Skip to main content

comdirect-mcp

PyPI Python Tests MCP License: MIT

Read-only Model Context Protocol server and typed Python client for the comdirect REST API.

Let Claude, GitHub Copilot or any other MCP client look at your accounts, transactions, securities depot and postbox documents. The login is confirmed with your photoTAN app, and there is no tool that can move money.

Warnung (in Deutsch weil Comdirect)

Leute es geht hier um euer Geld. Nutzt diese Bibliothek nur, wenn ihr den Code versteht und euch den Risiken bewusst seid.

Ich bin auch nicht perfekt, aber übernehme keine Haftung für Schäden, die durch die Nutzung dieser Software entstehen. Falls Euch was auffällt, gern PRs oder Issues.

Die API und damit das Repo hier nutzen aktuell nur lesende Endpunkte, aber Fehler können immer passieren. Comdirect kann die API ändern, Dependencies können im Zweifel auch Mist bauen (Supply-Chain Attacks) und 2FA hilft zwar, ist aber kein Freifahrtschein.

Bitte:

  • Nutzt das nur lokal auf eurem eigenen Rechner.
  • Teilt eure Zugangsdaten mit niemandem.
  • Packt Secrets in .env und committet die Datei nie.
  • Nutzt die Pre-Commit Hooks um Secrets zu scannen. Gute Zeit bissel Devops-Kram zu lernen.
  • Spielt Updates nicht blind ein (Lockfile/Pinning hilft) und schaut bei Änderungen kurz drüber.

MCP-Server: Wenn ihr den Server an einen nicht-lokalen AI-Client hängt, gehen deine Daten raus. Je nach Client/Setup können Kontodaten/Transaktionen in Logs/Telemetry landen oder durch Prompt-Injection aus Dokumenten/Verwendungszwecken in komische Richtungen gehen (MCP Horror Stories: The GitHub Prompt Injection Data Heist). Nutzt MCP nur, wenn ihr der Umgebung wirklich vertraut, und gebt nur die Daten frei, die ihr dafür braucht.

Da der gemeine r/finanzen User eh schon seine Kontoauszüge in ChatGPT kopiert, könnt ihr damit machen, was ihr wollt, auf eure eigene Verantwortung!

Idealerweise ohne unnötige personenbezogene Daten. (Hauptsache, ihr lasst 'nen Stern da.)

Privacy: prefer a local model

The server runs on your machine, but every tool result is sent to the language model behind your MCP client. With cloud assistants (Claude, GitHub Copilot, ChatGPT, ...) your balances, transactions and documents leave your computer and are processed under that provider's data policy.

  • Most private: use an MCP client with a local model, e.g. LM Studio (supports MCP servers directly) or another client running a model via Ollama or llama.cpp. Then nothing leaves your machine except the requests to comdirect. Pick a model with good tool-calling support.
  • With a cloud assistant: check its data retention and training settings, use an account where your data is not used for training, and ask only what you need.

Details: Privacy and security · Use a local model

Features

  • MCP specification 2026-07-28 on the official MCP Python SDK v2, with fallback for older clients
  • Push TAN login via elicitation: your client asks you to approve the login in the photoTAN app; the TAN never reaches the model
  • Credentials in the OS keychain: comdirect-mcp configure stores them once, client configs contain no secrets
  • No tool can move money: only read endpoints, truthful tool annotations, structured output with JSON schemas
  • Protects your access: stops logging in before comdirect's lock after five unconfirmed TAN challenges, and revokes the session at comdirect on logout and shutdown so it cannot be extended
  • Privacy defaults: counterparty IBANs masked, documents size-limited, untrusted-content hint for the model
  • Automatic token refresh and explicit session handling
  • Typed Python client (py.typed) for scripts and notebooks, independent of MCP
  • Listed in the MCP Registry as io.github.mad4ms/comdirect-mcp

Tools

Tool Description
login Starts a session; asks you to approve the push TAN
logout Ends the session and revokes it at comdirect (no further refresh)
list_accounts Accounts with balances
list_transactions Transactions of an account, filter by date, direction and state
list_depots Securities accounts
get_depot_positions Positions (name, ISIN, WKN, values, P&L) and depot balance
list_documents Postbox documents (statements, order confirmations, tax documents)
download_document A document as embedded resource (comdirect marks it as read)

Arguments and results: Tools reference.

Quickstart

New to this? Follow the Getting started tutorial.

1. Prerequisites

  • uv (provides uvx)
  • comdirect API access: in the online banking under Verwaltung → Entwicklerzugang you get a Client ID and Client Secret (step by step)
  • photoTAN Push as your default TAN method

2. Store your credentials in the OS keychain

uvx comdirect-mcp@0.4.0 configure

Prompts for Client ID, Client Secret, Zugangsnummer and PIN and stores them in the macOS Keychain, Windows Credential Manager or Linux Secret Service. Other options (VS Code inputs, environment, .env): Manage credentials.

3. Add the server to your MCP client

Claude Desktop (Settings → Developer → Edit Config) and LM Studio (Program → Install → Edit mcp.json):

{
  "mcpServers": {
    "comdirect": {
      "command": "uvx",
      "args": ["comdirect-mcp@0.4.0"]
    }
  }
}

Claude Code

claude mcp add --transport stdio --scope user comdirect -- uvx comdirect-mcp@0.4.0

VS Code (MCP: Open User Configuration)

{
  "servers": {
    "comdirect": {
      "type": "stdio",
      "command": "uvx",
      "args": ["comdirect-mcp@0.4.0"]
    }
  }
}

Pinning the version (@0.4.0) means updates only happen when you decide. More clients: Configure MCP clients.

4. Ask

Wie haben sich meine Ausgaben im letzten Monat entwickelt, und welche Depotposition läuft am schlechtesten?

The assistant calls login, your phone receives the push TAN, you approve it and confirm the dialog in your client. Then the assistant can use the other tools. Problems: Troubleshoot.

Python library

The same client is available for your own scripts:

from comdirect_mcp import ComdirectClient
from comdirect_mcp.utils import default_push_tan_callback

client = ComdirectClient(
    {"client_id": "...", "client_secret": "...", "username": "...", "password": "..."},
    {"push_tan_cb": default_push_tan_callback},
)
client.login()  # approve the push TAN, then press Enter

for account in client.list_accounts():
    print(account.id, account.balance, account.currency)

See Use the Python library, the Python API reference and the examples.

Documentation

The documentation is organized as tutorial, how-to guides, reference and explanation:

Tutorial Getting started
How-to API access · Credentials · MCP clients · Local model · Troubleshoot · Python library · Develop
Reference Tools · Configuration · Python API
Explanation Login and sessions · Privacy and security · Design

SECURITY.md describes the threat model and how to report vulnerabilities, CHANGELOG.md lists the changes per release.

Contributing

Issues and pull requests are welcome, see CONTRIBUTING.md and the Code of Conduct. AI coding agents find their instructions in AGENTS.md.

Disclaimer

This project is not affiliated with, maintained, or endorsed by comdirect bank AG. Use it at your own risk. There is no warranty and no liability for any financial losses or damages resulting from its use.

The software runs locally and does not send your credentials anywhere except to comdirect. Your MCP client and its model provider receive the data the tools return.

License

MIT

Metadata

Release files for comdirect-mcp 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for comdirect-mcp 0.4.0
File Size Uploaded
comdirect_mcp-0.4.0.tar.gz 84.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for comdirect-mcp 0.4.0
File Interpreter ABI Platform
comdirect_mcp-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 255.1 kB

Release files / comdirect_mcp-0.4.0.tar.gz

Download URL comdirect_mcp-0.4.0.tar.gz
Size 84.6 kB
Tags Source
SHA-256 checksum
How to use checksums
e2e0ed59e3d2aead7bc0bed50475f17c330cf870ede6b975f1bde34224ab89ce
BLAKE2b-256 checksum
How to use checksums
54ed9389ab66663531b8ee357eba4d7073473151580c7dd3976c4db47a8f57ba
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.

Transparency log

Release files / comdirect_mcp-0.4.0-py3-none-any.whl

Download URL comdirect_mcp-0.4.0-py3-none-any.whl
Size 170.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1470717867d494e8be7e4ad6e82387365e76e275b85236f26ec5343c482f1765
BLAKE2b-256 checksum
How to use checksums
c612ec915cb85f71e5a086c8c3ff37c9ff856f4d8fee597605fb3644ebfa21dd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.

Transparency log

Release history Release notifications | RSS feed

0.5.1

2 release files

0.5.0

2 release files

This release

0.4.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page