financecontext-mcp
Provides tools for interacting with a user's financial data stored in Supabase, enabling agents to list accounts, search transactions, summarize spending, and manage rule drafts and approval requests while enforcing row-level security via the user's own JWT.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@financecontext-mcpsummarize my spending last month"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
FinanceContext MCP
The open-source finance-context layer behind Lumi — a standalone remote MCP server that lets LLM agents reason over a user's real financial state without ever holding elevated credentials.
Extracted from the Lumi codebase; table names (lumi_*) reflect the production schema it runs against.
The security model (the interesting part)
The agent never gets more power than the user. The server validates Supabase-issued bearer JWTs against JWKS, then uses the user's own token for every Supabase read and write — so Postgres row-level security remains the single source of authority. There is no service-role key anywhere in this service. Misbehaving agent, compromised prompt, doesn't matter: the blast radius is exactly what the user themselves could do.
Layered on top:
OAuth protected-resource metadata (
/.well-known/oauth-protected-resource) for MCP client discoveryPermission claims enforced on every write and approval tool — fail-closed: a token with no permission claims can read but cannot write or approve
DNS-rebinding protection via a host allowlist when binding publicly
An activity log (
list_recent_activity) so tool usage is auditable
Permission model
Read tools require only a valid user token. Write and decision tools require an explicit permission claim on the JWT (permissions, app_metadata.permissions, or user_metadata.permissions):
Permission | Gates |
|
|
|
|
|
|
|
|
approvals_submit and approvals_decide are deliberately separate: an agent token should carry approvals_submit (propose) but never approvals_decide (dispose). The decision tools exist so a human-held token — not the agent — can accept or reject. Grant approvals_decide only to a principal you trust to be the human in the loop. If you previously ran with tokens that carried no permission claims, writes now fail closed until you add the claims above.
Related MCP server: ynab-mcp
Tool surface (19 tools)
Category | Tools |
Read & analyze |
|
Classification |
|
Agent memory |
|
Rule drafting |
|
Human approval |
|
Audit |
|
The write path is deliberately indirect: agents draft rules and preview their impact, then submit an approval request. The request only takes effect when it is approved through approve_pending_change, which requires the separate approvals_decide permission — so an agent holding only approvals_submit cannot approve its own change. Agents propose; a human-held token disposes.
Stack
TypeScript · Express 5 · @modelcontextprotocol/sdk (Streamable HTTP) · @supabase/supabase-js · jose (JWKS validation) · zod
Endpoints
GET /health · GET /.well-known/oauth-protected-resource · POST|GET|DELETE /mcp
Local development
cp .env.example .env # Supabase URL + publishable key
npm install
npm run dev # tsx watch
npm run check # typecheck
npm test # unit tests (node:test via tsx)
npm run build && npm startThis server cannot be deployed
Maintenance
Related MCP Connectors
The Remote MCP server acts as a standardized bridge between LLM applications (like Claude, ChatGPT, and Cursor) and external services, enabling AI agents to access external tools and resources. Its primary capability is providing a centralized search tool to discover other MCP servers and their respective tools. Unlike local implementations, it runs remotely with OAuth authentication and permission controls for security.
Personal finance for AI agents — onboard, import statements, categorize & budget over MCP.
MCP server connecting AI agents to 100+ apps (Gmail, Slack, Notion, GitHub) via one-click OAuth.
An MCP server that provides read access to your cloud storage providers, bank accounts and more.
Related MCP Servers
- AlicenseAqualityAmaintenanceThis MCP server bridges Copilot Money with AI platforms like Claude and Cursor. It provides tools for fetching transactions, account balances, and automated data cleanup. By enabling secure, programmable access to financial records, it allows agents to perform complex tasks like transaction tagging and spending audits autonomously.1490 npm79MIT
- AlicenseAqualityBmaintenanceAn MCP server that enables LLM clients to analyze and manage YNAB budgets, accounts, categories, and transactions.2775 npmMIT
- FlicenseAqualityBmaintenanceA lightweight MCP server for managing personal finances locally. It allows users to log transactions, view summaries, manage categories, and interact with their budget via any MCP-compatible LLM client.12-
- FlicenseNot gradedqualityBmaintenanceMCP server for personal finance management. Enables natural language expense logging, budgeting, recurring charge detection, and statement import with deterministic local calculations.-