Credit Karma MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CK_COOKIES | No | Full Cookie header from a signed-in creditkarma.com request | |
| CK_DB_PATH | No | Path to SQLite database file | ~/.creditkarma-mcp/transactions.db |
| CK_DISABLE_FETCHPROXY | No | Set to '1' to skip the fetchproxy fallback (headless / CI) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| ck_healthcheckA | Resolves the credential the way real tools do, then makes one authenticated request to creditkarma.com. Reports which source supplied the credential, whether creditkarma.com accepted it, the round-trip time, and a plain-English hint distinguishing 'no credential' from 'credential rejected' from 'a creditkarma.com-side problem'. Read-only; never returns the credential itself. Call this when a real tool fails and you want to know which hop broke. |
| ck_set_sessionA | Store a Credit Karma session to enable automatic token refresh. Pass the full Cookie header from a signed-in creditkarma.com request (Chrome DevTools → Network → any creditkarma.com request → Request Headers → right-click the |
| ck_forget_sessionA | Forget the Credit Karma session on this machine: delete the saved-session file (~/.creditkarma-mcp/session, or CK_SESSION_PATH) that ck_set_session and token refreshes write, and clear the credentials held in memory. Use when the user stops using this server or wants their stored login removed. Local only — Credit Karma is not contacted, synced transactions are kept, and a CK_COOKIES value set in the host config is not changed. |
| ck_sync_transactionsA | Sync Credit Karma transactions into the local SQLite database. Incremental by default (fetches since last sync + 30-day overlap for updates). If no valid token, initiates the login/MFA flow automatically. Bounded and resumable: when it pauses with more to fetch it returns another_run_needed:true and a note — run it again and it continues from where it stopped. |
| ck_list_transactionsC | List transactions with optional filters. Paginated. |
| ck_get_recent_transactionsA | Return the N most recent transactions. Convenience shortcut for ck_list_transactions. |
| ck_get_spending_by_categoryA | Group debit transactions by category and return totals. |
| ck_get_spending_by_merchantB | Return top merchants by total debit spend. |
| ck_get_account_summaryA | Return per-account debit, credit, and net totals. |
| ck_query_sqlA | Execute a raw SQL SELECT query (CTEs via WITH ... SELECT are supported) against the transactions database. Non-SELECT statements (INSERT, UPDATE, DELETE, DROP, etc.) are rejected. Returns at most max_rows rows (default 500, max 5000); a larger result comes back with truncated: true, so prefer aggregates or LIMIT/OFFSET paging. Tables: transactions, accounts, categories, merchants, sync_state. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 10 tools
Most tools target clearly distinct operations (session management, sync, list, aggregates, raw SQL). The only real overlap is ck_get_recent_transactions, which is explicitly documented as a convenience shortcut for ck_list_transactions, and ck_query_sql, which overlaps in capability with the aggregate tools but is clearly framed as a raw-SQL escape hatch.
All tools use the same ck_ snake_case prefix and are overwhelmingly verb_noun (set_session, forget_session, sync_transactions, list_transactions, get_*). ck_healthcheck is a noun-ish exception that breaks the verb_noun pattern, but it's a single minor deviation.
Ten tools is well-scoped for a Credit Karma transaction/session server: each covers a distinct lifecycle stage (health, auth, sync, read, aggregate, raw query) without obvious redundancy or padding.
The surface covers credential health, session lifecycle, sync, listing, recent-transaction shortcut, spending aggregates, account summary, and a raw SQL escape hatch, which is close to full lifecycle coverage. Minor gaps exist (no explicit tool to list accounts or check sync_state status without writing SQL), but these are workable via ck_query_sql.