Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

🎃 New adapter: Qonto business banking (read-only)

Aperta
#1,013 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
72/100
Tipo di issue
Funzionalità
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
json, typescript
Ambito
backend

Direzione di ricerca

Start from packages/backend/src/adapters/fr/pennylane.json as the closest French finance adapter, and check the composite Authorization header in de/jtl-wawi.json:22. Create fr/qonto.json with the seven read-only tools, then add fr/qonto.live.spec.ts. Done when npx jest src/adapters/fr/qonto passes in packages/backend, scripts/validate-adapters.mjs --warn is clean, and no tool uses a non-GET method.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

enhancement good first issue hacktoberfest help wanted

Part of the October Challenge #997.

Why

Qonto is one of Europe's largest business accounts for SMBs and freelancers, with large user bases in France, Italy, Germany and Spain. Its Business API covers transactions, client and supplier invoices, and quotes. With an adapter, a user could ask "which card payments over €500 last month have no receipt?", "list unpaid client invoices due this week" or "what came in from customer X?". The catalog has Revolut Business and Wise but no Qonto (ls packages/backend/src/adapters/*/ | grep -i qonto finds nothing).

Self-hosted vs Cloud

  • Self-hosted: available in Community and Business. Catalog adapters have no edition gating.
  • Cloud (DEPLOYMENT_MODE=cloud): available. thirdparty.qonto.com is public, so the SSRF guard allows it. On Cloud trial plans, installs count toward the trial's connector limit (license-guard.service.ts:65).
  • Who can use it: any role except VIEWER can install it (adapters.controller.ts:207). The connector and its encrypted authConfig belong to the installer's organization, so bank credentials are per organization and never shared. Because this is bank data, instructions must recommend assigning the connector only to MCP servers whose users may see the company's bank account.

What to build

packages/backend/src/adapters/fr/qonto.json (Qonto is French; the fr/ region already holds Pennylane and Sellsy). Start with npm run adapter:new -- qonto --region fr --auth API_KEY.

  • API docs: https://docs.qonto.com/get-started/business-api/authentication/api-key and the reference at https://docs.qonto.com (agent-friendly index: https://docs.qonto.com/llms.txt).
  • Base URL: https://thirdparty.qonto.com/v2.
  • Auth: API_KEY with headerName: "Authorization" and apiKey: "{{QONTO_LOGIN}}:{{QONTO_SECRET_KEY}}". Login and secret are joined by a colon with no Base64 and no Bearer. The same composite-header trick is used in de/jtl-wawi.json:22. Credentials: Qonto web app → Integrations & Partnerships → API key.
  • Category: banking. probe: qonto_get_organization.
  • Pagination: page, per_page. Filters use bracket names (filter[status]); map them in queryParams as de/clockodo.json:66 does.
Tool Endpoint Expected hints
qonto_get_organization GET /organization (returns the bank accounts with their id/IBAN) read-only
qonto_list_transactions GET /transactions (bank_account_id or iban required; settled_at_from, settled_at_to, side, status[], operation_type[], page, per_page) read-only
qonto_get_transaction GET /transactions/{id} read-only
qonto_list_client_invoices GET /client_invoices (status, due date and created-at ranges) read-only
qonto_list_supplier_invoices GET /supplier_invoices (filter[status], filter[created_at_from], query) read-only
qonto_list_clients GET /clients (filter[name], filter[vat_number], filter[email]) read-only
qonto_list_quotes GET /quotes read-only

All tools are GET, so they are derived as readOnlyHint: true, destructiveHint: false (docs/tool-definition.md:503-545). The tool descriptions must say that qonto_list_transactions needs a bank account id from qonto_get_organization first.

Where to look

  • packages/backend/src/adapters/fr/pennylane.json — a French finance adapter of similar size (10 tools).
  • packages/backend/src/adapters/intl/revolut-business.json — another banking adapter; copy the tone of its instructions for money data.
  • packages/backend/src/adapters/de/jtl-wawi.json:22 — custom Authorization value through API_KEY.
  • packages/backend/src/adapters/de/clockodo.json:66 — filter[...] query params.
  • packages/backend/src/adapters/intl/todoist.live.spec.ts — spec template; live calls behind RUN_QONTO_LIVE=1.
  • .github/CONTRIBUTING.md:136 — the "Add an adapter" checklist; #982 — good-first-issue adapter guide.

Acceptance criteria

  • fr/qonto.json exists with the 7 read-only tools, requiredEnvVars: ["QONTO_LOGIN","QONTO_SECRET_KEY"], and a docsUrl.
  • No tool uses POST/PUT/PATCH/DELETE (asserted in the spec).
  • validate-adapters.mjs --warn is clean (the validator requires instructions ≥ 800 chars and each tool description ≥ 60 chars, scripts/validate-adapters.mjs:32); catalog.ts is regenerated; adapter-count.mjs --check passes.
  • fr/qonto.live.spec.ts: static checks (base URL, Authorization header template contains :, read-only methods); with RUN_QONTO_LIVE=1 it calls /organization and /transactions in the sandbox. npx jest src/adapters/fr/qonto passes in packages/backend.
  • Logo at packages/frontend/public/logos/connectors/qonto.svg.
  • instructions explain the sandbox: base URL https://thirdparty-sandbox.staging.qonto.co/v2 plus header X-Qonto-Staging-Token (connector headers can be edited after install).
  • Docs updated: optional content/guides/en/qonto-to-mcp.mdx.

Out of scope

  • Any money movement: SEPA/internal transfers, beneficiaries, cards, bulk transfers. Those need OAuth plus strong customer authentication, and are a deliberate non-goal for a first adapter.
  • Creating or deleting invoices, clients or attachments; attachment upload (multipart).
  • The OAuth flow (OAUTH2). It can come later if Qonto partners ask.

Free / sandbox account: sign up on the Qonto Developer Portal (https://developers.qonto.com) and create an application. It gives you a sandbox organization with test data and a staging token. No real Qonto account needed.

Size

S (a few hours)

How to claim

Comment "I'd like to work on this" and we'll assign you. Rules in #997.

Lingua principale
TypeScript
Stelle
856
Fork
82
Merge medio
8h 27m
PR unite (30g)
104

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di HelpCode-ai/anythingmcp

Tutte le issue di HelpCode-ai/anythingmcp

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.