getStructuredError resolves an error with no `code` to UNKNOWN_ERROR, whose registry text is the constant "Något gick fel. Försök igen." So an agent branching on `code` saw "unknown" for a failure whose own message already named the accounts and the two tools that fix it. On production that was 40 of the create_voucher failures in 60 days. Everything needed already existed: the ACCOUNTS_NOT_IN_CHART code, its registry entry, its remediation pointing at the chart-of-accounts resource, and a typed error class that storno-service already throws. This path just never attached the code. Attached with Object.assign rather than by throwing AccountsNotInChartError, because that class builds its own generic English message from the account list and would discard the richer Swedish one, which is the more useful half. Pinned by a test asserting the same message WITHOUT the code still resolves to UNKNOWN_ERROR, so this cannot silently regress. Not fixed here: the MCP server has ~155 bare Swedish-prose throws against 3 uses of codedError(), so most domain failures remain undispatchable. This fixes the one instance telemetry actually proved rather than converting 155 sites blind. Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Accounted MCP server
JSON-RPC 2.0 server exposing the Accounted bookkeeping engine to MCP clients (Claude Desktop, Claude Code, etc.). Endpoint: /api/extensions/ext/mcp-server/mcp. Add ?tool_namespace=accounted for the Accounted tool names. Requests without it retain the legacy Gnubok namespace. OAuth and stdio bridges live alongside the API surface: see app/api/mcp-oauth/, packages/accounted-mcp/, and the compatibility package in packages/gnubok-mcp/.
Tool authoring contract
Enforced by tests in __tests__/: these are not style preferences, they're guard rails.
additionalProperties: falseon everyinputSchema. Guarded bystrict-schemas.test.ts. Forces clear rejections on hallucinated fields instead of silent ignores.- Descriptions ≤ 280 chars. Guarded by
output-schema.test.ts. NoArgs:/Returns:/Examples:prose: those belong in JSON Schema. Use agent-native hints ("Use to…", "Call X first", "HIGH risk"). - Staged-operation envelope for write tools:
outputSchema: STAGED_OPERATION_SCHEMA(server.ts). Fields:staged, risk_level, actor, message, preview, period_status?, next?. Thestaged: trueboolean is the explicit completion signal; agents must not infer completion from prose. Do NOT introduce a parallel{ success, shouldContinue, output }envelope. period_statusthreading: any tool that ties to a fiscal-period-bound date (categorize, mark paid, create voucher, correct/reverse entry, approve supplier invoice) passesdateForPeriodChecktostagePendingOperation. Response then includesperiod_status: { period_id, status: open|locked|closed, lock_date }so widgets and agents disable writes without round-trips.- Scope mapping: every new tool needs an entry in
lib/auth/api-keys.tsTOOL_SCOPE_MAP. Missing entries default to deny. - Tests for new write tools: add staging-gate coverage to
__tests__/voucher-tools.test.ts(or a sibling) plus executor coverage tolib/pending-operations/__tests__/voucher-executors.test.tsif the tool stages a newoperation_type.
Determinism / cache stability
Tool definitions (name, description, inputSchema, outputSchema, annotations) are declared as static object literals at module load: no timestamps, no UUIDs, no Date/Math.random in the definition layer. This makes the tools/list JSON payload byte-stable across requests, which lets agent-side prompt caches stay warm. Do not introduce per-request non-determinism into the definitions block. Anything time-bound or random belongs inside execute().
For internal Anthropic API usage (the SDK is called from lib/ai/provider.ts and lib/ai/services/anthropic-family.ts; features such as extensions/general/invoice-inbox/lib/extract-invoice-fields.ts go through getAiService() in lib/ai rather than the SDK directly): annotate stable prefixes with cache_control: { type: 'ephemeral' } and log usage.cache_read_input_tokens for hit-ratio observability. The 1h TTL from the agent-native API plan (item 10) requires the direct Anthropic API; Accounted's Bedrock path defaults to a shorter TTL.
Payload-size watchdog
payload-size.bench.test.ts enforces a tools/list JSON payload ceiling. If the test fires, the right answer is rarely "raise the ceiling". Instead, trim descriptions or set specialized wide tools to catalogVisibility: 'search'. Those tools remain discoverable with full schemas through gnubok_search_tools and callable through tools/call on the wire without bloating the default catalog. Claude.ai only calls tools present in tools/list, so a tool that a user or a skill must call directly stays in the default catalog.
Where things live
server.ts: the tools array + JSON-RPC dispatchertool-result.ts:withNext(),toToolError()response helpersresources/: read-onlyAccounted://URIs, registered inresources/index.ts:company/current,period/active,recent-activity,capabilities,attention,chart-of-accounts,settings/vat-treatments,booking-templates,ledger/context,reconciliation/summarywidgets/: inline HTML widgets (receipt-matcher, vat-review, pending-operations)prompts/: slash-command-style promptsskills/: domain-knowledge skill bodies served viagnubok_load_skillpublic-tools.ts: lazy authentication (issue #1814).ANONYMOUS_METHODS(initialize, ping, tools/prompts/resources listing) and the threePUBLIC_TOOLS(gnubok_search_tools,gnubok_list_skills,gnubok_load_skill) answer without credentials, rate-limited per truncated IP; every othertools/callgets a transport-level 401 +WWW-AuthenticatefromhandleMcpRequestinserver.ts, which is the challenge clients turn into their Connect prompttasks.ts: MCP Tasks extension (io.modelcontextprotocol/tasks): durable handles for long-running tool calls, rows inmcp_tasks(service-role writes only)origin-guard.ts: Origin-header validation on the Streamable HTTP endpoint (DNS-rebinding defence required by the MCP spec)staging-pii-guard.ts: refuses a plaintext personnummer in stagedpending_operationsparams/preview, so every staging tool inherits the encrypt-at-staging ruletool-namespace.ts:?tool_namespace=accountedhandling (accounted_*aliases for the canonicalgnubok_*ids)__tests__/: strictness guards + per-tool coverage