Atlar MCP server icon

Atlar

by Atlar

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Finance21 tools

Query live treasury data from your AI assistant: bank balances, cash flows, transactions, payments, forecasts and approval chains. 21 read tools listed, OAuth sign-in, and an org policy that decides whether the grant can write.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Atlar via MCP

https://mcp.atlar.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Use in Agentman

Connect Atlar once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Atlar Tools & Capabilities (21)

balances
cash_flows
forecast
get_account_groups
get_bank_accounts
get_payment_details
get_transaction_details
get_treasury_policies
payment_statistics
query_approval_chains
query_categorization_rules
query_credit_transfer_templates
query_entities
query_external_accounts
query_facilities
query_payment_schedules
query_portfolios
query_sweeping_rules
search_credit_transfers
search_direct_debits
search_transactions

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • The 21 listed tools all read, but the connector is not therefore read-only. Atlar's MCP documentation names creating a payment as an example of read/write access on the OAuth consent screen. If your organization policy is Read and write and a user grants read/write, the connection is not confined to the 21 read tools listed in Anthropic's directory. Treat the tool list as a snapshot of one surface, not a guarantee.
  • No scope separates reading from writing. Atlar publishes no scopes_supported in its authorization-server metadata and no scope list in its RFC 9728 descriptor (both fetched 2026-09-08). A consent screen cannot show a reader a scope string that names write access, so the audit trail for "was this grant read-only" is Atlar's settings and consent records, not the token.
  • Disabled by default, and gated on one admin. Atlar states no user in an organization can authorize an AI agent until an owner or admin enables the third-party OAuth policy. The connector will fail at OAuth for everyone until that happens.
  • Reading approval machinery is not approving. query_approval_chains and query_payment_schedules return the configuration that governs approvals. Atlar's Permissions reference places approval chains at READ in its Read financial data group, explicitly "not modify them". Nothing in the listed tool set advances a payment through a chain.
  • Coverage claims are Atlar's, not ours. The "100+ countries of bank and ERP connections" figure comes from Atlar's own directory description (2026-09-08). What your connector can actually see depends on which banks, PSPs and ERPs your organization has onboarded, and Atlar's own documentation describes third-party onboarding as an implementation project it runs with you.
  • Client allow-listing. Atlar states it supports OAuth Client ID Metadata Documents for "allow-listed clients only, e.g. only official Claude.ai + Claude Code clients". A third-party MCP client may not be able to complete the OAuth flow at all.
  • Some underlying data is on beta APIs. Atlar's own API reference publishes portfolios, holdings, forecasted transactions, GL accounts and internal transfers under v2beta paths (docs index, 2026-09-08). We cannot say which API version the MCP tools call, but the data behind query_portfolios and forecast is documented as beta on the REST side.
  • No per-tool schemas or safety annotations are available. The handshake is gated, so no tool on this page is confirmed annotated read-only. It is undocumented, which is not the same as confirmed.
  • Connection lifetime applies only under Read-only. Atlar states the configurable expiry is available when Read-only is enabled; by default and under Read and write, the connection lifetime matches a dashboard session.
  • Not financial or treasury advice. This page describes what tools return and what settings control. It takes no view on any balance, forecast, payment, counterparty, facility or policy.

Frequently asked questions

Not with the 21 tools Anthropic's directory lists, which all read. But Atlar's MCP documentation describes an OAuth consent screen offering read-only or read/write access, naming payment creation as a read/write example, so the grant rather than the tool list is the real boundary. Check the permission level you approved.

An admin has to enable it first. Atlar documents a Third-party OAuth client access policy under Settings, Security that is disabled by default, which blocks every user from authorizing an AI agent until an owner or admin changes it. Atlar states the change needs the organization:update permission, typically held by the owner.

Whatever the person who authorized it can already see. Atlar states the agent inherits the exact same permissions as the authorizing user, with the same role-based access and audit trail as the Atlar dashboard. The organization policy narrows it further: under Read-only, an agent cannot write even if the user's role allows it.

Set the organization policy to Read-only. Atlar documents three settings — Disabled, Read-only, and Read and write — and states that under Read-only an agent cannot create, update or delete resources even when the authorizing user's role would normally permit it. The policy overrides the individual grant.

No. Atlar documents OAuth 2.1 authorization code flow with PKCE, so you sign in on Atlar's own dashboard rather than in the chat. Atlar also states that access tokens issued to MCP clients are constrained to the connector host by audience claim, with no passthrough to its REST API at api.atlar.com.

Revoke the grant from your Atlar profile. Atlar documents a page at app.atlar.com/profile that lists your outstanding consents and lets you manage them. Separately, an organization on the Read-only policy can configure a Connection lifetime, after which the MCP connection expires and must be re-authorized whether or not it is in use.

Two causes, per Atlar's troubleshooting notes. Either the permission level granted during OAuth was read-only rather than read/write, or the authorizing user's own role does not allow the action. Atlar states Claude can only do what that user is allowed to do, so check the grant first and then the role.

Sources

Server Info

Category
Finance
Developer
Atlar
Tools
21
Domain
mcp.atlar.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.

Ready to connect Atlar?

Connect Atlar once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.