A firewall in front of a T-Bank personal-account MCP
Bank AI Firewall
Rules, limits and owner confirmation before every money-moving call: a safety layer in front of a fork of the unofficial 61-tool tbank-mcp
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- After an allowing rule or owner confirmation, tools transfer real money from a personal T-Bank account
- Login uses a phone number, SMS code and password over an unofficial protocol rather than an official API token
Install
Manual install
cp .env.example .env && docker compose up -d --buildStarts the firewall web UI on :8080 and the login daemon on :8765.
This is third-party code. Review the repository files before installing.
What it does
The project wraps a fork of the unofficial icyberdeveloper/tbank-mcp MCP server (61 tools against a personal T-Bank account, logging in with a phone number, SMS code and password through a reverse-engineered protocol) with a FastAPI and SQLite firewall web app. The owner writes rules by operation type, expense category, amount, recipient, account and card: allow, deny, or ask for confirmation. There are amount and count limits over time windows, a no-confirmation quota per allowing rule, allow and deny lists for recipients, protection against spoofed SBP recipient bank details (the recipient's bank comes only from the bank's own response, never from the agent-supplied phone number), card-number and CVV masking in model responses, and a call log that excludes passwords, PINs and SMS codes. Transfer confirmations go through a one-time link on a web UI at 127.0.0.1:8080. If the firewall is unreachable, the MCP denies every operation by default.
Who it is for. For technically capable T-Bank personal account owners who want to give an agent access to their money, but with tight control on top.
Good fit when
- You already use the unofficial tbank-mcp fork and want to add limits and transfer confirmation
- You want to allow small category-based spending without confirmation while sending large amounts to the owner for approval
- You want a separate Claude Desktop project so the financial system prompt and firewall stay out of ordinary chats
Not a fit when
- You need an official, bank-supported way to access the account: this is an unofficial reverse-engineered protocol, not approved or supported by T-Bank
- The firewall web UI has no authentication yet: do not expose it beyond localhost, the README warns about this directly
- You are looking for a production-ready tool: the author explicitly calls it a personal tool for their own account, not a product
Example request
Transfer 1500 rubles to this phone number, but first show what the money will go towardLimitations
The repo's license in GitHub metadata is marked Other, though the README and LICENSE state MIT. Login happens via phone number, SMS code and password through a protocol reverse-engineered by a third party, not an official bank API, and the project states plainly it is not affiliated with or approved by T-Bank. The firewall web UI has no authentication yet and is bound to 127.0.0.1. This is the author's personal tool for their own account, not a product meant for someone else's production use.
How to disable. Run docker compose down, delete the ~/.local/share/tbank-mcp/session.json session file, and remove tbank from your MCP client config.
MCP
- Transport
- stdio, http
- Authentication
- OAuth
Security check
- After an allowing rule or owner confirmation, tools transfer real money from a personal T-Bank account
- Login uses a phone number, SMS code and password over an unofficial protocol rather than an official API token
README in short
The README describes in detail the top-down ACL rule model, facets by operation type and amount, comparison conditions, time-windowed limits, a no-confirmation quota, two human-confirmation scenarios, protection against spoofed SBP recipient bank details, sensitive-data masking and a call log, a quick start via docker compose and venv, a sample agent dialogue with a confirmation request, a separate Claude Desktop instruction for an isolated project, and explicit credit to the original tbank-mcp author with a diff of the changes.
FAQ
Could the agent transfer money without the owner knowing?
Only if a rule explicitly allows it within a no-confirmation quota; otherwise the operation waits for a one-time confirmation via the web UI link.
What if the firewall goes down?
The MCP denies every operation by default; this is a deliberate design choice, not a side effect.
Related
A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice
Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data
Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language
inn-check-ru: counterparty risk traffic light
inn-check-ru
An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict