Affinity
Search your CRM, prep for meetings and update deal records from your AI assistant.
Screen public equities for accounting, fraud and management red flags.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Canary Data MCP server connects Canary's public-equity red-flag research to Claude, ChatGPT and any MCP-compatible agent. It screens the global listed universe for accounting, fraud, insider-trading and management-track-record warning signs, then drills into any company by ticker. Everything it does is a read. Sign-in is OAuth 2.0 with PKCE.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
new_accounting_issue. The name is real, but a reader working from the directory would miss the universe screen, the KPI history, the analyst plans and the 13F surface entirely.accounting_waterfall, business_quality and fundamentals_metrics scopes are advertised by the server with no published description, parameters or response shape. What they return is unknown to us.readOnlyHint or destructiveHint values exist on this page.grant_types_supported advertises password alongside authorization_code and refresh_token. The resource-owner password credentials grant is deprecated in OAuth 2.1 and hands a user's actual password to the client. MCP clients use the authorization-code flow, so this does not affect a Claude connection, but it is a broader surface than the connector itself needs./register returned 404 on 2026-08-22, and the authorization-server metadata declares no registration_endpoint. Clients that require DCR-based OAuth may not be able to complete sign-in without a pre-registered client.flag_screen. Long-horizon questions need several calls or an explicit since date.kpi_snapshot returns only the newest value per metric across both source types. Canary documents this and the document_type filter that fixes it, but an agent that does not pass the filter can quietly report a podcast number as the latest reported figure.Retry-After. A universe screen followed by per-company drill-downs across many rows will reach that quickly.Twenty-six, on the best available evidence. Anthropic's directory lists one. Canary's own documentation describes sixteen. The server's OAuth protected-resource descriptor, read on 2026-08-22, advertises twenty-six scopes named one-per-tool. The descriptor is the server speaking about itself, so it is the strongest of the three enumerations.
No. Anthropic's directory records the connector's permissions as read only, and every one of the twenty-six scopes the server advertises names a retrieval operation. No scope and no documented tool carries a create, update, delete, submit or send verb. The connector reads Canary's research datasets and returns them.
Red-flag research on public companies. Canary's documentation describes accounting and disclosure flags, insider trading, fraud and malfeasance, management track record, and fundamental business risk, plus KPI time series, earnings-call topics and bull/bear debates. Each flag record carries a date, severity, description and source links.
Yes to both. Canary's documentation states its universe-wide screen has no market-cap floor, so small caps are included, and lists supported markets as global public equity markets. Country filtering uses ISO 3166-1 alpha-2 codes, and the screen covers active companies only.
One scope per tool, twenty-six in total. Every scope name matches a tool name exactly, which is unusually fine-grained for an MCP server. Because all twenty-six are reads, the granularity limits which datasets an agent reaches rather than separating reading from writing — there is nothing destructive to fence off.
Canary's documentation states data is updated daily and that the server allows 120 requests per minute per access token. Exceeding that returns HTTP 429 with a Retry-After header. Access tokens live one hour and refresh tokens thirty days, rotating on use.
Add the server over HTTP transport, then authorise. Canary documents the command claude mcp add --transport http canary-data https://api.canary-data.com/mcp, followed by running the slash-mcp command in your session to complete the OAuth flow. Claude Desktop and Claude.ai Team and Enterprise add it from the Connectors settings page instead.
The response says so explicitly rather than returning a bare empty list. Canary's documentation describes a coverage object carrying a plain-language hint, the echoed ticker and country, and any active date bounds. It distinguishes no flags in this window from no flags at all, so an agent cannot mistake a narrow query for a clean record.
documentation URL Anthropic's directory publishes for this connector; 4,658 words of plain server-rendered HTML, no client-side payload. Source of all sixteen documented tool descriptions, parameters, response shapes, markets, freshness, rate limits and setup instructions. · retrieved 2026-08-22password grant type and the absence of a registration endpoint. · retrieved 2026-08-22initialize to https://api.canary-data.com/mcp returned HTTP 401 on 2026-08-22 with www-authenticate: Bearer resource_metadata="https://api.canary-data.com/.well-known/oauth-protected-resource". This is our own observation of the auth posture. · retrieved 2026-08-22tool_names entry, and the "Read only" permissions field. · retrieved 2026-08-16x-robots-tag: noindex and an empty robots.txt; api.canary-data.com/robots.txt and /llms.txt both return 404, so no crawl policy or Content-Signal was published on either host.Connect Canary Data once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.