Finance and revenue

The Ramp connector.

Card spend, limits and people (read-only). Connect once with your own key. Every agent your team runs reads the same 5 tools under one permission model.

How access is governed

5

Read tools

Open by default. They run when called, and every call is logged with the endpoint, tool and capability.

0

Write tools

Ramp exposes no write tools. Nothing it does mutates external state.

0

Destructive tools

Ramp defines no destructive tools. Nothing here deletes data.

Defaults come from the capability on each tool definition, and an admin can tighten or open any tool individually. The endpoint's capability ceiling can only tighten that policy. An endpoint scoped to read never surfaces a write tool.

Every Ramp tool

5 tools, named as the agent sees them.

  • list_transactionsread

    List card transactions, newest first. This list is long — always bound it with from_date/to_date or keep page_size small. Filter by user_id (from list_users), department_id (from list_departments), card_id (from list_cards), or amount range.

  • list_cardsread

    List issued cards. Ramp keeps physical and virtual cards on separate routes, so pick one with card_type (default virtual). Each card carries a fund_id (its spend limit, see list_spend_limits) and a user_id (its holder, see list_users).

  • list_usersread

    List the people on the Ramp account: name, email, role, status, and their department/location ids. Use this to resolve a person to the user_id that list_transactions filters on.

  • list_departmentsread

    List the departments configured on the Ramp account (id and name). Use the id to break spend down by team via list_transactions or list_users.

  • list_spend_limitsread

    List spend limits — Ramp calls these `funds` in v1 (the older /limits route is deprecated). Each carries its restrictions, current balance, and members. Use this to answer 'how much of the budget is left'. The returned id is the fund_id on a card and the limit_id on a transaction.

Use it from any agent

The same Ramp tools reach Claude Code, Cursor, Claude Desktop or your own agent through one MCP endpoint. The endpoint is scoped to a group, the token is issued per group and revocable from the dashboard, and an allowed-tool list and capability ceiling limit what it exposes. Reads run. Gated writes refuse unless an admin opens them. Destructive tools remain unavailable over MCP.

.mcp.json · works for Cursor and Claude Desktop too
{
  "mcpServers": {
    "growth": {
      "type": "http",
      "url": "https://app.notara.ai/mcp/g/acme/growth",
      "headers": {
        "Authorization": "Bearer ntr_mcp_xxxxxxxxxxxxxxxxxxxx"
      }
    }
  }
}

The URL and token are placeholders. Real endpoints are issued per group from the dashboard.

Setup

  1. 01

    Create a Ramp Client Secret in your Ramp account (where to find it). The key is yours: Notara stores it encrypted and never sees a bill.

  2. 02

    Paste it into the Notara dashboard. Credentials can be scoped to the workspace or to one person.

  3. 03

    The tools appear with their capability defaults already set. Tighten or open any of them per tool, then invite the agent to a channel or issue an MCP token.

More in finance and revenue

Connect Ramp once. Use it everywhere.

Use Notara directly, or bring us the workflow that needs to be redesigned and built.