Agents · Model Context Protocol

Connect your AI agent to your books

Setttle speaks Model Context Protocol over streamable HTTP. Your assistant reads balances and uses the same permissions, accounting commands, review states, and audit trail as the web app.

MCP endpoint

One URL, the same books

Point any MCP-speaking client at the endpoint below. Calls run against the live ledger — not a copy — so a balance your agent reports is the balance in your books.

Streamable HTTP

https://api.setttle.ca/mcp

Access

Two ways to connect

Owners and collaborators sign in with OAuth. Scripts and CI use a token scoped to a single company.

OAuth

For people. Add Setttle as a connector and sign in through your browser, then choose what the connection may do on the consent screen. The connection is account-wide, so you can switch companies with use_entity.

Works with Claude Desktop, ChatGPT connectors, Claude Code, and Cursor. Clients register themselves — there is nothing to pre-register.

sett_ API token

For developers and automation. Mint a token in Settings → API tokens; the plaintext is shown exactly once. A token is pinned to one company and never sees another.

Send it as Authorization: Bearer sett_…. Revoke it from the same page and the next call fails.

Setup

Connect a client

Most clients open the Setttle sign-in and consent screen on first use.

Claude Desktop & ChatGPT

Add a connector or integration and paste the endpoint URL. Your browser opens the Setttle sign-in, then the consent screen where you pick a permission tier.

Claude Code

Register the server, then run /mcp inside Claude Code to authenticate.

shell

claude mcp add --transport http setttle https://api.setttle.ca/mcp
Cursor

Settings → MCP → Add server → type HTTP, then the endpoint URL. Cursor opens the same OAuth flow the first time a tool runs.

Capability

What an agent can do

Read access is available at every tier. Drafting and posting depend on the permission granted at consent. A model suggestion is a draft; an explicit posting command must pass the same accounting rules as the web app.

Read — always

  • Account balances and trial balances
  • Journal entries, invoices, bills, and receipts
  • Bank transactions and reconciliation status
  • Reports and tax schedules for filing review
  • What still needs a decision, and why

Change — with permission

  • Draft and post balanced journal entries
  • Create invoices and vendor bills
  • Record invoice and bill payments
  • Void an unpaid manual invoice, preserving history
  • Switch companies with use_entity, within the connection's scope

Agents do not get a parallel accounting model or a shortcut around review. When the tier is read-only, nothing is written. When it is not, a post still has to satisfy the same rules as the web app.

Trust

Attribution, review, and revocation

Every action is attributed
Entries created through an agent record the actor as an agent, with a timestamp and source. The audit history looks the same whether a person or an agent made the change.
Drafts stay drafts
A suggestion from a model is not a posting. Drafts wait for review, and ambiguity is never silently resolved. Explicit posting tools are available only at a permission tier that allows them.
The ledger still has the final say
Posted entries cannot be deleted individually, corrections preserve history, and every entry must balance in the company's base currency. A tool call that breaks a rule fails loudly instead of guessing.
Revoking is immediate

Disconnect from Settings → Connections (or revoke a token from Settings → API tokens). The next tool call is rejected — there is no grace period.

Questions worth asking

Can an AI assistant change my books?

Only with a permission tier that allows changes. Read-only connections cannot write. Drafts wait for review; an explicit posting command must pass the same authorization and balance checks as a web action.

Does connecting an assistant give it every company?

No. API tokens are pinned to one company. An OAuth connection can switch only among companies the signed-in person is authorized to access.

How do I disconnect an agent?

Revoke its connection or API token in Settings. The next tool call is rejected.

Give your assistant the real books

Every plan includes MCP access. Permissions and accounting rules still apply to every tool call.

7-day Max trial · no credit card required