What BankMCP™ does with your data

It reads. It does not pay, it does not store your transactions, and it does not send anything to the people who wrote it. This page says what runs where and what you are responsible for.

What it does

What it does and does not do.

Read-only

It reads balances and transactions. It has no payment tools.

Runs on your server

The key and the bank consents stay on a server you control. The bank connection itself goes through Enable Banking; that part is not local.

Does not store your transactions

The server fetches balances and transactions when you ask and does not save them. It keeps your consents, your watches and your login. Your assistant keeps the conversation, as any chat does.

Any MCP client

Standard MCP, so Claude, ChatGPT, Mistral, Cursor or a local model can connect. Tested with Claude and Ollama.

2,700+ European banks

The banks Enable Banking covers. No contract is needed for your own accounts.

Easy to stop

Change the password, revoke the consent at your bank, or delete the server.

Data flow

Four hops.

Your assistant talks to your server over OAuth. Your server talks to Enable Banking with a signed key. Enable Banking talks to your bank under PSD2. Balances and transactions come back the same way and are not saved on your server or at Enable Banking. Your assistant keeps the conversation, as any chat does.

Security notes in the README →

Open source

Software, not a service.

There is no hosted version. You deploy your own copy and you are the only user. MIT licence.

Disclaimer. Use at your own risk. If you deploy BankMCP™, you own that deployment: the server, the key, the consents, the password and their security. The software is provided as is, without warranty of any kind, and the authors accept no liability for how it is used or for any loss that follows. It is not a bank, it does not give financial advice, and it is not affiliated with Enable Banking, Anthropic or any bank.