
Kova
com.kovatoolsv0.10.0Updated Oct 3, 2026
Saves a declared investment strategy so any agent can check a portfolio against it.
Overview
Kova gives an assistant a saved investment strategy and lets it check a portfolio against that strategy with approval steps.
- What it does
- Kova is a hosted strategy layer for agentic investors. It lets an assistant turn goals, constraints, and investing principles into a durable investment strategy, preview it, and save it only after explicit approval. It can also record portfolio assets and liabilities and produce a strategic brief covering alignment, tensions, and next questions. It does not execute trades, make market predictions, or choose securities.
- When to use it
- Worth adding when you want an assistant to keep one consistent investment strategy across sessions and use it as a stable reference for portfolio reviews. It suits users who want a documented strategy and alignment briefs rather than trade execution.
- Requirements
- A remote MCP endpoint at kovatools.com over streamable HTTP, reached through Kova's OAuth flow with PKCE. An active Kova subscription is required for MCP access. No local server, package, or API key file is needed.
Installation
In SourceWeft
- Open Kova in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"kova": {
"type": "http",
"url": "https://kovatools.com/mcp"
}
}
}README
Give every agent the same investment strategy.
Kova is the strategy layer for agentic investors. It gives compatible AI agents a persistent investment strategy, a shared way to check portfolio alignment, and a clear approval boundary before Kova saves a strategy or creates a brief.
Explore Kova · Install the Agent Plugin
From strategy to brief
Strategy → approval → portfolio → brief
- Turn your goals, constraints, and investing principles into a durable strategy.
- Review the exact strategy and approve it before Kova saves anything.
- Connect a portfolio, then ask an agent to check it against the same strategy.
- Approve the portfolio check and receive a strategic brief with alignment, tensions, and next questions.
What the plugin adds
- Create or refine a strategy. Shape a personal investment strategy in conversation, with a complete preview before it is saved.
- Check portfolio alignment. Use the strategy as the stable reference point for a portfolio review and strategic brief.
The plugin packages Kova's strategy workflows and secure MCP connection for clients that support Agent Plugins v1. It connects to Kova's hosted service, so there is no local server to build and no API key to place in a file.
Trust and approval boundaries
Kova asks for explicit approval before it saves a strategy, records portfolio assets or liabilities, or creates a brief. It does not execute trades, make market predictions, or choose securities for you.
Authentication happens through Kova's OAuth flow. The plugin contains no credentials, authorization headers, tokens, or client-specific OAuth configuration. Strategy text, holdings, and account data stay out of the plugin package.
The published Kova app in ChatGPT is a separate distribution channel. Installing that app does not install this Agent Plugin, and installing this Agent Plugin does not add the ChatGPT app.
Install
The directory containing plugin.json is the plugin root. Install the repository root, not its skills/ directory.
VS Code: install directly from Git
VS Code can clone and install a plugin from its repository URL:
- Make sure Agent Plugins are enabled with the
chat.plugins.enabledsetting. - Open the Command Palette and run Chat: Install Plugin From Source.
- Enter
https://github.com/kovatools/kova-agent-plugin. - Review the source trust prompt, install the plugin, and start a new chat.
To update, run Extensions: Check for Extension Updates. VS Code also checks automatically when extension auto-update is enabled. To uninstall, find Kova under Agent Plugins - Installed, open its context menu, and select Uninstall.
For a local clone instead, register the plugin root in VS Code settings:
See Agent plugins in VS Code for the current UI and settings.
Cursor: clone or symlink locally
Cursor loads local plugins from ~/.cursor/plugins/local:
Restart Cursor or run Developer: Reload Window. For development, you can clone elsewhere and symlink the repository root instead:
To update a cloned copy, run git -C ~/.cursor/plugins/local/kova pull --ff-only, then reload Cursor. To uninstall, remove only the kova clone or symlink from ~/.cursor/plugins/local, then reload Cursor. See Cursor Plugins for the current local-plugin flow.
Other compatible clients
Clone a release, then copy or symlink the repository root into the directory your client scans for plugins:
If Git is unavailable, download the v0.1.1 source archive from GitHub, extract it, and register the extracted repository root as a local plugin directory.
Registration, update, and uninstall behavior belongs to the client because Agent Plugins v1 defines the package format, not a universal installer. Consult the compatible clients list and your client's documentation. To update a clone tracking main, use git pull --ff-only; for an immutable release, replace the clone with a newer SemVer tag. To uninstall, unregister the plugin root and remove only that local clone or symlink.
Authenticate
The first time a client connects to https://kovatools.com/mcp, it should open Kova's OAuth authorization flow:
- Sign in to your Kova account in the browser window.
- Review the client name and requested access.
- Select Allow access.
- Return to the client and retry the request if it does not refresh automatically.
Kova uses OAuth with PKCE. Local clients may use an exact http://localhost, http://127.0.0.1, or http://[::1] callback. Cursor may also use its exact native callback, cursor://anysphere.cursor-mcp/oauth/callback; every other callback must use HTTPS. An active Kova subscription is required for MCP access.
To revoke a connection, remove its Kova API token from your account. Uninstalling the plugin does not revoke an already issued token.
Releases and support
Use immutable GitHub Releases for repeatable installs and version-specific compatibility notes. To report an installation problem, client compatibility issue, or workflow bug, open an issue.
License
MIT
Source: README.md at commit ffc64ce
Tools
0Version history
1- v0.10.0LatestOct 3, 2026