A Python client library and Model Context Protocol (MCP) server for accessing your AKSes KSEI (Acuan Kepemilikan Sekuritas Kustodian Sentral Efek Indonesia) portfolio data.
Retrieve complete Indonesian securities portfolio information:
- 💵 Cash balances (RDN)
- 📈 Equity holdings (Saham)
- 📊 Mutual funds (Reksadana)
- 📜 Bonds (Obligasi & SBN)
- 💼 Other investment instruments
- 👤 Account identity & SID
- Python 3.11 or higher
- Valid KSEI account credentials
uv(recommended for fast package management)
Set your KSEI credentials via environment variables or a .env file:
export KSEI_USERNAME="your_ksei_username"
export KSEI_PASSWORD="your_ksei_password"
# Optional: Override token cache location (defaults automatically to ~/.cache/ksei)
# export KSEI_AUTH_PATH="/custom/path"Tokens are automatically cached in ~/.cache/ksei with restricted 0o700/0o600 permissions.
import asyncio
from ksei import KSEIClient
# Initialize client (no auth_store boilerplate needed!)
client = KSEIClient(username="your_username", password="your_password")
# Synchronous usage
summary = client.get_portfolio_summary()
cash = client.get_cash_balances()
equities = client.get_equity_balances()
funds = client.get_mutual_fund_balances()
bonds = client.get_bond_balances()
# Asynchronous usage (fast parallel fetch)
async def main():
async with KSEIClient(username="your_username", password="your_password") as client:
all_portfolios = await client.get_all_portfolios_async()
print(all_portfolios)
asyncio.run(main())# Run directly with uvx
uvx ksei-mcp
# Or run from local checkout
uvx --from . ksei-mcpAdd this configuration to your MCP client (Claude Desktop, Cursor, Gemini CLI, etc.):
{
"mcpServers": {
"ksei": {
"type": "stdio",
"command": "uvx",
"args": ["ksei-mcp"],
"env": {
"KSEI_USERNAME": "your_ksei_username",
"KSEI_PASSWORD": "your_ksei_password"
}
}
}
}# Start MCP server
uv run ksei mcp
# Fetch and dump raw portfolio JSON
uv run ksei dump --output ./dataFor local MCP debugging:
npx @modelcontextprotocol/inspector uv run ksei-mcp- Zero Boilerplate Cache: Tokens are cached automatically in
~/.cache/ksei(XDG standard) with user-only permissions (0o700directory,0o600files). - Secret Protection: Passwords and tokens are never logged or exposed in
__repr__or unhandled exceptions. - Auto 401 Recovery: The client transparently refreshes expired tokens on 401 Unauthorized responses.
- Secure Transport: All requests communicate with official KSEI endpoints via HTTPS.
Licensed under the MIT License. See LICENSE for details.
This is an unofficial client for educational and personal use only. It is not affiliated with or endorsed by PT Kustodian Sentral Efek Indonesia (KSEI).
Adapted and inspired by chickenzord/goksei.