earmarkIQ Context is a live, read-only MCP server. Connect your earmarkIQ data to Claude — verified — or any MCP-capable assistant, and ask about your own finances with answers grounded in your real numbers rather than general knowledge.
It can read. It cannot act. Not because we have promised not to, but because no capability to act exists inside it — and a test in our build fails if anyone ever adds one.
You almost certainly already use an assistant that can answer general questions about money. It can explain what a Lifetime ISA is. It cannot tell you whether you paid into one this year, because it has never seen your accounts.
earmarkIQ Context closes that gap in the narrowest way available. earmarkIQ already connects to your UK bank accounts through read-only Open Banking and organises what it finds — categorising your spending, tracking your subscriptions, working out your net worth. Context makes that organised picture readable by an assistant you already use, and nothing more than readable.
The technical name for the plug is MCP, the Model Context Protocol: an open standard for connecting assistants to outside sources of information with your permission. If you want the fuller explanation, we have written what MCP is and why it matters for your money. For the purposes of this page, the only thing that matters is what the connection permits — and that is a short list.
This is the complete surface. An assistant connected through Context can ask for these things and nothing else, because nothing else is published for it to find.
Which makes questions like these answerable from your actual position rather than a general one:
The absences are the point, so here they are explicitly:
"Read-only" is claimed constantly and means different things. Sometimes it means a capability exists and is switched off. Sometimes it means a model has been instructed not to use it. Neither is worth much: switches get flipped and instructions get talked around.
What we mean is that the capability does not exist, and there are three independent layers holding that in place.
earmarkIQ's bank connection runs under Account Information Services — a reading permission — through Finexer Ltd (FRN 925695), an FCA-authorised provider. AIS has no ability to construct a payment instruction. So even before Context enters the picture, there is no payment capability upstream for anything to reach. How AIS and PIS differ →
An MCP server publishes a list of operations, and an assistant can invoke what is on that list and nothing else. Context's list contains read operations only. There is no mutating operation for an assistant to call, badly-worded prompt to trigger, or instruction to be argued into — because there is nothing there.
The reason a guarantee erodes is rarely a decision. It is a change that seemed reasonable at the time. So the constraint is enforced in the build itself: an automated test fails if any mutating capability is ever added to Context. Adding one is not a thing that can be done quietly — it breaks the build, visibly, and someone has to consciously remove the test to proceed.
On top of those three, two things give you visibility rather than assurances:
An assistant connected through earmarkIQ Context can read the five categories listed above. It cannot move money, make a payment, cancel anything, or change any setting, because no such capability exists in Context to be invoked. This is enforced by the permission earmarkIQ operates under, by the operations Context publishes, and by a test that fails the build if a mutating capability is added.
A connection like this involves three parties. Being clear about the boundaries is more useful than a reassuring adjective.
| Party | Holds | Never sees |
|---|---|---|
| Your bank | Your accounts; authenticates you directly | Nothing changes — it releases a limited, revocable feed |
| earmarkIQ | Your categorised financial picture | Your banking credentials — Open Banking never shares them |
| Your assistant | Whatever it reads from the published list | Your bank connection, your credentials, anything off the list |
Context controls what an assistant can read from earmarkIQ. It has no control over the assistant itself. Once an answer about your finances appears in a conversation, that conversation sits with whoever provides the assistant, under their retention and privacy terms.
Read-only stops your money being moved. It does not make the conversation private from the assistant's provider, and no server design can. If your financial position appearing in a chat log is a problem for you, that is a genuine reason not to connect — and it is a question about the assistant, not about Context.
Your personal earmarkIQ Context address comes from your earmarkIQ account. It is yours alone and reads only your data.
In your MCP-capable assistant, add earmarkIQ Context as a custom connector using that address. Claude is verified. Other MCP-capable assistants connect the same way, though we have not verified each one individually.
Your assistant will ask to connect. Approve it, and it can start answering from your data. Your bank connection and credentials stay with earmarkIQ, and the assistant never sees either.
Two independent routes, both immediate, neither requiring you to contact us:
Revoking Context changes nothing else. Your earmarkIQ account, your categorised data and your bank connections all carry on exactly as before — you have removed one reader, not unpicked anything. You can reconnect later if you want to.
So that nothing here has to be inferred:
| Capability | Status |
|---|---|
| Read-only MCP server (Context) | Live |
| Read-only Open Banking (AIS) via Finexer | Live |
| Claude as a verified assistant | Live, verified |
| Other MCP-capable assistants | Should work; not individually verified |
| Audit trail of Context access | Live |
| Self-service revocation | Live |
| Any assistant moving money | Does not exist, and is not planned |
| Payment initiation (PIS) by earmarkIQ | In permissions, on the roadmap, currently disabled |
On that last row, the accurate position: earmarkIQ does not initiate payments. Payment initiation sits within the permissions earmarkIQ operates under as an Appointed Representative of Finexer Ltd, and it is on the roadmap, but the capability is switched off. If it is ever enabled, it would be a payment you start, with an amount and payee you see and confirm, authenticated by you at your own bank, one payment at a time — never a standing power, and never something an assistant decides to do. Context would remain read-only, and the two would not be joined up. The longer argument is in the difference between an app that shows you your money and one that moves it.
New verified assistants and Context features, straight to your inbox — nothing else.
Occasional emails about earmarkIQ Context only.
Not using earmarkIQ yet? The iOS app is free to download — Context reads the picture it builds for you. You can also view your account on the web, or try the payday allocation calculator without an account.