Skip to main content
Glama
ezrazhang7

financecontext-mcp

by ezrazhang7

FinanceContext MCP

The open-source finance-context layer behind Lumi — a standalone remote MCP server that lets LLM agents reason over a user's real financial state without ever holding elevated credentials.

Extracted from the Lumi codebase; table names (lumi_*) reflect the production schema it runs against.

The security model (the interesting part)

The agent never gets more power than the user. The server validates Supabase-issued bearer JWTs against JWKS, then uses the user's own token for every Supabase read and write — so Postgres row-level security remains the single source of authority. There is no service-role key anywhere in this service. Misbehaving agent, compromised prompt, doesn't matter: the blast radius is exactly what the user themselves could do.

Layered on top:

  • OAuth protected-resource metadata (/.well-known/oauth-protected-resource) for MCP client discovery

  • Permission claims enforced on every write and approval tool — fail-closed: a token with no permission claims can read but cannot write or approve

  • DNS-rebinding protection via a host allowlist when binding publicly

  • An activity log (list_recent_activity) so tool usage is auditable

Permission model

Read tools require only a valid user token. Write and decision tools require an explicit permission claim on the JWT (permissions, app_metadata.permissions, or user_metadata.permissions):

Permission

Gates

memory_write

remember_financial_preference, forget_financial_memory

rules_draft

create_rule_draft

approvals_submit

submit_approval_request

approvals_decide

approve_pending_change, reject_pending_change

approvals_submit and approvals_decide are deliberately separate: an agent token should carry approvals_submit (propose) but never approvals_decide (dispose). The decision tools exist so a human-held token — not the agent — can accept or reject. Grant approvals_decide only to a principal you trust to be the human in the loop. If you previously ran with tokens that carried no permission claims, writes now fail closed until you add the claims above.

Related MCP server: Copilot Money MCP

Tool surface (19 tools)

Category

Tools

Read & analyze

list_accounts · get_balance_summary · search_transactions · summarize_spend · get_cashflow_summary · list_recurring_charges · get_sync_status

Classification

list_uncertain_transactions · explain_transaction_classification

Agent memory

remember_financial_preference · list_financial_memory · forget_financial_memory

Rule drafting

create_rule_draft · preview_rule_impact · list_rule_drafts

Human approval

submit_approval_request · approve_pending_change · reject_pending_change

Audit

list_recent_activity

The write path is deliberately indirect: agents draft rules and preview their impact, then submit an approval request. The request only takes effect when it is approved through approve_pending_change, which requires the separate approvals_decide permission — so an agent holding only approvals_submit cannot approve its own change. Agents propose; a human-held token disposes.

Stack

TypeScript · Express 5 · @modelcontextprotocol/sdk (Streamable HTTP) · @supabase/supabase-js · jose (JWKS validation) · zod

Endpoints

GET /health · GET /.well-known/oauth-protected-resource · POST|GET|DELETE /mcp

Local development

cp .env.example .env    # Supabase URL + publishable key
npm install
npm run dev             # tsx watch
npm run check           # typecheck
npm test                # unit tests (node:test via tsx)
npm run build && npm start
A
license - permissive license
Not graded
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    A comprehensive MCP server that enables AI assistants to manage Lunch Money finances through 37 tools for transactions, budgets, and accounts. It supports both local stdio and remote HTTP transport modes with secure, encrypted credential storage.
    10
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    This MCP server bridges Copilot Money with AI platforms like Claude and Cursor. It provides tools for fetching transactions, account balances, and automated data cleanup. By enabling secure, programmable access to financial records, it allows agents to perform complex tasks like transaction tagging and spending audits autonomously.
    14
    147
    74
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    An MCP server that exposes Akahu (New Zealand open-banking) data to LLM agents, allowing them to list bank accounts, inspect investment holdings, and pull transactions for analysis.
    3
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server that enables LLM clients to analyze and manage YNAB budgets, accounts, categories, and transactions.
    27
    67
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.

  • Paid remote MCP for agent design system guard MCP, structured receipts, audit logs, and reviewer-rea

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/ezrazhang7/financecontext-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server