Sberbank business API MCP server
@theyahia/sber-mcp
An MCP server for the Sberbank Business API: accounts, balance, statements, payment orders and counterparties for an AI agent
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- The create_payment tool creates a real payment order and moves money from the company account
- The implementation is unverified against a live bank environment; test on an account with a minimal limit
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/theyahia-sber-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport stdio sber -- npx -y @theyahia/sber-mcpOr add to the file .mcp.json, in the project
{
"mcpServers": {
"sber": {
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"sber": {
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"sber","type":"stdio","command":"npx","args":["-y","@theyahia/sber-mcp"]}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"sber": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add sber -- npx -y @theyahia/sber-mcpOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.sber]
command = "npx"
args = ["-y", "@theyahia/sber-mcp"]If the file already exists, append the block to the end.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"sber": {
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"sber": {
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"sber": {
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"sber": {
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"sber": {
"type": "local",
"command": [
"npx",
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"sber": {
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"sber": {
"command": "npx",
"args": [
"-y",
"@theyahia/sber-mcp"
]
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
SBER_TOKENsecret, optional
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Get a Bearer token or an SBER_CLIENT_ID and SBER_CLIENT_SECRET pair by applying to the bank for Sberbank Business API access, plus an mTLS certificate via SBER_PFX_PATH if required, and add the server with claude mcp add sber -e SBER_TOKEN=... -- npx -y @theyahia/sber-mcp.
Other ways from the author
claude mcp add sber -e SBER_TOKEN=ваш-токен -- npx -y @theyahia/sber-mcpCommand from the README for Claude Code.
This is third-party code. Review the repository files before installing.
What it does
A TypeScript server provides 8 tools on top of the Sberbank Business API: account list and balance, a statement for a period with pagination and a transaction summary (inflows, outflows, net total), creating a payment order and checking its status, a list of saved counterparties, and company details. Authorization is via a Bearer token or OAuth client_credentials, optionally over mTLS with a PFX file or separate PEM files. Every money-moving operation carries a stable idempotent RqUID key that is reused on retries so the bank does not create the payment twice.
Who it is for. For businesses with a Sberbank account who want to check balance, statements and build payment orders from a chat with an agent instead of internet banking.
Good fit when
- You want a quick look at balance and recent inflows on an account
- You need a transaction summary for a period without a manual export from internet banking
- You need to build a payment order and immediately check its status
Not a fit when
- You have no bank-approved application for the Sberbank Business API and no mTLS certificate: authorization will not work without them
- You need proven stability: the author states plainly the implementation is not verified against a live Sberbank Business API environment
Example request
Summarize account transactions for May and create a 150,000-ruble payment order to LLC Romashka for payment under contract no. 7Limitations
The production Sberbank Business API sits behind mTLS and a separate bank application, so the author states plainly the implementation is unverified against a live environment. Sberbank has coexisting API generations, and the README advises checking exact endpoint paths and parameters against your own integration agreement; spots needing verification are marked VERIFY in the source. The same codebase also lives inside the author's WWmcp monorepo.
How to disable. Remove the sber server from your MCP client settings, for example claude mcp remove sber.
MCP
- Transport
- stdio, http
- Authentication
- API key
| Environment variables | |
|---|---|
| SBER_TOKEN secret | A direct API Bearer token, one of the authorization options |
| SBER_CLIENT_ID secret | Client ID for OAuth client_credentials, paired with SBER_CLIENT_SECRET |
| SBER_CLIENT_SECRET secret | Client secret for OAuth client_credentials |
| SBER_PFX_PATH secret | Path to a .p12 or .pfx certificate for mTLS |
Security check
- The create_payment tool creates a real payment order and moves money from the company account
- The implementation is unverified against a live bank environment; test on an account with a minimal limit
README in short
The Russian README describes a quick start for Claude Desktop, Claude Code, VS Code, Cursor and Windsurf, the full list of environment variables for Bearer and OAuth authorization plus mTLS, a table of 8 tools covering accounts, statements, payments and counterparties, demo prompts, the idempotency and retry architecture, and a separate API-compliance section that honestly warns the implementation is unverified against Sberbank's live environment.
FAQ
Can I authorize without an mTLS certificate?
The README describes mTLS as optional on top of a Bearer token or OAuth, but the real requirements depend on your integration agreement with Sberbank.
What stops a payment from being created twice by accident?
Every payment carries an idempotent x-Introspect-RqUID reused on all retries, and the bank deduplicates the repeat.
Related
A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice
Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data
Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language
inn-check-ru: counterparty risk traffic light
inn-check-ru
An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict