Permissions, end to end

Security comes first.

Connect accounts, view your finances, and choose whether a supported AI client can access your Warm data. You can turn access off at any time.

Institution

You sign in and choose the accounts to connect. Warm never receives your bank password.

Plaid

Plaid secures the connection and returns approved financial data.

Warm

Warm organizes balances, activity, spending, and trends with a read-only connection.

You

View everything in your dashboard, or connect a supported AI client with a revocable API key.

What each connection can do.

Permission Where What it allows Boundary
Authentication Your institution and Plaid

You approve the financial accounts connected to Warm.

Warm does not receive or store your bank username or password.

Read-only financial context Plaid → Warm

Balances and transaction data can flow into your Warm account.

Warm cannot initiate transfers, make payments, or change bank accounts.

Dashboard visibility Warm → You

You can view accounts, spending, recurring costs, and net worth.

Warm informs and organizes; it does not provide financial advice.

Optional MCP access Warm → Supported client

A client can read Warm data and invoke approved Warm record automation.

MCP is opt-in, local, and cannot move money or write back to your bank.

Revocable API keys Settings

A key authorizes access to the owner's Warm data and documented tools.

Delete the key in Settings to stop that access.