actual-mcp-server (agigante80/actual-mcp-server) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.
Talk to your self-hosted Actual Budget from any MCP client: a remote HTTP server for LibreChat/LobeChat or a local stdio process for Claude Desktop, with 71 tools for transactions, budgets, rules, and bank sync. No Docker needed for local use.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
agigante80
Source: Glama · also listed on github_topic, npm
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
ACTUAL_API_CONCURRENCY5 No Max concurrent Actual API operationsACTUAL_BUDGET_PASSWORD_(none)_ No Optional encryption password for encrypted budgetsACTUAL_BUDGET_SYNC_IDe =your_sync_id \ACTUAL_DATA_DIRACTUAL_OP_TIMEOUT_MSACTUAL_PASSWORDe =your_password \ACTUAL_SERVER_URLe =http://localhost:5006 \AUTH_PROVIDERnone No Auth mode: none (static Bearer) or oidc (JWKS-validated JWT)BANK_SYNC_TIMEOUT_MSBUDGET_DEFAULT_NAMENo "Default"DIRECT_SYNC_LOG_DIRDOTENV_CONFIG_QUIETDRIFT_RESULTEXPECTED_TOOL_COUNTGH_TOKENGITHUB_OUTPUTGITHUB_REPOSITORYGITHUB_RUN_IDGITHUB_SERVER_URLGITHUB_WORKFLOWLOG_LEVEL_(none)_ No Debug-detection toggle: set to debug to enable extra transport debug output. Distinct from MCP_BRIDGE_LOG_LEVEL (the winston level); has no default and is not itself a log levelMAX_CONCURRENT_SESSIONS15 No Maximum concurrent MCP sessions allowedMCP_ALLOW_UNAUTHENTICATEDMCP_AUTH_TOKENMCP_BRIDGE_BIND_HOST0.0.0.0 No Host address to bind server to (0.0.0.0 = all interfaces)MCP_BRIDGE_DEBUG_TRANSPORTfalse No Enable transport-level debug loggingMCP_BRIDGE_HTTP_PATHsame as MCP_HTTP_PATH No Advertised HTTP path shown to clients (set when a reverse proxy rewrites the path)MCP_BRIDGE_LOG_DIRapp/logs (beside the install) No Directory for log files (if STORE_LOGS=true). .env.example and Docker set it explicitly (e.g. ./logs, /app/logs)MCP_BRIDGE_MAX_FILES14d No Keep rotated logs for N days (e.g., 14d, 30d)MCP_BRIDGE_MAX_LOG_SIZE20m No Rotate when file reaches size (e.g., 20m, 100m)MCP_BRIDGE_PORTServer starts at http://localhost:3600/http by default (the listen port is , default 3600).MCP_BRIDGE_PUBLIC_HOSTauto-detected No Public hostname/IP for server (shown in logs)MCP_BRIDGE_PUBLIC_SCHEMEauto-detected No Public scheme (http or https)MCP_BRIDGE_ROTATE_DATEPATTERNYYYY-MM-DD No Date pattern for rotated log filenamesMCP_BRIDGE_STORE_LOGSfalse No Enable file logging (vs console only)MCP_BRIDGE_USE_TLSfalse No Set to true to advertise https:// in the server URL (for reverse-proxy setups where TLS is terminated upstream)MCP_ENABLE_HTTPSfalse No Enable native TLS. Requires MCP_HTTPS_CERT and MCP_HTTPS_KEYMCP_HTTPS_CERTMCP_ENABLE_HTTPS false No Enable native TLS. Requires and MCP_HTTPS_KEYMCP_HTTPS_KEYMCP_ENABLE_HTTPS false No Enable native TLS. Requires MCP_HTTPS_CERT andMCP_HTTP_PATH/http No HTTP endpoint routing pathMCP_HTTP_URLMCP_SERVER_URLMCP_SSE_AUTHORIZATIONe =your_secret_token \MCP_STDIO_CONTAINERMCP_STDIO_DATA_DIRMCP_STDIO_FRAMING_TIMEOUT_MSMCP_STDIO_MODEMCP_STDIO_SMOKE_TIMEOUT_MSREGRESSION_ACTUAL_CTRREGRESSION_BOUND_MSSESSION_IDLE_TIMEOUT_MINUTES5 No Minutes before idle session cleanupSTALE_THRESHOLD_HOURSTRAIN_CURRENTTRAIN_JOB_NAMETRAIN_JOB_RESULTTRAIN_OUTCOMETRAIN_SOAK_HOURSTRAIN_VERSIONUSE_CONNECTION_POOLtrue No Enable session-based connection poolingVERIFY_GHCR_IMAGEVERIFY_HUB_IMAGEVERIFY_NPM_PACKAGEVERIFY_VERSIONVERSIONauto-detected No Server version (auto-set by build/Docker)Dependencies
18 dependencies, 1 flagged: @playwright/test
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
2/2 tools missing one or more hints — search.docs (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); math.add (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 0/2 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
17 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/agigante80-actual-mcp-server-w9sn4o)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check