Pluggy MCP Starter
This server lets AI agents read and query your aggregated Pluggy Open Finance accounts and transactions using read-only SQL.
pluggy_schema: inspect available tables, fields, SQL semantics, and query limitations; never exposes secrets.pluggy_query: run read-only SQLiteSELECTqueries overaccountsandtransactionsfor a requested UTC period.Query results include coverage metadata and reuse an in-memory collection cache for 15 minutes.
It aggregates multiple Pluggy
itemIds (multiple banks/cards) into one local database.It is strictly read-only: no writes, no moving money, and no destructive operations are allowed.
Allows querying Nubank accounts, transactions, balances, and cards through the Pluggy Open Finance integration.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Pluggy MCP Starterhow much did I spend on Uber this month?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Financeiro MCP — Pluggy Open Finance para Agentes de IA
Pergunte à sua IA quanto gastou, onde gastou e quais contas estão conectadas. Este servidor MCP exponde suas contas e transações do Pluggy Open Finance para agentes de IA — read-only, sem mover dinheiro nem alterar dados.
Por que esse projeto existe
O pluggy-mcp oficial é ótimo para demonstrações rápidas com um único itemId. Mas na vida real você tem Santander, Nubank, Itaú, Inter... cada um gera um itemId diferente, e seu agente precisa consultar todos de uma vez.
Este projeto:
Agrega múltiplos
itemIds em um único banco de dados localExpor ferramentas em português (
financeiro_query,financeiro_cartoes,financeiro_schema,financeiro_refresh_item)Read-only por padrão — o agente consulta, nunca movimenta
Self-hosted — seus dados financeiros não saem do seu servidor
Related MCP server: Banco MCP
Qual caminho faz sentido?
Situação | Use |
Demonstração rápida com um banco só | |
Consultar múltiplos bancos em agentes de IA | Este projeto |
Codex, Claude Code, Cursor, Claude Desktop | Instalação local com |
ChatGPT web ou Claude.ai | Servidor HTTP com HTTPS + Secure MCP Tunnel |
Exemplos de perguntas que ele responde
"Quanto gastei com Uber neste mês?"
"Mostre meus gastos por categoria nos últimos 90 dias."
"Quais contas e cartões eu conectei?"
"Qual meu saldo consolidado?"
"Liste as últimas 50 transações do Nubank"
Antes de instalar
Conecte cada banco e cartão no Meu Pluggy. Cada conexão gera um itemId:
PLUGGY_ITEM_IDS=item-id-santander,item-id-nubank,item-id-itau⚠️ A API do Pluggy não lista
itemIds existentes. Anote cada um quando conectar!
Guia passo a passo: docs/01-conectar-contas-meu-pluggy.md
Instalação local
Adicione ao seu cliente MCP:
{
"mcpServers": {
"financeiro": {
"command": "npx",
"args": ["-y", "@caiomioto/financeiro-mcp"],
"env": {
"PLUGGY_CLIENT_ID": "seu-client-id",
"PLUGGY_CLIENT_SECRET": "seu-client-secret",
"PLUGGY_ITEM_IDS": "item-id-1,item-id-2"
}
}
}
}No Claude Code:
claude mcp add pluggy \
--env PLUGGY_CLIENT_ID=seu-client-id \
--env PLUGGY_CLIENT_SECRET=seu-client-secret \
--env PLUGGY_ITEM_IDS=item-id-1,item-id-2 \
-- npx -y @caiomioto/financeiro-mcpServidor HTTP (ChatGPT / Claude.ai)
git clone https://github.com/caiomioto2/pluggy-mcp-starter.git
cd pluggy-mcp-starter
cp .env.example .env
docker compose up -d --buildO MCP atende em http://SEU_SERVIDOR:3000/mcp. Coloque um proxy HTTPS na frente.
Para OpenAI Secure MCP Tunnel, veja: docs/03-openai-secure-mcp-tunnel.md
Ferramentas disponíveis
Ferramenta | O que faz |
| Lista tabelas ( |
| Executa |
| Lista cartões, faturas, parcelas e a semântica documentada de |
| Solicita uma única sincronização de uma conexão específica, após mudança real e recente |
| Mostra estado da sincronização |
Uso responsável do refresh: use
financeiro_refresh_itemapenas após uma alteração real e recente. Não o use em loop, agendamento ou lote. A Pluggy reservaPATCH /items/{id}para atualizações disparadas pelo usuário; a sincronização de rotina é feita pelo auto-sync.
Para responder “quanto tenho de faturas para pagar no próximo mês?”, use faturas_a_vencer_no_periodo.total_por_moeda de financeiro_cartoes. Ele soma totalAmount das Credit Card Bills cujo vencimento cai no período solicitado. Só trate o resultado como total real quando coverage.complete for true; saldo_centavos é uso atual do cartão, não fatura. A cobertura conta cartões com Bill no período, e só fica completa quando cada cartão tem fatura retornada nesse período. bill_coverage_by_card separa fatura encontrada, bills fora do período, nenhuma fatura retornada e falha de API. Uma lista vazia ou faturas somente fora do período não prova que não há fatura no mês.
financeiro_cartoes separa metrics.card_spending, metrics.bills_due e metrics.bill_payments. provider_status preserva PENDING/POSTED; financial_state esclarece quando a evidência permite distinguir compra aberta, parcela ligada a uma fatura e parcela sem ciclo conhecido (installment_unassigned). Número de parcela sem vínculo de fatura não basta para chamá-la de futura. Datas de transação não são datas de vencimento por padrão; sem bill_id/expected_bill_id, ciclo ou vencimento fornecido, esses campos ficam vazios. next_bill_estimate contém apenas um subtotal cauteloso de compras abertas observadas, exclui parcelas futuras e sem ciclo conhecido e mantém projected_total_by_currency nulo quando não há evidência para projetar o total. Pares de pagamento por valor, moeda e data aparecem como candidatos (candidate_card_pending/candidate_card_posted), não confirmam quitação; PENDING no cartão continua pendente.
current_bill.paid_amount_centavos e remaining_amount_centavos permanecem nulos quando a coleta não consegue confirmar quitação. A Pluggy determina a liquidação comparando os pagamentos e encargos da fatura seguinte com o total da fatura anterior; um lançamento de pagamento POSTED sozinho não prova que o saldo inteiro foi pago.
Exemplo de consultas
-- Últimas 50 transações de todas as contas
SELECT merchant_name, description, amount, date, account_name
FROM transactions
ORDER BY date DESC
LIMIT 50
-- Gastos por categoria nos últimos 90 days
SELECT category, SUM(amount) as total
FROM transactions
WHERE date >= '2026-01-01'
GROUP BY category
ORDER BY total DESC
-- Saldo consolidado por conta
SELECT account_name, currency_code, current_balance
FROM accounts
WHERE type = 'BANK'Segurança
Nunca coloque
clientSecretouitemIdem commit, issue ou chatUse
.envlocal ou secrets do seu deployServidor bloqueia qualquer comando que escreva ou altere dados
Read-only por padrão — o agente consulta, nunca movimenta
Desenvolvimento
npm install
npm test
npm run buildLicença
Available Tools
2 toolspluggy_queryQuery Pluggy accounts and transactions with SQLARead-onlyIdempotent
Read-only SQLite SELECT over accounts and transactions for the requested UTC period. accounts includes every account returned by every configured Pluggy connection, including accounts without transactions. Reuses collection in memory for 15 minutes and returns coverage metadata. Call pluggy_schema before computing totals.
| Name | Required | Description | Default |
|---|---|---|---|
| to | Yes | ||
| sql | Yes | ||
| from | Yes | ||
| limit | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, openWorldHint and destructiveHint=false, so the safety profile is covered. The description adds genuinely new behavior beyond that: a 15-minute in-memory collection cache, returned coverage metadata, and the fact that accounts include connections with zero transactions — a non-obvious data-shape caveat.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Four short sentences, front-loaded with the operation and scope, with no redundant restatement of the name or title. The prerequisite call is placed last, where an agent will read it before invoking.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema exists, and the description partially compensates by mentioning coverage metadata and the accounts-without-transactions case. It is nearly complete for a 4-parameter read tool, but the absence of date-format and limit guidance leaves a small gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must carry the parameter burden. It clarifies that sql is a SELECT-only SQLite query and that from/to delimit a UTC period, but gives no date format and never mentions the limit parameter or its 200-row cap, leaving meaningful gaps.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and dialect (read-only SQLite SELECT) over named resources (accounts and transactions) scoped to a UTC period. It also distinguishes itself from the sibling by naming pluggy_schema as a prerequisite rather than an alternative query path.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit sequencing guidance ("Call pluggy_schema before computing totals") and implies the tool's role is querying for aggregates over a period. It does not, however, state when NOT to use it or contrast it with a filtering alternative, since pluggy_schema is the only sibling.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
pluggy_schemaPluggy finance schemaBRead-onlyIdempotent
SQL fields, semantics, and transaction limitations. Does not access secrets.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, non-destructive, and open-world behavior. The description adds a useful security note ('Does not access secrets'), but it does not disclose return format, scope of schema coverage, or other behavioral context beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is very short and front-loads the key content categories. Every sentence is brief, though the extreme terseness leaves some ambiguity that a slightly fuller structure could resolve.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a zero-parameter, read-only metadata tool with rich annotations and no output schema, the description covers the broad content areas and a security caveat. However, it does not clarify the relationship to pluggy_query or exactly what the schema output contains, leaving an agent to infer key context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters, so there is no parameter semantics burden. Per the rubric, a zero-parameter tool receives a baseline of 4 regardless of description detail.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description lists content categories (SQL fields, semantics, transaction limitations) but does not state a clear action such as returning or describing a schema. The name and title imply it is a schema tool, but the description itself is vague about what it does. It also does not distinguish this tool from the sibling pluggy_query.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no explicit guidance on when to use this tool versus pluggy_query or any other alternative. The phrase 'transaction limitations' weakly implies it should be consulted before querying, but no condition or alternative is stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
v0.1.0- First observed
pluggy_query - First observed
pluggy_schema
TDQS
Scored across 2 tools
The two tools have clearly distinct roles: pluggy_schema provides metadata and semantics, while pluggy_query executes read-only SQL. The query description explicitly directs agents to call the schema tool first, reducing any risk of misselection.
Both tools follow the same pluggy_ prefix and snake_case convention. The names are predictable and readable.
Only two tools are provided, which is borderline thin for a server with a defined domain. While the starter scope makes this acceptable, it is below the typical well-scoped range of 3-15 tools.
For a read-only query server, schema discovery plus SQL SELECT covers the core lifecycle. Minor convenience gaps exist, such as direct connection/account listing, but raw SQL can work around them.
Maintenance
Related MCP Connectors
Read-only bank & investment accounts via Plaid: balances, holdings, transactions, SQL analytics.
Chat with your bank data: balances, transactions, budgets, bills. Reads only, never moves money.
Ask data questions in natural language. Get SQL, insights, and charts from your databases.
Ask your databases questions in plain English, run read-only SQL and set up data alerts.
1
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to access financial data from 20,000+ banks across 40+ countries, allowing users to query account balances, transactions, and spending patterns through natural language.4MIT
- AlicenseNot gradedqualityFmaintenanceConnects Brazilian banks (Itaú, Bradesco, Nubank, etc.) to AI agents, enabling natural language queries about expenses, statements, investments, and credit cards via regulated Open Finance.24MIT
- AlicenseNot gradedqualityDmaintenanceConnects PagBank accounts to AI assistants via Open Finance Brasil, enabling natural language queries about balances, statements, credit card bills, and investments. Read-only and regulated by the Central Bank.MIT
- FlicenseNot gradedqualityCmaintenanceEnables secure, read-only analytical querying of financial data through natural language, with built-in SQL injection defense and automatic query repair.-