MCP Server for SEC EDGAR Data
The SEC-API.io MCP server connects AI assistants to SEC EDGAR data. An assistant takes a question in plain language, calls the API, and answers from live filing data instead of from its training set.
MCP is the Model Context Protocol, an open standard that lets an AI assistant call external tools. The SEC-API.io server is remote, so there is nothing to install. One URL gives an assistant access to search filings, pull financial statements, and read disclosures.
The server reaches all 20 million filings published on EDGAR from 1993 to today:
- Full-text search. Search the complete body of every filing and exhibit.
- Insider trades. Forms 3, 4 and 5, with the buyer, the size of the trade and the price.
- Institutional holdings. Form 13F positions, plus Schedules 13D and 13G for stakes above five percent.
- Material events. Form 8-K, split by item, from earnings under Item 2.02 to cybersecurity incidents under Item 1.05.
- Audit reports. Auditor opinions, going concern statements and audit fees.
- Executive compensation. Salary, bonus and equity awards per named officer.
- Financial statements. XBRL data as JSON, taken from the filings themselves.
- Entities. 1.1 million filers, survivorship-bias free. Companies that were acquired, went bankrupt or stopped reporting are still in the data.
- Investment advisers. Form ADV filings from more than 400,000 advisers and their representatives.
- Everything else. The list above is a sample. Every SEC-API.io product is reachable through the server. See the full API documentation for the complete set.
Use cases
Each question below is answered by one or more SEC-API endpoints. The assistant picks them and chains the calls on its own.
Find the link to NVIDIA's latest 8-K.
NVIDIA's latest 8-K was accepted July 2, 2026 at 9:23 AM ET.
| Item | 5.02, departure or election of directors and officers, compensatory arrangements |
| Document | nvda-20260628.htm |
| Filing index | 0001045810-26-000060-index.htm |
| Accession | 0001045810-26-000060 |
Want me to pull the actual contents of the item?
Summarize the differences between the risk factors from Lam Research's two most recent 10-K filings.
Comparing FY2026 10-K (filed Aug 7, 2026, FYE Jun 28) against FY2025 10-K (filed Aug 11, 2025, FYE Jun 29). Item 1A grew from ~12,050 to ~14,450 words (+20%), same four categories, with one risk factor added and one removed.
Legal exposure. The IP claims factor was retitled to add “Misuse of Third-Party Information” and now warns that law enforcement may investigate or charge Lam or its employees over improper receipt or misuse of designated technology or third-party confidential information under national/economic-security measures — with civil or criminal liability. The regulatory factor adds a candid admission: “there have been, and may continue to be, instances of our compliance policies and procedures not being effective.”
Cybersecurity (+792 words, roughly doubled). The biggest single change. FY2025 described conventional threats plus a two-sentence nod to AI. FY2026 adds prompt injection, hallucinations, agentic AI learning to circumvent security controls, and LLMs retrieving data using a user's credentials as a data-leakage vector. It also concedes that AI may discover and exploit vulnerabilities faster than Lam or its providers can patch them, and — new — that they may be unable to anticipate, identify, or remediate incidents in time. Threat actors are now named explicitly: ransomware, state-sponsored intrusions, corporate espionage, credential harvesting.
…
Summarize the debt covenants in Boeing's most recent credit agreement.
The document. Boeing's most recent credit agreement is the $3.0 billion 364-Day Credit Agreement dated August 25, 2025, filed as Exhibit 10.1 to an 8-K on August 28, 2025 (Items 1.01, 2.03, 9.01), accession 0000012927-25-000064. Citibank is administrative agent and JPMorgan Chase syndication agent. It replaced the $3.0 billion three-year facility from 2022 that terminated the same day. Schedule I sets total commitments at $3,000,000,000, upsizable to $4.0 billion.
The covenants.
| Covenant | Test |
|---|---|
| Leverage (4.2b) | Consolidated debt no more than 60% of total capital, at any time |
| Minimum liquidity (4.2f) | $5.0 billion at all times |
| Negative pledge (4.2a) | Liens on property, plant and equipment, with 12 carve-outs and a 15% basket |
| Cross-default (6.1) | $500 million threshold, 5 business days to cure |
| ERISA (6.1) | Liabilities above $500 million |
…
What are the terms of Plug Power's latest shelf offering?
The shelf itself. Plug Power's current shelf is a Form S-3ASR filed May 27, 2025, Registration No. 333-287577, accession 0001104659-25-052737. As an automatic shelf from a well-known seasoned issuer it became effective immediately on filing, and the fee table registers an indeterminate amount of common stock, preferred stock, warrants, debt securities and units under Rules 456(b) and 457(r), so there is no dollar cap on the shelf itself.
The ATM takedown. The main program off it is a $1,000,000,000 at-the-market common stock offering, prospectus supplement dated August 15, 2025 (424B5, accession 0001104659-25-079028), sold through B. Riley Securities as sales agent or principal. Commission is up to 3.0% of the gross sales price in agency transactions and 5.0% in principal transactions. Prospectus Supplement No. 1, dated September 30, 2025, added Yorkville Securities as a second agent.
…
Summarize the latest earnings from the technology sector.
212 Item 2.02 filings from technology issuers between August 1 and 12, 2026, from 209 distinct companies, filtered to SIC 3570–3579, 3670–3679 and 7370–7379. The peak was Thursday August 6 with 72 filings in one day.
AMD and Arista both filed on August 4. AMD (accession 0000002488-26-000121) reports Q2 revenue of $11,536M for the quarter ended June 27, up 50% year over year, with GAAP diluted EPS of $1.38. Data Center alone was $6.7B, up 107%. Arista (0001596532-26-000174) posted its first $3 billion quarter: revenue of $3.036B, up 37.7%, GAAP diluted EPS of $0.95.
Palantir was the software outlier. Its August 3 filing (0001321655-26-000039) reports Q2 revenue of $1.935B, up 93% year over year, with US commercial revenue up 149%.
…
Which companies disclosed a cybersecurity incident this quarter?
Seven Form 8-K filings carried Item 1.05, Material Cybersecurity Incidents, between July 1 and August 12, 2026. Three are new disclosures. The other four are amendments from a single filer updating one incident.
The three new disclosures. Amgen, filed July 31, accession 0000318154-26-000119: unauthorized activity in cloud environments hosted by third-party providers, with proprietary data and patient health information exfiltrated. Navient, filed July 2, accession 0001140361-26-027441: a ransomware attack on a third-party law firm exposed borrower names, dates of birth, addresses and Social Security numbers. AdaptHealth, filed July 2, accession 0001104659-26-080297: a social engineering attack compromised a contractor session and reached cloud-based patient systems. All three state the incident is not currently expected to be material.
…
Find credit agreements, bond indentures and lease agreements signed this year.
Counts for 2026 to date. These are exhibits, not form types, so the search runs across filing documents rather than filtering by form. “Credit agreement” returns 22,883 matching documents, “Indenture, dated as of” returns 23,228, and “lease agreement” returns 11,108. Two caveats: these are document-level hits, so one 8-K can produce several, and the filter is on filing date, not signing date.
Credit agreements and indentures. IBM filed an 8-K on June 23, 2026 extending both its $2.5B three-year and $7.5B five-year credit agreements by one year, as Exhibits 10.1 and 10.2, accession 0000051143-26-000061. Sysco filed on February 13, 2026 for $600M of 4.400% senior notes due 2031 and $650M of 4.950% notes due 2036, issued under the Forty-Eighth and Forty-Ninth Supplemental Indentures, accession 0001193125-26-051566.
One pattern worth flagging. Most credit agreement and lease hits are amendments to existing instruments rather than newly executed ones. Booz Allen's eleventh amendment and Crescent Energy's fifteenth are typical. Isolating first-time agreements means filtering the exhibit text, not the search phrase.
…
Which companies filed confidentially for an IPO recently?
178 draft registration statements hit EDGAR between May 1 and August 12, 2026: 93 original DRS filings, 84 DRS/A amendments and one DRSLTR, across 145 distinct CIKs. The bucket is not purely IPOs. Already-public issuers use confidential submission for follow-ons and de-SPAC registrations too. Filtering to first-time draft submissions leaves 89 companies.
Three that ran the full arc. Jersey Mike's Subs submitted confidentially on April 10, amended three times, filed publicly on Form S-1 July 2, and priced 43,478,261 Class A shares at $23.00 on the NYSE under JMKE via a 424B4 on July 31. Latigo Biotherapeutics went DRS March 27, S-1 July 17, 424B4 August 7. SK hynix took the foreign-issuer route: DRS March 24, four amendments, F-1 June 24, 424B4 July 10.
The mechanic behind those dates. Each DRS carries a March to June submission date but only became retrievable the day the company filed publicly. The draft sits non-public with Corp Fin until the S-1 or F-1 lands, then the whole confidential history is released at once with its original dates intact. A DRS query never surfaces anyone still in the confidential stage. It surfaces the ones who just crossed the line.
…
The server works with Claude, ChatGPT, Claude Code, Codex and Gemini CLI. See Connect an assistant for the steps for each one.
Endpoint and API key
The server address is one URL. The API key goes in the apiKey query parameter.
https://api.sec-api.io/mcp?apiKey=YOUR_API_KEYThe key can be found on the account page. The MCP section there shows the full URL with the key already in it, ready to copy.
There is nothing to install. The server is remote and speaks HTTP. The assistant connects to it directly.
Connect an assistant
Replace YOUR_API_KEY with a real key in every example below. The account page has the URL ready to copy.
Claude (Web & Desktop)
Claude in the browser and Claude Desktop use the same steps. Claude connects from Anthropic servers, not from the local machine.
- Open Settings, then Connectors.
- Click Add, then Add custom connector.
- Enter a name and paste the URL with the API key.
- Click Add.
- Click Connect.
Leave the OAuth Client ID and Client Secret empty. The key in the URL is the only credential needed. Turn the connector on per conversation with the plus button in the composer.
ChatGPT (Web)
ChatGPT on the web adds servers at the account or workspace level. The ChatGPT desktop app is different. It reads the Codex config below.
- Open Settings, then Security and login. Turn on Developer mode.
- Open Plugins and click the plus button.
- Enter a name and paste the URL. The URL must include the /mcp path.
- Create the connection and review the tools it finds.
Developer mode depends on the account and workspace policy. On Team and Enterprise plans only an owner can add connectors.
Claude Code
Add the server with one command, or write the file directly.
claude mcp add --transport http sec-api "https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY".mcp.json — Project scope. Shared with everyone who clones the repository.
{
"mcpServers": {
"sec-api": {
"type": "http",
"url": "https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY"
}
}
}Codex & ChatGPT Desktop
The Codex CLI, the ChatGPT desktop app and the IDE extension share one file. Set it up once and all three can use it.
codex mcp add sec-api --url "https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY"~/.codex/config.toml — TOML, not JSON.
[mcp_servers.sec-api]
url = "https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY"Gemini CLI
Gemini CLI defines servers in its settings file.
~/.gemini/settings.json — Use .gemini/settings.json for one project only.
{
"mcpServers": {
"sec-api": {
"httpUrl": "https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY"
}
}
}Troubleshooting
The server does not appear at all
Check which file was edited. Claude Code reads .mcp.json and ~/.claude.json. It does not read .claude/settings.json. A config in settings.json is ignored and no error is shown.
Gemini CLI will not start after the server is added
Remove the type key. Gemini rejects it and refuses to load the file. Use httpUrl for the address, not url.
Codex ignores the server
The table name is mcp_servers with an underscore. [mcp.servers."name"] is a common mistake and does nothing. Codex also requires HTTPS.
The connector fails in Claude or ChatGPT
Check the URL includes the /mcp path and the API key. Both products connect from their own servers, so a VPN or firewall on the local machine is not the cause.
Calls fail with an authentication error
The key in the URL is wrong or was rotated. Copy the URL again from the account page.
The assistant has the server but does not use it
Turn the connector on for the conversation. In Claude, use the plus button in the composer. In Claude Code and Gemini CLI, run /mcp to check the status.