* feat(mcp): distribution polish for agent-first onboarding: CIMD, plugin start skill, bridge hint Fourth PR of agent-first onboarding (#1814). - The OAuth AS metadata advertises client_id_metadata_document_supported next to the existing `none` token auth, the pair Claude.ai, Claude Code and Codex look for to use CIMD instead of registering a DCR client per connection. authorize/token never keyed on client_id (the redirect-URI allowlist is the trust boundary), so nothing else changes; DCR stays for ChatGPT. - The plugin's start skill no longer sends a user without an account to the website: the /mcp OAuth screen creates the account, and a NO_COMPANY_YET briefing failure routes to the onboarding skill and accounted_create_company. README updated to match. - `npx accounted-mcp` without ACCOUNTED_API_KEY prints the OAuth alternative (Claude Code, Codex, Claude.ai connector) and that the account can be created on the sign-in screen; package README too. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * fix(oauth): do not advertise CIMD until redirect URIs are matched against the client document CodeRabbit on #1866: advertising client_id_metadata_document_supported makes Claude and Codex send URL client_ids and expects an exact redirect_uri match against that document; the authorize endpoint only checks the global allowlist and never fetches client metadata. The flag is withheld until an SSRF-safe, cached CIMD fetch with exact redirect matching exists. DCR stays the registration path (stateless, so free). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2.7 KiB
2.7 KiB
name, description
| name | description |
|---|---|
| start | Connect and orient in the user's Accounted bookkeeping. Use on first contact with Accounted in a session, when the user says "kom igang", "get started", "connect my bookkeeping", "vad behover jag gora", or asks what this plugin can do. |
Start
Verify the connection, learn who this company is, and surface what needs attention. Run this before any other Accounted flow in a session.
Flow
- Call
accounted_get_agent_briefing. This is the single source for company facts: entity type (aktiebolag or enskild firma), accounting method (faktureringsmetoden or kontantmetoden), VAT period, employees, and ledger context. Never assume these; the flows below behave differently depending on them.- If the call fails with an auth error, the MCP server is not connected yet: tell the user to run
/mcpand authenticate with Accounted (OAuth consent screen; read-only scopes by default, write scopes are ticked explicitly). A user who has no Accounted account creates it on that same screen (BankID or e-mail, about a minute); nobody needs to visit the website first. Self-hosted users: see the plugin README. - If the call fails with
NO_COMPANY_YET, the account exists but has no company: this is a brand-new user. Loadaccounted_load_skill("onboarding")and follow it. It gathers the facts (company form, organisationsnummer, VAT and moms period, accounting method, fiscal year), previews and creates the company withaccounted_create_company, then hands out the bank and Skatteverket connect links. Do not attempt any other flow until the company exists.
- If the call fails with an auth error, the MCP server is not connected yet: tell the user to run
- Read
Accounted://attentionandAccounted://period/active. - Present a short orientation in the user's language: company name and form, active fiscal period and its lock status, and the top 3 items needing attention.
- Point at the flows, matched to what attention showed:
/accounted:bookkeep- clear unbooked transactions and receipts (daily)/accounted:check- read-only health check of the books/accounted:month-close- close the month/accounted:vat- prepare the momsdeklaration/accounted:payroll- monthly salary run and AGI/accounted:year-end- bokslut
- Mention that deeper, company-tailored guides exist on the server:
accounted_list_skillslists them (workflow guides plus Swedish regulatory skills, filtered to this company), andaccounted_load_skill(slug)loads any of them.
Rules
- Ground every statement in the briefing and resources; never guess company facts.
- Swedish accounting or tax questions are answered from loaded skills, never from memory.
- Every write in Accounted stages a pending operation for the user to approve. Nothing is ever booked without explicit approval.