74
/ 100
10 hours ago
glama

myfinance-mcp

Enables personal finance management through natural language: log expenses, snap receipt photos, and import bank statements. Computes budgets, trends, and net worth in any currency, with data persisted and accessible via MCP.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
27 tools verified — handlers match their declared behaviour
8 read-only tools verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 5 credentials: E2E_PASSWORD, GOOGLE_CLIENT_SECRET, RESEND_API_KEY, TELEGRAM_BOT_TOKEN, TOKEN_ENC_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

Zod denial of service vulnerability

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAUTO_SYNC_INTERVAL_MS_(optional)_ Bank auto-sync tick, default hourly (syncs connections >20h stale); 0 disables
configBASE_URLPublic URL of the server (OAuth issuer)
configDATABASE_URLPostgres connection string
configE2E_EMAIL
🔐 secretE2E_PASSWORD
configEB_API_ORIGIN
configEB_APP_ID
configEB_PRIVATE_KEY_B64
configFROM_EMAIL_(optional)_ Verified sender for notifications
configGOOGLE_CLIENT_ID_(optional)_ Google OAuth client ID for "Continue with Google"
🔐 secretGOOGLE_CLIENT_SECRET_(optional)_ Google OAuth client secret
configMYFINANCE_MCP_EMAILBootstrap user email
configMYFINANCE_MCP_PASSWORD_HASHBootstrap user password hash (see below)
configNOTIFY_EMAIL_(optional)_ Where signup notifications go
configPLAYWRIGHT_CORE
configPORTServer port (default 8788)
🔐 secretRESEND_API_KEY_(optional)_ Resend key for new-signup email notifications
🔐 secretTELEGRAM_BOT_TOKEN
configTELEGRAM_CHAT_ID
🔐 secretTOKEN_ENC_KEY
configZENMONEY_API_BASE
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/alex-odoo-myfinance-mcp-15m08l)](https://m8ven.ai/mcp/alex-odoo-myfinance-mcp-15m08l)
commit: 23b40dbb3e83e0838535d0161e96faa91fe74546
code hash: b64766be1950ccdde90d85c64715026c60880747b8a2653e5668299271cce173
verified: 7/31/2026, 8:56:42 AM
view raw JSON →