comdirect-mcp
Read-only MCP server and typed Python client for the comdirect banking API (photoTAN push login, OS keychain credentials)
Install / Use
claude mcp add mad4ms -- npx -y github:mad4ms/comdirect-mcpIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AI & Machine LearningSupported Platforms
Our assessment of comdirect-mcp
comdirect-mcp scores 81/100 on our quality scale, 740th of 964 AI & Machine Learning skills we index.
Its MCP Server is 11 KB long, well organised into 15 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated today, so comdirect-mcp is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-10. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
comdirect-mcp compared with similar skills
All 4 of these similar skills score higher than comdirect-mcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| comdirect-mcp (this skill)by mad4ms | 81 | 3 | today | MCP Server |
| claude-memby thedotmack | 100 | 99.1k | 1d ago | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 95.3k | 2d ago | CLAUDE.md |
| Understand-Anythingby Egonex-AI | 100 | 85.8k | 1d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.9k | today | CLAUDE.md |
Frequently asked questions
- How do I install comdirect-mcp?
- Run
claude mcp add mad4ms -- npx -y github:mad4ms/comdirect-mcp. The install tabs above show the steps for each supported agent. - Which AI agents does comdirect-mcp work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is comdirect-mcp safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is comdirect-mcp still maintained?
- The repository was last updated today, so comdirect-mcp is actively maintained.
Skill content
View source on GitHubcomdirect-mcp
<!-- mcp-name: io.github.mad4ms/comdirect-mcp -->Read-only Model Context Protocol server and typed Python client for the comdirect REST API.
Let Claude, GitHub Copilot or any other MCP client look at your accounts, transactions, securities depot and postbox documents. The login is confirmed with your photoTAN app, and there is no tool that can move money.
[!WARNING] This is an unofficial project, not affiliated with comdirect. It handles your banking credentials and sends your financial data to the AI model you connect it to. Read the warning below and SECURITY.md.
Warnung (in Deutsch weil Comdirect)
Leute es geht hier um euer Geld. Nutzt diese Bibliothek nur, wenn ihr den Code versteht und euch den Risiken bewusst seid.
Ich bin auch nicht perfekt, aber übernehme keine Haftung für Schäden, die durch die Nutzung dieser Software entstehen. Falls Euch was auffällt, gern PRs oder Issues.
Die API und damit das Repo hier nutzen aktuell nur lesende Endpunkte, aber Fehler können immer passieren. Comdirect kann die API ändern, Dependencies können im Zweifel auch Mist bauen (Supply-Chain Attacks) und 2FA hilft zwar, ist aber kein Freifahrtschein.
Bitte:
- Nutzt das nur lokal auf eurem eigenen Rechner.
- Teilt eure Zugangsdaten mit niemandem.
- Packt Secrets in
.envund committet die Datei nie. - Nutzt die Pre-Commit Hooks um Secrets zu scannen. Gute Zeit bissel Devops-Kram zu lernen.
- Spielt Updates nicht blind ein (Lockfile/Pinning hilft) und schaut bei Änderungen kurz drüber.
MCP-Server: Wenn ihr den Server an einen nicht-lokalen AI-Client hängt, gehen deine Daten raus. Je nach Client/Setup können Kontodaten/Transaktionen in Logs/Telemetry landen oder durch Prompt-Injection aus Dokumenten/Verwendungszwecken in komische Richtungen gehen (MCP Horror Stories: The GitHub Prompt Injection Data Heist). Nutzt MCP nur, wenn ihr der Umgebung wirklich vertraut, und gebt nur die Daten frei, die ihr dafür braucht.
Da der gemeine r/finanzen User eh schon seine Kontoauszüge in ChatGPT kopiert, könnt ihr damit machen, was ihr wollt, auf eure eigene Verantwortung!
Idealerweise ohne unnötige personenbezogene Daten. (Hauptsache, ihr lasst 'nen Stern da.)
Privacy: prefer a local model
The server runs on your machine, but every tool result is sent to the language model behind your MCP client. With cloud assistants (Claude, GitHub Copilot, ChatGPT, ...) your balances, transactions and documents leave your computer and are processed under that provider's data policy.
- Most private: use an MCP client with a local model, e.g. LM Studio (supports MCP servers directly) or Ollama with the ollmcp client. Then nothing leaves your machine except the requests to comdirect. Pick a model with good tool-calling support.
- With a cloud assistant: check its data retention and training settings, use an account where your data is not used for training, and ask only what you need.
Details: Privacy and security · Use a local model
Features
- MCP specification 2026-07-28 on the official MCP Python SDK v2, with fallback for older clients
- Push TAN login via elicitation: your client asks you to approve the login in the photoTAN app; the TAN never reaches the model
- Credentials in the OS keychain:
comdirect-mcp configurestores them once, client configs contain no secrets - No tool can move money: only read endpoints, truthful tool annotations, structured output with JSON schemas
- Protects your access: stops logging in before comdirect's lock after five unconfirmed TAN challenges, and revokes the session at comdirect on logout and shutdown so it cannot be extended
- Built for agents: compact results without empty fields, one
counterpartyinstead of SEPA roles, cleaned-up payment texts, server-side summaries for cash flow questions - Privacy defaults: IBANs and account numbers masked, optional name pseudonyms, documents size-limited, untrusted-content hint for the model
- Automatic token refresh and explicit session handling
- Typed Python client (
py.typed) for scripts and notebooks, independent of MCP - Listed in the MCP Registry as
io.github.mad4ms/comdirect-mcp
Tools
| Tool | Description |
| --- | --- |
| login | Starts a session; asks you to approve the push TAN |
| logout | Ends the session and revokes it at comdirect (no further refresh) |
| list_accounts | Accounts with type (Girokonto, Tagesgeld, ...) and balances |
| get_wealth_overview | All product balances with bank-supplied EUR totals, including loans and savings |
| list_depot_transactions | Securities purchases, sales and transfers with filters and continuation |
| get_instrument | Security metadata; optional fund fees/ratings and derivative details |
| list_transactions | Transactions with date, amount, counterparty and cleaned-up purpose; compact by default |
| summarize_transactions | Cash flow and spending per month, counterparty or type, computed on the server |
| list_cards | Card balances (Visa); the API has no card transactions |
| list_depots | Securities accounts |
| get_depot_positions | Positions (name, ISIN, WKN, values, P&L) and depot balance |
| list_documents | Postbox documents (statements, order confirmations, tax documents) |
| download_document | A document as embedded resource (comdirect marks it as read) |
| get_account_balance | Balance and masked static data for one account |
| get_depot_position | One securities position, with optional details |
| summarize_portfolio | Largest positions and allocation percentages per currency |
| list_orders / get_order | Read the order book and individual orders; never place or change orders |
| get_order_dimensions | Available trading venues, currencies and order types |
| get_document_cover | Bounded plain text from the document pre-page |
| extract_document_text | Bounded PDF text with page continuation; downloading marks it as read |
Arguments and results: Tools reference.
Quickstart
New to this? Follow the Getting started tutorial.
1. Prerequisites
- uv (provides
uvx) - comdirect API access: in the online banking under Verwaltung → Entwicklerzugang you get a Client ID and Client Secret (step by step)
- photoTAN Push as your default TAN method
2. Store your credentials in the OS keychain
uvx comdirect-mcp@0.5.1 configure
Prompts for Client ID, Client Secret, Zugangsnummer and PIN and stores them in the macOS Keychain, Windows
Credential Manager or Linux Secret Service. Other options (VS Code inputs, environment, .env):
Manage credentials.
3. Add the server to your MCP client
Claude Desktop (Settings → Developer → Edit Config) and LM Studio (Program → Install → Edit mcp.json):
{
"mcpServers": {
"comdirect": {
"command": "uvx",
"args": ["comdirect-mcp@0.5.1"]
}
}
}
Claude Code
claude mcp add --transport stdio --scope user comdirect -- uvx comdirect-mcp@0.5.1
VS Code (MCP: Open User Configuration)
{
"servers": {
"comdirect": {
"type": "stdio",
"command": "uvx",
"args": ["comdirect-mcp@0.5.1"]
}
}
}
Ollama (via ollmcp)
uvx ollmcp mcp add --scope user comdirect -- uvx comdirect-mcp@0.5.1
uvx ollmcp -m <model>
Pinning the version (@0.5.1) means updates only happen when you decide. More clients:
Configure MCP clients.
4. Ask
Wie haben sich meine Ausgaben im letzten Monat entwickelt, und welche Depotposition läuft am schlechtesten?
The assistant calls login, your phone receives the push TAN, you approve it and confirm the dialog in
your client. Then the assistant can use the other tools. Problems: Troubleshoot.
Python library
The same client is available for your own scripts:
from comdirect_mcp import ComdirectClient
from comdirect_mcp.utils import default_push_tan_callback
client = ComdirectClient(
{"client_id": "...", "client_secret": "...", "username": "...", "password": "..."},
{"push_tan_cb": default_push_tan_callback},
)
client.login() # approve the push TAN, then press Enter
for account in client.list_accounts():
print(account.id, account.balance, account.currency)
See Use the Python library, the Python API reference and the examples.
Documentation
The documentation is organized as tutorial, how-to guides, reference and explanation:
| | | | --- | --- | | Tutorial | Getting started | | How-to | API access · Credentials · MCP clients · Local model · Troubleshoot · Python library · Develop | | Reference | Tools · Configuration · Python API | | Explanation | Login and sessions · Privacy and security · Design |
SECURITY.md describes the threat model and how to report vulnerabilities, CHANGELOG.md lists the changes per release.
Contributing
Issues and pull requests are welcome, see CONTRIBUTING.md and the Code of Conduct. AI coding agents find their instructions in AGENTS.md.
Disclaimer
This project is not affiliated with, maintained, or endorsed by comdirect bank AG. Use it at your own risk. There is no warranty and no liability for any financial losses or damages resulting from its use.
The software runs locally and does not send your credentials anywhere except to comdirect. Your MCP client and its model provider receive the data the tools return.
License
Related Skills
claude-mem
99.1kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
95.3kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
Understand-Anything
85.8kGraphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
headroom
74.9kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
