LunchMoneyCAUTION
A Model Context Protocol (MCP) server implementation for LunchMoney, providing programmatic access to personal finance management through LunchMoney's API.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@akutishevsky/lunchmoney-mcp) [](https://www.npmjs.com/package/@akutishevsky/lunchmoney-mcp) [](https://github.com/akutishevsky/lunchmoney-mcp/releases) [](https://github.com/akutishevsky/lunchmoney-mcp/blob/main/LICENSE) [](https://www.typescriptlang.org/) [](https://lobehub.com/mcp/akutishevsky-lunchmoney-mcp)
A Model Context Protocol (MCP) server implementation for LunchMoney, providing programmatic access to personal finance management through LunchMoney's API. Also available as an MCP Bundle (.mcpb) for easy installation in Claude Desktop.
Heads up — v3.0.0 removes `get_all_crypto`. The crypto tools now use LunchMoney's v2 crypto endpoints, which split manual and synced holdings into separate resources and offer no combined equivalent of v1'sGET /crypto. Replaceget_all_cryptowithget_all_manual_cryptoandget_all_synced_crypto, which together return everything it did and more.update_manual_cryptoalso drops itscurrencyparameter. Nothing outside the crypto domain changed; if you don't use the crypto tools, upgrading from 2.x needs no action. See CHANGELOG.md. If you depend onget_all_crypto, pin@akutishevsky/lunchmoney-mcp@^2.2.0.
Heads up — v2.0.0 is a breaking release. This server now targets LunchMoney's v2 API (https://api.lunchmoney.dev/v2, currently in alpha). It is not backwards-compatible with v1.x of this server: tc1f2fd9a3bcfOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add lunchmoney-mcp --env LUNCHMONEY_API_TOKEN=${LUNCHMONEY_API_TOKEN} -- npx -y @akutishevsky/[email protected]Exposed tools (59)
32 read · 15 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_supported_cryptocurrency | write | |
attach_file_to_transaction | read | |
create_category | write | |
create_manual_account | write | |
create_manual_crypto | write | |
create_tag | write | |
create_transaction_group | write | |
create_transactions | write | |
delete_account_balance_history | destructive | |
delete_balance_history_entry | destructive | |
delete_category | destructive | |
delete_crypto_synced_balance_history | destructive | |
delete_manual_account | destructive | |
delete_manual_crypto | destructive | |
delete_tag | destructive | |
delete_transaction | destructive | |
delete_transaction_attachment | destructive | |
delete_transaction_group | destructive | |
delete_transactions_bulk | destructive | |
get_account_balance_history | read | |
get_all_categories | read | |
get_all_manual_accounts | read | |
get_all_manual_crypto | read | |
get_all_plaid_accounts | read | |
get_all_synced_crypto | read | |
get_all_tags | read | |
get_balance_history | read | |
get_budget_settings | read | |
get_budget_summary | read | |
get_crypto_synced_balance_history | read | |
get_recurring_items | read | |
get_single_category | read | |
get_single_manual_account | read | |
get_single_manual_crypto | read | |
get_single_plaid_account | read | |
get_single_recurring_item | read | |
get_single_synced_crypto | read | |
get_single_tag | read | |
get_single_transaction | read | |
get_supported_cryptocurrencies | read | |
get_synced_crypto_balance | read | |
get_transaction_attachment_url | read | |
get_transactions | read | |
get_user | read | |
refresh_synced_crypto | read | |
remove_budget | destructive | |
split_transaction | read | |
trigger_plaid_fetch | write | |
unsplit_transaction | read | |
update_category | write | |
update_deleted_account_details | write | |
update_manual_account | write | |
update_manual_crypto | write | |
update_tag | write | |
update_transaction | write | |
update_transactions_bulk | write | |
upsert_account_balance_history | read | |
upsert_budget | read | |
upsert_crypto_synced_balance_history | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (5)
"-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAA\n-----END OPENSSH PRIVATE KEY-----\n",
delete_account_balance_history, delete_balance_history_entry, delete_category, delete_crypto_synced_balance_history, delete_manual_account, delete_manual_crypto, delete_tag, delete_transaction, delete
const key = box.file("outside/id_rsa", FIXTURES.privateKey);@modelcontextprotocol/sdk, @toon-format/toon, zod, @eslint/js, @types/node, eslint, husky, prettier
[lunchmoney-mcp-cloudflare](https://github.com/bm1549/lunchmoney-mcp-cloudflare) wraps this package as a Cloudflare Worker with Google sign-in and an email allowlist in front of the MCP endpoint. The
Gates applied: no_behavioural_pass.
c1f2fd9a3bcffull audit observations/trust-audit/mcp-server/akutishevsky__lunchmoney-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c1f2fd9a3bcf | CAUTION | B | 89 | first audit |
Questions
What is the LunchMoney MCP server?
A Model Context Protocol (MCP) server implementation for LunchMoney, providing programmatic access to personal finance management through LunchMoney's API.
What tools does LunchMoney expose?
59 in total: 32 read-only, 15 that write, and 12 that can delete or overwrite (delete_account_balance_history, delete_balance_history_entry, delete_category, delete_crypto_synced_balance_history, delete_manual_account). Every one is listed on this page with its risk.
Is LunchMoney safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does LunchMoney need?
It reads LUNCHMONEY_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does LunchMoney run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @akutishevsky/lunchmoney-mcp at 3.0.0.
How current is this page?
The grade is for one exact copy of the source (c1f2fd9a3bcf), read on 2026-10-07. The repository is watched and re-audited when it changes.