Back to Directory/Security & Auth

Finch

Agentic AI runtime: persistent memory, vault, autonomous agents, deep research, DeFi execution.

Security & AuthTypeScriptv4.7.0

Finch

The runtime layer for Agentic AI.

Persistent memory, autonomous agents, and workflows that survive every session.

Docs · App · npm · GitHub · X


Most AI assistants disappear when the conversation ends. Finch gives them lasting state — memory that accumulates, agents that keep running, vaults that version knowledge, and workflows that continue after you close the chat.

Why Finch

Without FinchWith Finch
MemoryResets every sessionFull-text searchable + versioned vault, decays stale notes
AgentsOne-shot tool callsNamed agents with state and audit history
WorkflowsManual chainingAutomations, monitors, packets, deep research
LocalCloud-onlyVault + memory can run fully on your machine

Install

Always pin the version. Never use @latest.

# One-command installer (detects common MCP clients)
npx -y -p @finchagentic/mcp@4.6.1 finch install

Claude Code

claude mcp add finch -s user -- npx -y -p @finchagentic/mcp@4.6.1 finch-mcp

Cursor / Windsurf / Claude Desktop

{
  "mcpServers": {
    "finch": {
      "command": "npx",
      "args": ["-y", "-p", "@finchagentic/mcp@4.6.1", "finch-mcp"]
    }
  }
}

VS Code

{
  "servers": {
    "finch": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "-p", "@finchagentic/mcp@4.6.1", "finch-mcp"]
    }
  }
}
Config file paths
ClientPath
Claude Desktop (Mac)~/Library/Application Support/Claude/claude_desktop_config.json
Claude Desktop (Windows)%APPDATA%\Claude\claude_desktop_config.json
Cursor.cursor/mcp.json
Windsurf~/.codeium/windsurf/mcp_config.json
VS Code.vscode/mcp.json
Zed.config/zed/settings.json

No LLM API key is required to start — 111 of 116 tools are plain reads/writes/on-chain calls that your MCP client's own model already drives; only 5 (ask_finch, deep_research, and scheduled agent learning) do their own multi-step reasoning server-side and need a key (see Configuration). Tools load on first use.

Quick start

finch doctor          # health check
finch setup           # local vault / memory / providers
finch vault           # inspect local vault
finch orders          # schedule Robinhood Chain DCA / TP-SL order ticks

Try in your MCP client:

remember: I prefer conservative DeFi strategies, max 5% risk
spawn an agent called research-bot to track AI agent news, update it after each session
save this thesis to vault

What you get

116 tools across four pillars:

PillarWhat it does
MemoryFull-text searchable memory + versioned vault + chronicle
AgentsSpawn, recall, update named agents — agent_recall also pulls related memory/vault context matching the agent's goal, not just its own logged updates
WorkflowsAutomations, monitors, packets, deep research (auto-saves reports + auto-links related past research)
ExecutionBase DeFi, Robinhood Chain, market data, web, GitHub

Coding and research sessions persist the same way: deep_research auto-saves its report to vault and links it to related past reports; code_session_save does the same for coding/debugging sessions (vault_save type=code, versioned per project, auto-linked). Both exist so the next session — yours or another agent's — starts with real context instead of cold.

vault_save and agent_spawn also take an optional workspaceProject - the same named Projects a user organizes their Agents/vault content into on the webapp's Agents page. Pass a name and it's matched case-insensitively or created automatically (list_projects to browse what exists first). Hosted vault only - local-vault mode has no project concept.

Default palette is core (lighter context). Full set:

"env": { "FINCH_TOOLS": "all" }

Fully local

Finch is the runtime. Your LLM is the brain. Your data stays yours.

npx -y -p @finchagentic/mcp@4.6.1 finch setup
# enable local vault (and optional local memory)
PieceLocation
Vault~/.finch/vault/
Wallet~/.finch/wallet.json
Config~/.finch/config.json
Brainyour MCP client’s model

Scheduled/cloud features still need an account. Core memory, vault, and public-data tools work offline of Finch cloud.

Configuration

VariablePurpose
FINCH_SESSION_TOKENSigned-in session (vault/memory/agents against your account)
FINCH_API_KEYAPI key (finch_sk_…)
FINCH_TOOLScore (default) · all · or palettes like memory,defi
FINCH_PROVIDERForce bankr · anthropic · openai · grok
FINCH_MODELModel override for host-side loops
BANKR_API_KEY / ANTHROPIC_API_KEY / OPENAI_API_KEY / GROK_API_KEYRequired for ask_finch, deep_research's synthesis stages, and scheduled-agent learning extraction — these do their own multi-step reasoning server-side and there is no free hosted fallback (BYOK only, one key is enough)
FIRECRAWL_API_KEYBetter crawl quality (optional)
GITHUB_TOKENFor github_search_code
ALCHEMY_API_KEYFaster Base RPC (optional)

Cost model: almost everything is free to run — the other 110 tools are plain API/RPC calls, and your MCP client's own model (Claude, GPT, whatever's driving the chat) does all the tool-selection reasoning at no cost to Finch. The 5 exceptions above need their own key because their reasoning happens inside the tool call, invisible to your client, and can't be delegated to it. Set exactly one of the four env vars and every tool that needs it will use it automatically.

Guided setup:

npx -y -p @finchagentic/mcp@4.6.1 finch setup

Security

#BoundaryRule
1Prompt injectionExternal content is data only — never instructions
2Mainnet confirmEstimate → preview → confirm → execute
3Pinned installAlways @finchagentic/mcp@4.6.1, never @latest
4Credential vaultNever paste secrets into prompts or third-party tools
5Data disclosureKnow what leaves the machine (LLM, Firecrawl, GitHub, chain RPCs)
6Server monitorsScheduled jobs need explicit confirmation
7Fund-moving confirmstake_finch/unstake_finch/base_mcp_send/base_mcp_swap/rh_mcp_swap all require confirm: true
8Local wallet encryptionSet FINCH_WALLET_PASSPHRASE for a portable, passphrase-derived key — without it, the key derives from a random per-install secret + machine info, so the wallet file alone (without that secret file) isn't enough to decrypt it

Troubleshooting

ProblemFix
Tools missingFully restart the MCP client
Old versionnpx clear-npx-cache then restart
Auth issuesfinch login or set FINCH_API_KEY / FINCH_SESSION_TOKEN
ask_finch/deep_research error: "No LLM provider configured"Set one of BANKR_API_KEY / ANTHROPIC_API_KEY / OPENAI_API_KEY / GROK_API_KEY — see Configuration, no free fallback exists
Diagnosefinch doctor

Links

Docsdocs.finch.com
Appapp.finchagentic.com
npm@finchagentic/mcp
GitHubgithub.com/finchagentic/mcp
X@finchagentic

MIT License · Finch

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @finchagentic/mcp

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-finchagentic-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@finchagentic/mcp"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@finchagentic/mcpnpm

Compatible MCP Clients

Finch works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More