What connecting an assistant means
Some questions are faster to ask than to look up. "How much did I spend on coffee this month?" "What do I still owe?" Pocketbird can hand those questions to an AI assistant you already use — Claude — and let it answer from your real records instead of you retyping figures into a chat.
Nothing here is on until you switch it on. You start the connection yourself, you approve exactly what the assistant may see, and every single request it makes afterwards is re-checked against your switches on the server. Reading is one permission; creating and editing your records is a separate one, off by default.
Be clear-eyed about the trade: whatever you ask about is sent to the assistant's provider — for Claude, that is Anthropic PBC in the United States. The app's privacy notice gives this its own section, "Connecting an AI assistant".
- Everything is controlled from one screen: More → Settings → "Privacy & Security" / "ความเป็นส่วนตัวและความปลอดภัย" → "Connected Apps" / "แอปที่เชื่อมต่อ". There is no shortcut and no link into it — you tap through Settings.
- An assistant reads inside a read-only session locked to your own account, so a connection on your account can never reach anyone else's data.
- The two AI permissions are deliberately left out of the first-run privacy questions. You are asked for them at the moment you connect an assistant, not before you have any reason to care.
Connecting Claude in one tap
The normal way in starts inside Claude, not inside Pocketbird. You point Claude at Pocketbird's address, sign in to your own account in a browser, read a plain list of what the assistant is asking for, and approve. No token to copy, nothing to install.
- In Pocketbird, open More → Settings → Privacy & Security → Connected Apps and copy the address on the "MCP server URL" / "URL เซิร์ฟเวอร์ MCP" row. "How to connect" / "วิธีเชื่อมต่อ" below it has the same steps in front of you.
- "In the Claude app or claude.ai, open Settings → Connectors → Add custom connector."
- "Paste the MCP server URL above and confirm."
- "Sign in with your Pocketbird account when asked, review what the assistant may access, and approve."
- The connection then appears under "AI assistant connections" / "การเชื่อมต่อผู้ช่วย AI" back in Connected Apps, where you can revoke it at any time.
The approval page is a web page in your browser, and it is written in English. It is titled "Allow access to your Pocketbird data?", shows which account you are signed in as, and then lists — one line each — what the assistant asked for.
- Under "It will be able to read:" comes one row per thing requested: Transactions, Pockets, Balance & net worth, Debts, Categories, Accounts — each with a one-line description of what it covers.
- If the assistant also asked to change things, an amber block says "It will also be able to create and edit:" and states plainly: "This can change your financial records — not just read them."
- "It will also stay connected until you revoke access, without asking again." appears when the assistant asked to stay signed in — which is the normal case, and the reason the connection is yours to end, not its.
- Under the "Approve" button sits the sentence worth taking literally: "Only approve if you started this from your AI assistant." An approval page you did not open yourself is the one page to close.
- Approving records your permission for you — you do not have to turn the reading switch on in the app first. The record is written as you, from your own signed-in session.
- Once approved the connection stays live until you revoke it. The assistant quietly renews a short-lived key — 45 minutes at a time — rather than asking you again.
The two master switches
Under "Master switches" / "สวิตช์หลัก" sit two toggles that decide what any assistant may do. They are checked on the server for every request, which makes them the reliable way to stop things — more reliable than the connector list inside Claude, which is only Claude's own view of the world.
- The two are independent answers. Flipping one never touches the other, and neither implies the other in either direction.
- Enforcement fails closed. The server reads your latest answer for each permission before it does anything; if it cannot read one, the answer counts as no.
- A flip is saved on your device and pushed at once — that sync is how the server learns about it. With no connection the change is kept and takes effect the next time the device syncs.
- If an assistant asks for something while a switch is off, it is told in plain language that the permission was withdrawn and that this is a setting in your app, not a fault on the server. Turning the switch back on works on the very next request — no reconnecting, no new token. That message is English only.
What it can read
With reading on, an assistant has thirteen specific ways to look at your account. It never receives a copy of your data as a whole — it asks one narrow question and gets one narrow answer.
- Transactions — newest first, with amount, type, note, date, category name, account, pocket, merchant, tags, counterparty, trip and the needs-review flag. Filterable by date range, category, income or expense, and free text. 50 rows at a time by default, 200 at most; one transaction can also be fetched whole by id.
- A period summary — income, expense, net and how many rows over a date range, grouped by category, by type, by month, or not grouped at all.
- Balances — every account with its type and balance, plus your total balance, what you owe, what you are owed, and net worth.
- Pockets with their target and current amount, and debts with the balance worked out exactly the way the app works it out.
- Your categories with their monthly budgets, your accounts, account-to-account transfers, tags, saved people and merchants, trips, and your recurring rules with the whole schedule — frequency, interval, reminder days, subscription details and all.
- Amounts come back as plain numbers with the currency code THB attached. Everything in this is baht — there is no multi-currency support anywhere in it.
- Net worth and the period summary count personal money only — Shop and business categories are left out. Per-account balances are the exception: those count everything, transfers included.
- Deleted records are never returned, so something you threw away stays thrown away.
- A category summary folds subcategories into their top-level parent, matching the Summary screen; spending with no category gets its own bucket rather than being hidden.
Create and edit — the second permission
When it is available, create-and-edit is a genuinely separate grant. It can only ride on a one-tap connection, never on a token you made by hand, and it is checked against its own master switch on every single request.
- Log a transaction, or up to 25 in one go, and edit or delete one you already have.
- Create and edit accounts, categories and savings pockets, and move money between two of your own accounts.
- Create, edit and delete recurring rules with the full schedule — frequency, interval, day of month, weekday, an end date or a maximum number of occurrences, reminder lead days and subscription details.
- Attach a receipt photo to a transaction.
- Deletes are always soft. A deleted record disappears from every device you own, but it is never yanked out from underneath the sync.
- A pocket's balance is off limits. An assistant can create a pocket and set its target, but the balance moves only through a transfer you make in the app.
- An account's type and a category's type are fixed at creation. So are the cosmetic and advanced details: icon overrides, credit limits, auto-save, archiving, a pocket's lock — none of those can be written.
- A transfer between accounts is exactly that: not income, not expense, no effect on any budget — only the two balances move. Topping up a pocket this way is not supported.
- Every change carries a key, so a retry after a dropped connection returns the original result instead of creating a second copy.
- Rows an assistant creates are ordinary records — they sync like anything else and carry no "made by AI" marker. The terms say the same thing in fewer words: you are responsible for the entries it makes on your behalf.
Reading a connection card
"AI assistant connections" / "การเชื่อมต่อผู้ช่วย AI" lists every one-tap connection you have ever approved, newest first, live and revoked together. Before there is anything to show it reads "No AI assistants connected yet" / "ยังไม่มีผู้ช่วย AI ที่เชื่อมต่อ" with no button under it, because connecting starts inside the assistant, not here.
- The name on the card is whatever the assistant identified itself as — usually "Claude". If it sent no name at all, its raw client id is shown instead, which is still enough to tell two connections apart.
- A revoked card drops its read and edit lines on purpose: a revoked connection can reach nothing, so only its history is left standing.
- The behind-the-scenes permission that lets an assistant stay signed in is never listed as data, because it is not data.
- The list loads once when the screen opens, and there is no pull-to-refresh here. To see it fresh, leave the screen and come back. Revoking reloads it for you.
Cutting off access
Three controls cut access, at three widths. A master switch stops every assistant at once. Revoking a connection stops one assistant. Revoking a token stops one desktop client. All three bite on the next request, not at some later expiry.
- Open More → Settings → Privacy & Security → Connected Apps.
- Swipe the connection's row from right to left and tap "Revoke" / "เพิกถอน".
- Read the dialog "Disconnect this assistant?" / "ยกเลิกการเชื่อมต่อผู้ช่วยนี้?" — it warns that access ends immediately even if the assistant's own app still shows it as connected.
- Tap the red "Revoke Access" / "เพิกถอนการเข้าถึง". A success buzz confirms it; if something fails you get "Something went wrong" / "เกิดข้อผิดพลาดบางอย่าง" and nothing has changed.
- Revoking undoes nothing the assistant already did. Anything it created is an ordinary record in your account — delete it yourself if you want it gone.
- The revoked card stays on the list as your receipt, including the moment access ended, rather than vanishing and leaving you to remember.
Tokens, for Claude Desktop and Claude Code
Claude Desktop and Claude Code connect through a configuration file rather than an Approve button, so they need a token: a long password you paste into their config. This is the advanced path, it lives under "Access tokens (advanced)" / "โทเคนการเข้าถึง (ขั้นสูง)", and it is always read-only.
- Turn the reading master switch on first — "Create Token" / "สร้างโทเคน" stays greyed out until you do.
- Tap "Create Token" and name it in the "Name this token" / "ตั้งชื่อโทเคนนี้" alert — the field suggests "e.g. Claude" / "เช่น Claude". "Create" / "สร้าง" stays disabled until the name has at least one real character; there are no anonymous tokens, because the name is the only thing that will make the revoke list readable later.
- On the "Token Created" / "สร้างโทเคนแล้ว" sheet, tap "Copy Token" / "คัดลอกโทเคน". This is the only time the token is ever shown.
- Tap "How to connect" / "วิธีเชื่อมต่อ" and follow either "Claude Desktop (with a token)" / "Claude Desktop (ใช้โทเคน)" or "Claude Code (with a token)" / "Claude Code (ใช้โทเคน)", then close with "Done" / "เสร็จ".
- Only a fingerprint is stored. The token is generated on your phone, shown once, and sent to the server as a one-way hash — it cannot be read back by anyone, Pocketbird included.
- Every token starts with pbird_ followed by 43 characters, so you can recognise one at a glance in a config file.
- A token can never write. Even if one somehow carried an editing permission the server refuses it — creating and editing is one-tap-connection only.
- A token row shows its name, whether and when it was last used, and a "Revoked" / "เพิกถอนแล้ว" pill once cut off. Revoke it by swiping right to left → "Revoke" / "เพิกถอน" → "Revoke Access" / "เพิกถอนการเข้าถึง". Unlike a connection, a token row has no press-and-hold menu — the swipe is the only way.
- Claude Desktop needs Node.js installed for the config snippet to run; Claude Code needs its command-line tool. Claude's own "Add custom connector" screen has nowhere to paste a token at all, which is exactly why this path exists and why it is desktop-only.
What actually leaves your phone
"Connect an AI assistant" sounds bigger than what actually happens, so it is worth being precise about what travels where.
- Opening the Connected Apps screen sends nothing about your money anywhere. It fetches two lists from your own Pocketbird backend — your tokens and your connections — and only the non-secret parts of them: names, permissions, dates. Token fingerprints and authorisation codes sit in tables the app never reads.
- Financial data moves only when an assistant calls a tool, and only what that particular tool returns.
- What the provider receives is what you asked the assistant to look at — for Claude, Anthropic PBC in the United States. How they handle it is governed by their own terms and privacy policy, not Pocketbird's; the app's terms say this under "Connected AI Assistants", and the privacy notice under "Connecting an AI assistant".
- The app never sends the plain text of a token — only its fingerprint, the name you chose, and the list of permissions.
- Deleting your Pocketbird account takes every token and every connection with it.
- Pocketbird keeps its own log of every change an assistant makes — which client, which tool, which record — deliberately without amounts and without note text. It is not visible from the app or through any tool; it exists so a dispute can be settled, not for browsing.