Atlas / MCP servers / jeff-nasseri / Revolut

RevolutBLOCK

mcp/jeff-nasseri/revolut

This is the Revolut MCP server

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
29 20r · 7w · 2d
Transport
stdio
License
MIT
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Revolut MCP

Overview

Revolut MCP is a Model Context Protocol server that bridges AI assistants (Claude, Cursor, etc.) and the Revolut Business API. Through natural-language requests an assistant can list accounts and balances, browse transactions, manage counterparties, look up live exchange rates, move money, and more — across 21 tools organized into eight scopes.

⚠️ Revolut Business only. This server works exclusively with Revolut Business accounts via the Business API. It does not support personal Revolut accounts (Open Banking), RevolutX / crypto, or the Merchant API. It defaults to the sandbox; set REVOLUT_ENVIRONMENT=production with a production certificate to target a live business account.

Demo

https://github.com/user-attachments/assets/afb73925-9628-4473-b4c8-5527440357da

Documentation

📚 **[Full Documen

Read from source at commit f8fb1c3322e6OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add revolut-mcp --env REVOLUT_PRIVATE_KEY=${REVOLUT_PRIVATE_KEY} -- npx -y @jeff-nasseri/[email protected]
03

Exposed tools (29)

20 read · 7 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
accountsreadBusiness accounts: list accounts with balances and inspect bank details.
authreadAuthorize the application and exchange the authorization code for API tokens.
cancel_transactionwriteCancels a scheduled or pending transaction (payment/transfer) by ID. This is a destructive operation.
complete_authreadStep 2 of authentication. Exchanges the authorization code for access + refresh tokens and persists them to the token store. Run after setup_auth.
counterpartiesdestructiveSaved payees (counterparties): list, inspect, create, and delete.
create_counterpartywriteCreates a new counterparty (payee). Provide a
create_paymentwriteSends a payment from one of your accounts to a counterparty (payee). This moves money out of the account and is a write operation.
delete_counterpartydestructiveDeletes a counterparty (payee) by ID. This is a destructive, irreversible operation.
exchange_currencyreadExchanges currency between two of your own accounts at the current rate. This moves money and is a write operation.
foreign-exchangereadLive exchange rates and currency exchange between your own accounts.
get_accountreadGets a single Revolut Business account by ID, including its balance and state.
get_account_bank_detailsreadGets the bank details for a specific account — IBAN/BIC and/or local account number + sort code, supported schemes, and estimated settlement times.
get_accountsreadLists all Revolut Business accounts with their balance, currency, and state. Requires authentication.
get_counterpartiesreadLists all saved counterparties (payees) with their accounts and identifiers.
get_counterpartyreadGets a single counterparty by ID, including its linked accounts.
get_exchange_ratereadGets Revolut
get_payment_draftsreadLists pending payment drafts (payment orders awaiting approval).
get_team_membersreadLists the team members of the Revolut Business account with their email, role, and state.
get_transactionreadGets full details of a single transaction by ID, including type, state, timestamps, and all legs.
get_transactionsreadRetrieves transaction history with optional account, date range, and type filtering. Each transaction includes its legs (per-account amount, description, and running balance).
get_transfer_reasonswriteLists valid transfer reason codes (required for transfers/payments to certain countries and currencies). Optionally filter by country and/or currency.
paymentswritePayments and transfers: drafts, transfer reasons, pay a counterparty, move money between your accounts, and cancel scheduled transactions.
sandboxreadSandbox-only simulation helpers for generating and driving test data.
setup_authreadStep 1 of authentication. Returns the Revolut Business URL to open in a browser to authorize access. After approval the browser is redirected to your redirect URI with a
simulate_topupreadSandbox only. Tops up an account with simulated funds so you have test data to work with.
simulate_transaction_statewriteSandbox only. Drives a transfer/payment transaction into a target state (complete, revert, decline, or fail) for testing state transitions.
teamreadBusiness team members and their roles.
transactionsreadTransaction history and single-transaction detail.
transfer_between_accountswriteTransfers money between two of your own Revolut Business accounts. This moves money and is a write operation.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (11)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
.env.sandbox.template:18
# REVOLUT_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/getting-started/installation.md:69
-e REVOLUT_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
counterparties, delete_counterparty
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.sandbox.template
.env.sandbox.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/scope/accounts/index.ts:2
import { defineTool, Scope } from '../../utils/tool.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/scope/accounts/index.ts:3
import { BankDetail, RevolutAccount } from '../../types/revolut.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/scope/accounts/index.ts:4
import { formatMoney, joinParts } from '../../utils/format.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/scope/auth/index.ts:2
import { defineTool, Scope } from '../../utils/tool.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/scope/counterparties/index.ts:2
import { defineTool, Scope } from '../../utils/tool.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, dotenv, jsonwebtoken, uuid, zod, @types/jest, @types/jsonwebtoken
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/getting-started/installation.md:14
- You generate an X.509 key pair, upload the **public certificate** to the portal, and keep the matching **private key** locally. That private key signs the client-assertion JWT used at the token endp
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f8fb1c3322e6full audit observations/trust-audit/mcp-server/jeff-nasseri__revolut.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f8fb1c3322e6BLOCKD69first audit
06

Questions

What is the Revolut MCP server?

This is the Revolut MCP server

What tools does Revolut expose?

29 in total: 20 read-only, 7 that write, and 2 that can delete or overwrite (counterparties, delete_counterparty). Every one is listed on this page with its risk.

Is Revolut safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Revolut need?

It reads REVOLUT_PRIVATE_KEY, REVOLUT_PRIVATE_KEY_PATH and TOKEN_STORE_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Revolut run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @jeff-nasseri/revolut-mcp at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (f8fb1c3322e6), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement