\"\n    ]\n}\n```\n\n# List of available MCP features\n\nFrankfurterMCP has the following MCP features.\n\n## Tools\n\nThe following table lists the names of the tools as exposed by the FrankfurterMCP server. The descriptions shown here are for documentation purposes, which may differ from the actual descriptions exposed over the model context protocol.\n\n| Name         |  Description   |\n|--------------|----------------|\n| `get_supported_currencies` | Get a list of currencies supported by the Frankfurter API. |\n| `get_latest_exchange_rates` | Get latest exchange rates in specific currencies for a given base currency. |\n| `convert_currency_latest` | Convert an amount from one currency to another using the latest exchange rates. |\n| `get_historical_exchange_rates` | Get historical exchange rates for a specific date or date range in specific currencies for a given base currency. |\n| `convert_currency_specific_date` | Convert an amount from one currency to another using the exchange rates for a specific date. |\n| `greet` | Get a greeting from the FrankfurterMCP server. _This is mostly used for internal testing_. |\n\nThe required and optional arguments for each tool are not listed in the following table for brevity but are available to the MCP client over the protocol.\n\n# Contributing\n\nInstall [`prek`](https://prek.j178.dev/). Then enable `prek` by running the following in the _WD_.\n\n```bash\nprek install\n```\nPull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.\n\n# Testing and coverage\n\nTo run the provided test cases, execute the following. Add the flag `--capture=tee-sys` to the command to display further console output.\n\n```bash\nuv run --group test pytest tests/\n```\n\nInvoke `just test-coverage` to run all the tests and generate a coverage report as follows. If all tests are run, the generated coverage report may look like the one below.\n\n```bash\n---------------------------------------------------------------------------------------- benchmark: 2 tests ---------------------------------------------------------------------------------------\nName (time in ms)                         Min               Max              Mean            StdDev            Median               IQR            Outliers       OPS            Rounds  Iterations\n---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------\ntest_get_historical_exchange_rates     4.4944 (1.0)      5.1512 (1.0)      4.7919 (1.0)      0.2460 (1.0)      4.7819 (1.0)      0.3249 (1.0)           2;0  208.6840 (1.0)           5           1\ntest_get_latest_exchange_rates         4.7937 (1.07)     5.6976 (1.11)     5.3257 (1.11)     0.3345 (1.36)     5.4182 (1.13)     0.3575 (1.10)          2;0  187.7702 (0.90)          5           1\n---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------\n\nLegend:\n  Outliers: 1 Standard Deviation from Mean; 1.5 IQR (InterQuartile Range) from 1st Quartile and 3rd Quartile.\n  OPS: Operations Per Second, computed as 1 / Mean\n=============================================================== 15 passed in 4.09s ===============================================================\nName    Stmts   Miss    Cover   Missing\n---------------------------------------\nTOTAL     265      0  100.00%\n\n6 files skipped due to complete coverage.\nTest coverage complete.\n```\n\n# License\n\n[MIT](https://choosealicense.com/licenses/mit/).\n\n# Security considerations\n\nThis section documents security-related findings from vulnerability scans and provides context for deployment decisions.\n\n## Airtable vulnerability scan findings and rationale\n\nCheck for security-related findings from [the Airtable vulnerability scan](https://airtable.com/appXjXF6ejJL028Rl/shrwBNQSIDMCo00jO) (search for `frankfurtermcp`) below, along with rationale and counter-arguments.\n\n| Rule ID | Issue and counter arguments |\n|----------------------|-------------------|\n| MCP-R001 | **Issue**: Tools are registered dynamically at server startup without cryptographic signatures, immutable versioning, or integrity checks. The architecture permits hot-reload scenarios (via `register_features` pattern), but no signature verification or approval flow exists.\u003cbr/\u003e\u003cbr/\u003e**Counter arguments**: Tools are not loaded from external sources or plugins—they are defined directly in the application source code. Integrity is ensured through version control and code review processes. Since tools are part of the application binary (not dynamically loaded plugins), cryptographic signing would add complexity without meaningful security benefit. |\n| MCP-R004 | **Issue**: The server warns but accepts wildcard in CORS origins.\u003cbr/\u003e\u003cbr/\u003e**Counter arguments**: This server is not intended to be run directly in a production environment when using HTTP transports. _For deployments with stricter CORS origin control, users should use the `.env.template` defaults (`127.0.0.1`) and deploy the server behind their own reverse proxy with appropriate CORS origin controls at the reverse proxy level_. |\n| MCP-R013 | **Issue**: There is no support for HTTPS when the server binds to any IP other than 127.0.0.1.\u003cbr/\u003e\u003cbr/\u003e**Counter arguments**: This server is not intended to be run directly in a production environment with HTTPS support when using HTTP transports. _For deployments requiring HTTPS support, users should use the `.env.template` defaults (`127.0.0.1`) and deploy the server behind their own reverse proxy with appropriate HTTPS configuration_. |\n| MCP-R018 | **Issue**: There are no authentication or authorisation checks.\u003cbr/\u003e\u003cbr/\u003e**Counter arguments**: This server is not intended to be run directly in a multi-user mode of operation when using HTTP transports. _For deployments with access control, users should use the `.env.template` defaults (`127.0.0.1`) and deploy the server behind their own reverse proxy with appropriate security controls_. |\n\n# Project status\n\nThe current status of the project is **active** as of the last update of this README. See the [CHANGELOG](CHANGELOG.md) for a detailed list of changes.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanirbanbasu%2Ffrankfurtermcp","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fanirbanbasu%2Ffrankfurtermcp","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanirbanbasu%2Ffrankfurtermcp/lists"}