How to Access SEC Financial Data in ChatGPT

The SEC-API.io plugin gives ChatGPT access to 20 million filings from 1993 to today across 500 filing types, updated within 300 milliseconds of publication on EDGAR. It replaces ChatGPT's incomplete and outdated filing data with the SEC-API.io database via a MCP server. There is nothing to install and no process to run, and setup takes around 2 to 5 minutes. This blogpost explains how to set it up and how to get started.

How to connect the SEC-API.io MCP Server with ChatGPT

What you need

  • ChatGPT on the web at chatgpt.com, the ChatGPT desktop app or the Codex CLI.
  • SEC-API.io MCP server URL: https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY
  • A SEC-API.io API key: Get a free API key via https://sec-api.io/signup

Step-by-Step Guide

Option 1: ChatGPT on the web (chatgpt.com)

Follow the two steps to connect the SEC-API.io Plugin to ChatGPT. Once done its connected for all sessions, not just one conversation.

Step 1. Open 'Settings' -> 'Security and login'. Scroll to the 'Developer mode' section and turn Developer mode 'on'. ChatGPT states that developer mode allows unverified connectors that could modify or erase data. Availability depends on the account and the workspace policy - on Team and Enterprise plans only an owner can add connectors.

The Developer mode toggle in ChatGPT settings under Security and login

Step 2. Open 'Plugins' in the left sidebar and click the 'plus' button at the top right of the page, next to the search field.

The Plugins page in ChatGPT, with the plus button that creates a custom connection marked

Step 3. The 'New Plugin' dialog opens. Enter a name, for example sec-api. Leave Connection set to Server URL and paste the endpoint URL into the address field: https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY. Set Authentication to No Auth, marked 2, because the key in the URL is the only credential the server needs.

Step 4. Tick "I understand and want to continue", marked 3, and click Create, marked 4.

The New Plugin dialog with the URL field, the Authentication setting, the acknowledgement checkbox and the Create button marked 1 to 4

The connection page then shows the permission setting for the plugin, marked below, and under 'Actions' every tool the server exposes with its name, its description and its input schema.

The saved SEC-API.io connection, with the permission setting marked and the discovered tool list below it

If the connection fails, check that the URL includes the /mcp path and your API key. A VPN or a firewall on the local machine is not the cause of a failed connection.

Option 2: ChatGPT desktop app and Codex

The Codex CLI, the ChatGPT desktop app and the IDE extension share one file. Configure it once and all three can use the plugin.

1 codex mcp add sec-api --url "https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY"

The command writes the entry into ~/.codex/config.toml, which is TOML and not JSON. The same result can be written by hand:

1 [mcp_servers.sec-api]
2 url = "https://api.sec-api.io/mcp?apiKey=YOUR_API_KEY"

Common mistakes. The table name is mcp_servers with an underscore. A block written as [mcp.servers."name"] does nothing and produces no error. The url key is what selects the HTTP transport, do not add a command key as well. Codex requires HTTPS for remote servers.

How to get started

Turn the connector on for a conversation with the 'plus' button in the composer, then ask in plain language (see example below). ChatGPT picks the endpoints and chains the calls itself, so a question that spans several datasets does not have to be broken into separate requests. The 49 tools cover filing search, full text search, XBRL financials, insider trades, 13F holdings, 8-K items, executive compensation, Form ADV and the SEC enforcement databases.

A ChatGPT conversation with the SEC-API.io connector enabled, with the Called tool block marked

Expanding the 'Called tool' block, marked above, shows which tool ran, the request ChatGPT sent and the response it received, so the answer can be traced to the filing it came from.

Example prompts

Financial statements from 10-K filings

PromptWhat it returns
"Pull NVIDIA's income statement, balance sheet and cash flow statement from its last three 10-K filings, and chart revenue and gross margin by year."Standardized XBRL statements per fiscal year, plus the derived margin trend

Risk factor changes between annual reports

PromptWhat it returns
"Summarize the differences between the risk factors from Lam Research's two most recent 10-K filings."An Item 1A comparison covering added, removed and materially expanded risks

Institutional holdings and 13F positions

PromptWhat it returns
"Get Leopold Aschenbrenner's last two 13F holdings, and calculate the delta between all positions and AUM."Position level reconciliation, plus an Excel file
"Which institutional managers reported the largest new positions in Palantir last quarter?"13F holdings screened across every filer, ranked by position size

IPO filings and investment advisers

PromptWhat it returns
"Which companies filed confidentially for an IPO recently?"Unsealed DRS filings paired with their public S-1 or F-1
"Look up Bridgewater's Form ADV: assets under management, client types, fee arrangements and any disclosure items, plus its latest Part 2 brochure."Part 1A items and Schedule A to D detail, with links to the Part 2 brochures

More prompts are in the Financial Analysis Prompt Library.

Do you need an identifier?

Usually you do not need one. Name the identifier (company's Ticker, CIK, accession number for a specific filing) when the company or firm name is ambiguous, for example when several registrants share a name or when a manager files under an entity name that differs from the brand.

How to get the output you want?

Each step below adds detail to the one above it.

  • Format: "give me an Excel file", or Word, PDF, HTML, Markdown, MDX, plain text, a chart or an image.
  • Graphic type: "make it a bar chart".
  • Chart detail: "make it a horizontal bar chart of the quarter over quarter change, sorted from largest decline to largest increase, on a zero anchored axis".
  • Visual spec: "content dense, neutral colors, one typeface, labelled bars".

Say nothing about the output and ChatGPT returns prose. A tighter specification reduces the amount of rework.

Efficiency hacks

Set the order of operations

Stating the sequence is optional, but it is faster and more accurate on work that spans several steps. State the sequence in the prompt e.g. resolve the ticker to a CIK, find the filing, extract the section, compute the figures, then chart them. Fixing the sequence keeps ChatGPT from calling a tool before it has the identifier that tool needs.

Reuse a prompt that works

Once a prompt produces the output you want, keep it somewhere that is read automatically instead of pasting it again. In ChatGPT on the web, a project holds instructions that apply to every chat inside that project, so the sequence, the identifiers and the output specification are applied without being repeated. In Codex, an AGENTS.md file in the repository root is read at the start of a session, so the same instructions can be committed alongside the code they are used with.

Restricting what the plugin can do

When the connection is created, ChatGPT lists every tool it found on the server under 'Actions' on the connection page, with the name, the description and the input schema of each. That list is what the model can call.

Approval is set under Settings, then Plugins, then Permissions, and the same setting appears on the connection page for each plugin. There are three settings:

SettingBehaviour
Always askChatGPT asks before reading or making changes.
Allow read actionsChatGPT reads without asking and asks before making changes.
Allow low risk actionsChatGPT approves low risk actions automatically and may deny actions involving sensitive information.

Allow low risk actions is the default. The SEC-API.io server is read only against SEC data, so Always ask produces a confirmation on every query, and 'Allow read' actions runs queries without a prompt.

On ChatGPT Team and Enterprise plans, developer mode and connectors are governed by the workspace policy and only an owner can add a connector. A workspace owner therefore controls which servers exist for the workspace at all, independently of what an individual member configures.

FAQ

What is an MCP server? An MCP server exposes a set of tools over a defined protocol so that an assistant can call them. The SEC-API.io server is remote and runs over HTTP at https://api.sec-api.io/mcp, so there is nothing to install and no local process to keep running. It exposes 49 tools covering the SEC-API.io datasets.

What is developer mode in ChatGPT? Developer mode is the setting under Settings, then Security and login, that allows a custom MCP server to be added from the Plugins page. A custom server has not been reviewed by OpenAI, and its write actions run against the accounts it is connected to. Availability depends on the account and the workspace policy, and on Team and Enterprise plans only an owner can add connectors.

Which Authentication option applies to the SEC-API.io server? No Auth. The API key travels in the apiKey query parameter of the endpoint URL, so there is no OAuth client to configure. Leaving Authentication on OAuth makes the connection fail.

Does my API key leave my machine? Yes. The key sits in the endpoint URL, and ChatGPT connects to api.sec-api.io from OpenAI infrastructure rather than from the local machine. Treat the URL as a secret and rotate the key from the account page if it leaks.

The connector is added but ChatGPT does not use it. Turn the connector on for the conversation with the plus button in the composer, then repeat the question naming the data you want, for example the form type or the dataset. Confirm on the connection page that the tool list was discovered.

Calls fail with an authentication error. The key in the URL is wrong or has been rotated. Copy the key again from the SEC-API.io account page, including the /mcp path and the full key, and update the connection or the url value in ~/.codex/config.toml.

Does this work in the ChatGPT desktop app? Yes, through the Codex configuration instead of the web settings. The desktop app, the Codex CLI and the IDE extension read ~/.codex/config.toml, so one [mcp_servers.sec-api] entry serves all three.

What is the difference between this and ChatGPT web search? Web search retrieves pages that a search index has crawled and returns the text on them. The MCP server queries the SEC-API.io database directly and returns records from EDGAR filings, covering 20 million filings from 1993 to today across 500 filing types, updated within 300 milliseconds of publication, including XBRL financial statements, insider transactions, 13F holdings and Form ADV data that are held in the filings rather than on indexed web pages.

Educational content about accessing and analysing SEC filing data. Not investment advice, legal advice, or a recommendation to buy or sell any security.

Last updated: 14 September 2026