# io.beancount/beancount

Query, edit, and reconcile a hosted Beancount ledger: BQL, reports, files, and bank imports.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** io.beancount
- **License:** Unknown
- **Endpoints:** streamable-http https://beancount.io/api-gateway/mcp
- **Source:** https://github.com/bex-co/beancount-io
- **Endpoint health:** reachable (last checked 2026-10-10T00:47:47.796Z, 1 sample) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-10T07:01:38.922Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `FY2026`
- `main.bean`
- `renamed`
- `nullable`
- `list_accounts` — List available accounts
- `close-month` — Month-end close ritual: reconcile active accounts, verify balance assertions, check recurring-entry completeness, sweep flagged entries, and report the period's
- `reconcile-account` — Diff one account against one statement period, classify every discrepancy, and — after confirmation — append the missing transactions plus a period-end balance 
- `categorize-imports` — Sync a linked bank, deduplicate the staged transactions against what the ledger already holds, propose a counter-account for each from the ledger's own history,
- `spending-report` — Answer analytical questions about the ledger with shown, re-runnable BQL — spending, trends, net worth, burn rate, subscriptions. Strictly read-only; every figu
- `bankList` — Every bank connection linked to this ledger.
- `bank` — Status and institution details for a single bank connection.
- `bankAccountsForItem` — The accounts one bank connection shares.
- `bankAccounts` — Accounts across every linked bank, with their institution and ledger-account mapping.
- `bankUnsyncedTransactions` — Transactions pulled from a bank that have not been written into the ledger — what `manageBankImport` submits.
- `bankSuggestedCategories` — A ledger account suggested for each staged transaction, drawn from the ledger's own history. Requires ledger-content read, bank-connection read, and AI-use auth
- `bankSuggestedMapping` — Which ledger account each of a bank's accounts most likely corresponds to. Requires ledger-content read, bank-connection read, and AI-use authority.
- `aiCfoUsage` — Current account's billing-month token usage and plan limit. No user or ledger selector; read capability is required.
- `transactionCategorySuggestions` — Suggest a target account for each supplied transaction using the ledger's open accounts and recent history. transactions is a JSON-encoded array of {rowIndex, d
- `tempAssetDownloadUrl` — Presign a download for an objectKey owned by the current user. Returns downloadUrl and expiresIn in seconds. Foreign, malformed, and permanent object keys are r
- `publicUserProfile` — Profile, activities, and repositories for username. Authenticated self-views retain existing private enrichment; other targets use the public view.
- `getFeed` — Read your merged blog, release, and ledger activity. Requires a session or account-wide OAuth credential with ledger.read.
- `userProfile` — Read your account profile and limits. An explicit userId must be your own user ID.
- `allTierQuotas` — Public product limits for every tier; -1 means unlimited. No user billing information.
- `health` — Public application health probe; not a dependency readiness check.
- `featureFlags` — Public static feature configuration. The legacy userId does not affect the result.
- `ledgerArchive` — Download archive bytes as an MCP base64 blob. The archive name selects the same ZIP or tar/gzip variant as REST. Every call rechecks ledger read authority and s
- `ledgerAssetDownloadUrl` — Issue a presigned asset URL after resolving ledgerRepoId and checking current file-read authority. filename is relative to the repository's asset directory. The
- `ledgerArchiveDownloadUrl` — Get the authenticated HTTP URL for main.zip. Fetch it with the same session cookie, OAuth bearer token, or API key; no credential is embedded in the URL. This r
- `pullRequestDetails` — Read pull request metadata, file statistics, and diff with current repository read authority.
- `publicKeys` — List the authenticated user's SSH public keys. Requires administrative account authority; no ledger target.
- `publicKey` — Read one SSH public key from the authenticated user's key API. Requires keyId and administrative account authority.
- `ledgerCollaborators` — List ledger collaborators and permissions. Requires ledger.admin and current collaborator-inspection authority. Defaults to page 1, limit 10.
- `ledgerCollaboratorPermission` — Read one collaborator's permission and user information. Requires collaborator username, ledger.admin, and current collaborator-inspection authority.
- `ledgerAccounts` — Account names, optionally restricted to open or closed accounts.
- `ledgerMetadata` — Read ledger metadata, visibility, repository URLs, and caller permissions.
- `ledgerFile` — The text of one file in the ledger repository, addressed by its path. Reading it needs no tool call, so an agent can pull a file into context without spending a
- `runBqlQuery`
- `runBqlQueryStructured` — Execute BQL and return the typed table (column names, types, and rows) or structured text result. Uses the same query contract as REST JSON and GraphQL queryShe
- `listLedgers`
- `checkLedger`

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"beancount\": {\n      \"type\": \"http\",\n      \"url\": \"https://beancount.io/api-gateway/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.beancount%2Fbeancount
- Install plan: https://forgeregistry.com/api/v1/packages/io.beancount%2Fbeancount/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.beancount%2Fbeancount
- HTML page: https://forgeregistry.com/registry/io.beancount%2Fbeancount
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
