mrkeyoor.com_
Thu 01 Oct 08:15 UTC
Self-Hostedevaluationupdated 01 Oct 2026

bankmcp review

BankMCP is a single-user, read-only MCP server that lets an AI assistant inspect your European bank accounts through Enable Banking. It can retrieve balances and transactions, connect banks, label accounts, and run watched conditions without offering payment tools.

Verdict

Our BankMCP run installed 150 packages in 5 seconds and passed its tests, while npm audit found 2 moderate vulnerabilities. It is worth trying for one technical user who wants read-only access to their own accounts and will verify every answer. It is a poor fit for shared finances or unattended reporting until transaction search and pagination prevent the omissions documented in issues 12 and 13.

We ran it

Lab card: what happened when we ran bankmcpScreenshot of bankmcp (bankmcp.dk)
Install✓ · 5s150 packages · 63 MB
Build✓ · 7s
Tests✓ · 7sran, no count parsed
Known vulns20 critical · 0 high · 2 moderate · 0 low (npm audit)
Repo106 files~4,055 lines of source · 2.2 MB · 2 CI workflows · Dockerfile · tests dir

Answers from our run

Does bankmcp build from source?

Dependencies installed in 5 seconds (150 packages), and the build succeeded in 7 seconds. We cloned commit f28fac6 into a clean Debian container with 3 CPUs and no project-specific setup.

Do bankmcp's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does bankmcp have known vulnerabilities in its dependencies?

npm audit flagged 2 known advisories in the dependency tree at the time of our run.

Who should not use bankmcp?

Families or teams needing separate identities and permissions: BankMCP has one user and one administrative password.

What are the alternatives to bankmcp?

Actual Budget, Firefly III, Plaid Quickstart. Our BankMCP run installed 150 packages in 5 seconds and passed its tests, while npm audit found 2 moderate vulnerabilities.

Setup4/55-second install; bank registration and TLS add real work
Docs5/5Specific local, hosted, OAuth, privacy, and recovery guidance
Community3/5271 stars with active security and agent-experience issues
Maturity3/5v0.1.15 is tested, but large transaction answers can mislead

Who it’s for

Individuals who want to ask an MCP client questions about their own European bank accounts.
Claude Code and Claude Desktop users willing to operate a local Node 24 process.
Self-hosters who can protect one password, a persistent volume, TLS, and an Enable Banking key.
Users prepared to verify every financial total against the underlying transactions.

Who it’s NOT for

Families or teams needing separate identities and permissions: BankMCP has one user and one administrative password.
Commercial services for other people's accounts: Enable Banking's restricted mode is documented for personal, non-commercial access to your own accounts.
Anyone who expects every calculation from an assistant to be reliable: open issue 13 records a €5,866 spending miss after a 356-transaction response was clipped.
Users who require an entirely local data path: every bank request still passes through Enable Banking, and the MCP client may retain the conversation.
People who cannot assess untrusted transaction text: counterparty names and payment descriptions can contain instructions aimed at the model.

Setup reality

Our sandbox installed commit f28fac6 in 5 seconds, adding 150 packages and using 63 MB on disk. The build succeeded in 7 seconds, and the available tests succeeded in 7 seconds. Npm audit reported 2 known vulnerabilities, both moderate.

Local use needs Node 24 or newer, an Enable Banking account, an application id and private key, plus bank consent. Hosted use adds a persistent /data volume, public HTTPS, a password of at least 12 characters, and an allowed redirect host.

The server holds consents, account ids, watches, and OAuth tokens in one state file. Bank data still travels through Enable Banking, while assistants and notification webhooks may retain what they receive. The project is single-user and read-only, and restricted production access is for the operator's own accounts.

The 2,700-bank promise still has one outside provider

BankMCP turns balances and transactions into MCP tools for a single user. The README says Enable Banking covers more than 2,700 European banks. You can connect accounts, assign readable labels, fetch balances, inspect transactions, and create watches for thresholds or matching payments. There are no payment tools. The server is meant to answer questions about money without gaining the ability to move it. That boundary limits an MCP mistake to disclosure or misinterpretation rather than a payment sent by this server.

Self-hosted needs a qualifier here. BankMCP stores the application key, bank consents, account ids, watches, and OAuth tokens on your machine or server. It does not persist balances or transactions and sends no telemetry. Every live request still passes through Enable Banking before reaching the bank. Your assistant may keep the resulting conversation, and a notification webhook receives the transaction that triggered a watch.

A 5-second install makes the code easy to trial

Our sandbox installed commit f28fac6 in 5 seconds, pulling 150 packages and using 63 MB on disk. The build completed in 7 seconds, and the available tests completed successfully in another 7 seconds. Npm audit found 2 known vulnerabilities, both moderate. The checkout itself had 106 files, roughly 4,055 lines of source, and occupied 2.2 MB.

The repository has 2 CI workflows, a Dockerfile, a Compose file, and a tests directory. That is a reassuring amount of delivery machinery for a bank-data connector this small. The local route needs Node 24 or newer and can run through npx. Hosted deployment adds a persistent volume, public HTTPS, an Enable Banking application, and a password of at least 12 characters.

What happened when we ran it

Our run used an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets. Installation, build, and tests all succeeded in 19 seconds combined. We did not register an Enable Banking application, link a real bank, grant consent, start a watch, or expose the OAuth server. The measurement covers repository mechanics and dependency state, not correctness against live financial institutions.

Npm audit reported 2 moderate vulnerabilities after the 150-package install. The supplied measurement does not name the affected packages or prove that either advisory is reachable through the server. Reproduce the audit against the deployed image and check the runtime path. Bank data raises the cost of waving away a moderate label, even when the MCP tools cannot initiate a payment.

A 356-transaction answer can produce the wrong total

The most useful criticism comes from the project's own evaluations. Issue 13 describes a synthetic spending task where one account returned 356 transactions in a response too large for the agent to read at once. Claude read only part of the saved result and understated spending by €5,866. OpenCode fetched smaller date ranges and reached the correct answer. BankMCP returned the records, but its response shape made omission easy.

Issue 12 shows a related search problem. Finding 12 merchant charges required fetching all 356 transactions from one account, while a similar invoice number caused Claude to include the wrong payment. These are open issues from September 30, 2026. Until server-side search and small pages exist, split requests by account and date, then reconcile totals against exported bank records.

Transaction text creates another boundary. A sender controls payment descriptions and counterparty names, so those fields may contain instructions aimed at the assistant. Release v0.1.15 tells clients to treat those strings as data, adds a global password lockout, and lets operators bind the server to one interface. Those defenses help, but an assistant connected to other tools can still be manipulated by hostile text.

One user and 180-day consents define the product

BankMCP has one administrative password and one authorization boundary. A valid token can use the read-only banking tools, while changing the password logs every client out. Consents last up to 180 days according to the README. Enable Banking's restricted production mode is for personal, non-commercial access to your own accounts, so this is not a base for serving customers or sharing household roles.

Use BankMCP when one technically capable person wants conversational access to their own accounts and accepts Enable Banking as the regulated middle hop. Keep the server private, back up the state file, and treat every computed total as a draft until checked. Our tests passed, but issues 12 and 13 show that correct records can still become a wrong answer when the response is too large for the agent.

Alternatives

ProjectWhat it isPick it when
Actual Budget gh↗A local-first budgeting app with account import, rules, reports, and encrypted sync.pick this instead when budgeting and reconciliation matter more than asking an agent direct bank questions.
Firefly III gh↗A mature self-hosted personal finance manager for transactions, budgets, and reports.pick this instead when you want an auditable finance application rather than an MCP data connector.
Plaid QuickstartA reference integration for Plaid's hosted bank-data APIs across several languages.pick this instead when you are building a multi-user application and accept a commercial banking provider.

What people are saying

  1. [velocity-scout] noskillish/bankmcp

Sources

  1. BankMCP README
  2. BankMCP repository
  3. BankMCP v0.1.15 release
  4. Issue 12 on transaction search
  5. Issue 13 on clipped transaction results

More self-hosted reviews

Spun · 8086-xcheck-system · fanzha-ai-proxy · homarr · search-plugins · vphone-web · the whole board →