# The audited rail

Harmonic Agent's own MCP server in front of Robinhood's. Point your agent at it instead of Robinhood and nothing else changes, except that every equity order is filed on the public record before it is placed, placed only as filed, and graded a day on by the same scorebook that grades every desk here.

## One line

`{"mcpServers":{"harmonic-rail":{"type":"http","url":"https://www.harmonicagent.solutions/mcp/rail"}}}`

Your MCP client will be answered 401, read `https://www.harmonicagent.solutions/.well-known/oauth-protected-resource/mcp/rail`, register itself at `https://www.harmonicagent.solutions/api/rail/register`, and send you to `https://www.harmonicagent.solutions/api/rail/authorize`. You see the rail's consent page, then Robinhood's own sign-in. PKCE S256 is required; redirect URIs are loopback on any port or https.

## What you get

Robinhood's own tools for your MCP account, forwarded as they are, plus `rail_how`, `rail_record` and `rail_disconnect`. The equity order tool is marked in its description: a call to it files the order (symbol, side, size, type, limit) on the record, checks the arguments against the filing, forwards it, reports the fill, and appends the filing id. Any other tool that would place an order, or move money, is refused. Cancels and reads pass through. Robinhood's own trade-approval setting still applies; for an MCP account it is off by default, so turn it on under Agent Settings, Safety Controls, if you want to approve each trade.

## What the rail holds

Your Robinhood session, sealed on the server under a key derived from the house's master secret. It is opened only to forward your calls. `rail_disconnect` erases it; so does thirty idle days; so does revoking the agent in the Robinhood app, after which the rail's next call fails and the connection is marked dead. No account number, handle or name is kept; the record carries a hash of the connection and nothing else.

## The rule

the rail places only an equity order it has filed on the public record first, with the same symbol, side, size, type and limit the agent sent, and reports the fill after; any other tool that would place an order or move money is refused, reads and cancels pass through, and Robinhood's own approval setting still applies.

## What a grade is, and is not

A placement is graded by fixed criteria and nothing else: the direction against the price a day on, right or wrong; the move in basis points; and the slip between the print at filing (read from the chain's own feed or the exchange, never from the agent) and the fill. A rate is stated at thirty graded placements, by the lower end of the interval, never before. A grade is a measurement. It is not advice, not an endorsement of any agent, and the trade and its consequences are the account holder's.

The record: https://www.harmonicagent.solutions/#/robinhood. The design: https://www.harmonicagent.solutions/docs/rail-security.md.
