What this is

Glass Money exposes a Model Context Protocol (MCP) endpoint so Cursor, Claude Desktop, Claude.ai, and similar clients can query your Indian bank and card data — spend summaries, transactions, wallet balances, statement reconciliation, and manual categorization — without a local install.

How to connect

  1. Sign in to Glass Money on the web (glassmoney.app).
  2. In the same browser, open https://glassmoney.app/api/mcp/token (Fly origin also works: https://finmail.fly.dev/api/mcp/token). You get a JSON payload with a fresh session token (30-day TTL) and the exact client config.
  3. Add the server to your MCP client. Cursor example (mcp.json):
    {
      "mcpServers": {
        "glassmoney": {
          "url": "https://glassmoney.app/api/mcp",
          "headers": { "Authorization": "Bearer <token>" }
        }
      }
    }
    Replace <token> with the value from step 2. When it expires, revisit the token URL for a new one. Use https://glassmoney.app/api/mcp as the Streamable HTTP URL — /mcp on this site is this human walkthrough page, not the protocol endpoint.
    • Codex: use the same Streamable HTTP URL https://glassmoney.app/api/mcp with the Bearer token from /api/mcp/token.
    • Grok Bot: same URL and Bearer token — paste into the client’s MCP HTTP / headers field; no separate Glass Money schema.

Gmail: Connecting Gmail for alert sync is still on Google’s Testing / OAuth allowlist path — not open unrestricted Gmail for everyone yet. MCP only reads data already in your Glass Money tenant after you connect in the app.

Example prompts

  • How much did I spend this calendar month?
  • Show my UPI payments to Swiggy or Zomato in the last 30 days.
  • Break down last month’s debit spend by category.
  • What are my current wallet balances by bank or card account?
  • List my supported banks and card issuers.
  • Reconcile my latest credit-card statement against alert transactions.
  • Using SQL, which counterparties took the most money this quarter?
  • Mark transaction 123 as groceries.

Privacy and tenant isolation

Every MCP request must send Authorization: Bearer <token>. The token is an ordinary Glass Money session credential — treat it like a password; do not paste it into public chats. The server resolves the token to your user id and opens only your per-user SQLite database (users/<id>/finmail.db). There is no cross-tenant tool surface: another user’s token cannot read your rows, and cookie-only browser sessions are not accepted on /api/mcp.

Native OAuth inside the MCP transport is not part of this connect flow yet (session mint via /api/mcp/token only). Gmail connect and sync stay in the Glass Money app. Full privacy policy: glassmoney.app/privacy.

Tools available

get_account_status, get_summary, get_wallet, list_transactions, sql_query (SELECT-only), get_schema, list_banks, list_statements, reconcile, list_categories, set_category.