Atlas / MCP servers / robcerda / Monarch Money

Monarch MoneyCAUTION

mcp/robcerda/monarch-money

MCP Server for use with Monarch Money

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
61 39r · 19w · 3d
Transport
streamable-http
License
MIT
Stars
408
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/robcerda-monarch-mcp-server)

A Model Context Protocol (MCP) server for integrating with the Monarch Money personal finance platform. This server provides seamless access to your financial accounts, transactions, budgets, and analytics through Claude Desktop and Claude Code.

My MonarchMoney referral: https://www.monarchmoney.com/referral/ufmn0r83yf?r_source=share

Built with the [MonarchMoneyCommunity Python library](https://github.com/bradleyseanf/monarchmoneycommunity) - An actively maintained community fork of the Monarch Money API with full MFA support.

🚀 Quick Start

If you plan to use this MCP server locally / on the same computer as Claude Desktop or similar, start with the Local Installation section.

For other deployment scenarios - like containerized deployment or cloud hosting - start with the Containerized Deployment section.

1. Local Installation

  1. Clone this repository:
git clone https://github.com/robcerda/monarch-mcp-server.git
cd monarch-mcp-server
  1. Install dependencies:

Using `uv` (recommended):

uv sync --locked

--locked installs exactly what uv.lock pins, verified against the hashes it records, and refuses to re-resolve. Without it, uv sync is free to pick up whatever versions happen to satisfy the ranges today.

Using `pip`:

pip install -r requirements-lock.txt --require-hashes
pip install -e . --no-deps

requirements-lock.txt is generated from uv.lock and pins every transitive dependency with has

Read from source at commit df1d5f20306cOBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add monarch-mcp-server -- uvx monarch-mcp-server
claude-desktop
{
  "mcpServers": {
    "monarch-mcp-server": {
      "command": "uvx",
      "args": [
        "monarch-mcp-server"
      ]
    }
  }
}
03

Exposed tools (61)

39 read · 19 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_transaction_tagwrite
bulk_categorize_transactionsread
bulk_update_transactionswrite
categorize_transactionread
check_auth_statusreadCheck if already authenticated with Monarch Money.
create_transactionwrite
create_transaction_categorywrite
create_transaction_rulewrite
create_transaction_tagwrite
debug_session_loadingreadDebug session loading issues.
delete_transactiondestructive
delete_transaction_ruledestructive
get_account_balance_historyread
get_account_holdingsread
get_account_sync_healthwrite
get_accountsreadGet all financial accounts from Monarch Money.
get_budgetsread
get_business_entitiesread
get_cashflowread
get_cashflow_by_monthread
get_category_detailsread
get_debt_paydownread
get_goal_contributionsread
get_goalsread
get_merchantread
get_net_worthread
get_net_worth_by_account_typeread
get_recurring_transactionsread
get_spending_summaryread
get_transaction_categoriesreadGet all available transaction categories from Monarch Money.
get_transaction_category_groupsreadGet all transaction category groups (parent groupings for categories).
get_transaction_detailsread
get_transaction_rulesread
get_transaction_splitsread
get_transaction_tagsreadGet all available transaction tags from Monarch Money.
get_transactionsread
get_transactions_needing_reviewread
get_transactions_summaryread
mark_transaction_reviewedread
monarch_loginreadSign in to Monarch Money.
monarch_login_with_tokenreadSign in to Monarch Money using a browser-copied session token.
monarch_logoutdestructiveClear the stored Monarch Money session from the system keyring.
monarch_whoamiread
refresh_accountsreadRequest account data refresh from financial institutions.
reorder_transaction_ruleread
review_recurring_streamread
search_transactionsread
set_budget_amountwrite
set_business_entitywrite
set_goal_contributionwrite
set_transaction_tagswrite
setup_authenticationreadGet instructions for setting up secure authentication with Monarch Money.
split_transactionread
update_accountwriteUpdate an account
update_categorywrite
update_merchantwrite
update_savings_goalwrite
update_transactionwrite
update_transaction_noteswrite
update_transaction_rulewrite
upload_account_balance_historywrite
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (11)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/monarch_mcp_server/app.py:140
"http://127.0.0.1",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/monarch_mcp_server/app.py:141
"http://127.0.0.1:*",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_transaction, delete_transaction_rule, monarch_logout
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_read_only.py:175
module = __import__(fn.__module__, fromlist=["x"])
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:297
Connect your MCP client to `http://127.0.0.1:8000/mcp` using Streamable HTTP.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:327
Here a reverse proxy on the Docker host forwards `https://mcp.example.com/mcp` to `http://127.0.0.1:8000/mcp`, preserving the public Host header.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:356
Connect an MCP client using Streamable HTTP to `http://127.0.0.1:8000/mcp`.
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/monarch_mcp_server/secure_session.py:109
raw = base64.b64decode(payload[len(_DPAPI_PREFIX):])
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:314
> This MCP server is not multi-user or multi-account. All connected clients share the same session and permissions.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:714
If `login_setup.py` reports "Programmatic login is blocked by Cloudflare CAPTCHA", choose option 1 (browser cookies) instead. Email/password POSTs to Monarch's login endpoint are sometimes gated by Cl
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha df1d5f20306cfull audit observations/trust-audit/mcp-server/robcerda__monarch-money.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-05df1d5f20306cCAUTIONB86first audit
06

Questions

What is the Monarch Money MCP server?

MCP Server for use with Monarch Money

What tools does Monarch Money expose?

61 in total: 39 read-only, 19 that write, and 3 that can delete or overwrite (delete_transaction, delete_transaction_rule, monarch_logout). Every one is listed on this page with its risk.

Is Monarch Money safe to connect to an agent?

With care. The audit graded it B (86/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Monarch Money need?

No credential environment variables were found in its source, so it appears to need none.

How does Monarch Money run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as monarch-mcp-server.

How current is this page?

The grade is for one exact copy of the source (df1d5f20306c), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement