MCP (Model Context Protocol) is an open standard that lets AI assistants like Claude connect to your data sources with your permission. An MCP server for your finances means asking your assistant "what did I spend on eating out last month?" and getting an answer from your real transactions. The critical safety property is read-only design: the assistant can ask, never act. earmarkIQ Context — our MCP server — is live, and built exactly that way.
The gap: assistants that know everything except your life
Ask a frontier AI assistant to explain compound interest and you'll get a beautiful answer. Ask it whether you can afford to move flats this autumn, and it has nothing — because it can't see your rent, your income, your subscriptions or the £180 a month quietly leaking into food delivery. The knowledge is general; your finances are specific. Every personal finance question you ask a general assistant comes back with the same caveat: "it depends on your circumstances."
Until recently, the only fix was copy-and-paste: exporting statements, pasting spreadsheet fragments into a chat window, redacting account numbers by hand. Clumsy, error-prone, and stale the moment you did it.
What MCP actually is
The Model Context Protocol is an open standard — originally developed by Anthropic and now supported across a growing set of AI tools — that gives assistants a common way to connect to outside data sources and tools. Think of it like USB for AI: one standard plug, many devices. The assistant is on one side; on the other are MCP servers, each acting as a bridge to a specific source — your files, your calendar, a database… or your finances.
Three properties matter for a non-technical reader:
Permissioned. An MCP server only exposes what it is built to expose, and only after you connect it. The assistant doesn't roam your accounts; it asks the server, and the server answers with what you've allowed.
Scoped. The server defines exactly which questions can be answered — "monthly spending by category", "list of subscriptions", "net worth trend" — rather than opening a raw firehose.
Standard. Because MCP is an open protocol, one server works with any assistant that speaks it — Claude today, others as they adopt it. You're not wiring your data to one company's chatbot.
What this looks like for your money
Connect a financial MCP server and the "it depends on your circumstances" caveat disappears, because the assistant can check your circumstances:
The interesting shift isn't the individual answers — a good finance app gives you those. It's that the answers become available wherever you already think: drafting a budget in a document, planning a move in a chat thread, doing your monthly review in whichever tool you live in. The data follows the conversation instead of the conversation moving to the data.
Why read-only is the whole ballgame
Here's the question that should decide whether you ever connect financial data to an assistant: what can it do, at worst?
Language models are probabilistic. They misread, they occasionally hallucinate, and agentic systems can be manipulated by cleverly crafted inputs. None of that is acceptable anywhere near the ability to move money. Which is why the design answer isn't "make the AI more careful" — it's make the worst case structurally boring. A read-only connection means the worst realistic failure is a wrong answer, which you can check. Not a wrong payment, which you cannot un-send.
earmarkIQ's chain is read-only at every link. Bank data enters via Open Banking Account Information Services (AIS) — a regulated access category that structurally cannot initiate payments (that would be PIS, a separate permission earmarkIQ holds for planned features but keeps disabled). earmarkIQ Context, the MCP server we're building, adds no write access of any kind on top. An assistant connected through it can query your categorised data; it cannot touch your accounts, change a setting, or spend a penny. The regulated plumbing underneath — consent, revocation, the FCA-authorised provider chain — is the same machinery we've explained for professional audiences in our Open Banking guide for financial planners.
Before connecting any financial tool to any AI system, find the sentence in its documentation that says what happens in the worst case. If the honest answer is anything other than "you get a wrong answer", keep your hands in your pockets.
Where this is heading
The near-term version is question-answering: your assistant, grounded in your real numbers. The more interesting medium-term version is context that follows you — an assistant that knows, while you're weighing any decision with a price tag, what that price tag means for you specifically. Not because it guessed, but because your categorised financial picture is one permissioned query away.
The boring-but-important groundwork is data quality. An assistant is only as useful as the data behind the bridge: transactions have to be categorised, subscriptions detected, net worth assembled — before any protocol makes them queryable. That's the part earmarkIQ already does, live, today, for its iOS users. Context is the bridge being built on top.
Status, plainly: earmarkIQ Context is live. Get your Context address from your earmarkIQ account, add it as a custom connector in your assistant, and approve read-only access — setup steps here. The more of your data earmarkIQ already organises, the more the bridge is worth crossing.
FAQ
Be first through the bridge
earmarkIQ Context is live — connect Claude or any MCP-capable assistant to your own financial picture in a few minutes.
Connect your assistant →Read-only by design · Built on FCA-regulated Open Banking rails