A firewall in front of a T-Bank personal-account MCP

Bank AI Firewall

Rules, limits and owner confirmation before every money-moving call: a safety layer in front of a fork of the unofficial 61-tool tbank-mcp

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • After an allowing rule or owner confirmation, tools transfer real money from a personal T-Bank account
  • Login uses a phone number, SMS code and password over an unofficial protocol rather than an official API token
All reasons and checks
Russian stack

nikallass/tbank-ai-fw

Install

Manual install

cp .env.example .env && docker compose up -d --build

Starts the firewall web UI on :8080 and the login daemon on :8765.

This is third-party code. Review the repository files before installing.

What it does

The project wraps a fork of the unofficial icyberdeveloper/tbank-mcp MCP server (61 tools against a personal T-Bank account, logging in with a phone number, SMS code and password through a reverse-engineered protocol) with a FastAPI and SQLite firewall web app. The owner writes rules by operation type, expense category, amount, recipient, account and card: allow, deny, or ask for confirmation. There are amount and count limits over time windows, a no-confirmation quota per allowing rule, allow and deny lists for recipients, protection against spoofed SBP recipient bank details (the recipient's bank comes only from the bank's own response, never from the agent-supplied phone number), card-number and CVV masking in model responses, and a call log that excludes passwords, PINs and SMS codes. Transfer confirmations go through a one-time link on a web UI at 127.0.0.1:8080. If the firewall is unreachable, the MCP denies every operation by default.

Who it is for. For technically capable T-Bank personal account owners who want to give an agent access to their money, but with tight control on top.

Good fit when

  • You already use the unofficial tbank-mcp fork and want to add limits and transfer confirmation
  • You want to allow small category-based spending without confirmation while sending large amounts to the owner for approval
  • You want a separate Claude Desktop project so the financial system prompt and firewall stay out of ordinary chats

Not a fit when

  • You need an official, bank-supported way to access the account: this is an unofficial reverse-engineered protocol, not approved or supported by T-Bank
  • The firewall web UI has no authentication yet: do not expose it beyond localhost, the README warns about this directly
  • You are looking for a production-ready tool: the author explicitly calls it a personal tool for their own account, not a product

Example request

Transfer 1500 rubles to this phone number, but first show what the money will go toward

Limitations

The repo's license in GitHub metadata is marked Other, though the README and LICENSE state MIT. Login happens via phone number, SMS code and password through a protocol reverse-engineered by a third party, not an official bank API, and the project states plainly it is not affiliated with or approved by T-Bank. The firewall web UI has no authentication yet and is bound to 127.0.0.1. This is the author's personal tool for their own account, not a product meant for someone else's production use.

How to disable. Run docker compose down, delete the ~/.local/share/tbank-mcp/session.json session file, and remove tbank from your MCP client config.

MCP

Transport
stdio, http
Authentication
OAuth

Security check

  • After an allowing rule or owner confirmation, tools transfer real money from a personal T-Bank account
  • Login uses a phone number, SMS code and password over an unofficial protocol rather than an official API token

README in short

The README describes in detail the top-down ACL rule model, facets by operation type and amount, comparison conditions, time-windowed limits, a no-confirmation quota, two human-confirmation scenarios, protection against spoofed SBP recipient bank details, sensitive-data masking and a call log, a quick start via docker compose and venv, a sample agent dialogue with a confirmation request, a separate Claude Desktop instruction for an isolated project, and explicit credit to the original tbank-mcp author with a diff of the changes.

FAQ

Could the agent transfer money without the owner knowing?

Only if a rule explicitly allows it within a no-confirmation quota; otherwise the operation waits for a one-time confirmation via the web UI link.

What if the firewall goes down?

The MCP denies every operation by default; this is a deliberate design choice, not a side effect.

Editors’ pick

A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice

SkillMedium riskNo VPN needed16.6KRepository stars
Official

Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data

MCP serverHigh riskNeeds a VPN1.8KRepository stars
Official

Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language

MCP serverHigh risk995Repository stars
Editors’ pick

An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict

SkillLow riskRussian stackNo VPN needed4Repository stars
Foxx AIA firewall in front of a T-Bank personal-account MCP

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.