sh-mcp/servers/sh-mcp-finance
dependabot[bot] 6c37e0399b
chore(deps): bump the minor-and-patch group (#51)
Bumps the minor-and-patch group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.2` | `26.2.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.65.0` | `8.66.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.65.0` | `8.66.0` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) | `2.1134.0` | `2.1135.1` |
| [constructs](https://github.com/aws/constructs) | `10.7.2` | `10.8.1` |
| [eslint](https://github.com/eslint/eslint) | `10.8.0` | `10.8.1` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.1` | `4.23.11` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.6.1` | `8.6.2` |
| [jose](https://github.com/panva/jose) | `6.2.6` | `6.2.8` |
| [@aws-sdk/client-cognito-identity-provider](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-cognito-identity-provider) | `3.1101.0` | `3.1106.0` |
| [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb) | `3.1101.0` | `3.1106.0` |
| [@aws-sdk/client-secrets-manager](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-secrets-manager) | `3.1101.0` | `3.1106.0` |
| [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb) | `3.1101.0` | `3.1106.0` |

Updates `@types/node` from 26.1.2 to 26.2.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.65.0 to 8.66.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.65.0 to 8.66.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/parser)

Updates `aws-cdk` from 2.1134.0 to 2.1135.1
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1135.1/packages/aws-cdk)

Updates `constructs` from 10.7.2 to 10.8.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.7.2...v10.8.1)

Updates `eslint` from 10.8.0 to 10.8.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](https://github.com/eslint/eslint/compare/v10.8.0...v10.8.1)

Updates `tsx` from 4.23.1 to 4.23.11
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](https://github.com/privatenumber/tsx/compare/v4.23.1...v4.23.11)

Updates `express-rate-limit` from 8.6.1 to 8.6.2
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](https://github.com/express-rate-limit/express-rate-limit/compare/v8.6.1...v8.6.2)

Updates `jose` from 6.2.6 to 6.2.8
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](https://github.com/panva/jose/compare/v6.2.6...v6.2.8)

Updates `@aws-sdk/client-cognito-identity-provider` from 3.1101.0 to 3.1106.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-cognito-identity-provider/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1106.0/clients/client-cognito-identity-provider)

Updates `@aws-sdk/client-dynamodb` from 3.1101.0 to 3.1106.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1106.0/clients/client-dynamodb)

Updates `@aws-sdk/client-secrets-manager` from 3.1101.0 to 3.1106.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1106.0/clients/client-secrets-manager)

Updates `@aws-sdk/lib-dynamodb` from 3.1101.0 to 3.1106.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1106.0/lib/lib-dynamodb)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-cognito-identity-provider"
  dependency-version: 3.1106.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-dynamodb"
  dependency-version: 3.1106.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1106.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/lib-dynamodb"
  dependency-version: 3.1106.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.66.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.66.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1135.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: constructs
  dependency-version: 10.8.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint
  dependency-version: 10.8.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: express-rate-limit
  dependency-version: 8.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: jose
  dependency-version: 6.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-11 16:12:05 +00:00
..
cdk Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
src Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
test Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
cdk.json Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
package.json chore(deps): bump the minor-and-patch group (#51) 2026-08-11 16:12:05 +00:00
README.md Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00
tsconfig.json Phase 1: runnable MCP + OpenAPI servers (ops + finance) (#3) 2026-06-26 13:33:21 -04:00

sh-mcp-finance

Finance-tier Sea Haven MCP server. Exposes the finance tool registry (qbo search_vendors, payments lookup_payment_by_* — see docs/design.md §3) over the same two interfaces as sh-mcp-ops (MCP Streamable HTTP + OpenAPI 3.1), through the same shared dispatch path.

Finance is sensitive, read-only, and fully audited: every tool call emits a structured audit record and the response is redacted on egress (bank account / routing / card / SSN / tax-id masked) before it leaves the server (docs/design.md §2.5, §7.3).

Run locally (no AWS, no Cognito)

npm install
npm run build

SH_MCP_ENV=local PORT=8082 npm run start -w @sh-mcp/server-finance
# or:  SH_MCP_ENV=local npm run dev -w @sh-mcp/server-finance

Endpoints

Identical shape to sh-mcp-ops: GET /healthz, GET /openapi.json (both unauthenticated), POST /mcp, and POST /tools/:name (both authenticated).

Dev bearer tokens (local only)

Token Identity Scopes
dev-finance accounting@seahavenind.com ops:read, finance:read
dev-finance-admin adam@seahavenind.com ops:read, finance:read, finance:admin

Ops-tier tokens (dev-ops-only, dev-assistant) are rejected by this server (audience binding).

Sample curl — redaction on egress

TOKEN=dev-finance

curl -s -X POST localhost:8082/tools/lookup_payment_by_vendor \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{"vendor":"Harbor"}' | jq
# → bankAccountNumber / bankRoutingNumber / cardNumber are "[REDACTED]";
#   vendor, amount, invoice number are intact.

Each call writes one structured audit line to stdout (CloudWatch in Lambda):

{
  "kind": "audit",
  "sub": "...",
  "tool": "lookup_payment_by_vendor",
  "argsHash": "<sha256>",
  "decision": "allow",
  "result": "ok",
  "ts": "..."
}

Args are hashed, never logged raw — secrets never reach the audit log.

MCP Inspector

Point it at http://localhost:8082/mcp (Streamable HTTP) with Authorization: Bearer dev-finance.

Environment

Same as sh-mcp-ops plus PAYMENTS_TABLE (aws mode). Finance additionally applies the 15-minute TTL ceiling on finance:* tokens in aws mode (docs/design.md §2.5). aws mode is not runtime-exercised in Phase 1.

CDK

cdk/app.ts is a synth-only placeholder (no real IAM/Cognito/WAF) — the finance least-privilege role and audit wiring land in a later phase behind the mandatory IAM cross-review.