Your assistant knows you. Now let it know your money.
Connect Claude, ChatGPT, Gemini or any MCP client to Life Budget. It reads your real budget and retirement plan, runs the same tax-aware engine the app runs, and writes changes back — without ever touching your bank links or your money.
Your assistant
Claude · ChatGPT · Geminiquestion
no identity
engine-computed
Life Budget
your budget, your plan, the engineThe smartest assistant you own has no idea what you earn.
You have probably had this conversation. You ask a very capable model whether to throw the next $20,000 at the mortgage or the brokerage account, and you get back something genuinely thoughtful — a clear account of the trade-off, the right vocabulary, maybe a nod to your marginal rate. It is a good answer to a question about people in general. It is not an answer about you, because it does not know your mortgage rate, your bracket, your emergency fund, or that you are planning to stop working in nine years.
So you start pasting. Balances, rates, the spreadsheet you keep meaning to clean up. The answer gets sharper. Then the session ends, and every number you pasted is gone, and next week you do it again — slightly differently, from slightly staler memory, and you never quite notice that the two answers you got were built on two different sets of facts.
An assistant without your data is not giving you bad advice. It is giving you advice about someone else.
The gap is not intelligence. It is access — and access is a solved problem now. The Model Context Protocol is an open standard for letting an assistant call tools on a service you already use. Life Budget runs one of those servers. Connect it once, and the model stops guessing at your situation and starts reading it.
your work
your goals
how you think
what you spend
what you owe
how close you are
The same question, asked of something that knows the answer.
The difference is not that the assistant becomes more eloquent. It becomes checkable. Ask what you spent on groceries and it does not estimate from a story you told it in March — it pulls the rows, names the window it actually used, and adds them up. Ask what a decision costs and it does not reason in prose about compounding; it runs the projection and reports what came back.
Three ordinary questions, and the tool each one reaches for:
“Where did the money actually go last quarter?”
Reads your real categorized transactions for the window you named, and totals spending rather than cash movement — transfers between your own accounts and rows you excluded from the budget are left out, because they were never spending.
“What if I retire at 52 instead of 55?”
Runs your saved plan and the variation side by side through the full engine — taxes, inflation, per-account returns, the 59½ wall — and returns both year by year, so the comparison is the engine’s, not the model’s arithmetic.
“Rent is going up $300. Update my plan.”
Finds the housing item in your saved simulation and changes it, after confirming with you. The next projection — in the chat or in the app — starts from the new number, because there is only one plan.
It does not just read your data. It runs the model.
Most finance connectors are readers. They hand an assistant a ledger and leave the thinking to the language model, which then does retirement math in prose — and a language model doing thirty years of compounding, bracket by bracket, in its head is exactly as reliable as that sounds.
Life Budget hands over the engine too. run_what_if_simulation is not a summary of your plan; it is the simulator's own entry point, the same seven-step deterministic engine the app runs, called with your real profile. It knows that a dollar in a Traditional IRA and a dollar in a taxable brokerage are not the same dollar. It knows what happens if you need that money at 54. It applies your inflation assumption to expenses and your return assumption to accounts, separately, which is the single most common way a back-of-envelope retirement estimate goes quietly wrong.
Ask a chatbot when you can retire and you get an essay. Ask a connected assistant and it runs a tax-aware projection against your actual accounts and tells you the year.
That distinction is why this page exists. An assistant is extraordinary at the parts that are language — understanding a messy question, noticing what you did not ask, explaining a result in terms that mean something to you. It is poor at arithmetic it cannot check. Give it a tool that does the arithmetic properly and you get both halves: the reasoning of a good model, resting on numbers from a real engine.
The surface is 38 tools. Eleven read — transactions, a full-text search across them, categories, tag analysis, future and recurring rules, spending and investment breakdowns, your saved simulations — and one of those runs projections. Twenty-seven write. Amounts come back as strings, not floats, so nothing is lost to rounding on the way to the model.
RUNS A REAL ENGINE
Calculator connectors
A real engine — that has never seen your accounts.Life Budget
Your real data, and the simulator’s own entry point into the engine.A chatbot alone
Thoughtful answers about people in general.Ledger connectors
Your transactions — then thirty years of tax math left to the model.KNOWS YOUR ACTUAL NUMBERS
Ask it to change the plan, and the plan changes.
A connection that can only look is a party trick. The reason to keep one is the small maintenance work you would otherwise never do: the transactions you forgot to categorize, the rule that should have been updated in June, the plan that still assumes the rent you paid two apartments ago.
So the assistant can add and edit transactions, apply and remove tags, create and edit categories, set a month's spending goal, and write auto-categorization rules. It can edit a saved simulation's inputs — income and expense items, scenarios and their tax rates, savings rules, the primary path, global settings, and on Pro, custom life paths and life events. All of it lands in the same records the app reads, so a change made in conversation is simply there the next time you open your dashboard.
Three deliberate frictions come with that. The assistant is instructed to confirm before it writes, and to say plainly what it changed and how many rows. Edits take real record ids from a read tool, so it has to look before it touches. And if you changed the same simulation in the app since it last read, the edit is refused outright rather than overwriting you — it re-reads and tries again. You cannot lose work to a race with your own assistant.
What it will never be able to do.
Every honest version of this page needs this section, because "my AI can reach my finances" is a sentence that should make you pause. The answer is not a promise about behaviour. It is that the capability is absent from the surface — there is no tool to call, no permission to escalate, no setting that turns one on.
Start from the largest fact: Life Budget cannot move money. Not for you, not for an assistant, not for us. It holds no funds, initiates no transfers and places no trades, so the worst thing anything connected to it can do is be wrong about a record. Everything below narrows from there.
Read your transactions, categories, tags, rules and saved simulations
Analyze spending and (on Pro) investment holdings
Run what-if projections through the real engine (Pro)
Add and edit transactions, tags, categories, goals and rules
Edit a saved simulation’s inputs, scenarios and assumptions
Move money, transfer funds or place trades — no such capability exists
Delete anything, anywhere on the surface
Link, unlink or sync a bank account
Change billing, subscriptions or your plan tier
Change your account, sign-in or multi-factor settings
Create or delete a simulation, a recurring rule or a savings jar
Alter how a transaction is tied to a bank feed
Reach any data belonging to anyone but you
Only what the question needs. Never a credential.
It would be easy to claim we send your assistant as little as possible. That is not true, and the truthful version is more useful. Your financial detail is the product — you connected an assistant precisely so it could see what you spent at which merchant on which day, so amounts, dates, merchants, descriptions, categories, tags and notes are sent in full and deliberately unmasked. Holding those back would leave you with a connection that cannot answer anything.
What never leaves is the other category entirely: the things that are credentials, identity, or plumbing. None of it would improve a single answer, and all of it would cost you if it went astray.
Your assistant is told what you spent. It is never told who you are, where you were standing, or how to get back in without you.
Two details in that list are worth pulling out, because they are the ones people do not expect. Your bank sends us the address and coordinates of where you physically were when a card was used; we strip it, because a spending question never needs a location history. And the connection carries no identifier that could name you — not your user id, not the internal storage id, not the id of any field that might quietly be carrying one.
The mechanism matters more than the list, because a list ages. Every result is built by an allowlist: each serializer names, by hand, every field it is allowed to emit. Nothing dumps an object wholesale. So a field added to a model next year is invisible over this connection until a person deliberately adds it — the default for new data is silence, not exposure. A test plants a sentinel value in every forbidden field and walks the entire output of every serializer looking for it, so the rule is enforced rather than merely intended.
A few things sit in between and are sent deliberately reduced: account and card numbers arrive as their last four digits, and names as initials. Enough to tell two accounts apart in an answer, never enough to be the thing itself.
Amounts, dates, merchants
Categories, tags, notes and your rules
Your plan’s inputs and projected years
Balances and returns, by account type
Bank credentials and Plaid access tokens
Your user id — and anything holding one
MFA status, recovery codes, encryption keys
Where you physically were when you paid
Billing and payment identifiers
Other members of a shared profile
The connection is the security model.
You approve each client by name. The first time an assistant appears it shows up in Settings → Connections as pending, before it has done anything, so you approve a connection you recognise rather than discovering one later. Clients whose identity the authorization server can verify are shown with their verified origin; clients that merely report a name for themselves are shown as the raw identifier with an unverified marker, because a self-reported name is not evidence.
Keys are gated behind MFA. A personal API key reads and edits your budget from outside the app, so minting one requires multi-factor authentication — and if your MFA was reset recently, new keys are paused for 72 hours. That window exists precisely for the case where the reset was not you. One key is active at a time; making a new one retires the old.
Your identity comes from the credential, never the request. A connection resolves to you and to nothing else, and every tool hands that identity to the same service the app itself calls. No tool takes a user id as an argument, so there is no request an assistant could construct that reaches someone else's data.
And the data is encrypted underneath all of it. Sensitive fields are encrypted with AES-256-GCM under a key unique to your account before they ever reach the database. We are a tool provider, not a data broker: your financial profile is not sold, rented or shared.
One thing we do not control, and our advice on it. Everything above ends at the edge of our system. Once an answer reaches your assistant, what happens to it is governed by that provider's settings — so before you connect, we recommend turning off whatever data sharing that provider offers a switch for: training on your conversations, and retention as memory or history. Some consumer tiers have those on by default.
We deliberately do not print the steps here. Every provider names these controls differently and moves them whenever the settings screen is redesigned, so a list of clicks on this page would be wrong within months. Ask the assistant instead — "what settings control whether my conversations are used for training or kept as memory, and how do I turn them off?" — which is accurate today and still accurate next year. It is also a reasonable test of something you are about to trust with your finances: ask before you connect, and see whether you get a straight answer.
Four steps, about five minutes.
Nothing here needs a developer. Settings → Connections generates the exact snippet for your client and tells you where it goes; for OAuth clients there is no snippet at all, just an endpoint and a sign-in.
Create a free Life Budget account and add your numbers
The connection carries your data, so there has to be data. Add accounts, debts and expenses by hand, or let the onboarding wizard walk you through it. A budget and at least one saved simulation give an assistant the most to work with.
Open Settings → Connections
Every way of connecting an outside assistant lives on one page, at /profile?tab=connections. Nothing is enabled by default; an unconnected account has no external surface at all.
Connect through your assistant, or mint a key
Clients that speak OAuth — Claude and ChatGPT among them — take the endpoint https://api.life-budget.com/mcp/ and send you through a normal browser sign-in. Clients that take a header instead (Claude Code, Gemini CLI) use a personal API key, which you create on the same page. Creating a key requires multi-factor authentication, because a key reads and edits your budget from outside the app.
Approve the connection, then ask it something
A newly seen client appears in Settings → Connections as pending, named and marked verified or unverified, and waits for you to approve it. Once approved, ask a question you could not have answered from memory — "what did I actually spend on groceries last quarter, and what would cutting it by 15% do to my FI date?"
Things worth asking once it is connected.
The instinct is to test it with something you already know. Do the opposite — ask the questions you have been avoiding because answering them properly meant an hour in a spreadsheet.
“What did I spend last year, by category, and which three categories grew the most?”
“Find every recurring charge I have not touched in six months.”
“How much of what I call spending is actually transfers between my own accounts?”
“If I retire at 52 instead of 55, what happens to my net worth at 80?”
“What if the market returns two points less than I assumed for the next decade?”
“Model a two-year sabbatical starting in 2029 and tell me what it costs me in FI date.”
“Categorize everything from last month that is still uncategorized, and show me before you save.”
“My rent goes up $300 in January — update my plan and re-run it.”
“Write a rule that tags anything from that coffee shop as discretionary.”
Prefer not to bring your own? There is an advisor inside.
Connecting an outside assistant is for people who already live in one — who have a long-running Claude or ChatGPT conversation that knows their job, their family and what they are trying to build, and who want their finances in that same room rather than in a separate tab.
If that is not you, Life Budget's own AI Advisor sits inside the app on Pro, reads the same data, calls the same engine, and needs no setup whatsoever. Same numbers, same guarantees, one less thing to configure. Plenty of people use both, and they stay in step, because both are reading the one plan.
What's included on each tier
| Feature | Free | Pro |
|---|---|---|
| Connect Claude, ChatGPT, Claude Code or Gemini CLI | ||
| Read transactions, categories, tags and rules | ||
| Search and analyze spending | ||
| Add and edit transactions, categories, goals and rules | ||
| Read and edit saved simulation inputs | ||
| Per-connection approval and revocation | ||
| Run what-if projections through the full engine | ||
| Analyze investment holdings and asset mix | ||
| Edit custom life paths and life events |
Everything you might be wondering
Model Context Protocol is an open standard for letting an AI assistant call tools on an outside service. An MCP server is the service half. Life Budget runs one, so an assistant you already use can read your budget and retirement plan and act on them, instead of you pasting numbers into a chat window.
Any client that speaks MCP. Claude and ChatGPT connect over OAuth — you paste the endpoint and sign in through your browser, with no key to copy. Claude Code and Gemini CLI connect with a personal API key sent as an Authorization header. Settings → Connections generates the exact configuration snippet for each.
Pasted numbers go stale the moment you close the tab, and a model doing the arithmetic in prose has no tax engine behind it. A connected assistant reads your current data on every question and runs projections through the same seven-step, tax-aware engine the Life Budget simulator uses. The numbers it quotes are the numbers the app would show you.
No, and it is not a setting you can turn on. Life Budget has no ability to move money at all — it does not hold funds, initiate transfers or place trades. The connection reaches your records and your plan, never your accounts.
No. There is no delete operation anywhere on the MCP surface. To stop a rule an assistant sets it inactive, which keeps it visible to you; to zero out a plan item it sets the value to zero. Anything genuinely destructive stays in the app, behind your own hands.
No. Bank linking, Plaid syncing, billing, sign-in settings and multi-factor settings are permanently first-party — they are reachable only in the Life Budget app, by you. An assistant asked to do one of those is told to say so rather than imply it happened.
Budget records (add and edit transactions, tags, categories, a monthly spending goal, auto-categorization rules) and the inputs of a saved simulation (income and expense items, scenarios and their tax rates, savings rules, the primary path, global settings, and on Pro, custom life paths and life events). Every write lands immediately and the assistant is instructed to confirm with you first.
Two things. A connection resolves to you and nothing else, and every tool hands that identity to the same service the app itself calls — there is no path where a key reaches another person’s data. And every result passes through an allowlist that names each field by hand, so a field added to a model later is invisible to the MCP surface until someone deliberately adds it.
Only what the question needs. Your financial detail is sent in full and unmasked — amounts, dates, merchants, descriptions, categories, tags, notes — because that is what you connected an assistant to see, and withholding it would leave you with a connection that cannot answer anything. Everything that is a credential, an identifier or internal plumbing is withheld: bank credentials and Plaid access tokens, your user id and every field that might carry one, MFA status and recovery codes, encryption key material, billing and payment identifiers, and the names of other members of a shared profile. Account numbers are cut to the last four digits and names are masked to initials. Your bank even sends us the address and coordinates of where you physically were when a card was used — we strip that too, because no spending question needs your location history.
The serialization is an allowlist, never a denylist. Every result is assembled by naming each permitted field by hand — nothing serializes an object wholesale — so a field added to a data model next year is invisible over this connection until a person deliberately adds it. The default for new data is silence, not exposure. A test plants a sentinel value in every forbidden field on every fixture and walks the full output of every serializer looking for it, so this is enforced on each build rather than left to good intentions.
No. Reading and editing your budget, reading and editing saved simulations, and spending analysis all work on the free tier. Running what-if projections, analyzing investment holdings, and editing custom life paths and life events require Life Budget Pro — the same gates the app applies.
The edit is refused rather than silently overwriting you. Saved simulations carry a revision, and an assistant editing a stale copy is told to re-read and retry. You never lose a change to a race.
At any time, from Settings → Connections. Revoking a connection or a key takes effect on the next request. There is one active API key at a time, so creating a new one retires the old.
Not by us. Sensitive fields are encrypted with a key unique to your account before they reach our database, and we do not sell or share your profile. What your assistant does with an answer is governed by whichever provider you connected — that relationship is yours, not ours, which is exactly why the connection is opt-in and revocable, and why we recommend turning that provider’s data sharing off before you connect.
Yes. We recommend it, and we would rather say so plainly than let it go unmentioned. Once an answer leaves Life Budget it is in your assistant, and what happens to it there is governed by that provider’s settings — not by anything we control. Most providers let you decide whether your conversations are used to improve their models and whether they are retained as memory or history; some consumer tiers have those on by default. Turn them off before the first question about your money, not after.
Ask the assistant itself: "What settings control whether my conversations are used for training or retained as memory, and how do I turn them off?" That is genuinely the best route, not a dodge. Every provider names these controls differently and moves them whenever the settings screen is redesigned, so any list of clicks printed on a page like this one is wrong within months — whereas the assistant knows its own current settings and will walk you to the right screen. It is also a fair test of the thing you are about to trust with your finances: ask it before you connect, and see whether it gives you a straight answer.
