Help Center

Connect Greenback to Claude

The Greenback connector lets Claude answer questions about your own finances, such as your balances, recent spending and budgets. You can also ask it to set up categories and rules. It works in Claude on the web, the desktop and mobile apps, and Claude Code.

The connector reads data and can make two kinds of small change, both covered below. It cannot move money, make payments, delete anything, or edit your transactions.

What you can ask

  • "What accounts do I have, and what's my total balance?"
  • "How much did I spend at restaurants last month?"
  • "Show me my transactions from my checking account this week."
  • "Which of my budgets am I over this month?"
  • "Create a category called Travel with a $300 monthly budget."
  • "Make a rule that puts anything from Uber into Transportation."

Connect Greenback to Claude

You need a Greenback account with at least one linked bank account, and a Claude account.

On Claude (web, desktop or mobile)

  1. In Claude, go to Customize → Connectors.
  2. If Greenback is listed, select it. Otherwise click Add custom connector and enter this server URL: https://api.greenbackapp.com/mcp
  3. If Claude asks how to authenticate, choose Sign in now, then Use Claude's published identity. Leave any client ID and secret fields empty.
  4. Click Connect. Sign in to Greenback when asked, check the permissions on the next screen, and click Allow.
  5. In a chat, click +, open Connectors, and make sure Greenback is turned on.

A connector you add on the web also appears in the Claude desktop and mobile apps.

On a Claude Team or Enterprise plan, an organization Owner adds the connector once under Organization settings → Connectors → Add → Custom. Everyone else then finds Greenback under Customize → Connectors and clicks Connect to sign in with their own Greenback account.

In Claude Code

Run:

claude mcp add --transport http --scope user greenback https://api.greenbackapp.com/mcp

Then start a new Claude Code session, run /mcp, choose Greenback and sign in. The connection is only for you: everyone who uses it signs in with their own Greenback account.

What the connector can do

When you connect, Greenback shows you exactly what you are allowing. By default, Claude gets read-only access to:

  • Your name and email address, so Claude knows whose account it is looking at.
  • Your accounts and balances. Claude sees each account's institution, name, type and current balance, up to 100 accounts per request.
  • Your transactions, categories and budgets. Transactions come newest first, with their category, up to 200 per request, and can be filtered by date and account. When there are more than Claude asked for, Greenback tells it the list was cut short, so it doesn't present a partial total as the whole.

The approval screen describes each permission in full, which is a little broader than what Claude can currently see. For example, it mentions investments and recurring items, which the connector does not yet read.

Two optional permissions let Claude make changes. Greenback only asks for them when you ask Claude to do one of these things, on a second approval screen:

  • Create spending categories and set their monthly budgets. A category that already exists is not changed or overwritten.
  • Create rules that categorise your transactions automatically. A rule only fills in the category of transactions that don't have one yet. It never overrides a category you chose. Every rule needs at least one condition, so a rule cannot match everything.

The connector cannot:

  • move money, make payments or transfers
  • delete anything
  • edit, hide or re-categorise transactions you have already categorised
  • change your account settings, linked banks or subscription
  • see anyone else's data

If you'd rather Claude never use a particular tool, you can block it in Claude under Customize → Connectors.

Disconnect

In Greenback on the web, go to Settings → Security → Connected apps and click Disconnect next to Claude. This takes effect immediately: Claude's access and its ability to refresh that access are both revoked, and it would have to ask you again to reconnect.

You can also remove the connector in Claude under Customize → Connectors. That stops Claude from using it, but doesn't revoke the access on Greenback's side. Use Disconnect in Greenback for that.

Privacy

  • Greenback doesn't receive your conversations with Claude. It only receives the specific requests Claude makes to answer you, such as "list transactions from September".
  • Greenback doesn't keep the details of those requests. Account names, merchants and category names are excluded from Greenback's request logs.
  • What Greenback sends goes to Claude, and it only goes there when you ask. Claude uses it to answer you. How Anthropic handles it is covered by Anthropic's privacy policy.

Section 4 of our Privacy Notice covers AI assistant connections, including what we keep and for how long. For everything else about how Greenback handles your data, see the rest of the notice.

For IT and security teams

This section covers what a security review usually asks about the Greenback connector.

Summary

  • What it is: a remote MCP server at https://api.greenbackapp.com/mcp, operated by Greenback Holdings Inc. and hosted on AWS in the United States (us-east-1).
  • Who signs in: each person with their own Greenback account. There are no shared or service credentials, and no machine-to-machine access.
  • Default access: read-only. Write access is limited to creating categories and categorisation rules, and is only granted by a separate, explicit approval.
  • What it cannot do: it has no ability to move money, make payments, delete data, or edit existing transactions.

Authentication

  • OAuth 2.1 authorization code flow with PKCE. Only the S256 challenge method is accepted, and the flow follows the MCP authorization specification (revision 2026-07-28).
  • Claude identifies itself with a Client ID Metadata Document that Anthropic publishes on claude.ai. Greenback accepts client documents only from claude.ai, and there is no open client registration endpoint, so no one else can register an app against the connector. Before a document is fetched, Greenback checks where it would connect: requests that would reach private or internal network addresses are refused, and so is anything that redirects off the allowed domain or uses a shared client secret.
  • Every sign-in ends on a consent screen. Nothing is approved silently. The screen names the app, shows the domain that published its details, which can't be forged, lists every permission in plain words, and warns when the approval can only be delivered to the user's own computer, as it is for Claude Code.
  • Authorization responses carry the issuer (RFC 9207), so a client can detect a code sent from the wrong authorization server.
  • Discovery follows RFC 9728 (protected resource metadata) and RFC 8414 (authorization server metadata).

Tokens

  • Scoped to the connector. Access tokens are bound to https://api.greenbackapp.com/mcp (RFC 8707) and are refused by every other Greenback API. Greenback's own app sessions are likewise refused by the connector.
  • Short-lived. Access tokens last two hours. Refresh tokens are single use: each refresh issues a new one and retires the old.
  • Stored hashed. Tokens are never kept in readable form.
  • Only what was approved. Each token carries exactly the permissions the user approved. A request for anything else is refused with 403 insufficient_scope, naming the missing permission so Claude can ask the user for it.

Permissions

The descriptions below are the wording users see on the consent screen. Each permission is described in full, and today the connector uses only part of each one: the tools listed below are everything a token can reach.

Granted at first sign-in, all read-only:

  • profile:read: name and email (used by get_profile)
  • accounts:read: accounts, balances, net worth, investments and crypto wallets (used by list_accounts, which returns accounts and their current balances)
  • transactions:read: transactions, categories, budgets and recurring items (used by list_transactions and list_categories)

Requested only when needed, on a second approval screen:

  • categories:write: create categories and monthly budgets
  • rules:write: create categorisation rules

Tools

The read-only tools are:

  • get_profile
  • list_accounts
  • list_transactions
  • list_categories

The two write tools only create things. They never change or remove what is already there:

  • create_category
  • create_categorization_rule

Every tool is annotated as read-only or not in the way MCP defines, so Claude and your organization's tool policies can tell them apart. None of them is destructive.

Data isolation and handling

  • One user's data per token. A token belongs to one Greenback user, and every tool answers from that user's data only. No tool takes an argument that names another user.
  • No conversations. Greenback doesn't receive or store Claude conversations. Tool arguments are excluded from Greenback's request logs.
  • What's recorded: Greenback records that a connection was requested, approved, denied or refused, along with the app's name and domain and the permission names involved. This is so connection problems can be diagnosed. Balances and transaction details are never included in these records.

Controls and revocation

  • Users can disconnect at any time under Settings → Security → Connected apps in Greenback on the web, which revokes access immediately.
  • Claude Team and Enterprise Owners decide whether the connector is available to their organization under Organization settings → Connectors. Individual tools can be blocked under Customize → Connectors.
  • Greenback can turn the connector off for every account at once, without a release.

Network and limits

  • Hosted Claude apps (web, desktop, mobile) reach the connector from Anthropic's published IP range, 160.79.104.0/21.
  • Claude Code connects directly from the user's computer. Allow outbound HTTPS to api.greenbackapp.com, and to web.greenbackapp.com for the sign-in and approval screens.
  • No inbound changes to your network are needed.
  • Rate limit: 120 requests per minute. For Claude's hosted apps the limit applies to each connection. For Claude Code it applies to each network address.

Troubleshooting

"The Greenback connector is not enabled for this account yet." The connector is being rolled out gradually. Email support@greenbackapp.com and we can tell you when it will reach your account.

Claude says it needs permission to do something. You asked for something your current connection doesn't allow, such as creating a category. Approve the new permission on the screen Greenback shows, then ask again.

Claude stopped being able to reach Greenback. Reconnect it under Customize → Connectors in Claude. If you disconnected it in Greenback, this is expected.

Balances or transactions look out of date. Claude sees what Greenback has. If a bank connection needs attention, fix it in Greenback first. See Managing Connected Accounts.

Still stuck? Email support@greenbackapp.com.