RevolutBLOCK
This is the Revolut MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Revolut MCP
Overview
Revolut MCP is a Model Context Protocol server that bridges AI assistants (Claude, Cursor, etc.) and the Revolut Business API. Through natural-language requests an assistant can list accounts and balances, browse transactions, manage counterparties, look up live exchange rates, move money, and more — across 21 tools organized into eight scopes.
⚠️ Revolut Business only. This server works exclusively with Revolut Business accounts via the Business API. It does not support personal Revolut accounts (Open Banking), RevolutX / crypto, or the Merchant API. It defaults to the sandbox; set REVOLUT_ENVIRONMENT=production with a production certificate to target a live business account.Demo
https://github.com/user-attachments/assets/afb73925-9628-4473-b4c8-5527440357da
Documentation
📚 **[Full Documen
f8fb1c3322e6OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add revolut-mcp --env REVOLUT_PRIVATE_KEY=${REVOLUT_PRIVATE_KEY} -- npx -y @jeff-nasseri/[email protected]Exposed tools (29)
20 read · 7 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
accounts | read | Business accounts: list accounts with balances and inspect bank details. |
auth | read | Authorize the application and exchange the authorization code for API tokens. |
cancel_transaction | write | Cancels a scheduled or pending transaction (payment/transfer) by ID. This is a destructive operation. |
complete_auth | read | Step 2 of authentication. Exchanges the authorization code for access + refresh tokens and persists them to the token store. Run after setup_auth. |
counterparties | destructive | Saved payees (counterparties): list, inspect, create, and delete. |
create_counterparty | write | Creates a new counterparty (payee). Provide a |
create_payment | write | Sends a payment from one of your accounts to a counterparty (payee). This moves money out of the account and is a write operation. |
delete_counterparty | destructive | Deletes a counterparty (payee) by ID. This is a destructive, irreversible operation. |
exchange_currency | read | Exchanges currency between two of your own accounts at the current rate. This moves money and is a write operation. |
foreign-exchange | read | Live exchange rates and currency exchange between your own accounts. |
get_account | read | Gets a single Revolut Business account by ID, including its balance and state. |
get_account_bank_details | read | Gets the bank details for a specific account — IBAN/BIC and/or local account number + sort code, supported schemes, and estimated settlement times. |
get_accounts | read | Lists all Revolut Business accounts with their balance, currency, and state. Requires authentication. |
get_counterparties | read | Lists all saved counterparties (payees) with their accounts and identifiers. |
get_counterparty | read | Gets a single counterparty by ID, including its linked accounts. |
get_exchange_rate | read | Gets Revolut |
get_payment_drafts | read | Lists pending payment drafts (payment orders awaiting approval). |
get_team_members | read | Lists the team members of the Revolut Business account with their email, role, and state. |
get_transaction | read | Gets full details of a single transaction by ID, including type, state, timestamps, and all legs. |
get_transactions | read | Retrieves transaction history with optional account, date range, and type filtering. Each transaction includes its legs (per-account amount, description, and running balance). |
get_transfer_reasons | write | Lists valid transfer reason codes (required for transfers/payments to certain countries and currencies). Optionally filter by country and/or currency. |
payments | write | Payments and transfers: drafts, transfer reasons, pay a counterparty, move money between your accounts, and cancel scheduled transactions. |
sandbox | read | Sandbox-only simulation helpers for generating and driving test data. |
setup_auth | read | Step 1 of authentication. Returns the Revolut Business URL to open in a browser to authorize access. After approval the browser is redirected to your redirect URI with a |
simulate_topup | read | Sandbox only. Tops up an account with simulated funds so you have test data to work with. |
simulate_transaction_state | write | Sandbox only. Drives a transfer/payment transaction into a target state (complete, revert, decline, or fail) for testing state transitions. |
team | read | Business team members and their roles. |
transactions | read | Transaction history and single-transaction detail. |
transfer_between_accounts | write | Transfers money between two of your own Revolut Business accounts. This moves money and is a write operation. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (11)
# REVOLUT_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----"
-e REVOLUT_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----
counterparties, delete_counterparty
.env.sandbox.template
import { defineTool, Scope } from '../../utils/tool.js';import { BankDetail, RevolutAccount } from '../../types/revolut.js';import { formatMoney, joinParts } from '../../utils/format.js';import { defineTool, Scope } from '../../utils/tool.js';import { defineTool, Scope } from '../../utils/tool.js';@modelcontextprotocol/sdk, axios, dotenv, jsonwebtoken, uuid, zod, @types/jest, @types/jsonwebtoken
- You generate an X.509 key pair, upload the **public certificate** to the portal, and keep the matching **private key** locally. That private key signs the client-assertion JWT used at the token endp
Gates applied: critical_finding, no_behavioural_pass.
f8fb1c3322e6full audit observations/trust-audit/mcp-server/jeff-nasseri__revolut.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f8fb1c3322e6 | BLOCK | D | 69 | first audit |
Questions
What is the Revolut MCP server?
This is the Revolut MCP server
What tools does Revolut expose?
29 in total: 20 read-only, 7 that write, and 2 that can delete or overwrite (counterparties, delete_counterparty). Every one is listed on this page with its risk.
Is Revolut safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Revolut need?
It reads REVOLUT_PRIVATE_KEY, REVOLUT_PRIVATE_KEY_PATH and TOKEN_STORE_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Revolut run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @jeff-nasseri/revolut-mcp at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (f8fb1c3322e6), read on 2026-10-08. The repository is watched and re-audited when it changes.