* feat(mcp): distribution polish for agent-first onboarding: CIMD, plugin start skill, bridge hint Fourth PR of agent-first onboarding (#1814). - The OAuth AS metadata advertises client_id_metadata_document_supported next to the existing `none` token auth, the pair Claude.ai, Claude Code and Codex look for to use CIMD instead of registering a DCR client per connection. authorize/token never keyed on client_id (the redirect-URI allowlist is the trust boundary), so nothing else changes; DCR stays for ChatGPT. - The plugin's start skill no longer sends a user without an account to the website: the /mcp OAuth screen creates the account, and a NO_COMPANY_YET briefing failure routes to the onboarding skill and accounted_create_company. README updated to match. - `npx accounted-mcp` without ACCOUNTED_API_KEY prints the OAuth alternative (Claude Code, Codex, Claude.ai connector) and that the account can be created on the sign-in screen; package README too. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * fix(oauth): do not advertise CIMD until redirect URIs are matched against the client document CodeRabbit on #1866: advertising client_id_metadata_document_supported makes Claude and Codex send URL client_ids and expects an exact redirect_uri match against that document; the authorize endpoint only checks the global allowlist and never fetches client metadata. The flag is withheld until an SSRF-safe, cached CIMD fetch with exact redirect matching exists. DCR stays the registration path (stateless, so free). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
accounted-mcp
Connect Claude Desktop, Claude Code, or another stdio MCP client to your Accounted bookkeeping account.
This zero-dependency bridge forwards JSON-RPC over stdio to the hosted Accounted
MCP server. New connections receive the accounted_* tool namespace. Existing
gnubok-mcp configurations remain supported separately.
Setup
- Create an API key in Accounted under Settings > API.
- Add the bridge to your MCP client:
{
"mcpServers": {
"accounted": {
"command": "npx",
"args": ["-y", "accounted-mcp"],
"env": {
"ACCOUNTED_API_KEY": "gnubok_sk_test_...",
"ACCOUNTED_CLIENT": "claude-desktop"
}
}
}
}
The credential value retains the legacy gnubok_sk_* wire prefix for backward
compatibility. Only the MCP integration is being renamed in this release.
Environment variables
| Variable | Required | Default | Description |
|---|---|---|---|
ACCOUNTED_API_KEY |
yes | none | Your existing Accounted API key. |
ACCOUNTED_URL |
no | Accounted hosted MCP endpoint | Override for self-hosted Accounted. The bridge adds tool_namespace=accounted when omitted. |
ACCOUNTED_CLIENT |
no | none | Telemetry-only distribution marker such as claude-desktop. |
The API key scopes determine which tools are visible and callable. Write tools stage pending operations for explicit approval before anything is booked.
OAuth connector (no API key, no account needed up front)
Clients with OAuth support connect directly without this bridge and without an
existing API key. The sign-in screen lets a new user create the Accounted
account (BankID or e-mail), and company setup then continues in the
conversation through the onboarding skill and accounted_create_company:
https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted
# Claude Code
claude mcp add --transport http accounted \
"https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted"
# OpenAI Codex
codex mcp add accounted --url \
"https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted"
Claude.ai and Claude Desktop: Settings > Connectors > Add custom connector, paste the URL. The connector works before you connect (documentation tools); the first company-scoped call opens the Connect prompt.
Compatibility
The legacy gnubok-mcp package, environment variables, endpoint behavior, and
gnubok_* tool aliases remain supported. Existing installations do not need to
change.