feature mcp developers security

Connect your AI assistant with browser sign-in

EnvelopeBudget MCP now supports OAuth 2.1 and dynamic client registration. Sign in in your browser, choose the budgets to share, and keep access read-only unless you approve more.

By EnvelopeBudget Team · 3 min read
Connect your AI assistant with browser sign-in

Connecting an assistant to your budget should include a clear decision about what it can see and change. It should not require copying a long-lived secret into a configuration file when your client supports browser authorization.

EnvelopeBudget MCP now supports OAuth 2.1 browser sign-in and dynamic client registration (DCR). A compatible client opens EnvelopeBudget in your browser. You sign in, select the budgets to share, and approve the requested permissions. Read-only access is the default. Existing developer API keys still work.

Sign in, select budgets, then connect

The server address is unchanged:

https://envelopebudget.com/mcp

In a Streamable HTTP client that supports OAuth discovery and DCR:

  1. Add the server address. The client discovers the authorization service and registers its callback automatically.
  2. Sign in on EnvelopeBudget in your browser. Review the client name and callback address before continuing. Registered client names are unverified; a familiar name is not an endorsement.
  3. Select one or more budgets you can access. Leave optional write permissions unchecked unless you want that specific workflow, then approve the connection.

The assistant can then review the selected budgets with the tools its permissions allow. Start with a bounded question:

Summarize spending by envelope for the last 30 days in my selected budget. Do not include transaction memos or change anything.

OAuth support varies by client and version. The flow has been verified locally with the actual MCP SDK, including discovery, registration, browser-login and consent handling, tool calls, refresh, and revocation. That does not establish compatibility with every assistant or confirm acceptance into a client catalog. Check your client's documentation and the MCP setup guide.

Read-only stays the starting point

Browser sign-in changes how you grant access. It does not give an assistant general control over your finances.

A connection defaults to mcp:read. Optional, separately approved permissions allow a trusted client to resolve existing categorization suggestions or categorize recently reviewed inbox transactions. The client must request those permissions, and you must explicitly approve them at consent.

Those writes retain the existing safeguards: current budget membership and role checks, selected-budget boundaries, signed stale-state checks for direct categorization, idempotency, attribution, and batch Undo. OAuth cannot grant access to budgets you do not already have permission to use.

The assistant cannot use these categorization permissions to rewrite transaction amounts, dates, payees, memos, or accounts, move funds, or change envelope targets. See the MCP information page for the tool and permission boundaries.

Short-lived access, revocable connections

OAuth access tokens last 15 minutes. A client registered for refresh can renew access with rotating refresh credentials, but the connection's refresh lifetime ends 30 days after consent. Refreshing does not restart that clock. Detected reuse of a consumed refresh token revokes the connection.

Open MCP connections to review selected budgets, permissions, and expiry, or revoke a connection. Revocation stops further access through that connection. To change the selected budget set, authorize again. Revocation cannot remove information an assistant or provider has already received.

Your chosen client and AI provider can process sensitive financial information returned by MCP tools. Review their data policies before connecting. Never put credentials in a prompt, screenshot, issue, or source-controlled file. Imported payee and memo text remains untrusted content, even when the connection is authenticated.

For client developers

The authorization-code flow requires S256 PKCE, exact registered redirect matching, and an explicit resource binding to https://envelopebudget.com/mcp. Browser consent and connection revocation are CSRF-protected.

The server provides:

  • RFC 7591 public dynamic client registration: clients can register without a pre-provisioned client secret. Registration does not grant budget access.
  • RFC 8414 authorization-server discovery: /.well-known/oauth-authorization-server advertises the authorization, token, registration, and revocation endpoints.
  • RFC 9728 protected-resource discovery: /.well-known/oauth-protected-resource/mcp describes the MCP resource. An unauthenticated MCP response advertises this metadata in its WWW-Authenticate header.
  • Resource-bound tokens: authorization, code exchange, and refresh require the canonical MCP resource. These OAuth tokens are for MCP, not the general EnvelopeBudget API.

Clients must support Streamable HTTP and this public-client authorization flow. Legacy SSE-only clients are not supported. If your client uses a static Authorization header, the existing developer API-key path remains available without migrating your current setup.

Connect an assistant through the MCP setup guide, or review MCP capabilities and access controls before granting access.

Share this post:
By EnvelopeBudget Team