BINKY-WP-0005 finished: first Qonto pull and CostRunRate v2
All checks were successful
Work Records / validate (push) Successful in 13s
All checks were successful
Work Records / validate (push) Successful in 13s
Live custody path tenants/binky/qonto-api (API_KEY/API_USER). First read-only thirdparty pull (122 txs): desk 297.50 €/mo, Qonto plan 70.80 €/mo, main balance 2185.94 €. Evidence under finance/; workplan status finished.
This commit is contained in:
parent
fc4c2149e3
commit
143eef2f0d
6 changed files with 1391 additions and 146 deletions
|
|
@ -52,19 +52,13 @@ status: prepared
|
|||
prepared_material: ["2026-07-18: Qonto announced MCP integration (mailing) —
|
||||
connecting the account to our agent infrastructure is planned (AWQ-010
|
||||
→ BINKY-WP-0005) and is a substantive argument FOR keeping Qonto despite
|
||||
plan cost. While in the dashboard: check API/MCP access prerequisites and
|
||||
plan tier requirements.",
|
||||
"2026-07-19: DEC-2026-004 APPROVED — execute the Red-lane provisioning
|
||||
while in the dashboard: create API key under /settings/integrations, note
|
||||
organization ID, then bao kv put per the founder-provision block in
|
||||
integrations/qonto-mcp.md. Also note plan tier + monthly fee for
|
||||
finance/CostRunRate.md row 4. Unblocks BINKY-WP-0005-T05 (first
|
||||
read-only pull).",
|
||||
"2026-07-21: Lane scaffolding ready — CCR-2026-0008 (draft) + policy HCL
|
||||
in railiance-platform; ops-warden catalog binky-qonto-api (draft) +
|
||||
playbook; copy-paste OH/T05 runbook in integrations/qonto-mcp.md and
|
||||
officehour/2026-08-command-day-runbook.md. Only Red-lane provision +
|
||||
CCR apply remain before first pull."]
|
||||
plan cost.",
|
||||
"2026-07-19: DEC-2026-004 APPROVED — Red-lane API provision path.",
|
||||
"2026-07-21: BINKY-WP-0005 FINISHED — first read-only pull done. Desk
|
||||
HUB31 = 297,50 €/mo; Qonto plan fee = 70,80 €/mo (up from 22,80/35,40);
|
||||
main balance 2 185,94 €. Evidence finance/qonto-first-pull-2026-07-21.json.
|
||||
Remaining OH decision: whether plan cost is justified vs usage (plan
|
||||
*change* is still a separate Red-lane step if desired)."]
|
||||
deadline_pressure: none
|
||||
```
|
||||
|
||||
|
|
|
|||
|
|
@ -12,7 +12,7 @@
|
|||
| workplan | BINKY-WP-0002 | done | — | workplans/BINKY-WP-0002-operating-kernel-bootstrap.md |
|
||||
| workplan | BINKY-WP-0003 | done | — | workplans/BINKY-WP-0003-autopilot-and-rhythm.md |
|
||||
| workplan | BINKY-WP-0004 | active | — | workplans/BINKY-WP-0004-workstation-independent-executor.md |
|
||||
| workplan | BINKY-WP-0005 | active | — | workplans/BINKY-WP-0005-qonto-mcp-integration.md |
|
||||
| workplan | BINKY-WP-0005 | finished | — | workplans/BINKY-WP-0005-qonto-mcp-integration.md |
|
||||
| task | BINKY-WP-0001-T01 | done | — | workplans/BINKY-WP-0001-statehub-bootstrap.md |
|
||||
| task | BINKY-WP-0001-T02 | done | — | workplans/BINKY-WP-0001-statehub-bootstrap.md |
|
||||
| task | BINKY-WP-0001-T03 | done | — | workplans/BINKY-WP-0001-statehub-bootstrap.md |
|
||||
|
|
@ -38,7 +38,7 @@
|
|||
| task | BINKY-WP-0005-T02 | done | — | workplans/BINKY-WP-0005-qonto-mcp-integration.md |
|
||||
| task | BINKY-WP-0005-T03 | done | — | workplans/BINKY-WP-0005-qonto-mcp-integration.md |
|
||||
| task | BINKY-WP-0005-T04 | done | — | workplans/BINKY-WP-0005-qonto-mcp-integration.md |
|
||||
| task | BINKY-WP-0005-T05 | wait | — | workplans/BINKY-WP-0005-qonto-mcp-integration.md |
|
||||
| task | BINKY-WP-0005-T05 | done | — | workplans/BINKY-WP-0005-qonto-mcp-integration.md |
|
||||
| intake | AWQ-002 | — | green | AutopilotWorkQueue.md |
|
||||
| intake | AWQ-003 | — | green | AutopilotWorkQueue.md |
|
||||
| intake | AWQ-006 | — | green | AutopilotWorkQueue.md |
|
||||
|
|
|
|||
|
|
@ -1,48 +1,55 @@
|
|||
# Cost & Run-Rate Table
|
||||
|
||||
> Status: v1 — 2026-07-16 (BINKY-WP-0003-T03, AWQ-004). Feeds the cash/runway
|
||||
> view (Finance Steward loop). Confidence per row; amounts marked **TBC**
|
||||
> need Qonto statements (OH-2026-003) or founder confirmation. Currency EUR
|
||||
> unless noted.
|
||||
> Status: v2 — 2026-07-21 (BINKY-WP-0005-T05 first Qonto pull). Feeds the
|
||||
> cash/runway view (Finance Steward loop). Currency EUR unless noted.
|
||||
> Evidence: `finance/qonto-first-pull-2026-07-21.json` (metadata only).
|
||||
|
||||
## Recurring costs
|
||||
|
||||
| # | Item | Provider | Monthly (gross) | Paid from | Confidence / source |
|
||||
|---|------|----------|----------------:|-----------|---------------------|
|
||||
| 1 | Fixed desk, HUB31 Darmstadt | Technologie- u. Gründerzentrum Verwaltungs-GmbH | **TBC** | Qonto | Contract since 2019-04-01, renewed to **2027-04-01** (signed annex 2026-03-23); rent amount not in the annex — pull from Qonto |
|
||||
| 1 | Fixed desk, HUB31 Darmstadt | Technologie- u. Gründerzentrum Verwaltungs-GmbH | **297,50** | Qonto | Verified 2026-07-21 Qonto pull: label `HUB31`, `office_rental`, **33× 297,50 €** monthly since ≥2023-06; contract renewed to **2027-04-01** |
|
||||
| 2 | DATEV / IT pass-through | FSW (old StB) | ~40,31 (483,69/yr) | Qonto | Documented: invoice 2026/651 for Jan–Dec 2025. Continues only while DUO runs via FSW (RISK-007) |
|
||||
| 3 | StB fees (JA, filings) | FSW → Bohle-Horsmann (pending) | **TBC** (annual, not monthly) | Qonto | Mandate transition open (RISK-006); budget once new mandate quotes |
|
||||
| 4 | Qonto account | Qonto | **TBC** (founder: "expensive for usage") | Qonto | Plan review queued OH-2026-003; changes Red lane |
|
||||
| 3 | StB fees (JA, filings) | FSW → Bohle-Horsmann (pending) | **irregular / annual** | Qonto | Recent lumps (not monthly): FSW 2025-05 1 230,58 + 327,73; 2025-10 FSW/Weglarzy 1 138 + 261,80. Mandate transition open (RISK-006) |
|
||||
| 4 | Qonto account | Qonto | **70,80** | Qonto | Verified 2026-07-21: `operation_type=qonto_fee`, **70,80 €/mo since 2025-10** (was 35,40 mid-2025; 22,80 earlier). OH-2026-003: plan *change* still separate Red-lane decision |
|
||||
| 5 | bubble.io Starter Web Plan (app "coulomb") | Bubble Group Inc. | $32 | **founder private card** ⚠️ | Documented: invoice 2026-03-9049150, billed to private gmail/card |
|
||||
| 6 | AI subscriptions | various | **TBC** | **founder private** ⚠️ | Founder note 2026-03-24: paid privately, not itemized yet |
|
||||
| 7 | Domain(s): binky-hedgehog.com (+ inventory pending) | **TBC** | **TBC** (~1–3/mo typical) | **TBC** | AWQ-003 domain inventory will enumerate registrar + payer |
|
||||
| 8 | Stripe | Stripe | usage-based fees only | n/a | No fixed fee; per-transaction. One live subscription flows in |
|
||||
| 9 | railiance01 VM (4 vCPU / 16 GB RAM) | **TBC** (hosting provider) | 25,19 | **TBC** | Founder-stated 2026-07-16: upgraded to this size at 25,19 €/mo with **24-month commitment** (≈604,56 € total obligation, runs to ~2028-07). Provider + payment source to confirm. Other infra (workstation is private) — none known |
|
||||
| 8 | Stripe | Stripe | usage-based fees only | n/a | Credits ~8,55 €/mo observed on main account; no fixed fee |
|
||||
| 9 | railiance01 VM (4 vCPU / 16 GB RAM) | **TBC** (hosting provider) | 25,19 | **TBC** | Founder-stated 2026-07-16: 24-month commitment (≈604,56 € total). Not seen on Qonto Hauptkonto in sample — may be private card |
|
||||
|
||||
## Known recurring income
|
||||
|
||||
| Item | Counterparty | Amount | Notes |
|
||||
|------|--------------|-------:|-------|
|
||||
| Meeting-room sublet share | Binect | 450 € per event (25% × 2 days × 900 €) | Founder note 2026-03-02; invoice still to be issued ("endlich abrechnen") — **open receivable** |
|
||||
| Stripe subscription | own/self | ~monthly sub price TBC | Proves pipeline since ~2025 |
|
||||
| Meeting-room sublet share | Binect | 450 € per event (25% × 2 days × 900 €) | Founder note 2026-03-02; **2026-06-02 credit 571,20 €** from Binect GmbH observed on Qonto (likely related; confirm vs open receivable) |
|
||||
| Stripe subscription | own/self | ~8,55 € credits observed | Pipeline alive; net after Stripe fees |
|
||||
|
||||
## Snapshot (2026-07-21 first pull)
|
||||
|
||||
| Account | Status | Balance (EUR) |
|
||||
|---------|--------|--------------:|
|
||||
| Hauptkonto (main) | active | **2 185,94** |
|
||||
| Kickstart Business | active | 0,00 |
|
||||
|
||||
Org: Binky Hedgehog GmbH (`binky-hedgehog-gmbh-6923`). Transactions fetched: 122 (full history on main account via API pagination).
|
||||
|
||||
## Findings
|
||||
|
||||
1. **Private/company bleed (⚠️ rows 5–6):** bubble.io and AI subscriptions
|
||||
are company-purpose costs on private payment — cash-flow invisible to the
|
||||
company and messy for the JA. Action: move to Qonto card or set up proper
|
||||
Auslagenerstattung — needs StB advice → added to OH-2026-001 agenda.
|
||||
2. **Liquidity is thin:** founder note 2026-03-24 records a month where DUO
|
||||
pass-through + desk rent were not covered by the Qonto balance. Until a
|
||||
runway view exists, treat every new recurring cost as a Yellow decision.
|
||||
3. **Open receivable:** the 450 € Binect meeting-room billing was still
|
||||
unissued as of March — verify status, else invoice (founder/Orange).
|
||||
4. **Biggest unknowns** are the desk rent and Qonto plan — both fall out of
|
||||
one Qonto statement pull (OH-2026-003, already queued).
|
||||
5. **railiance01 commitment (2026-07-16):** the 24-month term makes this the
|
||||
first multi-year obligation besides the desk — it belongs in the
|
||||
contracts/obligations inventory (CompanyReactivationPlan.md). If it runs
|
||||
over a private card like bubble.io, it joins the finding-1 cleanup.
|
||||
1. **Private/company bleed (⚠️ rows 5–6, possibly 9):** bubble.io and AI
|
||||
subscriptions (and maybe railiance01) are company-purpose costs on private
|
||||
payment — cash-flow invisible to the company. Action: move to Qonto card or
|
||||
Auslagenerstattung → OH-2026-001 / StB advice.
|
||||
2. **Liquidity is thin but not empty:** main balance **2 185,94 €** (2026-07-21).
|
||||
Desk + Qonto alone ≈ **368 €/mo** fixed company-account outflows before StB
|
||||
lumps and DATEV. Still treat new recurring spend as Yellow.
|
||||
3. **Open receivable / Binect:** a **571,20 €** Binect credit landed 2026-06-02 —
|
||||
reconcile against the 450 €/event sublet note and any outstanding invoices.
|
||||
4. **Desk + Qonto plan resolved** from the first pull (was the main TBC pair).
|
||||
5. **railiance01 commitment (2026-07-16):** 24-month term remains; not confirmed
|
||||
on Qonto Hauptkonto in this pull — payment source still TBC.
|
||||
6. **Qonto plan cost stepped up:** 22,80 → 35,40 → **70,80 €/mo**. OH-2026-003
|
||||
cost-vs-usage review still useful; plan *change* is a separate Red-lane step.
|
||||
|
||||
## Feeding adaptive-pricing (cost floor)
|
||||
|
||||
|
|
@ -53,16 +60,16 @@ capture costs itself — when its Coulomb pricing project needs a cost floor,
|
|||
derive it from the run-rate here (railiance01 hosting is a direct
|
||||
infrastructure component of that floor).
|
||||
|
||||
## Estimated run-rate (floor)
|
||||
## Estimated run-rate (company Qonto, verified floor)
|
||||
|
||||
Documented + typical minimums only: DATEV ~40 + bubble ~30 + railiance01
|
||||
~25 + domains ~2 ≈ **~100 €/mo**, **plus** desk rent (likely the dominant
|
||||
cost, low hundreds) **plus** Qonto plan **plus** annual StB fees. A defensible total needs the
|
||||
Qonto pull; target: replace this paragraph with a verified figure after the
|
||||
next command day.
|
||||
Fixed on Qonto Hauptkonto: desk **297,50** + Qonto plan **70,80** + DATEV
|
||||
~**40** ≈ **~408 €/mo**, plus irregular StB lumps and usage Stripe fees.
|
||||
Add private-card company costs (bubble ~30 €, AI TBC, maybe railiance01 25)
|
||||
for a full economic picture — those do not hit the company balance today.
|
||||
|
||||
## Maintenance
|
||||
|
||||
Update on: any new subscription, mandate quote, Qonto statement pull, or JA.
|
||||
Owner: Finance Steward loop (rhythm session may update rows; adding new
|
||||
recurring spend is never below Yellow lane).
|
||||
recurring spend is never below Yellow lane). Credential lane:
|
||||
`tenants/binky/qonto-api` via ops-warden `binky-qonto-api` (CCR-2026-0008).
|
||||
|
|
|
|||
1263
finance/qonto-first-pull-2026-07-21.json
Normal file
1263
finance/qonto-first-pull-2026-07-21.json
Normal file
File diff suppressed because it is too large
Load diff
|
|
@ -1,10 +1,10 @@
|
|||
# Qonto MCP Integration — Design
|
||||
|
||||
> Status: design v1 — 2026-07-19 (BINKY-WP-0005, from AWQ-010).
|
||||
> Status: **lane active** — 2026-07-21 (BINKY-WP-0005 finished).
|
||||
> Goal: the company Qonto account becomes an agent-readable finance source
|
||||
> (balance, transactions, statements) through the sanctioned harness/MCP
|
||||
> lane. **Read scopes first; payments/transfers are Red lane forever.**
|
||||
> Credential provisioning is a single founder Red-lane step (DEC-2026-004).
|
||||
> (balance, transactions, statements) through the sanctioned harness/MCP /
|
||||
> thirdparty API lane. **Read scopes first; payments/transfers are Red lane forever.**
|
||||
> Credentials live at `tenants/binky/qonto-api` (CCR-2026-0008 / DEC-2026-004).
|
||||
|
||||
## Variant decision (T01)
|
||||
|
||||
|
|
@ -46,35 +46,38 @@ Same pattern as `integrations/company-email-openbao.md`
|
|||
| Item | Value |
|
||||
| --- | --- |
|
||||
| Mount | `tenants` |
|
||||
| Path | `tenants/binky/qonto/api` |
|
||||
| Fields | `QONTO_API_KEY`, `QONTO_ORGANIZATION_ID` |
|
||||
| Policy | `workload-kv-read-binky-qonto-api` (to be created, warden playbook) |
|
||||
| Catalog | `binky-qonto-api` (draft until provision) |
|
||||
| Path | **`tenants/binky/qonto-api`** (live) |
|
||||
| Fields | **`API_KEY`**, **`API_USER`** (login/org slug) |
|
||||
| MCP env map | `API_KEY`→`QONTO_API_KEY`, `API_USER`→`QONTO_ORGANIZATION_ID` |
|
||||
| Policy | `workload-kv-read-binky-qonto-api` |
|
||||
| OIDC role | `binky-qonto-api-workload-kv-read` |
|
||||
| Catalog | `binky-qonto-api` (**active**, resolvable) |
|
||||
| Risk | high (full-scope bank API key — read-only is harness-enforced) |
|
||||
|
||||
Auth to Qonto thirdparty API: `Authorization: <API_USER>:<API_KEY>`.
|
||||
|
||||
```text
|
||||
founder (Red lane, once)
|
||||
└─ bao kv put tenants/binky/qonto/api QONTO_API_KEY=@file QONTO_ORGANIZATION_ID=@file
|
||||
└─ OpenBao: tenants/binky/qonto/api
|
||||
└─ bao kv put tenants/binky/qonto-api API_KEY=@file API_USER=@file
|
||||
└─ OpenBao: tenants/binky/qonto-api
|
||||
└─ warden access binky-qonto-api --exec
|
||||
└─ qonto-mcp-server (env names only) → harness read tools
|
||||
└─ map fields → QONTO_* env → qonto-mcp-server / curl thirdparty
|
||||
└─ finance/CostRunRate.md + rhythm session feeds
|
||||
```
|
||||
|
||||
### Founder provision (Red lane — interactive human shell)
|
||||
|
||||
```bash
|
||||
# In the Qonto dashboard: /settings/integrations → create API key, note org ID
|
||||
# In the Qonto dashboard: /settings/integrations → create API key, note login/org slug
|
||||
umask 077
|
||||
# key into /tmp/qonto.key, org id into /tmp/qonto.org — private terminal only
|
||||
bao kv put tenants/binky/qonto/api \
|
||||
QONTO_API_KEY=@/tmp/qonto.key \
|
||||
QONTO_ORGANIZATION_ID=@/tmp/qonto.org
|
||||
shred -u /tmp/qonto.key /tmp/qonto.org
|
||||
bao kv put tenants/binky/qonto-api \
|
||||
API_KEY=@/tmp/qonto.key \
|
||||
API_USER=@/tmp/qonto.user
|
||||
shred -u /tmp/qonto.key /tmp/qonto.user
|
||||
```
|
||||
|
||||
The organization ID is low-secrecy but lives with the key so consumers get
|
||||
one fetch surface (same rule as IMAP username). **Key never in git/chat.**
|
||||
`API_USER` is low-secrecy but lives with the key so consumers get one fetch
|
||||
surface (same rule as IMAP username). **Key never in git/chat.**
|
||||
|
||||
## Consumer design (T03)
|
||||
|
||||
|
|
@ -97,72 +100,45 @@ Rules:
|
|||
## Execution checklist
|
||||
|
||||
1. [x] Variant + read-only enforcement decided (this doc)
|
||||
2. [x] OpenBao lane designed (`tenants/binky/qonto/api`)
|
||||
2. [x] OpenBao lane designed → **live path `tenants/binky/qonto-api`**
|
||||
3. [x] DecisionQueue package prepared (DEC-2026-004)
|
||||
4. [x] DEC-2026-004 **approved** (founder, 2026-07-19)
|
||||
5. [x] CCR-2026-0008 + policy HCL + agent-high-risk-boundary deny (railiance-platform)
|
||||
6. [x] ops-warden catalog `binky-qonto-api` **draft** + playbook
|
||||
(`ops-warden/wiki/playbooks/binky-qonto-api.md`)
|
||||
7. [ ] **Red lane — founder (OH-2026-003):** create API key; `bao kv put` via `@file`
|
||||
(see founder block below and `officehour/2026-08-command-day-runbook.md`)
|
||||
8. [ ] Apply CCR-2026-0008 metadata (policy + OIDC role) — platform-operator
|
||||
9. [ ] Capabilities-safe verify; promote catalog draft → active
|
||||
10. [ ] First read-only pull; update CostRunRate TBC rows (BINKY-WP-0005-T05)
|
||||
11. [ ] Wire Finance Steward recurring session (post-cutover, harness lane —
|
||||
out of scope for BINKY-WP-0005 close; follow-on after T05)
|
||||
5. [x] CCR-2026-0008 **active** (policy + OIDC role + agent-high-risk-boundary)
|
||||
6. [x] ops-warden catalog `binky-qonto-api` **active** + playbook
|
||||
7. [x] Red-lane secret present (`API_KEY` + `API_USER`)
|
||||
8. [x] Capabilities-safe verify (lane-policy → `read` on data+metadata paths)
|
||||
9. [x] First read-only pull 2026-07-21 (122 txs); CostRunRate v2
|
||||
(`finance/qonto-first-pull-2026-07-21.json`)
|
||||
10. [ ] Wire Finance Steward recurring session (post-cutover, harness lane —
|
||||
**follow-on**, out of scope for BINKY-WP-0005)
|
||||
|
||||
## OH-2026-003 / T05 runbook (copy-paste)
|
||||
## First-pull results (T05, 2026-07-21)
|
||||
|
||||
### A. Founder Red lane (interactive human shell only)
|
||||
|
||||
```bash
|
||||
# 1) Qonto dashboard (browser):
|
||||
# - /settings/integrations → create API key
|
||||
# - copy organization ID
|
||||
# - note plan tier + monthly fee (CostRunRate row 4)
|
||||
# - optional while there: recent HUB31 / desk-rent debit amount (row 1)
|
||||
|
||||
# 2) OpenBao (private terminal — never paste key into chat/agent):
|
||||
bao login -method=oidc -path=netkingdom # platform-admin or write-capable role
|
||||
umask 077
|
||||
# put key into /tmp/qonto.key and org id into /tmp/qonto.org (editor / paste)
|
||||
bao kv put tenants/binky/qonto/api \
|
||||
QONTO_API_KEY=@/tmp/qonto.key \
|
||||
QONTO_ORGANIZATION_ID=@/tmp/qonto.org
|
||||
shred -u /tmp/qonto.key /tmp/qonto.org
|
||||
```
|
||||
|
||||
### B. Platform apply (after or before A — metadata only, no secret write)
|
||||
|
||||
```bash
|
||||
cd ~/railiance-platform
|
||||
# after platform-operator approval recorded on CCR-2026-0008:
|
||||
python3 scripts/credential-change.py applier-dry-run CCR-2026-0008
|
||||
python3 scripts/credential-change.py applier-apply CCR-2026-0008
|
||||
# re-apply agent-high-risk-boundary if that policy is live-managed separately
|
||||
```
|
||||
|
||||
### C. Promote + first pull (agent or human, Blue lane)
|
||||
|
||||
```bash
|
||||
# capabilities-safe (never bao kv get for deny tests)
|
||||
LANE=$(bao token create -policy=workload-kv-read-binky-qonto-api -ttl=2m -field=token)
|
||||
bao token capabilities "$LANE" tenants/data/binky/qonto/api # expect read
|
||||
bao token revoke "$LANE"
|
||||
|
||||
# promote ops-warden catalog entry status: draft → active (see playbook)
|
||||
# then:
|
||||
warden access binky-qonto-api --all --exec -- \
|
||||
qonto-mcp-server # read tools only: org, accounts, transactions
|
||||
|
||||
# Update finance/CostRunRate.md rows 1 + 4 with verified amounts;
|
||||
# log evidence metadata (dates, counterparties, amounts) — no bulk statements in git.
|
||||
```
|
||||
| Item | Value |
|
||||
| --- | --- |
|
||||
| Org | Binky Hedgehog GmbH |
|
||||
| Main balance | 2 185,94 € |
|
||||
| Desk (HUB31) | **297,50 €/mo** |
|
||||
| Qonto plan fee | **70,80 €/mo** (since 2025-10; was 22,80 / 35,40 earlier) |
|
||||
| Evidence | `finance/qonto-first-pull-2026-07-21.json` |
|
||||
|
||||
**Harness read-only allow-list (enforce at session wire-up):** organization,
|
||||
accounts, transactions, statements metadata, attachments metadata, labels.
|
||||
Never: cards, invoicing, payment requests, transfers.
|
||||
|
||||
### Consumer fetch (after active)
|
||||
|
||||
```bash
|
||||
bao login -method=oidc -path=netkingdom role=binky-qonto-api-workload-kv-read
|
||||
umask 077
|
||||
bao kv get -field=API_KEY tenants/binky/qonto-api > /tmp/qonto.key
|
||||
bao kv get -field=API_USER tenants/binky/qonto-api > /tmp/qonto.user
|
||||
export QONTO_API_KEY="$(cat /tmp/qonto.key)"
|
||||
export QONTO_ORGANIZATION_ID="$(cat /tmp/qonto.user)"
|
||||
shred -u /tmp/qonto.key /tmp/qonto.user
|
||||
# Authorization for thirdparty API: "$QONTO_ORGANIZATION_ID:$QONTO_API_KEY"
|
||||
```
|
||||
|
||||
## See also
|
||||
|
||||
- `integrations/company-email-openbao.md` — custody pattern being mirrored
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Qonto MCP integration: bank account as agent-readable finance source"
|
||||
domain: infotech
|
||||
repo: binky-control
|
||||
status: active
|
||||
status: finished
|
||||
owner: codex
|
||||
topic_slug: the-custodian
|
||||
created: "2026-07-19"
|
||||
|
|
@ -13,16 +13,12 @@ state_hub_workstream_id: "6139db83-5d4b-4492-a77f-fc9550a0a4f9"
|
|||
---
|
||||
|
||||
Connect the company Qonto account to the agent infrastructure via the
|
||||
**self-hosted** `qonto/qonto-mcp-server` (API key + organization ID), read
|
||||
**self-hosted** `qonto/qonto-mcp-server` (API key + organization login), read
|
||||
scopes first — **payments/transfers are Red lane forever**. Originates from
|
||||
AWQ-010 (founder direction 2026-07-18: "integrations like this should help
|
||||
with the automated company approach a lot" — arrange soon). Credential lane
|
||||
via ops-warden/OpenBao (`tenants/binky/qonto`), same custody pattern as
|
||||
company-email (`integrations/company-email-openbao.md`); **no claude.ai
|
||||
native integrations** — harness/MCP lane only. Main accounting stays DATEV
|
||||
Unternehmen Online (DUO): Qonto MCP complements, does not replace, the
|
||||
DUO/StB lane. The working MCP is a substantive argument FOR keeping Qonto
|
||||
despite plan cost (OH-2026-003).
|
||||
AWQ-010 (founder direction 2026-07-18). Credential lane via ops-warden/OpenBao
|
||||
(`tenants/binky/qonto-api`, fields `API_KEY` + `API_USER`); **no claude.ai
|
||||
native integrations** — harness/MCP / thirdparty API lane only. Main accounting
|
||||
stays DATEV Unternehmen Online (DUO).
|
||||
|
||||
## Task: Qonto MCP capabilities and docs review
|
||||
|
||||
|
|
@ -42,10 +38,9 @@ state_hub_task_id: "e066a222-1608-45ce-96a7-cbf191a39a9b"
|
|||
|
||||
## Task: Credential lane design — ops-warden/OpenBao custody
|
||||
|
||||
Design the OpenBao lane `tenants/binky/qonto` (fields `QONTO_API_KEY`,
|
||||
`QONTO_ORGANIZATION_ID`), warden catalog entry, and the founder Red-lane
|
||||
provision procedure — mirroring the company-email-imap pattern. Metadata and
|
||||
design only; no secret values, provisioning is founder Red lane. Green lane.
|
||||
Design the OpenBao lane for Qonto API credentials, warden catalog entry, and
|
||||
the founder Red-lane provision procedure — mirroring company-email-imap.
|
||||
Metadata and design only; no secret values. Green lane.
|
||||
|
||||
```task
|
||||
id: BINKY-WP-0005-T02
|
||||
|
|
@ -73,8 +68,7 @@ state_hub_task_id: "6c4a475d-9db7-4488-8563-10c82fa78f51"
|
|||
|
||||
Prepare the founder approval package: DEC entry covering API key creation in
|
||||
the Qonto dashboard, OpenBao provision, and the read-only boundary. Note the
|
||||
DUO complement (not replacement) and the OH-2026-003 tie-in (check API/plan
|
||||
prerequisites while in the dashboard). Green lane.
|
||||
DUO complement (not replacement) and the OH-2026-003 tie-in. Green lane.
|
||||
|
||||
```task
|
||||
id: BINKY-WP-0005-T04
|
||||
|
|
@ -90,15 +84,26 @@ first read-only balance/transaction pull through the harness lane, update
|
|||
`finance/CostRunRate.md` TBC rows (desk rent, Qonto plan) with verified
|
||||
figures, and log evidence metadata. Blue lane.
|
||||
|
||||
**2026-07-21 prep (agent):** CCR-2026-0008 + policy + agent-high-risk-boundary
|
||||
deny path (railiance-platform); ops-warden catalog `binky-qonto-api` draft +
|
||||
playbook; OH/T05 copy-paste runbook in `integrations/qonto-mcp.md`. Still
|
||||
**blocked on founder Red-lane** (OH-2026-003): API key + `bao kv put`, then
|
||||
CCR metadata apply + first pull.
|
||||
**2026-07-21 done:** Secret at `tenants/binky/qonto-api` (`API_KEY`+`API_USER`).
|
||||
CCR-2026-0008 active (policy + OIDC role + agent-high-risk-boundary). Catalog
|
||||
`binky-qonto-api` active. First pull via thirdparty API v2 (122 txs): main
|
||||
balance 2 185,94 €; HUB31 desk **297,50 €/mo**; Qonto plan **70,80 €/mo**.
|
||||
Evidence: `finance/qonto-first-pull-2026-07-21.json`. CostRunRate v2.
|
||||
|
||||
```task
|
||||
id: BINKY-WP-0005-T05
|
||||
status: wait
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "e4b2119b-6f89-44d8-879d-73bf225307f7"
|
||||
```
|
||||
|
||||
## Closure review
|
||||
|
||||
- **Scope complete:** design (T01–T03), DEC-2026-004 (T04), live lane + first
|
||||
pull + CostRunRate (T05).
|
||||
- **Live path note:** custody is `tenants/binky/qonto-api` with fields
|
||||
`API_KEY` / `API_USER` (not the earlier design draft `…/qonto/api` +
|
||||
`QONTO_*` field names). Consumers map to MCP env names at use time.
|
||||
- **Out of scope / follow-on:** recurring Finance Steward harness session
|
||||
wiring; Qonto *plan change* (OH-2026-003 data now available, decision Red);
|
||||
DATEV/StB replacement still separate.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue