Affinity
Search your CRM, prep for meetings and update deal records from your AI assistant.
Query corporate treasury — cash, debt, payments, accounting and forecasts.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Embat MCP server connects a corporate treasury system — cash, debt, payments, accounting, reconciliation and forecasts — to Claude, ChatGPT and any MCP-compatible agent. Anthropic lists a single tool that forwards plain-language questions to Embat's treasury agent and answers from your live bank data. Sign-in is OAuth through your existing Embat account.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
ask_tellme routes natural language to Embat's orchestrator, which dispatches to domain agents across every Embat module. The reachable operation count is unpublished, so no allowlist, verb census or scope grant can bound it.scopes_supported: [] and the authorization server advertises only identity claims. There is no boundary between the routine read and any future write — the exact place a boundary would matter on a treasury connector.readOnlyHint or destructiveHint is published here.Not today, on Embat's own statement. Embat writes that Claude cannot act autonomously through the connector and that it merely retrieves, synthesises and surfaces information. Embat also names payment initiation and transaction approval as roadmap items for 2026, which is an explicit statement that they are not shipped. Treat the read-only boundary as a current property, not a permanent one.
One tool name, an unknown number of operations. ask_tellme forwards natural language to Embat's Ask-mode agent, which Embat describes as an orchestrator routing to domain agents for categorisation, reconciliation and accounting, enrichment, treasury and forecasting. Each domain agent holds its own bounded action set that Embat never enumerates, so the tool count tells you nothing about reach.
Yes, and beneficiary details too. Embat's connector article shows queries returning per-entity and per-account balances, accounts below minimum thresholds, and pending payments listed with beneficiary, amount, currency and due date. Embat draws this from 15,000-plus financial institutions over PSD2, EBICS, host-to-host and SWIFT connections, synced every few minutes.
None that constrain anything. The server's RFC 9728 descriptor declares scopes_supported as an empty array, and its WorkOS AuthKit authorization server advertises only email, offline_access, openid and profile. Every one of those is an identity claim. No scope separates reading a balance from any other operation the server implements.
No, and that is the structural weakness of a one-tool natural-language server. An allowlist can permit or deny ask_tellme and nothing finer, because the operation is chosen by Embat's router from your sentence rather than by the tool name. Allowing the tool grants whatever its domain agents can reach, now and after Embat ships more.
Only as far as your own account already does. Embat states that the connector inherits your existing data-level permissions and enforces them on the server. Embat's payments module grades roles as View, Edit and Approve. A treasurer holding Approve carries that ladder into the agent session, so the boundary is your role, not the connector.
No, and this is easy to misread. The documentation URL Anthropic lists describes TellMe inside the Embat web app, including Silent Mode background writes to categorisations and forecasts. Those are product features, not connector tools. Embat's connector runs only Ask mode. The connector's real documentation is a post on embat.io, linked in Sources.
Existing Embat customers, authenticating with credentials they already hold. Embat states the integration authenticates through existing Embat credentials and that no new login or setup is required once the connector is added. Anthropic's directory records the server as a commercial, partner-tier remote connector requiring authentication, which our anonymous probe confirmed.
help_center JSON API, which robots.txt permits. · retrieved 2026-08-23initialize to https://tellme.embat.io/mcp returned HTTP 401 with a WWW-Authenticate header naming https://tellme.embat.io/.well-known/oauth-protected-resource/mcp; that descriptor declares scopes_supported: [] and the authorization server https://complete-book-76.authkit.app/.well-known/oauth-authorization-server advertises email, offline_access, openid and profile (2026-08-23). Four control paths on the same host returned a matching 404 body, so the descriptor is genuine rather than a catch-all. · retrieved 2026-08-23Connect Embat once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.