Qonto MCP server icon

Qonto

by Qonto

Finance52 tools

Read a European business bank account from your AI assistant and act on invoicing, cards and approvals. Qonto blocks outgoing transfers and beneficiary changes at the connector: no tool initiates a payment.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Qonto via MCP

https://mcp.qonto.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Qonto Tools & Capabilities (52)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • No payment initiation, by design. Qonto's Terms and Disclosures state that sensitive actions such as initiating payments are unavailable through this connection. SEPA outgoing transfers, international transfers and SEPA direct debit are all outside the tool surface.
  • No beneficiary management. No tool creates, edits or trusts a SEPA beneficiary, and the allow-list blocks the underlying endpoints even when the token would permit them.
  • Approval is not delegable. approve_request returns a link; the approver confirms in the Qonto web app, with SCA where PSD2 requires it. Qonto states the server cannot bypass SCA.
  • Your role caps everything. The assistant sees only tools your role can use, so two colleagues connecting the same organisation may see different surfaces. A reporting user's write calls are refused with an authorization error.
  • Managers and employees are blocked until enabled. The OAuth flow completes and the connection looks healthy while every tool call is refused — a failure mode Qonto documents explicitly.
  • Your AI provider controls the data once it leaves. Qonto warns that retention, training and onward sharing are governed by the provider's terms, that Qonto cannot retrieve or delete data after transmission, and that this holds even after you disconnect.
  • Qonto may restrict the connector unilaterally. Its terms reserve the right to revoke or restrict the permissions granted to the connector at any time.
  • Presigned URLs are live credentials for their TTL, including the card PAN iframe URL.
  • Rate limits are the Business API's. Qonto does not publish an MCP-specific ceiling and notes that bursting tool calls in a chat can trip them.
  • No schemas or safety annotations were read. The endpoint requires OAuth, so no parameter-level detail, readOnlyHint or destructiveHint is published here. The read/write split above is derived from Qonto's per-tool documentation, not from annotations.
  • The server also states it is stateless — no conversation content, tool inputs or outputs stored, only operational telemetry. That is Qonto's claim about its own infrastructure and was not independently verified.

Frequently asked questions

Can the Qonto MCP server send money or make a transfer?

No. Qonto's own Terms and Disclosures state that certain sensitive actions, such as initiating payments, are not available through this connection. Its capability page confirms the server does not expose SEPA outgoing transfers, international transfers, or SEPA direct debit. Those remain in the Qonto app and the Business API, outside the MCP tool surface entirely.

Can an AI assistant add or change a payment beneficiary in Qonto?

No. No tool on the Qonto MCP server creates, edits, or trusts a SEPA beneficiary. Qonto defines platform scopes for beneficiary management, but its documentation maps them to Business API endpoints rather than MCP tools, and the server only exposes an allow-listed subset. Beneficiary substitution is not reachable through the assistant.

What does create_multi_transfer_request actually do in Qonto MCP?

It drafts a batch of one to 400 SEPA transfers as a pending approval request; it does not move money. Qonto documents the approver later signing the batch with Strong Customer Authentication in the Qonto web app. The assistant composes amounts and recipients, and a human reviews every line before anything leaves the account.

Does approve_request let the assistant approve a Qonto payment?

No, despite the name. Qonto documents approve_request as returning a link to the approve page in the Qonto web app, and states plainly that the MCP server does not approve on your behalf. The approver reviews and confirms there, where the underlying transfer execution or card issuance and any Strong Customer Authentication take place.

Can Qonto MCP create a card or see the full card number?

Yes to both, within your role. Qonto documents create_card issuing standard, plus, metal, virtual, flash, and advertising cards, and change_card_status locking, unlocking, or discarding one. Separately, get_card_iframe_url returns a short-lived URL rendering the PAN, expiry, and CVV, which Qonto tells you to treat like a password.

What Qonto account data does the connector expose to my AI provider?

Balances, IBANs, transactions, statements, invoices, and member details. Qonto classifies the governing organization.read scope as sensitive, covering balance, IBAN, transaction, and team information. Qonto warns that the AI provider, not Qonto, controls that data once it leaves, including possible retention, training, and onward sharing under the provider's own terms.

Why does my Qonto MCP connection work but show no tools?

Your Qonto role is probably not allowed to use MCP yet. Qonto documents that owners, admins, and accountants can connect by default, while managers and employees need an owner or admin to enable Qonto MCP for the organization from the Qonto AI panel in the web app. The OAuth flow still succeeds, which is why the connection looks healthy.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Finance
Developer
Qonto
Tools
52
Domain
mcp.qonto.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.