A policy governed qonto domain API and MCP assistant for binky-control.
Find a file
tegwick c3e69373ca QONTO-WP-0003-T05: pin REST/MCP audit-schema parity with a test
CapabilityService._emit_audit was already the single audit call site for
both transports since T02, but nothing failed if a future change diverged
one transport's shape. Add tests/test_audit_parity.py: same capability
called through protocol="rest" and protocol="mcp" (allow path and deny
path) must produce identical audit events except request_id/timestamp/
latency_ms (expected to vary) and protocol (expected to differ). Also pins
down that no audit event ever contains a secret-shaped field name.

Confirmed via grep: no State Hub coupling anywhere in src/qonto_assistant/
-- the only audit sink is AuditLogger, so there's no per-call hot-path
write to accidentally wire up.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 11:01:16 +02:00
docs QONTO-WP-0003-T04: document finance-qonto-read tool profile contract 2026-07-23 09:48:36 +02:00
research Bootstrap qonto-assistant: intent, blueprint, research, workplans 2026-07-21 23:32:24 +02:00
scripts Complete Phase 1: policy kernel, REST service, and local smoke tooling 2026-07-22 21:21:05 +02:00
specs Seeded intent and initial workplan 2026-07-22 00:31:50 +02:00
src/qonto_assistant QONTO-WP-0003-T03: MCP client auth + shared multi-harness config snippet 2026-07-23 09:41:25 +02:00
tests QONTO-WP-0003-T05: pin REST/MCP audit-schema parity with a test 2026-07-23 11:01:16 +02:00
workplans QONTO-WP-0003-T05: pin REST/MCP audit-schema parity with a test 2026-07-23 11:01:16 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-07-23 09:48:55 +02:00
.gitignore Bootstrap qonto-assistant: intent, blueprint, research, workplans 2026-07-21 23:32:24 +02:00
.repo-classification.yaml Complete Phase 1: policy kernel, REST service, and local smoke tooling 2026-07-22 21:21:05 +02:00
AGENTS.md Complete Phase 1: policy kernel, REST service, and local smoke tooling 2026-07-22 21:21:05 +02:00
INTENT.md Seeded intent and initial workplan 2026-07-22 00:31:50 +02:00
LICENSE Initial commit 2026-07-21 21:19:44 +00:00
Makefile Complete Phase 1: policy kernel, REST service, and local smoke tooling 2026-07-22 21:21:05 +02:00
pyproject.toml QONTO-WP-0003-T01: MCP adapter skeleton on shared capability core 2026-07-22 21:41:24 +02:00
README.md QONTO-WP-0003-T03: MCP client auth + shared multi-harness config snippet 2026-07-23 09:41:25 +02:00
SCOPE.md Bootstrap qonto-assistant: intent, blueprint, research, workplans 2026-07-21 23:32:24 +02:00
WORK-RECORDS.md chore(consistency): sync WORK-RECORDS.md for QONTO-WP-0003-T04 [auto] 2026-07-23 09:49:05 +02:00

qonto-assistant

Policy-governed Qonto domain API and MCP assistant for Binky (and later multi-tenant dogfood).

One choke point for bank access across every coding agent and harness. Clients never hold the Qonto API key. v1 policy: read for awareness only — no spend, no volume-cost actions.

Start here

Doc What
INTENT.md Why this exists; boundaries
specs/ArchitectureBlueprint.md Architecture, phases, policy model
research/2026-07-21-mcp-gateway-and-governed-domain-assistant.md External + internal research
docs/operator-runbook.md How to run and verify Phase 1

Status

Phase 1 runtime is implemented:

  • Python 3.12 service under src/qonto_assistant/
  • default-deny YAML policy
  • Qonto read-only client (organization, transactions)
  • REST endpoints: /v1/health, /v1/accounts, /v1/transactions, /v1/snapshot
  • audit metadata, rate limiting, concurrency bounds, tests

Phase 2 (MCP surface, workplans/QONTO-WP-0003-mcp-surface.md) is in progress: a streamable-HTTP MCP adapter is mounted at /mcp on the same capability core and policy kernel as REST, with tools qonto_org_summary, qonto_list_transactions, and qonto_cost_run_rate_hints. The endpoint is gated by a shared-secret bearer token (QONTO_ASSISTANT_MCP_TOKEN) — see docs/mcp-integration.md for the auth model, its gap vs. the OIDC/workload target, and the shared multi-harness client config snippet. The finance-qonto-read tool profile is not yet implemented.

Current verification:

  • PYTHONPATH=src ../state-hub/.venv/bin/python -m pytest16 passed
  • python3 -m compileall src tests scripts
  • ../state-hub/.venv/bin/python scripts/smoke_rest_api.py --python ../state-hub/.venv/bin/python

Local fixture-backed smoke mode is available through QONTO_FIXTURE_DIR, so the service can be exercised without real Qonto credentials. The smoke path checks both a 31-day recent snapshot and a 90-day recurring-cost snapshot.

Normal local workflow, when toolchain support exists:

make install-dev
make test
make run
  • OpenBao lane: tenants/binky/qonto-api (ops-warden binky-qonto-api)
  • First pull / CostRunRate: binky-control BINKY-WP-0005