Back to Browse

Myfinance MCP Server

FinanceLow Risk9.5MCP RegistryRemote
Free

Server data from the Official MCP Registry

Personal finance by conversation: expenses, receipts, statement import, budgets, net worth.

About

Personal finance by conversation: expenses, receipts, statement import, budgets, net worth.

Remote endpoints: streamable-http: https://myfinance-mcp.com/mcp

Security Report

9.5
Low Risk9.5Low Risk

Valid MCP server (2 strong, 2 medium validity signals). 1 known CVE in dependencies Imported from the Official MCP Registry.

Endpoint verified · Requires authentication · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-alex-odoo-myfinance-mcp": {
      "url": "https://myfinance-mcp.com/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MyFinance MCP

A remote MCP server for personal finance - log expenses by talking, snap receipt photos, import whole bank statements, and get budgets, trends and net worth computed for you, in any currency.

Website: myfinance-mcp.com · Free while in beta · Built by Rteam

Quick Start

Already hosted and ready to use - just connect it to your MCP client:

https://myfinance-mcp.com/mcp

On Claude.ai: Customize → Connectors → + → Add custom connector → paste the URL → Connect. Leave the OAuth Client ID and Client Secret fields empty - filling them breaks sign-in.

On ChatGPT: Settings → Apps → Create app → paste the URL → choose OAuth → Create.

On first connect you sign in with Google or register with an email and password. Your data persists across reconnections.

Why

  • No app, no forms, no spreadsheet. "Spent 24.50 eur on groceries at Lidl" is the whole workflow.
  • Every number is computed in SQL. The server owns the data and the math; the AI reads the results, it never guesses arithmetic.
  • Any currency. Transactions keep their original currency; the FX rate to your base currency is frozen at transaction date, so history never rewrites itself.
  • Statements in one message. Drop a CSV/PDF export; hundreds of rows import in one call with idempotent deduplication, hand-logged twins merged, totals reconciled.
  • Personal vs business. Entity tag on accounts and transactions, filterable everywhere, included in CSV export for your accountant.
  • Dashboards in the chat. Budgets, trends, summaries and accounts render as interactive panels (MCP Apps) right in the conversation.

Tech Stack

  • Bun - runtime and package manager
  • Express - HTTP layer
  • MCP SDK - Model Context Protocol over Streamable HTTP (stateless)
  • OAuth 2.1 - PKCE + dynamic client registration, Google sign-in optional
  • Prisma + PostgreSQL - all money as numeric, all stats as SQL aggregates
  • Docker - single container deployment

MCP Tools

ToolDescription
log_expenseRecord one purchase, bill or receipt (negative amount = refund)
log_incomeRecord income: salary, invoice, refund, interest
log_transferMove money between accounts, cross-currency supported; never counts as spending
log_balanceAnchor an account's balance at a date; later flows compute from the snapshot
import_transactionsBulk statement import (up to 500 rows/call): dedup by bank reference or derived key, twin merge, reconciliation check
create_accountCreate a bank / card / cash / investment account with currency and personal/business entity
update_accountRename an account or change its type, entity or main currency
delete_accountDelete one money account (with its transactions after explicit confirmation)
merge_accountsFold one account into another: move rows, de-duplicate both sides, rewrite transfers
get_accountsAll accounts with balances and net worth, converted to base currency
get_summaryPeriod totals by category, merchant or month; expense or income breakdown, category drill-down and exclusions
get_transactionsList and filter raw transactions
get_trendsMonth-over-month spending trends and deltas
set_budgetMonthly cap per category or overall
get_budget_progressLive budget progress with days left; renders as a dashboard
update_transactionFix any field of an existing transaction, including its type (e.g. turn a cash withdrawal into a transfer); category fixes are remembered per merchant for future syncs
delete_transactionDelete one transaction by id
delete_transactionsBulk delete by ids
get_settingsBase currency and timezone
update_settingsChange base currency or timezone
export_transactionsFull CSV export (includes the entity column for accountant handoff)
connect_bankLink a real bank via open banking (Enable Banking, EU/UK): list banks, start consent, status, per-account sync toggle, disconnect
sync_bankPull booked transactions and balances from the connected bank; incremental, transfer pairing, dedup-safe. Healthy connections also auto-sync server-side roughly daily
connect_zenmoneyLink a ZenMoney account (international and .ru backends auto-detected) for read-only sync
sync_zenmoneyPull ZenMoney accounts and transactions; incremental, dedup-safe, keeps your manual edits
delete_all_dataPermanently delete the user profile and ALL data (GDPR erasure)
pingHealth and auth check

MCP Apps

Four tools return an interactive dashboard (ui://myfinancemcp/dashboard) rendered directly in the chat on clients that support MCP Apps: budget rings, monthly trends, category summaries and the accounts/net-worth panel. Light and dark theme aware.

Security & Privacy

  • Receipt photos are parsed by YOUR AI client; images never reach this server.
  • Amounts, merchants and notes are never written to server logs (blind logs); telemetry stores event types and ids only.
  • OAuth 2.1 with PKCE, encrypted tokens, rate-limited sign-in.
  • All 27 tools carry MCP annotations (read-only and destructive ops flagged, connector tools marked open-world), so clients can gate confirmations correctly.
  • Bank access is strictly read-only: open banking consent via Enable Banking (the bank authenticates the user; we never see credentials), ZenMoney via the user's own API token. Session ids and tokens are stored AES-256-GCM encrypted.
  • CSV export and instant full deletion are tools, not support tickets.
  • Hosted instance: EU data residency, row-level security keyed to your account.
  • 154 automated end-to-end checks (full OAuth flow, every tool, import dedup semantics, GDPR deletion) run in CI and as a hard deploy gate.

See SECURITY.md for the disclosure policy.

Self-hosting

MIT-licensed; runs anywhere Bun and Postgres run.

1. Postgres

Any PostgreSQL 15+ works. Supabase free tier is a good fit: create a project and copy the session pooler connection string (IPv4).

Apply the schema:

bun install
bunx prisma db push

2. Environment variables

VariableDescription
PORTServer port (default 8788)
BASE_URLPublic URL of the server (OAuth issuer)
DATABASE_URLPostgres connection string
MYFINANCE_MCP_EMAILBootstrap user email
MYFINANCE_MCP_PASSWORD_HASHBootstrap user password hash (see below)
GOOGLE_CLIENT_ID(optional) Google OAuth client ID for "Continue with Google"
GOOGLE_CLIENT_SECRET(optional) Google OAuth client secret
RESEND_API_KEY(optional) Resend key for new-signup email notifications
NOTIFY_EMAIL(optional) Where signup notifications go
FROM_EMAIL(optional) Verified sender for notifications
AUTO_SYNC_INTERVAL_MS(optional) Bank auto-sync tick, default hourly (syncs connections >20h stale); 0 disables

Generate the password hash:

bun -e "console.log(await Bun.password.hash(process.argv[1]))" 'your-password'

3. Run

docker compose up -d      # uses the included Dockerfile, port 8788

Put nginx (or any TLS-terminating proxy) in front and point BASE_URL at your domain. The static landing in site/ is optional - serve it from the same origin if you want one.

Development

bun install
cp .env.example .env   # fill in your values
bun run dev            # hot reload on :8788
bun run e2e            # self-contained end-to-end suite (spawns its own server)
bun run lint

The e2e suite (154 checks) covers the full OAuth flow (discovery, dynamic registration, PKCE, refresh rotation), every tool, statement-import dedup semantics, ZenMoney sync against a stubbed Diff API, and GDPR deletion.

API Endpoints

EndpointDescription
POST /mcpMCP endpoint (Bearer auth)
GET /healthHealth check
GET /.well-known/oauth-authorization-serverOAuth metadata discovery
GET /.well-known/oauth-protected-resource/mcpProtected resource metadata
POST /registerDynamic client registration
GET /authorizeOAuth authorization (sign-in page)
POST /tokenToken exchange
GET /auth/googleGoogle sign-in start (when configured)
GET /api/statsPublic aggregate counters (counts only, never amounts)

License

MIT - Rteam FZE LLC

Reviews

No reviews yet

Be the first to review this server!