ebill-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ebill-mcpWhat bills are in my eBill archive?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ebill-mcp
Read your Swiss eBill archive and download the invoice PDFs. Read-only — it cannot approve, release or pay anything.
Unofficial, and attached to your bank. eBill is reached only through an authenticated e-banking session, so this server reads through a window you logged into. It is read-only by construction — see What it cannot do — but it is still pointed at a payment system, and it is inherently fragile: the portal is an Angular app that changes without notice. Use it for your own account and respect the provider's terms of service.
An MCP server for the Swiss eBill portal operated by SIX. From any MCP client (Claude Code, Claude Desktop, …) you can list the bills in your archive — biller, amount, due date, delivery date — and download the invoice PDFs.
There is no credential to hold
That is the fact everything else follows from. eBill has no API you can get a key for; the portal is entered by SSO redirect from your bank's e-banking, and the login is second-factor-bound. So a run cannot start without a human.
You log in. The server reads. It opens a visible browser window at your e-banking and hands it to you; it never types into that window. Afterwards it attaches to the same window over the debugging port and reads through the session you established. One login serves many calls — disconnecting a debug client leaves the window standing, which is the whole reason this is usable.
flowchart TD
C["MCP client"] -->|"stdio JSON-RPC"| S["ebill-mcp"]
S -->|"ebill_open"| W["a visible browser window<br/>opens at YOUR e-banking"]
W --> YOU["you log in — second factor,<br/>then open eBill"]
YOU --> TAB[("the eBill tab<br/>stays open")]
S -->|"every other tool"| ATT["attach over the debugging port"]
ATT --> TAB
TAB -->|"fetch with the browser's<br/>own session cookie"| P[("SIX eBill portal")]
ATT --> G{"is the path on<br/>the allow-list?"}
G -->|"no"| NO["refused before it is sent"]
G -->|"yes — five read paths"| P
P -.->|"bills, billers, PDFs"| OUT["answers, and files on disk"]
classDef gate fill:#fff4e5,stroke:#d9822b
classDef bad fill:#fdecea,stroke:#c0392b
classDef you fill:#eafaf1,stroke:#27ae60
class G gate
class NO bad
class YOU,W youNo token ever reaches this process. The session lives in the browser and the browser applies it, so there is nothing here to leak — and nothing to store.
Related MCP server: datagate-mcp
What it cannot do
Approving a bill, releasing one for payment, editing an amount, adding a biller subscription and cancelling a standing approval are all one call away in the same API, and one click away in the same page. "We only wrote reads" is a property of today's code, so it is enforced twice:
Every request goes through one function that takes no method and no body. There is no code path in this server that can send anything but a
GET.Every path is matched against an allow-list first. Five patterns, all reads. Nothing that changes state is on it, so reaching one takes editing the source rather than passing an argument.
Both are tested, and the fixture answers 405 to anything but a GET — so the
assertion "only reads arrived" cannot pass for the wrong reason.
Prerequisites
Node.js ≥ 20.19
A Chromium for Playwright, and ideally a real Chrome to log in with
Swiss e-banking with eBill enabled
git clone https://github.com/sapn95/ebill-mcp.git
cd ebill-mcp
npm install
npx playwright install chromiumRegister in Claude Code
claude mcp add ebill --scope user -- node /absolute/path/to/ebill-mcp/index.jsSet your bank's entry page once, so ebill_open does not have to be told every
time — this server does not guess which bank you use:
export EBILL_BANK_URL=https://your-bank.example.com/loginThe normal flow
ebill_open— a window opens at your e-banking. You log in and open eBill.ebill_status— confirms the session is reachable and says how long it has left.ebill_list_bills,ebill_download_all, … for as long as the session lasts.When it expires, every tool says so and names the fix: log in again.
Tools
Tool | Arguments |
| — |
|
|
| — |
|
|
|
|
| — |
|
|
|
|
Environment variables
Variable | Default | Purpose |
|
| portal origin |
|
| where the logged-in window listens |
|
| browser profile — holds a live banking session |
| unset | your e-banking entry page for |
|
| channel or absolute path |
| unset |
|
A variable that is set, even to the empty string, is authoritative: an empty
EBILL_BANK_URL means there is no bank here, not "fall back to the default".
Anything else would make "no bank" impossible to express, and would let a test
that thought it was isolated open a real login page.
Security: the profile directory holds a live e-banking session. It is a secret, it is git-ignored, and it belongs outside any repository. Delete it when a run is done.
Three things the portal does that cost a day to find out
A 200 is not evidence. The Angular server answers any unknown path under
its own prefix with the app shell and a 200 application/json. The four obvious
guesses at a PDF endpoint — payments/{id}/receipt, /document, /bill,
/pdf — all "work" if you read status codes. None of them exists. Every
download here is checked by its first bytes instead.
The PDF is not under /api/. It is
/ebill-portal/ui/payment-pdfs/<businessCaseId>/<receiptFileName>, and the
filename out of the record is part of the path — URL-encoded, not derivable, not
optional. Records without a filename have no document, and are reported as such
rather than given a synthesised name.
One status is half an archive. The bills live under two, done and open,
and the default view shows one of them. ebill_list_bills reads both unless you
narrow it on purpose.
Also worth knowing: businessCaseDate is the date eBill delivered the bill,
which is days to weeks away from the date printed on the document. If you are
filing these, the printed date is usually the one you want.
Checks
npm run gate # lint + smoke + hygiene + tests with coverage enforced
npm test # just the tests
npm run mutate # mutation-test the lines this branch changedRuns offline and without a bank: the suites attach to a throwaway Chromium holding a local fixture, so nothing they do can reach a real account.
The fixture is the interesting part. It answers the app shell with a 200 for
unknown paths exactly as the portal does — a fixture that returned 404 there
would make the guard against it untestable — and it refuses anything that is not
a GET, so the test asserting that only reads left this process means something.
Mutation testing
npm run mutate asks a different question: not "do the tests pass" but "would
they notice if a guard were removed". StrykerJS deletes one piece of behaviour
at a time and reruns the suite; whatever survives is something no assertion is
watching. It found eleven real gaps in the sibling
pingen-mcp after model review rounds had
stopped turning anything up. Here it runs over the lines a branch changed,
because this suite launches a real browser and a full pass costs hours.
License
MIT © sapn95 — see LICENSE.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceA read-only MCP server for securely accessing Xendit payment platform data. It enables querying balances, invoices, transactions, disbursements, refunds, and virtual account payments while preventing any money-moving operations.Last updated13MIT
- AlicenseBqualityCmaintenanceMCP server for the DataGate billing platform API, providing read-only tools to manage customers, invoices, products, agreements, sites, and payments.Last updated13MIT
- Alicense-qualityCmaintenanceRead-only MCP server for FinTS/HBCI banking; enables account information retrieval such as balances and transactions via PIN-TAN.Last updatedMIT
- AlicenseAqualityAmaintenanceMCP server for the Canton of Bern tax portal TaxMe/BE-Login that reads account statements and tax returns via Playwright browser automation.Last updated13475MIT
Related MCP Connectors
Read-only MCP server for ClassQuill, a tutoring-business-management platform.
Read-only MCP server for searching Japan government procurement bid information from the KKJ portal.
A paid remote MCP for hosted MCP server, built to return verdicts, receipts, usage logs, and audit-r
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/sapn95/ebill-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server