The 2,700-bank promise still has one outside provider
BankMCP turns balances and transactions into MCP tools for a single user. The README says Enable Banking covers more than 2,700 European banks. You can connect accounts, assign readable labels, fetch balances, inspect transactions, and create watches for thresholds or matching payments. There are no payment tools. The server is meant to answer questions about money without gaining the ability to move it. That boundary limits an MCP mistake to disclosure or misinterpretation rather than a payment sent by this server.
Self-hosted needs a qualifier here. BankMCP stores the application key, bank consents, account ids, watches, and OAuth tokens on your machine or server. It does not persist balances or transactions and sends no telemetry. Every live request still passes through Enable Banking before reaching the bank. Your assistant may keep the resulting conversation, and a notification webhook receives the transaction that triggered a watch.
A 5-second install makes the code easy to trial
Our sandbox installed commit f28fac6 in 5 seconds, pulling 150 packages and using 63 MB on disk. The build completed in 7 seconds, and the available tests completed successfully in another 7 seconds. Npm audit found 2 known vulnerabilities, both moderate. The checkout itself had 106 files, roughly 4,055 lines of source, and occupied 2.2 MB.
The repository has 2 CI workflows, a Dockerfile, a Compose file, and a tests directory. That is a reassuring amount of delivery machinery for a bank-data connector this small. The local route needs Node 24 or newer and can run through npx. Hosted deployment adds a persistent volume, public HTTPS, an Enable Banking application, and a password of at least 12 characters.
What happened when we ran it
Our run used an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets. Installation, build, and tests all succeeded in 19 seconds combined. We did not register an Enable Banking application, link a real bank, grant consent, start a watch, or expose the OAuth server. The measurement covers repository mechanics and dependency state, not correctness against live financial institutions.
Npm audit reported 2 moderate vulnerabilities after the 150-package install. The supplied measurement does not name the affected packages or prove that either advisory is reachable through the server. Reproduce the audit against the deployed image and check the runtime path. Bank data raises the cost of waving away a moderate label, even when the MCP tools cannot initiate a payment.
A 356-transaction answer can produce the wrong total
The most useful criticism comes from the project's own evaluations. Issue 13 describes a synthetic spending task where one account returned 356 transactions in a response too large for the agent to read at once. Claude read only part of the saved result and understated spending by €5,866. OpenCode fetched smaller date ranges and reached the correct answer. BankMCP returned the records, but its response shape made omission easy.
Issue 12 shows a related search problem. Finding 12 merchant charges required fetching all 356 transactions from one account, while a similar invoice number caused Claude to include the wrong payment. These are open issues from September 30, 2026. Until server-side search and small pages exist, split requests by account and date, then reconcile totals against exported bank records.
Transaction text creates another boundary. A sender controls payment descriptions and counterparty names, so those fields may contain instructions aimed at the assistant. Release v0.1.15 tells clients to treat those strings as data, adds a global password lockout, and lets operators bind the server to one interface. Those defenses help, but an assistant connected to other tools can still be manipulated by hostile text.
One user and 180-day consents define the product
BankMCP has one administrative password and one authorization boundary. A valid token can use the read-only banking tools, while changing the password logs every client out. Consents last up to 180 days according to the README. Enable Banking's restricted production mode is for personal, non-commercial access to your own accounts, so this is not a base for serving customers or sharing household roles.
Use BankMCP when one technically capable person wants conversational access to their own accounts and accepts Enable Banking as the regulated middle hop. Keep the server private, back up the state file, and treat every computed total as a draft until checked. Our tests passed, but issues 12 and 13 show that correct records can still become a wrong answer when the response is too large for the agent.

