Skip to main content
Moneda uses OAuth 2.0 with PKCE to securely connect your account to AI clients. This is the same standard used by Google, GitHub, and other services when you click “Sign in with…”.

How does the OAuth flow work?

  1. Your AI client requests access — it opens a Moneda authorization page in your browser
  2. You sign in and approve — with your passkey, Google, or Apple, then review the permissions the AI is requesting and approve or deny
  3. A secure token is issued — the AI client receives a token to access your account data. Your password is never shared.
  4. Tokens refresh automatically — the connection stays active without you needing to re-authorize

What permissions does my AI assistant need?

When you authorize, you’ll see a consent screen listing the specific permissions your AI needs. These are grouped into read and write scopes:
  • Read scopes let your AI view data (balances, transactions, contacts, etc.)
  • Write scopes let your AI take actions (update your display name, categorize transactions, initiate payments)
See the full list of permissions on the Scopes page.
Payments always require your approval. Even with write permissions, payment requests are sent to the Moneda app on your phone where you must confirm with biometric authentication before any money moves.

How do I revoke access?

Ask your assistant to list your connected agents and disconnect the one you no longer want (list_active_sessions, then disconnect_connected_service). A disconnected connection is refused on its very next request — by the MCP server and by the REST API alike, so a client can’t fall back to one after losing the other.

Learn more

Scopes reference

Full list of 24 read and 12 write permission scopes.

Security

How Moneda protects your funds and data.