BankCAUTION
Give your AI assistant secure, read-only access to your bank accounts. MCP server supporting Plaid, Teller, Enable Banking, and Tink.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Give your AI assistant secure, read-only access to your bank accounts.
[](https://www.npmjs.com/package/@bank-mcp/server) [](https://opensource.org/licenses/MIT) [](https://github.com/elcukro/bank-mcp/actions/workflows/ci.yml) [](https://nodejs.org/) [](https://www.typescriptlang.org/)
Most people manage their finances by logging into bank portals, downloading CSVs, and building spreadsheets. bank-mcp eliminates that friction by letting your AI assistant query your bank accounts directly — balances, transactions, spending breakdowns — through natural conversation. It connects to real bank APIs via the Model Context Protocol so any MCP-compatible client (Claude Code, Claude Desktop, and others) can understand your finances.
- 5 providers, 15,000+ institutions — US and European banks covered
- Read-only by design — no write access, no transfers, no modifications
- Works with any MCP client — Claude Code, Claude Desktop, Cursor, and more
- Pluggable architecture — add your own provider in under 100 lines
Table of Contents
- Supported Providers
- Quick Start
- Client Setup
- Available Tools
- Screenshots
- Architecture
- Provider Setup Guides
- Caching
- Multiple Connections
- Security
- Adding a New Provider
- [Troubleshooting](#tro
d0d3e71c04c4OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add server -- npx -y @bank-mcp/[email protected]
{
"mcpServers": {
"server": {
"command": "npx",
"args": [
"-y",
"@bank-mcp/[email protected]"
]
}
}
}Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_balance | read | Get current account balance(s). Returns closing booked balance and expected balance when available. |
list_accounts | read | List all bank accounts across configured connections. Returns account UIDs, IBANs, names, and currencies. |
list_transactions | read | List bank transactions with optional filters. Defaults to last 90 days. Supports date range, amount range, and debit/credit type filtering. |
search_transactions | read | Full-text search across transaction descriptions, merchant names, and references. Use for finding specific payments or payees. |
spending_summary | read | Group expenses by merchant or category with totals. Shows where money is being spent. Use groupBy |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (21)
console.log(` Token valid for ${mins} more minutes — refreshing anyway...`);console.log(` New token expires: ${(conn.config.tokenExpiresAt as string).slice(0, 19)}`);const url = new URL(req.url || "/", `http://127.0.0.1:${port}`);const url = new URL(req.url || "/", "http://127.0.0.1");
const callbackUrl = `http://127.0.0.1:${port}/callback`;import { generateJwt } from "../../providers/enable-banking/auth.js";import { httpFetch } from "../../utils/http.js";opts: import("../../utils/http.js").FetchOptions,import { httpFetch } from "../../utils/http.js";import type { BankAccount } from "../../types.js";const url = new URL(req.url || "/", `http://127.0.0.1`);
const localUrl = `http://127.0.0.1:${port}`;@clack/prompts, @modelcontextprotocol/sdk, jsonwebtoken, zod, @types/jsonwebtoken, @types/node, eslint, typescript
architecture.png
bank-mcp.png
screenshots/3-list-transactions.png
screenshots/5-transactions-by-category.png
screenshots/6-group-by-merchants.png
console.log(" 3. Production — Full access (requires Plaid approval)\n");console.log(" 3. Production — Full access (requires mTLS certificate)\n");6. Serve Teller Connect HTML locally, open browser, capture access token from callback
Gates applied: no_behavioural_pass.
d0d3e71c04c4full audit observations/trust-audit/mcp-server/elcukro__bank.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d0d3e71c04c4 | CAUTION | B | 86 | first audit |
Questions
What is the Bank MCP server?
Give your AI assistant secure, read-only access to your bank accounts. MCP server supporting Plaid, Teller, Enable Banking, and Tink.
What tools does Bank expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Bank safe to connect to an agent?
With care. The audit graded it B (86/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Bank need?
No credential environment variables were found in its source, so it appears to need none.
How does Bank run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @bank-mcp/server at 0.2.1.
How current is this page?
The grade is for one exact copy of the source (d0d3e71c04c4), read on 2026-10-08. The repository is watched and re-audited when it changes.