bokio-mcp
Enables MCP clients to read and write Bokio accounting data for one company through 85 tools covering invoices, customers, suppliers, journal entries, chart of accounts, fiscal years, items, tags, uploads, SIE export, and bank payments.
README
bokio-mcp
An MCP server for the Bokio accounting API. It exposes 85 tools over one Bokio company — invoices, customers, suppliers, supplier invoices, journal entries, credit notes, the chart of accounts, fiscal years, items, tags, uploads, SIE export and bank payments — so an MCP client can read and (optionally) write your bookkeeping.
No accounts, no database, no hosted service. One company per server instance.
"Which invoices are still unpaid?"
"Book the attached receipt against account 6570."
"Export the SIE file for the 2025 fiscal year."
Quick start
Try it with fixtures, no Bokio account needed:
BOKIO_MOCK=true npx bokio-mcp status
# { "companyName": "Testbolaget AB", "status": "active", ... }
BOKIO_MOCK=true serves an in-process fake Bokio, so the full tool surface works
before you have any credentials.
For real data, pick one of the two credential routes below and add the server to your MCP client.
Route A — private integration token (recommended)
In Bokio: company settings → Integrations → API tokens → Create private integration. The token is long-lived, scoped to that one company, and needs no OAuth review.
{
"mcpServers": {
"bokio": {
"command": "npx",
"args": ["-y", "bokio-mcp"],
"env": {
"BOKIO_INTEGRATION_TOKEN": "your-token",
"BOKIO_COMPANY_ID": "the-company-uuid-from-the-bokio-url"
}
}
}
}
Route B — OAuth
Register an integration in Bokio's developer portal with the redirect URI
http://127.0.0.1:7337/callback, then:
export BOKIO_CLIENT_ID=... BOKIO_CLIENT_SECRET=...
npx bokio-mcp login
That opens Bokio in your browser and writes the tokens to
~/.config/bokio-mcp/tokens.json (mode 0600). Access tokens are refreshed
automatically, including refresh-token rotation. Point your MCP client at
npx -y bokio-mcp with the same two env vars set.
Writes are off by default
A fresh install can read but not write. Mutating tools are not merely blocked — they are
absent from tools/list, so the model never proposes an edit it cannot make:
BOKIO_ALLOW_WRITES=true
Of the 85 tools, 38 are read-only and 47 mutate. Start without the flag, confirm the model is reading what you expect, then turn writes on.
Commands
bokio-mcp |
Serve over stdio — what MCP clients launch |
bokio-mcp serve --http |
Serve over streamable HTTP on $PORT |
bokio-mcp login |
Connect a company via OAuth |
bokio-mcp status |
Print the current connection and exit |
HTTP transport
For self-hosting, e.g. behind a reverse proxy or in a container:
MCP_AUTH_TOKEN=$(openssl rand -hex 32) bokio-mcp serve --http
/mcp is then guarded by that static bearer. Without MCP_AUTH_TOKEN the server
binds 127.0.0.1 only rather than exposing an unauthenticated bridge to live
accounting data. A Dockerfile is included; it defaults to this transport.
Environment
| Variable | Default | |
|---|---|---|
BOKIO_INTEGRATION_TOKEN |
— | Route A: private integration token |
BOKIO_COMPANY_ID |
— | Route A: the company's UUID |
BOKIO_CLIENT_ID / BOKIO_CLIENT_SECRET |
— | Route B: OAuth credentials |
BOKIO_ALLOW_WRITES |
false |
Register mutating tools |
BOKIO_MOCK |
false |
Serve in-process fixtures instead of Bokio |
BOKIO_SCOPES |
see src/config.ts |
OAuth scopes requested by login |
BOKIO_TOKEN_FILE |
~/.config/bokio-mcp/tokens.json |
Where OAuth tokens live |
BOKIO_TOKEN_ENCRYPTION_KEY |
— | Optional AES-256-GCM at rest; openssl rand -base64 32 |
BINARY_MAX_BYTES |
4194304 |
Cap on inline uploads/downloads |
PORT / HOST |
3000 / auto |
HTTP transport |
MCP_AUTH_TOKEN |
— | Bearer guarding /mcp |
OAUTH_CALLBACK_PORT |
7337 |
Loopback port used by login |
See .env.example for the annotated version.
A note on token storage
The OAuth token file is plaintext at mode 0600 unless BOKIO_TOKEN_ENCRYPTION_KEY is
set — the same posture as the gh and aws CLIs. On a personal machine a key stored
next to the thing it encrypts adds little; set it when the file lives somewhere less
private, such as a container image or a shared host.
Development
npm install
npm test # 36 tests, no database, no credentials
npm run typecheck
npm run dev # tsx watch, stdio transport
BOKIO_MOCK=true routes every Bokio request into an in-process mock at the fetch
layer, so it behaves identically under stdio, under HTTP, and inside tests with no
server running. test/mcp.test.ts drives the real MCP protocol end to end against it.
Tool definitions are hand-written in src/tools/bokio/, but each one's path and method
are checked against the OpenAPI spec at compile time by the op() helper — a typo in a
route fails the build. Regenerate the spec types with:
npm run gen:bokio
Not supported
- More than one company per instance. Bokio credentials are per-company; run a second instance for a second company.
- Elevated scopes.
bank-payments:*requires per-integration approval from Bokio. The bank payment tools are registered but will fail until your integration is approved and the scopes are added toBOKIO_SCOPES.
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。