Intuit Credit Karma MCP server icon

Intuit Credit Karma

by Intuit Credit Karma

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Finance1 tool

Read your credit score factors from an AI agent. Anthropic lists one tool, get_credit_factors; Credit Karma names no tool at all and documents three capabilities, two of them ChatGPT-only. Reading is a soft pull that cannot affect your score.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Intuit Credit Karma via MCP

https://anthropic.mcp.creditkarma.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Intuit Credit Karma Tools & Capabilities (1)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • Credit Karma publishes no tool names, so the one listed name is unverifiable by comparison. The match between get_credit_factors and "Understand your Credit Health" is semantic, not literal. A rename — or a widening of scope from factors to full report data — would not be detectable from any public source.
  • The directory lists one capability where Credit Karma documents three. The two omitted are marked ChatGPT Only, so the directory is arguably correct *for Claude* while being an incomplete picture of the server. One of the omitted two is the commercial offer surface.
  • The tool's output fields are undocumented. No source states whether tradelines, balances, account histories or individual inquiry records are returned alongside the six factors. We report this as unestablished, not as a bounded read.
  • The auth posture is unverifiable from outside, and the edge is a blanket redirect. Every request we made to anthropic.mcp.creditkarma.com — anonymous POST initialize, plain GET, browser-user-agent GET, the host root, a deliberately bogus path, and four .well-known paths — returned an identical zero-byte HTTP 302 from AkamaiGHost to a static error page, with no www-authenticate header. Because a nonexistent path answers exactly as the real endpoint does, none of those responses says anything about the origin. authMode comes from Credit Karma's documented phone-code flow, and authVerified is false.
  • No OAuth scopes could be read, so no scope-level boundary can be shown to exist. No RFC 9728 descriptor and no authorization-server metadata was served. On a one-tool read surface the missing boundary matters less than usual — but it also means the scope-versus-tool-name diff, the check that exposes hidden write surfaces elsewhere, could not be run.
  • No tool schemas or safety annotations are published here. With no handshake there is no parameter detail, so a parameter-level capability cannot be positively ruled out.
  • The data is as of your last Credit Karma login, not live. Credit Karma documents this and the workaround is manual: log into Credit Karma, then return to the agent.
  • Credit Karma publishes no accuracy disclaimer for LLM output. Its article warns about stale data but says nothing about the reliability of model-generated financial advice built on it, unlike the sibling TurboTax connector, which disclaims its estimates as reference only.
  • Nothing is documented about what Anthropic receives, retains or trains on. The connector article has no privacy link and does not describe what the consent step covers. Intuit's Global Privacy Statement names generative AI providers among its service providers, which is the closest published statement.
  • No disconnect procedure is documented. Credit Karma's article covers connection only.
  • Region is never stated, though the evidence points to US-only. Every supporting help article is US-suffixed and the footnotes cite the CFPB, but Credit Karma publishes no availability statement, and it operates in the UK and Canada too.
  • The connect flow doubles as account signup. A user with no Credit Karma account creates one inside the connector installation, accepting Credit Karma's terms in a chat-adjacent flow rather than on its website.
  • www.creditkarma.com serves an identical error shell to non-browser clients for every path, including its own robots.txt-declared sitemap, so no page on the marketing host could be read and none is cited here. All Credit Karma prose on this page comes from the support host.

Frequently asked questions

No. Credit Karma reads your report through what it calls a soft inquiry, also known as a soft pull, and states that soft pulls from Credit Karma will never hurt your credit no matter how many appear. Hard inquiries come from applying for credit with a lender, and nothing in this connector submits an application.

Score factors, not a raw credit report. Anthropic's directory names one tool, get_credit_factors, and its description lists payment history, credit utilization, credit age, credit mix, new inquiries and total accounts. Whether individual tradelines, balances or account histories come back is not documented anywhere, so treat account-level detail as unestablished.

No, and Credit Karma's own capability list confirms it. The connector documents no application, no checkout and no offer acceptance. Credit Karma states that browsing offers does not affect your scores while applying causes a hard inquiry, and applying happens on the lender's site, not through any tool this server exposes.

Not on Claude today. Credit Karma documents an offer-shopping capability that surfaces credit cards and personal loans, but marks it ChatGPT Only. Its own footnote scopes its savings claim to Credit Karma's personal loan partners, so where that capability does run, read its output as a marketplace placement rather than neutral advice.

One by Anthropic's count, and Credit Karma publishes no tool names at all. Its help article describes three capabilities in prose — credit health, spending analysis and offer shopping — and marks the last two ChatGPT Only. Because no vendor name exists to compare, a rename inside this server would be invisible from outside.

You need one, but the setup flow will create it for you. Credit Karma's article says that if you do not yet have an account you supply a date of birth and an email and accept terms during the connect flow. Authentication is a cell phone number plus a verification code, not a password.

Because it reflects your last Credit Karma login, not a live pull. Credit Karma states the data shown in Claude and ChatGPT is pulled from your account based on your last login, and tells you to log into Credit Karma directly first, then return to the agent. If it stays stale, Credit Karma directs you to member support.

Credit-bureau derived data about you specifically. Credit Karma sources score factors from TransUnion and Equifax, and Intuit's privacy statement says bureau partners may also supply employment or income data and a Social Security number. Nothing states which of those fields the tool returns, so assume the agent sees identified financial data.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Finance
Developer
Intuit Credit Karma
Tools
1
Domain
anthropic.mcp.creditkarma.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.