Who can connect
Connecting an MCP client authorizes a third-party app on your Qonto organization, so who may do it follows Qonto’s rules for connected apps:- Owners, admins, and accountants can connect right away.
- Managers and employees can connect once an owner or an admin has enabled Qonto MCP for the organization. See Enabling Qonto MCP for managers and employees.
Enabling Qonto MCP for managers and employees
Owners and admins can extend Qonto MCP to the rest of the organization. The setting is per organization: it applies to every manager and employee in the organization you are signed into, and it changes nothing for owners, admins, and accountants, who can connect either way.1
Open Qonto AI
Sign in to the Qonto web app and open Qonto AI from the left sidebar.
2
Find the Qonto MCP panel
On that page, find the Qonto MCP panel and the Enable for managers and employees card.
3
Turn access on
Switch Give managers and employees access to Qonto MCP on.
Only owners and admins see the Qonto MCP panel. If you are a manager or an employee you cannot enable it yourself, ask an owner or an admin of your organization.
What you will see
The first time you connect an MCP client (Claude, Cursor, ChatGPT, Le Chat, …) tohttps://mcp.qonto.com/mcp:
- Your browser opens at Qonto.
- You sign in if you are not already, pick the organization to connect, and review the permissions the client is asking for.
- You confirm. The client stores the resulting authorization locally and reconnects to the MCP server.
- The Qonto tools become available in your chat.
On the multi-organization endpoint (
https://mcp.qonto.com/multi-organization/mcp), step 2 shows a multi-select list instead: you tick every organization you want the assistant to access, and a single authorization covers them all.What it can do on your behalf
The MCP server acts as you:- It cannot exceed what your role and your organization’s price plan allow.
- It is bound to the permissions you granted at consent time. To grant more, you have to re-authorize.
- Sensitive operations (PSD2-classified actions like creating certain cards) still require Strong Customer Authentication in the Qonto mobile app. The MCP server cannot bypass SCA, when one of these is triggered, your assistant will ask you to approve in the app and continue once you have.
Reviewing and revoking access
Active connections are listed in the connected apps section of your Qonto account. From there you can revoke a connection at any time; the MCP client can no longer reach Qonto until you grant consent again. Removing the server from your MCP client (Claude, Cursor, …) cleans up the client side. Revoking the consent inside Qonto cleans up the server side. Doing both is the safest way to fully disconnect.Sandbox vs production
The public Qonto MCP server (https://mcp.qonto.com/mcp) targets the production Qonto environment. A separate sandbox deployment is intended for partner development; reach out to your Qonto contact if you need access.