Files
accounted/packages/gnubok-mcp/index.mjs
T
188816652d docs(api,mcp): tool counts, changelog backfill, version-header honesty, lazy auth, endpoint map (#1929)
Brings the developer-facing API and MCP docs back in line with origin/main
(audit 2026-08-26). Docs only; no runtime behaviour changes.

- Tool counts: the server registers 153 tools; docs said 90+/100+/120.
  All now say "150+" (connect-claude, gnubok-mcp README, plugin README,
  mcp-server rules, CLAUDE.md, registry entry with refreshed updatedAt).
  Not derived from the tools array: lib/ must not import @/extensions/.
- REST changelog: backfilled the additive 2026-08 changes (#1909 report
  date ranges + PDFs, #1864 POST /companies, #1773 vat-declarations,
  #1405 PATCH settings, #1724/#1788 customer personal_number, #1809
  cash_account_id filter). API version date unchanged.
- Version headers: Gnubok-Deprecation is planned, not emitted; the
  Gnubok-Version request header is not read today (version.ts comment,
  versioning page, conventions overlay, regenerated skills/accounted-api).
- connect-claude Path A documents lazy auth (connector works before an
  account exists; sign-in on the first company-scoped call).
- MCP server README: real Anthropic SDK call sites, real resource URIs,
  pending-operations widget, public-tools/tasks/origin-guard/pii-guard.
  Rules file gains Lazy auth + feedback/tasks paragraphs.
- api-routes endpoint map regenerated from the filesystem (560 routes,
  55 families incl. v1, agent, reconciliation account-keyed, dimensions,
  peppol, rot-rut, webshop-orders, mileage, billing, skatteverket,
  receipt-hunt).
- gnubok-mcp/accounted-mcp: /settings?tab=api is the pre-redesign URL;
  now /settings/api (README + help hints, no version bump).

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-26 13:35:54 +02:00

135 lines
3.6 KiB
JavaScript
Executable File

#!/usr/bin/env node
/**
* gnubok-mcp: Connect Claude Desktop to your Accounted bookkeeping account.
*
* Usage in claude_desktop_config.json:
* {
* "mcpServers": {
* "gnubok": {
* "command": "npx",
* "args": ["gnubok-mcp"],
* "env": {
* "GNUBOK_API_KEY": "gnubok_sk_..."
* }
* }
* }
* }
*
* Get your API key at: https://app.gnubok.se/settings/api
*/
const API_KEY = process.env.GNUBOK_API_KEY
const MCP_URL = process.env.GNUBOK_URL || 'https://app.gnubok.se/api/extensions/ext/mcp-server/mcp'
// Optional distribution-channel marker (e.g. 'openclaw'). Forwarded as
// X-Gnubok-Client and recorded in server telemetry only, never affects auth.
// Mirrors the server's allow-list so an invalid value degrades to "no header"
// instead of fetch() rejecting every request with an invalid-header error.
const rawClient = process.env.GNUBOK_CLIENT
const CLIENT = rawClient && /^[A-Za-z0-9._-]{1,64}$/.test(rawClient) ? rawClient : undefined
if (rawClient && !CLIENT) {
process.stderr.write('gnubok-mcp: ignoring GNUBOK_CLIENT: must match [A-Za-z0-9._-]{1,64}\n')
}
if (!API_KEY) {
process.stderr.write(
'Error: GNUBOK_API_KEY is required.\n' +
'Get your API key at: https://app.gnubok.se/settings/api\n' +
'\n' +
'Add it to your Claude Desktop config:\n' +
'{\n' +
' "mcpServers": {\n' +
' "gnubok": {\n' +
' "command": "npx",\n' +
' "args": ["gnubok-mcp"],\n' +
' "env": {\n' +
' "GNUBOK_API_KEY": "gnubok_sk_..."\n' +
' }\n' +
' }\n' +
' }\n' +
'}\n'
)
process.exit(1)
}
let buffer = ''
process.stdin.setEncoding('utf8')
process.stdin.on('data', (chunk) => {
buffer += chunk
let newlineIdx
while ((newlineIdx = buffer.indexOf('\n')) !== -1) {
const line = buffer.slice(0, newlineIdx).trim()
buffer = buffer.slice(newlineIdx + 1)
if (!line) continue
handleMessage(line).catch((err) => {
process.stderr.write(`gnubok-mcp error: ${err.message}\n`)
})
}
})
process.stdin.on('end', () => {
process.exit(0)
})
async function handleMessage(line) {
let parsed
try {
parsed = JSON.parse(line)
} catch {
process.stderr.write(`gnubok-mcp: invalid JSON\n`)
return
}
const isNotification = parsed.id === undefined || parsed.id === null
try {
const res = await fetch(MCP_URL, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Authorization': `Bearer ${API_KEY}`,
...(CLIENT ? { 'X-Gnubok-Client': CLIENT } : {}),
},
body: line,
})
if (res.status === 202 || res.status === 204) {
return
}
const text = await res.text()
// Guard against non-JSON error responses (CDN HTML pages, proxy errors)
if (!res.ok && !isNotification) {
let message = `HTTP ${res.status}`
try {
const json = JSON.parse(text)
if (json.error) message = typeof json.error === 'string' ? json.error : JSON.stringify(json.error)
} catch { /* body wasn't JSON: use generic message */ }
const errorResponse = JSON.stringify({
jsonrpc: '2.0',
id: parsed.id,
error: { code: -32000, message },
})
process.stdout.write(errorResponse + '\n')
return
}
if (text) {
process.stdout.write(text + '\n')
}
} catch (err) {
if (!isNotification) {
const errorResponse = JSON.stringify({
jsonrpc: '2.0',
id: parsed.id,
error: { code: -32000, message: `Connection error: ${err.message}` },
})
process.stdout.write(errorResponse + '\n')
}
}
}