mrkeyoor.com_
Fri 02 Oct 15:00 UTC
Dataevaluationupdated 26 Aug 2026

ccxt review

CCXT is an MIT-licensed library that gives developers one API for market data and trading across 103 cryptocurrency exchange markets and 7 prediction-market exchanges. It covers JavaScript, TypeScript, Python, C#, PHP, Go, and Java, with an optional CLI and MCP server for terminal or agent access.

+57stars / 7d
Verdict

Our CCXT install finished in 41 seconds with 498 packages, then both the build and test commands stopped on the same TypeScript error. Use the published package when you need broad exchange coverage and accept that exchange-specific behavior still needs testing. Contributors should wait for or make a source fix before treating commit 5aa7c0b as a green baseline, and agent users should begin with public data or sandbox credentials.

We ran it

Lab card: what happened when we ran ccxtScreenshot of ccxt (docs.ccxt.com)
Install✓ · 41s498 packages · 323 MB
Build✗ · 20s
Tests✗ · 17sran, no count parsed
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo9625 files~5,951,638 lines of source · 392.3 MB · 16 CI workflows · Dockerfile

Answers from our run

Does ccxt build from source?

Dependencies installed in 41 seconds (498 packages), and the build failed. We cloned commit 5aa7c0b into a clean Debian container with 3 CPUs and no project-specific setup.

Do ccxt's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does ccxt have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use ccxt?

Anyone looking for a finished trading bot, strategy engine, or backtesting product: the project describes CCXT as library software, not a hosted service or server.

What are the alternatives to ccxt?

Freqtrade, Hummingbot, XChange. Our CCXT install finished in 41 seconds with 498 packages, then both the build and test commands stopped on the same TypeScript error.

Setup3/5Package install passed; source build and test path failed
Docs4/5Detailed manual, examples, CLI, and MCP security guidance
Community5/5Recent push and release with active issue and PR traffic
Maturity4/5Wide exchange coverage, offset by a failing pinned source build

Who it’s for

Developers collecting prices, order books, trades, or candles from several exchanges.
Trading teams that want one library across JavaScript, Python, PHP, C#, Go, or Java.
Engineers building bots or backtests who need a connector layer and will supply their own strategy, storage, and risk controls.
MCP users who want public market data by default and can configure private account permissions carefully.

Who it’s NOT for

Anyone looking for a finished trading bot, strategy engine, or backtesting product: the project describes CCXT as library software, not a hosted service or server.
Teams that require a clean source build at commit 5aa7c0b: our build and test commands both stopped on the same TypeScript type error in ts/src/upbit.ts.
Latency-sensitive Python systems that expect the default signer to be enough: the README says its pure Python ECDSA path may miss that requirement and recommends the optional Coincurve package.
Agent operators who cannot isolate credential files: the MCP guide says a local agent with filesystem access may be able to read its config, even though tool calls never expose keys.
Desks unwilling to audit fee settings: CCXT says its listed builder-program exchanges add 1 bps unless builderFee is disabled.

Setup reality

Our Node 22 sandbox installed 498 packages in 41 seconds and used 323 MB. The build failed after 20 seconds, and the test command failed after 17 seconds at the same TypeScript compile error: ts/src/upbit.ts assigned a Dict where a List was required. The log does not show a deeper cause or a completed test summary.

Public market data needs no account or API key. Private balances and trading require accounts and exchange-issued credentials, sometimes after identity verification. The MCP server requires Node.js 18 or newer; live trading, fund transfers, and raw writes each need explicit configuration, while the guide recommends sandbox keys, IP allowlists, withdrawal-disabled keys, and a mode-600 config file.

The checkout at commit 5aa7c0b contained 9,625 files, about 5,951,638 source lines, and occupied 392.3 MB. It includes 16 CI workflow files, a Dockerfile, and a compose file, although our detector found no top-level tests directory. Published packages offer the shorter consumer path across 7 languages; contributors inherit a generated multi-language tree and the failed TypeScript build we observed.

110 exchange and prediction-market entries share one interface

Version 4.5.75 gives applications common methods for tickers, order books, trades, candles, balances, and orders. The README lists 103 cryptocurrency exchange markets and 7 prediction-market exchanges. That breadth is hard to reproduce inside one product, especially when every venue uses its own authentication, symbols, response fields, and error codes. CCXT supplies public and private REST APIs, plus WebSocket access through its Pro classes.

The library reaches beyond its original JavaScript audience. Version 4.5.75 ships interfaces for JavaScript, TypeScript, Python, C#, PHP, Go, and Java, and several generated implementations originate from the TypeScript source. Public data can be used without registering or providing a key. Private calls require credentials issued by each exchange, and an exchange may require identity verification before it grants them. CCXT handles the connection; it does not create the account or decide whether a trade is sensible.

What happened when we ran it

Our sandbox installed 498 npm packages in 41 seconds, consuming 323 MB on disk. The next step was decisive: npm run build failed after 20 seconds. TypeScript reported that ts/src/upbit.ts assigned a Dict value to a field typed as a List. The compiler added that the dictionary lacked array properties such as length, pop, and push. That is the full cause visible in the supplied log tail, so we cannot responsibly claim more.

The test command failed after 17 seconds because it passed through the same TypeScript build and reached the same Upbit error. We did not receive a completed test count. The checkout was also substantial: 9,625 files, roughly 5,951,638 source lines, and 392.3 MB checked out at commit 5aa7c0b. Our scan found 16 CI workflow files, a Dockerfile, and a compose file. Npm audit reported 0 known vulnerabilities across the installed dependency tree.

Public reads need no key; private calls need exchange credentials

CCXT supports Node.js 18 and newer, and public market data needs no user account. Install the package, create an exchange instance, and make a read call. The README documents synchronous and asynchronous use, a built-in leaky-bucket limiter, and an optional rolling window whose default span is 60 seconds. There are still venue-specific parameters and capabilities, so an application must inspect what each exchange supports and handle its errors rather than assume every method behaves identically.

Trading raises the stakes because private APIs can place orders, transfer funds, or request withdrawals. CCXT also participates in builder programs for the 7 exchanges listed in that section of the README; those calls add 1 bps unless the application disables builderFee. That setting deserves a configuration test. So do exchange-side permissions, symbol precision, rate limits, and sandbox behavior. A common method name reduces adapter work, but it does not turn different exchanges into the same venue.

The MCP server starts read-only and can reach live funds

The Node.js 18+ MCP server gives Claude Code and other hosts access to more than 100 exchanges through local stdio. With no configuration it exposes public market data. Adding an account enables private reads, while trading, funds, and raw write endpoints are separate capability tiers that start disabled. Live trading requires the literal live setting and a chosen per-order cap. Write actions have previews, confirmations, and an append-only journal. Those are sensible boundaries for an agent that can act on financial accounts.

The MCP security guide also states the caveat plainly: another local tool with filesystem access could read the credential file. A mode-600 file helps with other operating-system users, not an agent already allowed to read that path. Use exchange keys with withdrawals disabled and an IP allowlist, then start on a sandbox. The README's AI skills cover Claude Code, Cursor, Copilot, Windsurf, Codex, and more than 30 other assistants, but generated code still needs review before it touches a live account.

Active releases fix venue-specific mistakes every week

CCXT was pushed on August 25, 2026, four days after the v4.5.75 release. GitHub reported 807 open issues and pull requests combined, while an issue-only search returned 230 open issues. That is a large maintenance queue, yet the dates and the v4.5.75 release notes show current work. That release fixed WebSocket routing, order-side handling, withdrawal network mapping, authentication races, position parsing, and several language ports.

Those fixes explain both CCXT's value and its burden. A connector spanning 110 listed markets absorbs changes that individual application teams would otherwise chase. It also sits directly between code and money, where a wrong amount rounding or network mapping can matter. Recent open reports cover a positive amount rounding to zero on Hyperliquid, Kraken Futures rate-limit costs, and a C# WebSocket crash. Pin versions, test every used venue against a sandbox where available, and treat upgrades as trading-system changes.

Choose CCXT for connectors, Freqtrade for a finished bot

Version 4.5.75 is the broad connector here, covering 103 crypto exchange markets and 7 prediction venues. It provides the adapter layer, examples, a CLI, and agent access, while leaving strategy, portfolio logic, persistence, monitoring, and deployment to you. That separation is ideal for a team building its own trading system. It is extra work for someone who wants to configure a strategy and run a bot.

Freqtrade packages backtesting and strategy operation around a Python bot. Hummingbot is closer to a deployed trading and market-making platform. Java-only teams should compare XChange before accepting CCXT's generated multi-language repository. For CCXT itself, the consumer package is the safer starting point because our 41-second install passed with 0 known vulnerabilities. The pinned source tree needs its Upbit type error resolved before its build and test path earns the same confidence.

Alternatives

ProjectWhat it isPick it when
Freqtrade gh↗A Python crypto bot with strategy development, backtesting, optimization, and live operation.pick this instead when you want a working bot framework rather than a low-level exchange connector.
HummingbotA bot platform focused on automated and high-frequency crypto trading.pick this instead when market-making workflows and bot deployment matter more than embedding an exchange API in your own application.
XChangeA Java library that provides a consistent trading and market-data API across many exchanges.pick this instead when your stack is Java-only and you prefer a narrower codebase built around that ecosystem.

What people are saying

  1. [velocity-scout] ccxt/ccxt

Sources

  1. CCXT repository and README
  2. CCXT v4.5.75 release notes
  3. CCXT manual
  4. CCXT MCP server security and configuration
  5. CCXT open issues

More data reviews

WeFlow · awesome-reasoning-generalization · osquery · rocksdb · INSLIB · HowToLiveBetter · the whole board →