Unofficial read-only T-Bank CLI and MCP
tbank-cli-mcp
A local read-only CLI and MCP for a T-Bank personal account via a web session: operations, receipts and statements, no payments
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- It uses the bank's unofficial internal API via a browser session, and use may conflict with T-Bank's terms
- The local file with cookies and session_id grants read access to the personal account and must be stored as carefully as a password
Install
Manual install
python3 -m venv .venv && . .venv/bin/activate && python -m pip install ".[dev]"Install into a virtual environment per the README; a session file must be prepared afterward.
This is third-party code. Review the repository files before installing.
What it does
The tool reads a personal T-Bank account's data through the internal web API, using the user's already authenticated browser session: the list of products and accounts, operations over a period with details, a receipt for an operation, and statements. Dates and auth are not re-entered, and no password or SMS code is asked for via the CLI: the user manually prepares a local JSON with cookies and a session_id from their own browser. There is both a plain CLI and a stdio MCP server running on the same code. There is no persistent server, cloud service or Docker, only a local process.
Who it is for. For people who want to read their own T-Bank operations and statements through an agent, accepting the risks of an unofficial API.
Good fit when
- You only need to view your own account's operations, receipts and statements, with no payments
- You are willing to manually extract cookies and a session_id from an authorized browser
- You accept the risk that the internal API contract may change after a site update
Not a fit when
- You need payments, transfers, top-ups or card and limit management: these are deliberately not implemented
- You are not willing to use an unofficial internal API client that may conflict with T-Bank's terms
- You need access to a corporate or business account rather than a personal one
Example request
Show my T-Bank card operations for the last week and pull the receipt for the largest purchaseLimitations
The README explicitly calls the project an unofficial client of T-Bank's internal web API, unaffiliated with the bank: the contract may change after a site update, and use may conflict with T-Bank's terms of service. Payments, transfers, top-ups, card and limit management, applications, settings and messages to the bank are deliberately not implemented. Authorization is manual, via preparing a local file with cookies and a session_id from the browser; there is no automatic password-based login.
How to disable. Delete the local session file and remove the server from your MCP client configuration.
MCP
- Transport
- stdio
- Authentication
- not required
Security check
- It uses the bank's unofficial internal API via a browser session, and use may conflict with T-Bank's terms
- The local file with cookies and session_id grants read access to the personal account and must be stored as carefully as a password
README in short
The Russian README describes in detail the verified read-only contracts of T-Bank's internal API: products and accounts, operations, receipts, statements, checked as of August 19, 2026, with a reference to the jfk9w-go/tinkoff-api project. A separate Status and risks section plainly warns that this is an unofficial client, the contract may change, and use may conflict with T-Bank's terms.
FAQ
Can the tool make a transfer or payment?
No, the README states this is deliberately not implemented.
Do I need a password or SMS code?
No, passwords and SMS codes are not entered via the CLI; an already authenticated browser session is used instead.
Related
A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice
Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data
Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language
inn-check-ru: counterparty risk traffic light
inn-check-ru
An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict