Tochka Bank MCP: accounts and payments for signing
tochka-bank-mcp
An MCP server for Tochka Bank's live business API: accounts, statements, and drafting rouble payments that a human signs via SMS in online banking
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Drafts real payments by bank details, though sending requires a human's signature
- Reads balances, statements and company details, sensitive banking data
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/tochka-bank-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport stdio --env 'TOCHKA_CLIENT_ID=<TOCHKA_CLIENT_ID value>' --env 'TOCHKA_CLIENT_SECRET=<your TOCHKA_CLIENT_SECRET>' tochka-bank -- npx -y @theyahia/tochka-bank-mcpOr add to the file .mcp.json, in the project
{
"mcpServers": {
"tochka-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"tochka-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"tochka-bank","type":"stdio","command":"npx","args":["-y","@theyahia/tochka-bank-mcp"],"env":{"TOCHKA_CLIENT_ID":"<TOCHKA_CLIENT_ID value>","TOCHKA_CLIENT_SECRET":"<your TOCHKA_CLIENT_SECRET>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"tochka-bank": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add tochka-bank --env 'TOCHKA_CLIENT_ID=<TOCHKA_CLIENT_ID value>' --env 'TOCHKA_CLIENT_SECRET=<your TOCHKA_CLIENT_SECRET>' -- npx -y @theyahia/tochka-bank-mcpOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.tochka-bank]
command = "npx"
args = ["-y", "@theyahia/tochka-bank-mcp"]
env = { TOCHKA_CLIENT_ID = "<TOCHKA_CLIENT_ID value>", TOCHKA_CLIENT_SECRET = "<your TOCHKA_CLIENT_SECRET>" }If the file already exists, append the block to the end.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"tochka-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"tochka-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"tochka-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"tochka-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"tochka-bank": {
"type": "local",
"command": [
"npx",
"-y",
"@theyahia/tochka-bank-mcp"
],
"environment": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"tochka-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"tochka-bank": {
"command": "npx",
"args": [
"-y",
"@theyahia/tochka-bank-mcp"
],
"env": {
"TOCHKA_CLIENT_ID": "<TOCHKA_CLIENT_ID value>",
"TOCHKA_CLIENT_SECRET": "<your TOCHKA_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
TOCHKA_CLIENT_IDrequiredTOCHKA_CLIENT_SECRETsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Create an application in Tochka's online banking (Integrations and API), get the client id and secret, run the one-time TOCHKA_CLIENT_ID=... TOCHKA_CLIENT_SECRET=... npx -y @theyahia/tochka-bank-mcp auth command in a browser, then add the server to your MCP client config with the same variables.
Other ways from the author
TOCHKA_CLIENT_ID=... TOCHKA_CLIENT_SECRET=... npx -y @theyahia/tochka-bank-mcp authOne-time browser authorization before the server's first run.
This is third-party code. Review the repository files before installing.
What it does
The server gives seven tools over Tochka's live API (enter.tochka.com/uapi): listing business accounts, account balances, transactions for a period (asynchronous, with status polling), client codes, company details, drafting an outgoing rouble payment, and its status. The server itself sends no money: create_payment builds a payment through the "for signing" flow, showing a preview with no send until the confirm flag is explicitly passed, after which a person signs the payment in Tochka's online banking via SMS. The tool has an amount limit via an environment variable and an optional recipient account whitelist. Authorization uses a hybrid OAuth 2.0 flow: a one-time auth command opens a browser to confirm rights, after which the server refreshes access and refresh tokens itself.
Who it is for. For companies with a Tochka Bank account who want account and statement access from an agent, and payment drafting with no risk of sending money without a human's confirmation.
Good fit when
- You want to check an account balance and statement from a chat with an agent
- You want to draft a payment by recipient details, but a human must sign it
- You want a recipient whitelist and an amount limit to bound what the agent can even draft
Not a fit when
- You need a list of external counterparties as a separate entity: Tochka does not expose them that way, you derive them from get_statement transactions
- You need single-tenant JWT authentication: the server currently implements only the OAuth flow, JWT is not supported
Example request
Draft a payment of 75,000.50 roubles to OOO Romashka, account 40702810000000005678, BIC 044525225, for web development services, show the preview firstLimitations
Requires a one-time auth command that opens a browser before first use; headless deployments need a pre-issued TOCHKA_REFRESH_TOKEN. External counterparties cannot be fetched as a separate list. Works against the live API, with a sandbox available via a separate base URL. The access token lives about a day, the refresh token about a month.
How to disable. Remove the tochka-bank server from claude_desktop_config.json and delete the token file ~/.config/tochka-bank-mcp/tokens.json.
MCP
- Transport
- stdio
- Authentication
- OAuth
| Environment variables | |
|---|---|
| TOCHKA_CLIENT_ID required | OAuth client id from the Tochka developer dashboard |
| TOCHKA_CLIENT_SECRET required, secret | OAuth client secret |
| TOCHKA_MAX_PAYMENT_RUB | Maximum payment amount for create_payment, defaults to 100000 |
| TOCHKA_ALLOWED_RECIPIENTS | Comma-separated whitelist of recipient accounts |
| TOCHKA_REFRESH_TOKEN secret | A pre-issued refresh token for headless deployments, skipping the auth step |
Security check
- Drafts real payments by bank details, though sending requires a human's signature
- Reads balances, statements and company details, sensitive banking data
README in short
The README opens with a warning that the server can draft real payments but never sends them itself, explains the hybrid OAuth flow with a one-time auth command and a headless option via a pre-issued refresh token, an environment variable table with the amount limit and recipient whitelist, a seven-tool table flagged by operation type, and a security section on masking INNs and account numbers in logs and errors.
FAQ
Can the agent send money itself?
No, create_payment only drafts a payment for signing; sending and signing happen in Tochka's online banking via SMS by a human.
Can I limit who and how much the agent can draft payments for?
Yes, TOCHKA_MAX_PAYMENT_RUB sets an amount limit, and TOCHKA_ALLOWED_RECIPIENTS restricts recipient accounts.
Related
A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice
Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data
Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language
inn-check-ru: counterparty risk traffic light
inn-check-ru
An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict