Monarch MoneyCAUTION
MCP Server for use with Monarch Money
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/robcerda-monarch-mcp-server)
A Model Context Protocol (MCP) server for integrating with the Monarch Money personal finance platform. This server provides seamless access to your financial accounts, transactions, budgets, and analytics through Claude Desktop and Claude Code.
My MonarchMoney referral: https://www.monarchmoney.com/referral/ufmn0r83yf?r_source=share
Built with the [MonarchMoneyCommunity Python library](https://github.com/bradleyseanf/monarchmoneycommunity) - An actively maintained community fork of the Monarch Money API with full MFA support.
🚀 Quick Start
If you plan to use this MCP server locally / on the same computer as Claude Desktop or similar, start with the Local Installation section.
For other deployment scenarios - like containerized deployment or cloud hosting - start with the Containerized Deployment section.
1. Local Installation
- Clone this repository:
git clone https://github.com/robcerda/monarch-mcp-server.git cd monarch-mcp-server
- Install dependencies:
Using `uv` (recommended):
uv sync --locked
--locked installs exactly what uv.lock pins, verified against the hashes it records, and refuses to re-resolve. Without it, uv sync is free to pick up whatever versions happen to satisfy the ranges today.
Using `pip`:
pip install -r requirements-lock.txt --require-hashes pip install -e . --no-deps
requirements-lock.txt is generated from uv.lock and pins every transitive dependency with has
df1d5f20306cOBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add monarch-mcp-server -- uvx monarch-mcp-server
{
"mcpServers": {
"monarch-mcp-server": {
"command": "uvx",
"args": [
"monarch-mcp-server"
]
}
}
}Exposed tools (61)
39 read · 19 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_transaction_tag | write | |
bulk_categorize_transactions | read | |
bulk_update_transactions | write | |
categorize_transaction | read | |
check_auth_status | read | Check if already authenticated with Monarch Money. |
create_transaction | write | |
create_transaction_category | write | |
create_transaction_rule | write | |
create_transaction_tag | write | |
debug_session_loading | read | Debug session loading issues. |
delete_transaction | destructive | |
delete_transaction_rule | destructive | |
get_account_balance_history | read | |
get_account_holdings | read | |
get_account_sync_health | write | |
get_accounts | read | Get all financial accounts from Monarch Money. |
get_budgets | read | |
get_business_entities | read | |
get_cashflow | read | |
get_cashflow_by_month | read | |
get_category_details | read | |
get_debt_paydown | read | |
get_goal_contributions | read | |
get_goals | read | |
get_merchant | read | |
get_net_worth | read | |
get_net_worth_by_account_type | read | |
get_recurring_transactions | read | |
get_spending_summary | read | |
get_transaction_categories | read | Get all available transaction categories from Monarch Money. |
get_transaction_category_groups | read | Get all transaction category groups (parent groupings for categories). |
get_transaction_details | read | |
get_transaction_rules | read | |
get_transaction_splits | read | |
get_transaction_tags | read | Get all available transaction tags from Monarch Money. |
get_transactions | read | |
get_transactions_needing_review | read | |
get_transactions_summary | read | |
mark_transaction_reviewed | read | |
monarch_login | read | Sign in to Monarch Money. |
monarch_login_with_token | read | Sign in to Monarch Money using a browser-copied session token. |
monarch_logout | destructive | Clear the stored Monarch Money session from the system keyring. |
monarch_whoami | read | |
refresh_accounts | read | Request account data refresh from financial institutions. |
reorder_transaction_rule | read | |
review_recurring_stream | read | |
search_transactions | read | |
set_budget_amount | write | |
set_business_entity | write | |
set_goal_contribution | write | |
set_transaction_tags | write | |
setup_authentication | read | Get instructions for setting up secure authentication with Monarch Money. |
split_transaction | read | |
update_account | write | Update an account |
update_category | write | |
update_merchant | write | |
update_savings_goal | write | |
update_transaction | write | |
update_transaction_notes | write | |
update_transaction_rule | write | |
upload_account_balance_history | write |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (11)
"http://127.0.0.1",
"http://127.0.0.1:*",
delete_transaction, delete_transaction_rule, monarch_logout
streamable-http
module = __import__(fn.__module__, fromlist=["x"])
Connect your MCP client to `http://127.0.0.1:8000/mcp` using Streamable HTTP.
Here a reverse proxy on the Docker host forwards `https://mcp.example.com/mcp` to `http://127.0.0.1:8000/mcp`, preserving the public Host header.
Connect an MCP client using Streamable HTTP to `http://127.0.0.1:8000/mcp`.
raw = base64.b64decode(payload[len(_DPAPI_PREFIX):])
> This MCP server is not multi-user or multi-account. All connected clients share the same session and permissions.
If `login_setup.py` reports "Programmatic login is blocked by Cloudflare CAPTCHA", choose option 1 (browser cookies) instead. Email/password POSTs to Monarch's login endpoint are sometimes gated by Cl
Gates applied: no_behavioural_pass.
df1d5f20306cfull audit observations/trust-audit/mcp-server/robcerda__monarch-money.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | df1d5f20306c | CAUTION | B | 86 | first audit |
Questions
What is the Monarch Money MCP server?
MCP Server for use with Monarch Money
What tools does Monarch Money expose?
61 in total: 39 read-only, 19 that write, and 3 that can delete or overwrite (delete_transaction, delete_transaction_rule, monarch_logout). Every one is listed on this page with its risk.
Is Monarch Money safe to connect to an agent?
With care. The audit graded it B (86/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Monarch Money need?
No credential environment variables were found in its source, so it appears to need none.
How does Monarch Money run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as monarch-mcp-server.
How current is this page?
The grade is for one exact copy of the source (df1d5f20306c), read on 2026-10-05. The repository is watched and re-audited when it changes.