sh-mcp/servers/sh-mcp-finance
dependabot[bot] 1fd59d7939
chore(deps): bump the minor-and-patch group across 1 directory with 11 updates (#36)
Bumps the minor-and-patch group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.1` | `26.1.2` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1132.0` | `2.1133.0` |
| [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) | `2.261.0` | `2.262.1` |
| [eslint](https://github.com/eslint/eslint) | `10.7.0` | `10.8.0` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.30.0` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.6.0` | `8.6.1` |
| [jose](https://github.com/panva/jose) | `6.2.3` | `6.2.4` |
| [@aws-sdk/client-cognito-identity-provider](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cognito-identity-provider) | `3.1092.0` | `3.1096.0` |
| [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1092.0` | `3.1096.0` |
| [@aws-sdk/client-secrets-manager](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-secrets-manager) | `3.1092.0` | `3.1096.0` |
| [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1092.0` | `3.1096.0` |



Updates `@types/node` from 26.1.1 to 26.1.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `aws-cdk` from 2.1132.0 to 2.1133.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1133.0/packages/aws-cdk)

Updates `aws-cdk-lib` from 2.261.0 to 2.262.1
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.262.1/packages/aws-cdk-lib)

Updates `eslint` from 10.7.0 to 10.8.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.7.0...v10.8.0)

Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.30.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0)

Updates `express-rate-limit` from 8.6.0 to 8.6.1
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](https://github.com/express-rate-limit/express-rate-limit/compare/v8.6.0...v8.6.1)

Updates `jose` from 6.2.3 to 6.2.4
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](https://github.com/panva/jose/compare/v6.2.3...v6.2.4)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1092.0 to 3.1096.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1096.0/clients/client-cognito-identity-provider)

Updates `@aws-sdk/client-dynamodb` from 3.1092.0 to 3.1096.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1096.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1092.0 to 3.1096.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1096.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1092.0 to 3.1096.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1096.0/lib/lib-dynamodb)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1096.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1096.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1096.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1096.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1133.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk-lib
  dependency-version: 2.262.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint
  dependency-version: 10.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: express-rate-limit
  dependency-version: 8.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: jose
  dependency-version: 6.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 11:57:17 -04:00
..
cdk Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
src Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
test Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
cdk.json Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
package.json chore(deps): bump the minor-and-patch group across 1 directory with 11 updates (#36) 2026-07-28 11:57:17 -04:00
README.md Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
tsconfig.json Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00

sh-mcp-finance

Finance-tier Sea Haven MCP server. Exposes the finance tool registry (qbo search_vendors, payments lookup_payment_by_* — see docs/design.md §3) over the same two interfaces as sh-mcp-ops (MCP Streamable HTTP + OpenAPI 3.1), through the same shared dispatch path.

Finance is sensitive, read-only, and fully audited: every tool call emits a structured audit record and the response is redacted on egress (bank account / routing / card / SSN / tax-id masked) before it leaves the server (docs/design.md §2.5, §7.3).

Run locally (no AWS, no Cognito)

npm install
npm run build

SH_MCP_ENV=local PORT=8082 npm run start -w @sh-mcp/server-finance
# or:  SH_MCP_ENV=local npm run dev -w @sh-mcp/server-finance

Endpoints

Identical shape to sh-mcp-ops: GET /healthz, GET /openapi.json (both unauthenticated), POST /mcp, and POST /tools/:name (both authenticated).

Dev bearer tokens (local only)

Token Identity Scopes
dev-finance accounting@seahavenind.com ops:read, finance:read
dev-finance-admin adam@seahavenind.com ops:read, finance:read, finance:admin

Ops-tier tokens (dev-ops-only, dev-assistant) are rejected by this server (audience binding).

Sample curl — redaction on egress

TOKEN=dev-finance

curl -s -X POST localhost:8082/tools/lookup_payment_by_vendor \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{"vendor":"Harbor"}' | jq
# → bankAccountNumber / bankRoutingNumber / cardNumber are "[REDACTED]";
#   vendor, amount, invoice number are intact.

Each call writes one structured audit line to stdout (CloudWatch in Lambda):

{
  "kind": "audit",
  "sub": "...",
  "tool": "lookup_payment_by_vendor",
  "argsHash": "<sha256>",
  "decision": "allow",
  "result": "ok",
  "ts": "..."
}

Args are hashed, never logged raw — secrets never reach the audit log.

MCP Inspector

Point it at http://localhost:8082/mcp (Streamable HTTP) with Authorization: Bearer dev-finance.

Environment

Same as sh-mcp-ops plus PAYMENTS_TABLE (aws mode). Finance additionally applies the 15-minute TTL ceiling on finance:* tokens in aws mode (docs/design.md §2.5). aws mode is not runtime-exercised in Phase 1.

CDK

cdk/app.ts is a synth-only placeholder (no real IAM/Cognito/WAF) — the finance least-privilege role and audit wiring land in a later phase behind the mandatory IAM cross-review.