SettingsAI & API Connections

AI & API Connections

Connect your own AI assistant or app to Forbidden Finance, and control exactly what it can see and change. Create a connection, choose its permissions and privacy settings, get a show-once key, and revoke it any time. Premium, limited beta.

Overview

AI & API Connections let you connect your own tools to Forbidden Finance — most often an AI assistant like Claude, ChatGPT, or Perplexity, so it can answer questions like "how much did I spend on dining last month?" from your real data without you copying anything by hand. You can also connect your own script or spreadsheet. This page is where you create and manage those connections; to set an assistant up step by step, see Connect Your AI Assistant.

You stay in control of every connection. For each one you decide what it can do, what it can change, and — just as importantly — what it can see. Your privacy choices are enforced on Forbidden Finance's servers, not by the app you connect, so a connection only ever receives the filtered view you set up.

Connections are a Premium feature and are currently in limited beta. What a connection can do may change while the beta is open.
This is a different setting from Settings > AI, which holds the single Let AI read my receipts switch for receipt scanning. That switch is about Forbidden Finance reading your receipts; this page is about your tools reading your Forbidden Finance data. See AI.

Requirements

  • Tier: Premium. AI & API Connections do not appear on Free, Starter, or Pro.
  • The app or assistant you want to connect. Most people connect an AI assistant over MCP — see Connect Your AI Assistant. Developers can call the API directly — see Getting Started with the API.

How to Create a Connection

Open AI & API Connections

Go to Settings > AI & API Connections and tap New Connection (or the + button).

Name it

Give the connection a name you will recognize later, like "Claude on my laptop" or "Budget spreadsheet." The name is just for you — it helps you tell connections apart when you manage or revoke them.

Choose what it can read

Pick the areas of data this connection may read: accounts, connection sync status, transactions, categories, budgets, goals, net worth, investments, liabilities and debt, bills and recurring, and spending insights. Grant only what the tool actually needs.

Decide whether it may change anything

A separate Allow changes switch sits below, and it is off by default. Leave it off and the connection is read-only no matter what else is selected.

Turn it on and you choose which kinds of change are permitted — see the table below. You can leave it off now and turn it on later.

Set its privacy

Choose what this connection is not allowed to see:

  • Hide fields — strip specific details, like merchant names, transaction amounts, memos, purchase locations, or account balances, from everything the connection receives.
  • Exclude accounts — keep entire accounts invisible to this connection.
  • Exclude categories — keep entire spending categories out of view.

The picker warns you when hiding a field (like an amount) also switches off insights that could rebuild it. See Data Privacy & Redaction for the full model.

Review and create

Check the summary — name, what it can read, whether changes are allowed, and your privacy choices — then tap Create Connection.

The Five Change Permissions

Allow changes is the master switch: with it off, a connection can only read. With it on, these are the permissions you can grant, individually.

PermissionWhat it allows
Categorize & annotate transactionsSet a transaction's category, tags, memo, or purchase location — singly or in a batch. Nothing else.
Edit transactions (add, change, delete)The above, plus adding a transaction, changing its amount, merchant, description or date, and deleting one.
Manage custom categoriesCreate, rename, restyle, and delete your own categories. The app's built-in categories cannot be changed.
Change budgetsSwitch your active budgeting method.
Change goalsUpdate a goal's name, description, target amount or target date, and log a contribution toward it.
Grant Categorize & annotate transactions on its own for anything you leave to run unattended. It does the whole tidying-up job, and it cannot change an amount or remove a row — that is a property of the permission, not a matter of trusting the app.

Whatever you grant, no connection can move money, close an account, or reach the credentials behind a bank connection. Those operations do not exist in this system.

What Happens After You Create It

  • Your key is shown once. Forbidden Finance generates an API key (it starts with ff_ak_) and displays it a single time. Copy it now and store it somewhere safe, like a password manager. We keep only a fingerprint of the key — we cannot show it again or recover it. If you lose it, revoke the connection and create a new one.
  • A ready-to-paste setup snippet. For AI assistants, the app also shows a configuration snippet you can paste into your assistant's connector settings. See Connect Your AI Assistant.
  • A confirmation email. We email you whenever a new connection is created, so a connection can never appear on your account without your knowledge.
Treat your ff_ak_ key like a password. Anyone who has it can read your data within the permissions and privacy limits you set. Never paste it into a chat message — it belongs only in your app's connector settings.

Managing a Connection

From Settings > AI & API Connections you see every connection you have created, with its name and status. Tap one to:

  • Change what it can read — grant or remove areas of data.
  • Turn Allow changes on or off, and adjust which change permissions it holds.
  • Change privacy settings — adjust which fields, accounts, and categories are hidden.

Your changes are enforced the moment you save them. You do not need to reconnect the app, and nothing has to restart.

Turning Allow changes off is a useful middle step: the connection keeps working read-only, and its permissions stay configured for whenever you want them back.

Revoking a Connection

If you no longer use an app, or you think a key may have leaked, revoke the connection:

Open the connection

Go to Settings > AI & API Connections and tap the connection you want to remove.

Revoke it

Tap Revoke and confirm. The connection's key stops working immediately, and any app using it loses access.

Revoking is instant and final. If you need the app again later, create a fresh connection with a new key. Revoking one connection never affects your others.

See What an App Accessed

Every connection keeps an audit log — a running record of what it did and when. Open a connection and tap Activity (or Audit log) to see each request: what was accessed, which permission was used, and whether it succeeded. Use it to confirm an app is behaving as expected, or to spot activity you did not expect. If something looks wrong, revoke the connection.

Your Privacy Model

The point of this feature is that you decide what leaves Forbidden Finance:

  • You choose the fields. There are 18 you can hide, across transactions, accounts, bank connections, investments, liabilities, and goals. A hidden field is left out of what the app receives — not blanked or masked, simply omitted. There is nothing for the app to reverse-engineer.
  • You choose the accounts and categories. Excluded ones are invisible to the connection: absent from lists, absent from search, and indistinguishable from data that does not exist.
  • Hiding covers changes too. A connection cannot edit a field it is not allowed to see; the attempt is refused.
  • We enforce it, not the app. Your choices are applied on Forbidden Finance's servers, at the one point every request passes through. A connected app cannot opt out of them, request a hidden field, or widen its own access.
  • Your own view never changes. Redaction and exclusion apply only to connections. What you see in the app is always complete.

Read the full explanation in Data Privacy & Redaction.

Key Details

  • Read-first by design. A new connection is read-only unless you deliberately turn on Allow changes, and even then it holds only the specific permissions you granted.
  • Changes to bank-synced transactions are recoverable. The first time anything edits a bank-synced transaction, the value the bank recorded is kept, and it can be restored later. Bank-synced transactions can never be deleted at all. Transactions you added yourself, and categories you delete, are gone for good — which is why those permissions are separate.
  • Categorizing does not rewrite your rules. A connection filing one transaction under Dining does not create a merchant rule or change how anything else is categorized. Rules stay yours to set in the app.
  • Switching budgets is a real change. It archives your current budget and creates a new one. If the budget is shared with a partner, the switch needs your partner's approval in the app first.
  • One key per connection. Each connection has its own key, its own permissions, and its own audit log, so you can give different apps different levels of access and revoke them independently.

Tips

Start narrow. Give a new connection only the areas it needs, leave Allow changes off, and exclude any account you would rather keep private. You can always widen access later.
Create a separate connection per app. That way each has its own key and audit log, and revoking one never disrupts the others.
If you ever suspect a key has leaked, revoke that connection immediately and create a new one. Revocation takes effect right away.

Frequently Asked Questions

Do I need this to use the app?

No. AI & API Connections are entirely optional and only for connecting your own tools. The app works fully without ever creating one.

Can a connected app change my data?

Only if you turn on Allow changes, and then only within the specific permissions you granted — transactions, categories, budgets, and goals. Left off (the default), a connection can only read. No connection can move money, close an account, or reach your bank login.

How is this different from Settings > AI?

Settings > AI controls whether Forbidden Finance reads your receipts with AI. This page controls whether your own tools — an AI assistant, a script — can read your Forbidden Finance data. They are independent settings.

Can an app see accounts I hid from it?

No. Excluded accounts and categories are enforced on our servers. The app cannot see them, search for them, or tell that they exist.

I lost my key. Can you resend it?

No. We store only a fingerprint of your key and cannot recover or re-display it. Revoke the connection and create a new one to get a fresh key.

How do I connect Claude, ChatGPT, or Perplexity?

Create a connection here, then follow Connect Your AI Assistant for the setup for each client.

Is my financial data used to train an AI?

Forbidden Finance does not send your data to any AI model through this feature. When you connect your own assistant, that assistant and its provider handle whatever you ask under their own terms. Use permissions, field hiding, and account exclusion to limit what any assistant can read.

Connect Your AI Assistant

Set up Claude, ChatGPT, or Perplexity.

Data Privacy & Redaction

How field hiding and exclusion work.

Getting Started with the API

Call the API from your own scripts.

Subscription & Plans

See what Premium includes.

Need more help? Contact us at [email protected].