Alfa API MCP: Alfa-Bank accounts and payments
alfa-bank-mcp
An MCP server for the Alfa-Bank Business Alfa API: accounts, statements, payments and rates, flagged as an unverified demo until a bank agreement is signed
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- create_payment_order can move real money once a signing module is connected
- Requires mTLS certificates and a bank agreement; a misconfiguration can expose banking data
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/alfa-bank-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport stdio --env 'ALFA_CLIENT_ID=<ALFA_CLIENT_ID value>' --env 'ALFA_CLIENT_SECRET=<your ALFA_CLIENT_SECRET>' alfa-bank -- npx -y @theyahia/alfa-bank-mcpOr add to the file .mcp.json, in the project
{
"mcpServers": {
"alfa-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"alfa-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"alfa-bank","type":"stdio","command":"npx","args":["-y","@theyahia/alfa-bank-mcp"],"env":{"ALFA_CLIENT_ID":"<ALFA_CLIENT_ID value>","ALFA_CLIENT_SECRET":"<your ALFA_CLIENT_SECRET>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"alfa-bank": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add alfa-bank --env 'ALFA_CLIENT_ID=<ALFA_CLIENT_ID value>' --env 'ALFA_CLIENT_SECRET=<your ALFA_CLIENT_SECRET>' -- npx -y @theyahia/alfa-bank-mcpOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.alfa-bank]
command = "npx"
args = ["-y", "@theyahia/alfa-bank-mcp"]
env = { ALFA_CLIENT_ID = "<ALFA_CLIENT_ID value>", ALFA_CLIENT_SECRET = "<your ALFA_CLIENT_SECRET>" }If the file already exists, append the block to the end.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"alfa-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"alfa-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"alfa-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"alfa-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"alfa-bank": {
"type": "local",
"command": [
"npx",
"-y",
"@theyahia/alfa-bank-mcp"
],
"environment": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"alfa-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"alfa-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/alfa-bank-mcp"
],
"env": {
"ALFA_CLIENT_ID": "<ALFA_CLIENT_ID value>",
"ALFA_CLIENT_SECRET": "<your ALFA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
ALFA_CLIENT_IDrequiredALFA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Get ALFA_CLIENT_ID and ALFA_CLIENT_SECRET on the developers.alfabank.ru developer portal, prepare mTLS certificates and a GOST signing module for production access, then add the server to your MCP client config via npx -y @theyahia/alfa-bank-mcp with those variables.
Other ways from the author
{
"mcpServers": {
"alfa-bank": {
"command": "npx",
"args": ["-y", "@theyahia/alfa-bank-mcp"],
"env": {
"ALFA_CLIENT_ID": "your-client-id",
"ALFA_CLIENT_SECRET": "your-client-secret"
}
}
}
}Demo mode with no mTLS or GOST signing.
This is third-party code. Review the repository files before installing.
What it does
The server gives eight tools over the Alfa API: listing business accounts, the current balance for an account, transactions for a period, creating a payment order (flagged as a destructive action), payment order or registry status, saved counterparties, exchange rates, and salary registries. Authorization uses OAuth 2.0 client credentials with token caching. The author explicitly and thoroughly explains that production access needs an mTLS client certificate, GOST PKCS#7 request signing, and a signed technical-interaction agreement with the bank; without those, the server only works in demo mode and cannot reach the live environment. create_payment_order has no default signer implemented: without your own Signer module, the tool returns a clear error instead of sending money.
Who it is for. For companies with an Alfa-Bank business account and a signed technical-interaction agreement who want Alfa API access from an agent.
Good fit when
- You want to check a business account balance and statement from a chat with an agent
- You have a bank agreement, mTLS certificates and a ready GOST signing module, and need production payment access
- You need an exchange rate or the list of saved Alfa-Bank Business counterparties
Not a fit when
- You have no technical-interaction agreement, mTLS certificates or GOST signing: the server only works in demo mode, production payments will not go through
- You need a guarantee of exact API paths: part of the endpoints in the README are marked "verify" and not confirmed live
Example request
Show all my Alfa-Bank business accounts and their balancesLimitations
Production access needs mTLS certificates, GOST PKCS#7 signing and a signed bank agreement, none of which the server provides on its own. The signer for create_payment_order has no default implementation and must be wired up yourself. Some endpoint paths (account balance, salary registries, counterparty list) are compiled from documentation and explicitly marked by the author as unverified, needing a Swagger check.
How to disable. Remove the alfa-bank server from claude_desktop_config.json, or with claude mcp remove alfa-bank.
MCP
- Transport
- stdio, http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| ALFA_CLIENT_ID required | OAuth 2.0 client ID from the Alfa-Bank developer portal |
| ALFA_CLIENT_SECRET required, secret | OAuth 2.0 client secret |
| ALFA_TLS_CERT secret | mTLS client certificate, required for production access |
| ALFA_TLS_KEY secret | mTLS client private key |
| ALFA_TLS_CA | mTLS root certificate bundle |
Security check
- create_payment_order can move real money once a signing module is connected
- Requires mTLS certificates and a bank agreement; a misconfiguration can expose banking data
README in short
The README opens with a warning to read the endpoint-verification section before use, shows a quick start for Claude Desktop, Claude Code, VS Code, Cursor and Windsurf, a table of eight tools flagged read-only or destructive, the authorization and mTLS architecture, and a detailed per-tool table with an API-path verification status (documented, likely, verify).
FAQ
Will the server work right after installation?
Only in demo mode; production access to real accounts requires mTLS certificates, GOST signing and an agreement with Alfa-Bank.
Can the server send a payment on its own?
Not by default: create_payment_order without a connected Signer module returns an error instead of sending money, and the tool has destructiveHint set for explicit confirmation.
Related
A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice
Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data
Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language
inn-check-ru: counterparty risk traffic light
inn-check-ru
An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict