MCP server for Manager.io bookkeeping: read-first with opt-in scoped task and write tools
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
An MCP (Model Context Protocol) server that connects AI assistants such as Claude and ChatGPT to a Manager accounting instance. It exposes Manager's data and operations as a set of scoped tools. The default is read-only, with reporting, diagnostic and reconciliation tools available out of the box and every write capability behind explicit configuration.
This project began as a fork of manager-mcp 0.2.6. See Attribution below.
Onexur Manager MCP lets an AI assistant read and, where explicitly permitted, act on a Manager accounting instance through a structured tool interface rather than free-form API calls. The server enforces a tiered permission model so that read access and write access are each opted into separately, and delete access is opted into separately again.
Typical uses:
Nothing that changes Manager is registered by default. Every write request is also checked against a permanent denylist before any scope is consulted (see Configuration).
The package is named mcp-manager.io, the Python module is manager_mcp, and the commands are manager-mcp and manager-mcp-dev. It requires Python 3.10 or later and uv.
Until the first release is published to PyPI, run it from a clone:
After publication, no clone is needed:
The server speaks MCP over stdio. To use it from a client, configure the client to run one of the commands above with your Manager connection details as environment variables, for example:
Client integrations in this repository:
mcpb/ holds the manifest for a Claude Desktop extension bundle. Built bundles are not committed. The manifest runs the published mcp-manager.io package through uv, so it works once the package is published..cursor-plugin/plugin.json is a Cursor plugin manifest..cursor/mcp.json or .vscode/mcp.json entry in your own project, use the pattern above.ChatGPT Apps need a hosted HTTP endpoint. This package is stdio only.
One process talks to one Manager instance, configured through environment variables:
| Variable | Purpose |
|---|---|
MANAGER_API_URL | Base URL of the Manager API, including /api2 when required. Required. |
MANAGER_API_KEY | Access token created in Manager Settings, sent as X-API-KEY. Required. |
MANAGER_MCP_WRITE_SCOPES | Comma-separated write scopes. Empty by default. |
MANAGER_MCP_DELETE_SCOPES | Comma-separated delete scopes. Empty by default, and never implied by write scopes. |
MANAGER_MCP_AUDIT_LOG_PATH | Where corrective writes are logged as JSON lines (before and after state). Defaults to ~/.manager_mcp/audit_log.jsonl. |
MANAGER_MCP_DEV_SUPERVISOR | Set to 1 to restart the server automatically when source files change. Development use only. |
The older MANAGER_MCP_ALLOW_WRITES, ALLOW_WRITES and MANAGER_MCP_WRITES variables are rejected with an error that points to the two scope variables above.
Never commit your API key. Keep it in the environment of the MCP client or in a private env file.
stdio is the default and the only transport a registry-launched (uvx) process uses. HTTP is additive and opt-in for self-hosted deployments that need this server reachable over a network rather than only through local stdio pipes:
| Variable | Purpose |
|---|---|
MANAGER_MCP_TRANSPORT | stdio (default) or http. |
MANAGER_MCP_HTTP_HOST | Bind host for HTTP mode. Defaults to loopback (127.0.0.1) when unset. |
MANAGER_MCP_HTTP_PORT | Bind port for HTTP mode. Defaults to 8000 when unset. |
MANAGER_MCP_HTTP_AUTH_TOKEN | Optional bearer token. When set, every HTTP request must carry a matching Authorization: Bearer <token> header or is rejected with 401 before it reaches any tool. |
HTTP mode exposes the exact same tools, the exact same scope/policy enforcement, and the exact same single-Manager-instance-per-process model as stdio -- only the transport changes. It does not add multi-tenancy or multiple Manager instances per process; that belongs in a separate gateway service in front of this one.
Security note: MANAGER_MCP_HTTP_AUTH_TOKEN is a single shared secret for the whole process, checked at the transport layer -- it is not per-caller identity, OAuth, or a replacement for a real auth boundary. When it is unset, HTTP mode has no transport-level authentication at all: any client that can reach the configured host:port can call every tool this process exposes, subject only to the scope/denylist policy above (which governs what can be done, not who may connect). That is only safe when network placement -- loopback binding, a private Docker network, a VPN, or a gateway/reverse proxy that performs the real authentication -- is genuinely the sole access control. The server prints a warning to stderr at startup when running in HTTP mode with no token configured, rather than staying silent about it. Given this server can expose real bookkeeping data (and, depending on configured scopes, write/delete access to it), operators are strongly encouraged to set the token, place the server behind a gateway, or both.
Valid scopes are quotes, orders, parties, items, sales, purchases, banking, payroll and ledger, plus raw, an escape hatch that enables the full create and update (or delete) set for every domain. A recommended starting point for day-to-day bookkeeping is banking,sales,parties.
With no scopes set, 30 read-only tools are registered. Enabling a scope registers only the tools for that domain. Scopes are additive and independent, and unknown scope names are refused at startup. With every write and delete scope enabled, up to 126 tools are registered.
Every request that would change Manager passes a policy check first. Requests to paths such as access tokens, the chart of accounts, tax codes, exchange rates, starting balances, bank reconciliation, custom fields, email settings and the customer portal are permanently denied, whatever scopes are enabled.
Read tools (registered by default, 30 in total)
list_resources, list_records, get_record, get_fixed_asset and get_server_info (server identity, process, git state, registered tools and active scopes).aged_receivables, aged_payables, bank_balances, trial_balance, profit_and_loss, balance_sheet and tax_summary. These return Manager's current state or raw feeds and are not finished reports (see Reporting limitations).reporting.py): manager_report_catalogue, get_report_definition, ledger_transactions, reconstructed_trial_balance, reconstructed_profit_and_loss, reconstructed_aged_receivables and reconstructed_aged_payables.diagnostics.py): find_records, find_broken_invoice_references, find_unallocated_transactions, find_duplicate_transactions, verify_invoice_balance, account_ledger, bank_activity, find_suspense_candidate_accounts and general_ledger_summary.reconciliation.py): reconcile_period.list_incomplete_reconstructions (corrections.py): invoice-reconstruction attempts that started but have not completed, from the local audit log only.Write tools (registered only when the matching scope is enabled)
task_tools.py) shaped around an intent, for example issue_sales_invoice, issue_purchase_invoice, record_customer_payment, record_supplier_payment, record_expense, transfer_between_accounts and post_journal_entry. These are the recommended write path.create_* and update_* tools for each enabled scope, and delete_* tools for each enabled delete scope. create_fixed_asset and update_fixed_asset (fixed_assets.py) need the ledger scope.corrections.py): propose_correction and apply_correction, propose_*_reconstruction and apply_*_reconstruction for purchase and sales invoices, reallocate_payment_line and reallocate_receipt_line, and snapshot_and_void, which is preferred over the plain void_document tool. Nothing here writes without a separate apply step after a proposal, and each corrective write is recorded in the audit log.No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/onexur-manager-mcp)<a href="https://allmcps.com/mcp/onexur-manager-mcp"><img src="https://allmcps.com/api/badge/onexur-manager-mcp?style=directory" alt="Onexur Manager MCP on AllMCPs" /></a>