comdirect

io.github.mad4msv0.4.0更新於 Oct 10, 2026

Read-only access to comdirect bank accounts, transactions, depots and postbox documents.

已驗證STDIO僅桌面Data & AnalyticsFinance

概覽

AI 產生的概覽

透過 MCP 用戶端唯讀存取 comdirect 銀行帳戶、交易、證券保管帳戶與信箱文件。

功能
將 MCP 用戶端連接到 comdirect REST API,僅讀取銀行資料。工具涵蓋登入與登出、帳戶與餘額列表、資產總覽、附伺服器端現金流彙總的交易、證券保管帳戶與持倉、投資組合配置彙總、卡片餘額、訂單與訂單維度,以及信箱文件(含有限長度的 PDF 文字擷取)。沒有任何工具可以轉帳或下單。
適用情境
適合讓助理查看自己的 comdirect 帳戶、支出、保管持倉或對帳單,而不必手動登入網路銀行。適合本機、重視隱私的環境,最好搭配本機模型,因為每個工具結果都會傳送給 MCP 用戶端背後的模型。
執行需求
透過 uvx 以 stdio 本機程序執行,需要 Python 的 uv 工具。需要 comdirect API 存取權(在網路銀行開發者存取中取得 Client ID 與 Client Secret)、Zugangsnummer 與 PIN,並將 photoTAN Push 設為預設 TAN 方式。可用 configure 指令將憑證存入作業系統鑰匙圈,或透過 COMDIRECT_CLIENT_ID、COMDIRECT_CLIENT_SECRET、COMDIRECT_USERNAME 與 COMDIRECT_PASSWORD 環境變數提供。
安裝前請注意
它會處理銀行憑證,並把財務資料傳送給 MCP 用戶端背後的模型;使用雲端助理時這些資料會離開你的電腦。機密包括 COMDIRECT_CLIENT_ID、COMDIRECT_CLIENT_SECRET、COMDIRECT_USERNAME 與 COMDIRECT_PASSWORD,切勿寫入會被提交的檔案。登入需在 photoTAN 應用程式中批准。下載文件會在 comdirect 端標記為已讀。本專案為非官方專案,與 comdirect 無關,API 或相依套件可能變動。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 comdirect,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

comdirect-mcp

[PyPI] [Python] [Tests] [MCP] [License: MIT]

Read-only Model Context Protocol server and typed Python client for the comdirect REST API.

Let Claude, GitHub Copilot or any other MCP client look at your accounts, transactions, securities depot and postbox documents. The login is confirmed with your photoTAN app, and there is no tool that can move money.

[!WARNING] This is an unofficial project, not affiliated with comdirect. It handles your banking credentials and sends your financial data to the AI model you connect it to. Read the warning below and SECURITY.md.

Warnung (in Deutsch weil Comdirect)

Leute es geht hier um euer Geld. Nutzt diese Bibliothek nur, wenn ihr den Code versteht und euch den Risiken bewusst seid.

Ich bin auch nicht perfekt, aber übernehme keine Haftung für Schäden, die durch die Nutzung dieser Software entstehen. Falls Euch was auffällt, gern PRs oder Issues.

Die API und damit das Repo hier nutzen aktuell nur lesende Endpunkte, aber Fehler können immer passieren. Comdirect kann die API ändern, Dependencies können im Zweifel auch Mist bauen (Supply-Chain Attacks) und 2FA hilft zwar, ist aber kein Freifahrtschein.

Bitte:

  • Nutzt das nur lokal auf eurem eigenen Rechner.
  • Teilt eure Zugangsdaten mit niemandem.
  • Packt Secrets in .env und committet die Datei nie.
  • Nutzt die Pre-Commit Hooks um Secrets zu scannen. Gute Zeit bissel Devops-Kram zu lernen.
  • Spielt Updates nicht blind ein (Lockfile/Pinning hilft) und schaut bei Änderungen kurz drüber.

MCP-Server: Wenn ihr den Server an einen nicht-lokalen AI-Client hängt, gehen deine Daten raus. Je nach Client/Setup können Kontodaten/Transaktionen in Logs/Telemetry landen oder durch Prompt-Injection aus Dokumenten/Verwendungszwecken in komische Richtungen gehen (MCP Horror Stories: The GitHub Prompt Injection Data Heist). Nutzt MCP nur, wenn ihr der Umgebung wirklich vertraut, und gebt nur die Daten frei, die ihr dafür braucht.

Da der gemeine r/finanzen User eh schon seine Kontoauszüge in ChatGPT kopiert, könnt ihr damit machen, was ihr wollt, auf eure eigene Verantwortung!

Idealerweise ohne unnötige personenbezogene Daten. (Hauptsache, ihr lasst 'nen Stern da.)

Privacy: prefer a local model

The server runs on your machine, but every tool result is sent to the language model behind your MCP client. With cloud assistants (Claude, GitHub Copilot, ChatGPT, ...) your balances, transactions and documents leave your computer and are processed under that provider's data policy.

  • Most private: use an MCP client with a local model, e.g. LM Studio (supports MCP servers directly) or Ollama with the ollmcp client. Then nothing leaves your machine except the requests to comdirect. Pick a model with good tool-calling support.
  • With a cloud assistant: check its data retention and training settings, use an account where your data is not used for training, and ask only what you need.

Details: Privacy and security · Use a local model

Features

  • MCP specification 2026-07-28 on the official MCP Python SDK v2, with fallback for older clients
  • Push TAN login via elicitation: your client asks you to approve the login in the photoTAN app; the TAN never reaches the model
  • Credentials in the OS keychain: comdirect-mcp configure stores them once, client configs contain no secrets
  • No tool can move money: only read endpoints, truthful tool annotations, structured output with JSON schemas
  • Protects your access: stops logging in before comdirect's lock after five unconfirmed TAN challenges, and revokes the session at comdirect on logout and shutdown so it cannot be extended
  • Built for agents: compact results without empty fields, one counterparty instead of SEPA roles, cleaned-up payment texts, server-side summaries for cash flow questions
  • Privacy defaults: IBANs and account numbers masked, optional name pseudonyms, documents size-limited, untrusted-content hint for the model
  • Automatic token refresh and explicit session handling
  • Typed Python client (py.typed) for scripts and notebooks, independent of MCP
  • Listed in the MCP Registry as io.github.mad4ms/comdirect-mcp

Tools

ToolDescription
loginStarts a session; asks you to approve the push TAN
logoutEnds the session and revokes it at comdirect (no further refresh)
list_accountsAccounts with type (Girokonto, Tagesgeld, ...) and balances
get_wealth_overviewAll product balances with bank-supplied EUR totals, including loans and savings
list_depot_transactionsSecurities purchases, sales and transfers with filters and continuation
get_instrumentSecurity metadata; optional fund fees/ratings and derivative details
list_transactionsTransactions with date, amount, counterparty and cleaned-up purpose; compact by default
summarize_transactionsCash flow and spending per month, counterparty or type, computed on the server
list_cardsCard balances (Visa); the API has no card transactions
list_depotsSecurities accounts
get_depot_positionsPositions (name, ISIN, WKN, values, P&L) and depot balance
list_documentsPostbox documents (statements, order confirmations, tax documents)
download_documentA document as embedded resource (comdirect marks it as read)
get_account_balanceBalance and masked static data for one account
get_depot_positionOne securities position, with optional details
summarize_portfolioLargest positions and allocation percentages per currency
list_orders / get_orderRead the order book and individual orders; never place or change orders
get_order_dimensionsAvailable trading venues, currencies and order types
get_document_coverBounded plain text from the document pre-page
extract_document_textBounded PDF text with page continuation; downloading marks it as read

Arguments and results: Tools reference.

Quickstart

New to this? Follow the Getting started tutorial.

1. Prerequisites

  • uv (provides uvx)
  • comdirect API access: in the online banking under Verwaltung → Entwicklerzugang you get a Client ID and Client Secret (step by step)
  • photoTAN Push as your default TAN method

2. Store your credentials in the OS keychain

bash
uvx [email protected] configure

Prompts for Client ID, Client Secret, Zugangsnummer and PIN and stores them in the macOS Keychain, Windows Credential Manager or Linux Secret Service. Other options (VS Code inputs, environment, .env): Manage credentials.

3. Add the server to your MCP client

Claude Desktop (Settings → Developer → Edit Config) and LM Studio (Program → Install → Edit mcp.json):

json
{  "mcpServers": {    "comdirect": {      "command": "uvx",      "args": ["[email protected]"]    }  }}

Claude Code

bash
claude mcp add --transport stdio --scope user comdirect -- uvx [email protected]

VS Code (MCP: Open User Configuration)

json
{  "servers": {    "comdirect": {      "type": "stdio",      "command": "uvx",      "args": ["[email protected]"]    }  }}

Ollama (via ollmcp)

bash
uvx ollmcp mcp add --scope user comdirect -- uvx [email protected]uvx ollmcp -m <model>

Pinning the version (@0.5.0) means updates only happen when you decide. More clients: Configure MCP clients.

4. Ask

Wie haben sich meine Ausgaben im letzten Monat entwickelt, und welche Depotposition läuft am schlechtesten?

The assistant calls login, your phone receives the push TAN, you approve it and confirm the dialog in your client. Then the assistant can use the other tools. Problems: Troubleshoot.

Python library

The same client is available for your own scripts:

python
from comdirect_mcp import ComdirectClientfrom comdirect_mcp.utils import default_push_tan_callback
client = ComdirectClient(    {"client_id": "...", "client_secret": "...", "username": "...", "password": "..."},    {"push_tan_cb": default_push_tan_callback},)client.login()  # approve the push TAN, then press Enter
for account in client.list_accounts():    print(account.id, account.balance, account.currency)

See Use the Python library, the Python API reference and the examples.

Documentation

The documentation is organized as tutorial, how-to guides, reference and explanation:

SECURITY.md describes the threat model and how to report vulnerabilities, CHANGELOG.md lists the changes per release.

Contributing

Issues and pull requests are welcome, see CONTRIBUTING.md and the Code of Conduct. AI coding agents find their instructions in AGENTS.md.

Disclaimer

This project is not affiliated with, maintained, or endorsed by comdirect bank AG. Use it at your own risk. There is no warranty and no liability for any financial losses or damages resulting from its use.

The software runs locally and does not send your credentials anywhere except to comdirect. Your MCP client and its model provider receive the data the tools return.

License

MIT

來源:README.md,提交 e705941

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.4.0最新Oct 10, 2026