The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Jithox EU business checks listing page.
Jithox runs a remote MCP server. Its front
door is preflight_payment: one free call, before an agent pays an invoice,
that answers stop, review_required or no_blockers_found with signed
evidence. Next to it are read-only checks for e-invoices and payments: IBAN
structure, supplier bank-detail changes, Peppol BIS Billing 3.0 rule
validation, Peppol participant (receiver) lookup, and VIES lookup.
It is for developers and AI agents that prepare an e-invoice or a payment and want a check before something is sent, submitted to Peppol, or paid.
This repository holds examples and a registry manifest only. It contains no server code. The server itself is hosted by Jithox.
preflight_paymentCall preflight_payment once, before your agent pays an invoice. It compares
what the person approved, as your agent reports it (payee, amount, currency,
account), with what is about to be paid; checks the IBAN and a changed
supplier bank account against the one on file; and answers stop,
review_required or no_blockers_found, with every check, what it does not
prove, and a signed evidence token. No account, no token. It never pays and
never calls an account safe: a check that did not run is listed as not_run,
never as a pass.
Today only the invoice_bank rail has checks. For x402, card_or_giftcard
and crypto_bridge payments no rail checks run, and the best answer is
review_required with reason rail_not_covered (measured 2026-09-25).
The person approved paying invoice 2026-105 to Acme BV; the invoice now asks for a different account than the one on file:
The tool result (result.content[0].text), unwrapped; run against production
on 2026-09-25, … marks where it was shortened for this page:
Anyone can check that a verdict was not changed: POST the jws (optionally
with the input and its inputSalt) to
https://jithox.com/api/v1/evidence/verify. The untouched token answered
"status": "valid"; the same token with its verdict changed answered
"invalid" with reason signature_mismatch (tested 2026-09-25).
Transport: Streamable HTTP (POST, JSON-RPC 2.0).
No account or token is needed for tools/list.
Open Settings → Developer → Edit Config, and add the block above to
claude_desktop_config.json (macOS:
~/Library/Application Support/Claude/claude_desktop_config.json; Windows:
%APPDATA%\Claude\claude_desktop_config.json). Restart Claude Desktop.
Use tools/list on this endpoint as the source for current availability:
tool names, descriptions and input schemas. Read that live response rather
than relying on a fixed tool count or catalog in this README.
Limits: 30 requests per minute per IP on this endpoint; above that you get
HTTP 429 with Retry-After.
Output is shown as returned; … marks where it was shortened for this page.
The tool result (result.content[0].text), unwrapped:
Change issueDate to "23/09/2026" or drop buyerReference and the same
call returns "verdict": "will_be_rejected" with the specific rule that
failed (e.g. PEPPOL-EN16931-F001, PEPPOL-EN16931-R003) — checked
2026-09-22.
This asks the live Peppol directory about a THIRD PARTY. It is never a promise the invoice will arrive, be accepted or be paid — every answer says so.
examples/python/preflight_payment.py —
standard library only: initialize, then preflight_payment on a payment
whose supplier bank account changed, then POST /api/v1/evidence/verify on
the signed answer. Run with python examples/python/preflight_payment.py.
Real output against production, 2026-09-25:
examples/python/peppol_ready.py —
standard library only: initialize, then check_peppol_ready on a
compliant invoice, then lookup_peppol_participant on the buyer. Run with
python examples/python/peppol_ready.py. Real output against production,
2026-09-23:
examples/python/free_tools.py — standard
library only: initialize, tools/list, then verify_iban.examples/csharp/Program.cs — .NET Framework 4.x,
no packages: initialize, then the free check_payment_change with fictitious
Belgian accounts. Prints the server, verdict, reason, human steps and
doesNotProve from the response (charged only when supplied). HTTP timeout:
15 seconds; HTTP, JSON-RPC, tool errors and missing/invalid result fields exit
nonzero. From examples/csharp, compile with
csc /nologo /r:System.Net.Http.dll /r:System.Runtime.Serialization.dll Program.cs,
run offline checks with Program.exe --self-test, then the live example with
Program.exe. Exit 0 means a valid response, not permission to pay.examples/dogfood/ — our own
dogfood example (in Dutch): the paid check_vat_list on the VAT number of an invoice we received.skills/pay-invoices-safely/SKILL.md
is an Agent Skill for an agent that
is about to pay a supplier invoice or change a supplier's bank account. It
teaches the agent to call check_payment_change on every new IBAN and to hold
the payment for a call-back by a person, to check the invoice with the free
POST /api/invoice/review, and to check VAT numbers against the EU VIES
register with the paid review_invoice. Copy the folder into your agent's
skills directory.
Every example in the skill runs against production. To check that it still does (Node 18+, no dependencies):
It checks the spec rules, runs each curl example, requires every tool it
calls to be in the live tools/list, and fails on a euro sign, EUR, USD, a
$ amount or " credits" in the text.
server.json in this repository, following the official MCP
registry schema (2025-12-11). The server is also published in the
official MCP registry as com.jithox/jithox
(registry.modelcontextprotocol.io/v0/servers?search=com.jithox/jithox).Nothing on this endpoint sends an invoice, submits it to Peppol, posts, pays or delivers anything. Results are technical checks, not legal or tax advice.
The examples and files in this repository are MIT-licensed (see LICENSE). The Jithox service itself is not open source.