claude.ai's two-step "Add custom connector" dialog probes the server URL
without credentials and pre-fills the Authentication choice from the
answer. Our lazy-auth endpoint (issue #1814) answers 200 on an anonymous
initialize, which the dialog reads as an authless server: it suggests
"None", and a connector added with that default never opens the sign-in
when the challenge arrives later. Per Anthropic's connector docs a 401 is
the only answer it reads as OAuth ("Claude does not honor a
WWW-Authenticate header on a 200 response").
- `auth=required` on the endpoint URL (extensions/general/mcp-server/
auth-mode.ts) turns lazy auth off for that URL: every tokenless
request, initialize included, answers the 401 + WWW-Authenticate
challenge. Callers with a token are unaffected; the bare URL keeps
lazy auth for Claude Code, the plugin, Cursor and ChatGPT, and existing
connector records are untouched.
- The links we control carry the flag: Settings -> API & MCP (install
link and copy block), the onboarding checklist, both docs pages and
claude-plugin/CONNECTORS.md (plugin 1.2.3). The docs' Path A now
describes the eager flow (sign-in opens on Add) instead of telling
users to override the dialog's "None".
- Tests: eager-auth.test.ts (401 on initialize/tools/list/public tools,
namespaced metadata pointer, token no-op, exact-flag only); checklist
link shape updated.
Companion: gnubok-website PR (Kom igång connector link + regenerated
connect-claude / anslut-claude pages).
Claude-Session: https://claude.ai/code/session_013yw62FMXGSzo6icFDiBwP3
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
From the fourth E2E run: the agent correctly refused to reproduce a
104 KB SIE file token by token (silent mid-verifikat truncation) and
dead-ended to the web wizard, and its replies were walls of compliance
prose.
1. gnubok_create_sie_upload: signed same-origin upload URL (reuses the
pending-document infra; .se/.sie/.si only, 50 MB HTTP cap).
gnubok_sie_preflight and gnubok_import_sie accept upload_id as the
byte-exact source, plus optional sha256 (hex of the raw bytes)
verified on the upload_id/base64 paths so truncation is DETECTED,
never silent. Inline content above 120k chars is refused with a
pointer to the upload flow. Scope bookkeeping:write (same intent as
import_sie).
2. Skill: brevity rule (max ~8 short lines per reply, one warning per
step, no legal essays), memory-first rule (check what is already
known before asking the opening questions), the upload-first SIE
step, and gnubok_explain_voucher_gap after import for skipped
voucher numbers.
3. CONNECTORS.md starter prompt rewritten memory-first so it stays
copy-paste ready without the user's own data in it. Plugin v1.2.2.
tools/list ceiling 62K to 62.4K documented in the bench.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(onboarding): minimal input: orgnr + moms period is the whole ask
Two fixes from the third E2E attempt (2026-08-26):
1. accounting_method is now optional in CompanySetupSchema and defaults by
form in planCompanySetup: aktiebolag = accrual (the norm), enskild
firma = cash (the common small-EF choice; legal under 3 MSEK, BFL 4
kap 4 paragraf). The plan flags the default (resolved.accountingMethodDefaulted)
and gnubok_create_company's preview carries accounting_method_defaulted
so the readback names it and the user overrides in the same 'ja'.
Never silent: the preview is the checkpoint. Applies to the MCP tool
and POST /api/v1/companies (additive; response shows the resolved
value). The lookup tool's still_to_ask no longer lists it.
2. The agent refused a real orgnr because the user said 'nytt bolag' and
the registry showed an established company ('Stopp. Numret matchar
inte ett nytt bolag'): lookup instructions now state that an
established company with F-skatt/VAT is the NORMAL case (new = new to
Accounted) and the orgnr is never second-guessed for looking
established.
Skill + plugin (v1.2.1) updated; API skill regenerated; DECISIONS.md entry.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(onboarding): surface the kontantmetod 3-MSEK condition on the defaulted cash method
Compliance-review finding on #1952: the EF cash default carries a legal
eligibility condition (turnover normally under 3 MSEK, BFL 4 kap 4 §)
that a client not reading the onboarding skill would never see. The
create preview now carries accounting_method_note with the condition
whenever cash was defaulted, and the v1 pitfall states it for API
integrators. The registry cannot verify turnover, so the confirm-time
human check is the gate; the default itself stays (a brand-new EF has
zero turnover by definition).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
The onboarding flow now mirrors the web wizard: ask for the
organisationsnummer first, look the company up in the public registry (one
TIC Lens call through the extracted extensions/general/tic/lib/lookup.ts,
shared with the /lookup HTTP route), and present the facts for confirmation
instead of interrogating the user.
The new gnubok_lookup_company tool (companies:read, company-independent,
default catalog) returns the registry facts, a prefilled
suggested_create_company_input, and a still_to_ask list that encodes the
same fact-vs-question rules as lib/onboarding-journey/reducer.ts: F-skatt
is a fact both ways, VAT is a fact only when positively registered (ML 17
kap 24 paragraf), moms period and accounting method are always asked, an
enskild firma's verksamhetsnamn is the user's choice, and a known fiscal
year becomes a confirm question. Registry outages degrade to the full
question list instead of failing onboarding.
The onboarding skill and the plugin's /accounted:setup command are updated
to the orgnr-first flow (plugin 1.2.0). tools/list ceiling bumped 61.2K to
61.5K with the reason documented in the bench.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
The Claude plugin is the one-click install for Cowork and Claude Code,
so it should also be the entry to agent-first onboarding (#1814).
/accounted:setup connects the bundled connector (creating the account on
the sign-in screen if needed), hands off to the server-side onboarding
skill when the account has no company, then the bank and Skatteverket
links. CONNECTORS.md documents the single bundled connector the way
Anthropic's own plugins do. Version 1.1.0 so marketplaces that sync on
version bumps pick it up. The plugin-refs guard now also validates
commands/*.md against the server.
Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
The plugin has been installable from erp-mafia/accounted since #1088, but
three things would fail review at the Claude plugin directory:
- `homepage` pointed at https://app.gnubok.se/docs/api/connect-claude, which
404s. next.config.ts redirects /docs/api/* to the separate docs.gnubok.se
repo, where that page was never ported, so app/docs/api/connect-claude is
unreachable dead code. Point homepage at the plugin README instead.
- `license: MIT` was a bare claim with no artifact next to it. Add the MIT
text and make the README explicit that the plugin is MIT while the platform
it connects to is a separate AGPL-3.0 work.
- Version stayed at 0.1.0 for a plugin that has been live and working.
Also give /accounted:start a path for a user who installs from the directory
with no Accounted account: previously it only handled a not-yet-authenticated
MCP server, and a cold user would hit OAuth with nowhere to go.
Both manifests pass `claude plugin validate`, the same check the review
pipeline runs on every submission.
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Ships an installable Claude Code plugin (/plugin marketplace add
erp-mafia/accounted) that bundles the MCP connection (OAuth, zero-key)
with seven short workflow skills following the Swedish bookkeeping
rhythm: start, bookkeep, check, month-close, vat, payroll, year-end.
Wrappers are deliberately thin: they ground in the agent briefing and
Accounted:// resources, load server-side workflow skills and regulatory
atoms via gnubok_load_skill at need, and stage every write for user
approval. No knowledge is duplicated into the plugin.
A vitest cross-checks every skill slug, atom id, resource URI, and tool
name the wrappers reference against the MCP server source, so a server
rename fails CI instead of a user's chat session.
Assessment and follow-ups in dev_docs/claude_plugin.md (local, dev_docs
is unpublished by design).
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>