Sberbank business API MCP server

@theyahia/sber-mcp

An MCP server for the Sberbank Business API: accounts, balance, statements, payment orders and counterparties for an AI agent

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • The create_payment tool creates a real payment order and moves money from the company account
  • The implementation is unverified against a live bank environment; test on an account with a minimal limit
All reasons and checks
Russian stack

theyahia/sber-mcp

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add mcp/theyahia-sber-mcp

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

This entry is high risk, so there is no one-click install. Review the code and add the config by hand.

Run in a terminal

claude mcp add --transport stdio sber -- npx -y @theyahia/sber-mcp

Or add to the file .mcp.json, in the project

{
  "mcpServers": {
    "sber": {
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.cursor/mcp.json, for all projects

{
  "mcpServers": {
    "sber": {
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

code --add-mcp '{"name":"sber","type":"stdio","command":"npx","args":["-y","@theyahia/sber-mcp"]}'

Or add to the file .vscode/mcp.json, in the project

{
  "servers": {
    "sber": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the servers key.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

codex mcp add sber -- npx -y @theyahia/sber-mcp

Or add to the file ~/.codex/config.toml, for all projects

[mcp_servers.sber]
command = "npx"
args = ["-y", "@theyahia/sber-mcp"]

If the file already exists, append the block to the end.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.gemini/settings.json, for all projects

{
  "mcpServers": {
    "sber": {
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/devin/mcp_config.json, for all projects

{
  "mcpServers": {
    "sber": {
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Formerly Windsurf.

Add to the file cline_mcp_settings.json, for all projects

{
  "mcpServers": {
    "sber": {
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .roo/mcp.json, in the project

{
  "mcpServers": {
    "sber": {
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

A fork of Roo Code, same .roo folders.

Add to the file opencode.json, in the project

{
  "mcp": {
    "sber": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the mcp key.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/zed/settings.json, for all projects

{
  "context_servers": {
    "sber": {
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the context_servers key.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .codeassistant/mcp.json, in the project

{
  "mcpServers": {
    "sber": {
      "command": "npx",
      "args": [
        "-y",
        "@theyahia/sber-mcp"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

SBER_TOKENsecret, optional

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

You will need: Node.js

Checked against the repository on Sep 25, 2026, commit d9b7d34.

Text for your agent

Get a Bearer token or an SBER_CLIENT_ID and SBER_CLIENT_SECRET pair by applying to the bank for Sberbank Business API access, plus an mTLS certificate via SBER_PFX_PATH if required, and add the server with claude mcp add sber -e SBER_TOKEN=... -- npx -y @theyahia/sber-mcp.

Other ways from the author
claude mcp add sber -e SBER_TOKEN=ваш-токен -- npx -y @theyahia/sber-mcp

Command from the README for Claude Code.

This is third-party code. Review the repository files before installing.

What it does

A TypeScript server provides 8 tools on top of the Sberbank Business API: account list and balance, a statement for a period with pagination and a transaction summary (inflows, outflows, net total), creating a payment order and checking its status, a list of saved counterparties, and company details. Authorization is via a Bearer token or OAuth client_credentials, optionally over mTLS with a PFX file or separate PEM files. Every money-moving operation carries a stable idempotent RqUID key that is reused on retries so the bank does not create the payment twice.

Who it is for. For businesses with a Sberbank account who want to check balance, statements and build payment orders from a chat with an agent instead of internet banking.

Good fit when

  • You want a quick look at balance and recent inflows on an account
  • You need a transaction summary for a period without a manual export from internet banking
  • You need to build a payment order and immediately check its status

Not a fit when

  • You have no bank-approved application for the Sberbank Business API and no mTLS certificate: authorization will not work without them
  • You need proven stability: the author states plainly the implementation is not verified against a live Sberbank Business API environment

Example request

Summarize account transactions for May and create a 150,000-ruble payment order to LLC Romashka for payment under contract no. 7

Limitations

The production Sberbank Business API sits behind mTLS and a separate bank application, so the author states plainly the implementation is unverified against a live environment. Sberbank has coexisting API generations, and the README advises checking exact endpoint paths and parameters against your own integration agreement; spots needing verification are marked VERIFY in the source. The same codebase also lives inside the author's WWmcp monorepo.

How to disable. Remove the sber server from your MCP client settings, for example claude mcp remove sber.

MCP

Transport
stdio, http
Authentication
API key
Environment variables
Environment variables
SBER_TOKEN
secret
A direct API Bearer token, one of the authorization options
SBER_CLIENT_ID
secret
Client ID for OAuth client_credentials, paired with SBER_CLIENT_SECRET
SBER_CLIENT_SECRET
secret
Client secret for OAuth client_credentials
SBER_PFX_PATH
secret
Path to a .p12 or .pfx certificate for mTLS

Security check

  • The create_payment tool creates a real payment order and moves money from the company account
  • The implementation is unverified against a live bank environment; test on an account with a minimal limit

README in short

The Russian README describes a quick start for Claude Desktop, Claude Code, VS Code, Cursor and Windsurf, the full list of environment variables for Bearer and OAuth authorization plus mTLS, a table of 8 tools covering accounts, statements, payments and counterparties, demo prompts, the idempotency and retry architecture, and a separate API-compliance section that honestly warns the implementation is unverified against Sberbank's live environment.

FAQ

Can I authorize without an mTLS certificate?

The README describes mTLS as optional on top of a Bearer token or OAuth, but the real requirements depend on your integration agreement with Sberbank.

What stops a payment from being created twice by accident?

Every payment carries an idempotent x-Introspect-RqUID reused on all retries, and the bank deduplicates the repeat.

Editors’ pick

A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice

SkillMedium riskNo VPN needed16.6KRepository stars
Official

Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data

MCP serverHigh riskNeeds a VPN1.8KRepository stars
Official

Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language

MCP serverHigh risk995Repository stars
Editors’ pick

An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict

SkillLow riskRussian stackNo VPN needed4Repository stars
Foxx AISberbank business API MCP server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.