financecontext-mcp
Provides tools for interacting with a user's financial data stored in Supabase, enabling agents to list accounts, search transactions, summarize spending, and manage rule drafts and approval requests while enforcing row-level security via the user's own JWT.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@financecontext-mcpsummarize my spending last month"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
FinanceContext MCP
The open-source finance-context layer behind Lumi — a standalone remote MCP server that lets LLM agents reason over a user's real financial state without ever holding elevated credentials.
Extracted from the Lumi codebase; table names (lumi_*) reflect the production schema it runs against.
The security model (the interesting part)
The agent never gets more power than the user. The server validates Supabase-issued bearer JWTs against JWKS, then uses the user's own token for every Supabase read and write — so Postgres row-level security remains the single source of authority. There is no service-role key anywhere in this service. Misbehaving agent, compromised prompt, doesn't matter: the blast radius is exactly what the user themselves could do.
Layered on top:
OAuth protected-resource metadata (
/.well-known/oauth-protected-resource) for MCP client discoveryPermission claims enforced when present (default read-capable when absent)
DNS-rebinding protection via a host allowlist when binding publicly
An activity log (
list_recent_activity) so tool usage is auditable
Related MCP server: Copilot Money MCP
Tool surface (19 tools)
Category | Tools |
Read & analyze |
|
Classification |
|
Agent memory |
|
Rule drafting |
|
Human approval |
|
Audit |
|
The write path is deliberately indirect: agents draft rules and preview their impact, but changes land only through an explicit approval request a human accepts or rejects. Agents propose; people dispose.
Stack
TypeScript · Express 5 · @modelcontextprotocol/sdk (Streamable HTTP) · @supabase/supabase-js · jose (JWKS validation) · zod
Endpoints
GET /health · GET /.well-known/oauth-protected-resource · POST|GET|DELETE /mcp
Local development
cp .env.example .env # Supabase URL + publishable key
npm install
npm run dev # tsx watch
npm run check # typecheck
npm run build && npm startThis server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityAmaintenanceA comprehensive MCP server that enables AI assistants to manage Lunch Money finances through 37 tools for transactions, budgets, and accounts. It supports both local stdio and remote HTTP transport modes with secure, encrypted credential storage.Last updated181MIT
- AlicenseAqualityBmaintenanceThis MCP server bridges Copilot Money with AI platforms like Claude and Cursor. It provides tools for fetching transactions, account balances, and automated data cleanup. By enabling secure, programmable access to financial records, it allows agents to perform complex tasks like transaction tagging and spending audits autonomously.Last updated1414568MIT
- FlicenseAqualityCmaintenanceAn MCP server that exposes Akahu (New Zealand open-banking) data to LLM agents, allowing them to list bank accounts, inspect investment holdings, and pull transactions for analysis.Last updated3
- AlicenseAqualityBmaintenanceAn MCP server that enables LLM clients to analyze and manage YNAB budgets, accounts, categories, and transactions.Last updated27110MIT
Related MCP Connectors
Paid remote MCP for agent design system guard MCP, structured receipts, audit logs, and reviewer-rea
User-owned memory for AI agents, Copilot, Claude, IDEs, CLIs, and chat apps over remote MCP.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ezrazhang7/financecontext-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server