
Monarch Money
com.pulsemcpv0.0.13更新於 Sep 29, 2026
MCP server for Monarch Money — account, transaction, and budget management.
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Monarch Money,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
Monarch Money MCP Server
MCP server for Monarch Money — a personal finance app that aggregates accounts, transactions, budgets, and net worth across institutions. This server gives an AI assistant read and write access to the same data the Monarch web/mobile app shows you, scoped to your own account.
Highlights
- 23 consolidated tools across two groups (
readonly,manage) covering accounts, balances, net worth, cashflow, transactions, categories, tags, transaction rules, and budgets - Encrypted on-disk session at
~/.monarch-money-mcp/session.enc— the server never accepts a Monarch password through a tool input - Tool group filtering via env vars — run the server in a strict read-only mode, or hand-pick the exact tools you want exposed to the agent
- Custom thin GraphQL transport targeting
api.monarch.com/graphql— no third-party Monarch client dependency
Why a custom GraphQL client?
The tools in this server span accounts, transactions, budgets, rules, categories, and net worth. We evaluated existing TypeScript Monarch clients and didn't find one that covered the surface we needed and was actively maintained. Rather than wrap a partial third-party client and patch around its gaps, this server ships a small in-house transport (shared/src/monarch-client/graphql-transport.ts) that is deliberately minimal: build the request, surface auth/network errors with typed exceptions, return the typed data payload. Operations live as named GraphQL strings in shared/src/monarch-client/operations.ts so the surface is grep-able and easy to extend.
Authentication
Monarch's /auth/login/ endpoint gates first-time logins from an unfamiliar device behind an email OTP Monarch sends to your inbox, plus per-IP throttling and a Cloudflare bot challenge. That makes a fully unattended email + password flow impossible on a fresh install — the user has to read the code from email at least once. After that one-time pairing, the same install can log in with credentials alone.
Because of that, the recommended path is to paste a session token rather than ship credentials in the env. The server supports four ways to authenticate, in priority order:
1. Env-var session token (recommended)
Paste a token once into the launcher's environment. Headless, autonomous, no OTP gate.
Where to get a token:
- Run
npm run login(option 3) once and copy it out of~/.monarch-money-mcp/session.enc(after decrypting), OR - Open the Monarch web app DevTools → Network → any
/graphqlrequest → copy the value of theAuthorization: Token <…>header.
The token is resolved at startup, validated, and persisted to disk so the env var becomes optional after the first run.
2. Tool-based token paste
If you can't set env vars (e.g., a UI that doesn't expose the launcher's env), call the monarch_login_with_token tool with the token as input. The server validates it via Monarch's me endpoint before saving.
3. Env-var email + password (best-effort)
Set credentials in the env and let the server log in:
On the first launch from a fresh install Monarch sends an OTP to your email. The server logs a clear stderr message explaining what to do; set MONARCH_EMAIL_OTP=<code> and restart. Subsequent launches reuse the persisted device-uuid and skip the OTP gate.
4. Interactive CLI
Prompts for email, password, optional TOTP, and (if challenged) the email OTP. Writes the encrypted token to ~/.monarch-money-mcp/session.enc.
Session encryption
The token is encrypted at rest with AES-256-GCM. The encryption key is derived via scrypt from a passphrase:
- If
MONARCH_SESSION_PASSPHRASEis set, that's the passphrase. - Otherwise, the passphrase is derived from the machine's hostname (
os.hostname()) and the current user (os.userInfo().username) — making the encrypted file machine-bound by default.
This isn't a defense against a local attacker who already controls your shell, but it does prevent accidental cross-host disclosure (e.g., the file ending up in a backup that gets restored on another machine).
Tool Groups
Tools are tagged with one or more groups. The default exposes everything; setting MONARCH_ENABLED_TOOL_GROUPS (or MONARCH_ENABLED_TOOLS / MONARCH_DISABLED_TOOLS) narrows the surface.
Filter precedence: MONARCH_ENABLED_TOOLS (whitelist, exact names) > MONARCH_ENABLED_TOOL_GROUPS (group filter) > MONARCH_DISABLED_TOOLS (blacklist, exact names).
Tools
Authentication / session
Accounts
Net worth
Transactions (read)
Transactions (write)
Categories & tags
Transaction rules (auto-classification)
Budgets
Quick Start
Install
Authenticate
Claude Desktop configuration
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
Restart Claude Desktop and you should be ready. The server reads the encrypted session file from disk — no env vars are required for normal use.
Environment Variables
Security Considerations
- No password through MCP tools. Authentication happens via the CLI login script or env vars, never through a tool input. Tool inputs may end up in transcripts and prompt caches; passwords don't belong there.
- Session file is encrypted at rest with AES-256-GCM. The default passphrase (host + user) ties the file to the machine that wrote it.
- Tool group filtering is the primary write-protection mechanism. Set
MONARCH_ENABLED_TOOL_GROUPS=readonlyfor a strict read-only deployment. - Read tools are not gated. Reading account/transaction data is unrestricted once the session is unlocked. If you need read-side approval, run the server behind a client that wraps tool calls in its own confirmation flow.
Development
Project Structure
Running Tests
License
MIT
來源:experimental/monarch-money/README.md,提交 0ed34de
工具
0版本歷史
1- v0.0.13最新Sep 16, 2026


