version: 1
name: Credit Karma
slug: creditkarma
summary: >-
  Credit Karma transaction tracking for Claude — sync and query your
  transactions, spending by category and merchant, and account summaries via
  natural language
#
# Hosting note (a comment, not user-facing summary text): this is a
# BROWSER-BRIDGE MCP — it reaches its site through the user's signed-in
# tab via the fetchproxy bridge. A bridged registration also needs runtime
# `fly-shared`, `bridge: true` and a `bridgePortEnv`, which are registration
# fields this manifest has no schema for (set them over the control API).
# `state.dataDir` below is required for `bridge`.
env:
  - name: CK_COOKIES
    secret: true
    required: false
    help: >-
      Optional. The full Cookie header from a signed-in creditkarma.com request.
      Leave unset to use the browser fallback — install ContextMint Bridge
      (https://github.com/nullnet-app/contextmint-bridge/releases), sign into creditkarma.com, and the MCP reads cookies automatically.
      Otherwise copy the header from DevTools → Network → any creditkarma.com
      request → Request Headers.
  - name: CK_DISABLE_FETCHPROXY
    required: false
    help: >-
      Set to 1 to skip the ContextMint Bridge browser-extension fallback (missing creds
      become a hard error — useful in headless CI).
  - name: CK_DB_PATH
    required: false
    help: >-
      Optional override for the SQLite database file. Defaults to
      ~/.creditkarma-mcp/transactions.db. Set to a custom absolute path if you
      want the data stored elsewhere.
  - name: CK_SYNC_MAX_PAGES
    required: false
    help: >-
      Pages one sync call may fetch before pausing. Unset means unbounded, up to
      the hard ceiling of 300 pages that bounds a runaway loop.
state:
  dataDir: true
  reason: >-
    The fetchproxy identity lives at $HOME/.fetchproxy/identity/<name>.json
    and the pair code derives from it. Without a persistent $HOME every cold
    start mints a fresh identity and re-prompts pairing in the browser; the
    API refuses bridge without it.
egress:
  allow:
    # Only hosts the SERVER process actually fetches. Hosts that appear
    # solely in a URL this server BUILDS and returns are excluded.
    #
    # The bridge here is BOOTSTRAP-ONLY: `@fetchproxy/bootstrap` lifts the
    # CKAT/CKTRKID cookies out of the signed-in tab over a loopback socket
    # (src/auth.ts) and every request after that is a plain Node fetch from
    # this process, in every mode (CK_COOKIES, ck_set_session, fetchproxy).
    # None of these hosts redirects (checked 2026-08-28).
    #
    # GraphQL gateway — every ck_sync_transactions call (src/client.ts).
    - api.creditkarma.com
    # Token refresh POST (/member/oauth2/refresh) and the signed-in
    # /networth/transactions page read during persisted-query-hash
    # rediscovery (src/client.ts, src/queryHash.ts).
    - www.creditkarma.com
    # Next.js chunk fetches during hash rediscovery. The host is scraped
    # from the page at runtime (src/queryHash.ts CHUNK_URL_RE), so it is
    # not pinned in code; this is the only CDN CK has served.
    - creditkarmacdn-a.akamaihd.net
