Files
accounted/claude-plugin/CONNECTORS.md
T
Jakob Wennberg a1af9adb05 docs(connector): name the Claude.ai auth mode and OAuth client to pick (#1914)
Claude.ai's Add custom connector dialog auto-detects Authentication
"None" for a server that answers the handshake without credentials,
which is exactly what lazy auth does; a user who accepts that default
gets an error instead of the sign-in on the first company-scoped call.
State the two correct choices ("Required when the server asks", DCR
client registration) in the bridge README and the plugin's CONNECTORS.md.


Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-26 08:58:02 +02:00

2.2 KiB

Connectors

This plugin bundles exactly one connector: the Accounted MCP server, the same server that backs the Accounted connector in Claude.ai and the accounted-mcp stdio bridge.

Connector Server Auth What it reaches
Accounted https://app.accounted.se/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted OAuth 2.1 (PKCE). Read-only scopes by default; write scopes are ticked explicitly on the consent screen. The user's own companies in Accounted: ledger, transactions, invoices, VAT, payroll, reconciliation, year-end.

How the connection works

  • Lazy authentication. The server answers initialize, tools/list and the documentation tools (accounted_search_tools, accounted_list_skills, accounted_load_skill) without any credentials. The first company-scoped call returns an authentication challenge, which Claude Code surfaces as /mcp → authenticate and Claude.ai as an inline Connect prompt.
  • Adding it by hand in Claude.ai (Settings → Connectors → Add custom connector): choose Authentication "Required when the server asks" (not the auto-detected "None") and OAuth client "register one automatically" (DCR); the server does not advertise CIMD yet. No extra headers, Streamable HTTP.
  • Account creation inside the sign-in. A user who has no Accounted account creates one on the sign-in screen the challenge opens (BankID or e-mail + 2FA). No visit to the website first. /accounted:setup walks the whole flow, including creating the company from the conversation.
  • Every write is staged. Write tools create a pending operation with a preview; nothing is booked until the user approves, either in chat via accounted_approve_pending_operation or in the web app.
  • Data stays in the user's tenant. The connector only ever sees companies the signed-in user is a member of, enforced server-side per call.

Self-hosted Accounted

Point the plugin at your own instance: remove the bundled server and add yours with claude mcp add --transport http accounted "https://your-host/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted". The same OAuth flow, skills and commands apply.