Files
accounted/packages/accounted-mcp
e92365b86e feat(mcp): distribution polish for agent-first onboarding: CIMD, plugin start skill, bridge hint (#1814 PR 4) (#1866)
* feat(mcp): distribution polish for agent-first onboarding: CIMD, plugin start skill, bridge hint

Fourth PR of agent-first onboarding (#1814).

- The OAuth AS metadata advertises client_id_metadata_document_supported
  next to the existing `none` token auth, the pair Claude.ai, Claude Code
  and Codex look for to use CIMD instead of registering a DCR client per
  connection. authorize/token never keyed on client_id (the redirect-URI
  allowlist is the trust boundary), so nothing else changes; DCR stays
  for ChatGPT.
- The plugin's start skill no longer sends a user without an account to
  the website: the /mcp OAuth screen creates the account, and a
  NO_COMPANY_YET briefing failure routes to the onboarding skill and
  accounted_create_company. README updated to match.
- `npx accounted-mcp` without ACCOUNTED_API_KEY prints the OAuth
  alternative (Claude Code, Codex, Claude.ai connector) and that the
  account can be created on the sign-in screen; package README too.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6

* fix(oauth): do not advertise CIMD until redirect URIs are matched against the client document

CodeRabbit on #1866: advertising client_id_metadata_document_supported
makes Claude and Codex send URL client_ids and expects an exact
redirect_uri match against that document; the authorize endpoint only
checks the global allowlist and never fetches client metadata. The flag
is withheld until an SSRF-safe, cached CIMD fetch with exact redirect
matching exists. DCR stays the registration path (stateless, so free).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-25 13:05:59 +02:00
..
2026-07-24 15:03:50 +02:00
2026-07-24 15:03:50 +02:00

accounted-mcp

Connect Claude Desktop, Claude Code, or another stdio MCP client to your Accounted bookkeeping account.

This zero-dependency bridge forwards JSON-RPC over stdio to the hosted Accounted MCP server. New connections receive the accounted_* tool namespace. Existing gnubok-mcp configurations remain supported separately.

Setup

  1. Create an API key in Accounted under Settings > API.
  2. Add the bridge to your MCP client:
{
  "mcpServers": {
    "accounted": {
      "command": "npx",
      "args": ["-y", "accounted-mcp"],
      "env": {
        "ACCOUNTED_API_KEY": "gnubok_sk_test_...",
        "ACCOUNTED_CLIENT": "claude-desktop"
      }
    }
  }
}

The credential value retains the legacy gnubok_sk_* wire prefix for backward compatibility. Only the MCP integration is being renamed in this release.

Environment variables

Variable Required Default Description
ACCOUNTED_API_KEY yes none Your existing Accounted API key.
ACCOUNTED_URL no Accounted hosted MCP endpoint Override for self-hosted Accounted. The bridge adds tool_namespace=accounted when omitted.
ACCOUNTED_CLIENT no none Telemetry-only distribution marker such as claude-desktop.

The API key scopes determine which tools are visible and callable. Write tools stage pending operations for explicit approval before anything is booked.

OAuth connector (no API key, no account needed up front)

Clients with OAuth support connect directly without this bridge and without an existing API key. The sign-in screen lets a new user create the Accounted account (BankID or e-mail), and company setup then continues in the conversation through the onboarding skill and accounted_create_company:

https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted
# Claude Code
claude mcp add --transport http accounted \
  "https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted"

# OpenAI Codex
codex mcp add accounted --url \
  "https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted"

Claude.ai and Claude Desktop: Settings > Connectors > Add custom connector, paste the URL. The connector works before you connect (documentation tools); the first company-scoped call opens the Connect prompt.

Compatibility

The legacy gnubok-mcp package, environment variables, endpoint behavior, and gnubok_* tool aliases remain supported. Existing installations do not need to change.