Unofficial read-only T-Bank CLI and MCP

tbank-cli-mcp

A local read-only CLI and MCP for a T-Bank personal account via a web session: operations, receipts and statements, no payments

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • It uses the bank's unofficial internal API via a browser session, and use may conflict with T-Bank's terms
  • The local file with cookies and session_id grants read access to the personal account and must be stored as carefully as a password
All reasons and checks
Russian stack

tlmonko/tbank-mcp

Install

Manual install

python3 -m venv .venv && . .venv/bin/activate && python -m pip install ".[dev]"

Install into a virtual environment per the README; a session file must be prepared afterward.

This is third-party code. Review the repository files before installing.

What it does

The tool reads a personal T-Bank account's data through the internal web API, using the user's already authenticated browser session: the list of products and accounts, operations over a period with details, a receipt for an operation, and statements. Dates and auth are not re-entered, and no password or SMS code is asked for via the CLI: the user manually prepares a local JSON with cookies and a session_id from their own browser. There is both a plain CLI and a stdio MCP server running on the same code. There is no persistent server, cloud service or Docker, only a local process.

Who it is for. For people who want to read their own T-Bank operations and statements through an agent, accepting the risks of an unofficial API.

Good fit when

  • You only need to view your own account's operations, receipts and statements, with no payments
  • You are willing to manually extract cookies and a session_id from an authorized browser
  • You accept the risk that the internal API contract may change after a site update

Not a fit when

  • You need payments, transfers, top-ups or card and limit management: these are deliberately not implemented
  • You are not willing to use an unofficial internal API client that may conflict with T-Bank's terms
  • You need access to a corporate or business account rather than a personal one

Example request

Show my T-Bank card operations for the last week and pull the receipt for the largest purchase

Limitations

The README explicitly calls the project an unofficial client of T-Bank's internal web API, unaffiliated with the bank: the contract may change after a site update, and use may conflict with T-Bank's terms of service. Payments, transfers, top-ups, card and limit management, applications, settings and messages to the bank are deliberately not implemented. Authorization is manual, via preparing a local file with cookies and a session_id from the browser; there is no automatic password-based login.

How to disable. Delete the local session file and remove the server from your MCP client configuration.

MCP

Transport
stdio
Authentication
not required

Security check

  • It uses the bank's unofficial internal API via a browser session, and use may conflict with T-Bank's terms
  • The local file with cookies and session_id grants read access to the personal account and must be stored as carefully as a password

README in short

The Russian README describes in detail the verified read-only contracts of T-Bank's internal API: products and accounts, operations, receipts, statements, checked as of August 19, 2026, with a reference to the jfk9w-go/tinkoff-api project. A separate Status and risks section plainly warns that this is an unofficial client, the contract may change, and use may conflict with T-Bank's terms.

FAQ

Can the tool make a transfer or payment?

No, the README states this is deliberately not implemented.

Do I need a password or SMS code?

No, passwords and SMS codes are not entered via the CLI; an already authenticated browser session is used instead.

Editors’ pick

A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice

SkillMedium riskNo VPN needed16.6KRepository stars
Official

Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data

MCP serverHigh riskNeeds a VPN1.8KRepository stars
Official

Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language

MCP serverHigh risk995Repository stars
Editors’ pick

An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict

SkillLow riskRussian stackNo VPN needed4Repository stars
Foxx AIUnofficial read-only T-Bank CLI and MCP

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.