AI agent

MCP Server + MoneySprout

Technical reference

One HTTPS MCP endpoint powers every agent guide. Discovery and consent live on moneysprout.app. Write tools run only after you approve write:transactions or write:categories.

Read-only MCP. MoneySprout tools list transactions, budgets, accounts, and insights—they do not create, edit, or delete financial data. Manage money in the MoneySprout app; use agents to understand it.
Create free accountConnect MCP Server

You

Call tools/list on MoneySprout MCP—are any tools mutating?

MCP Server

Read tools are always listed. update_transaction, recategorize_transactions, and the category tools run only with write:transactions or write:categories.

How to connect MCP Server

  1. Add the server URL to OAuth-capable clients: https://moneysprout.app/mcp
  2. Client discovers authorization metadata and opens MoneySprout consent.
  3. Personal access tokens from Settings → Developer work with Authorization: Bearer for debugging.
  4. Call tools/list after connect. Write tools error until the grant includes write:transactions or write:categories.

MoneySprout MCP server URL

https://moneysprout.app/mcp

Cursor (.cursor/mcp.json)

{
  "mcpServers": {
    "moneysprout": {
      "url": "https://moneysprout.app/mcp"
    }
  }
}

OAuth sign-in is recommended for remote clients. Personal access tokens in Settings → Developer work for local stdio bridges. MCP requires standard encryption mode (not zero-knowledge) so tools can read your linked data.

What you can do with MCP Server

  • OAuth 2.0

    Browser consent for remote MCP clients like Cursor and Claude.

  • Read-only surface

    Transactions, budgets, accounts, goals, metrics, alerts, and briefings.

  • Encryption gate

    Standard encryption mode required for MCP and API access.

  • Scoped writes

    update_transaction, recategorize_transactions, and custom category tools. No payments, transfers, or budget edits.

MoneySprout MCP tools

Read tools are available on every grant. Write tools run only when the grant includes write:transactions or write:categories.

Transactions

  • list_transactions
  • get_transaction
  • query_spending
  • update_transaction
  • recategorize_transactions

Budgets and categories

  • list_budgets
  • list_categories
  • create_category
  • update_category
  • delete_category

Accounts, goals, and net worth

  • list_accounts
  • get_net_worth_history
  • list_goals

Insights and briefings

  • get_daily_summary
  • get_alerts
  • get_metrics
  • get_life_hub_briefing

Follow-up

  • get_tasks

Example prompts

  • Explain OAuth vs personal access token for remote MCP.
  • Show curl tools/list with a PAT from Settings → Developer.

FAQ

Is MoneySprout preinstalled in ChatGPT or Claude?
No. Add MoneySprout as a custom MCP connector (or complete OAuth when your client supports remote MCP). Sign in with your MoneySprout account during consent.
Can an agent change my budgets or add transactions?
Read tools cannot. With write:transactions an agent can change a transaction's category, note, or follow-up flag, including a bulk recategorize by id or merchant. With write:categories it can create, rename, or delete your custom categories. It still cannot add or delete transactions, edit budgets, goals, or accounts, or move money. Existing grants stay read-only until you reconnect and approve the write scopes.
Why does MCP require standard encryption mode?
Read-only tools need server-side access to linked account data. Zero-knowledge mode keeps keys only on your devices, so MCP and API access are disabled until you switch to standard encryption in Settings → Privacy & encryption.
Does the model see my bank passwords?
No. OAuth connects the MCP client to MoneySprout. Bank credentials stay with Plaid inside MoneySprout; agents receive structured summaries and transaction rows your account already synced.
Where is OAuth documented?
Open Settings → Developer in MoneySprout for the MCP URL, PAT creation, and example client configs. OAuth consent is at /oauth/consent when a client connects.
Is there a separate write API?
REST API v1 stays read-only (plus POST /api/v1/sync). Remote MCP can recategorize transactions and manage custom categories when the grant includes write:transactions or write:categories. Reconnect an older grant to approve those scopes.

More agents