The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Tallied listing page.
Tallied is a time-tracking and invoicing MCP server. It's connector-first: Claude and ChatGPT (or any MCP client) are the primary UI — you tell an assistant what you worked on and it logs the hours, ask what's unbilled and it drafts the invoice. A minimal web app handles the things chat is bad at: account settings, CSV import, and billing. Clients pay invoices through a Stripe payment link on a public, tokenized page.
Then connect with the MCP Inspector:
Choose Streamable HTTP, point it at http://localhost:3000/mcp, and connect. The inspector will hit the OAuth flow and open the login page in your browser. Without SMTP_URL or RESEND_API_KEY set, magic-link sign-in doesn't send an email — the link is printed to the server log and also shown directly on the "check your email" page, so local dev never needs a real mailbox.
| Variable | Required | Purpose |
|---|---|---|
NODE_ENV | no (default development) | production enables prod-only behavior (rate limiting, no dev magic-link shortcut) |
PORT | no (default 3000) | HTTP port |
BASE_URL | no (default http://localhost:3000) | Public origin. Everything — MCP, OAuth, web app, invoice pages — is served from here by default |
MCP_URL | no (default ${BASE_URL}/mcp) | Override to put the MCP endpoint on its own subdomain |
AUTH_ISSUER_URL | no (default BASE_URL) | Override to put the OAuth authorization server on its own subdomain |
APP_URL | no (default ${BASE_URL}/app) | Override to put the web app on its own subdomain |
DATABASE_URL | no (default local docker-compose Postgres) | Postgres connection string |
SESSION_SECRET | yes in production | Signs session cookies and magic links; openssl rand -hex 32 |
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET | no | Enables "Continue with Google"; omit to offer only magic links |
REVIEWER_EMAIL / REVIEWER_ACCESS_CODE | no | Enables an access-code sign-in for directory reviewers into one seeded account. Remove after review |
SMTP_URL | no | Any SMTP provider, e.g. smtps://LOGIN:KEY@smtp-relay.brevo.com:465; takes precedence over Resend |
RESEND_API_KEY | no | Alternative to SMTP_URL. With neither set, emails are printed to the log (dev only) |
EMAIL_FROM | no | From address for outbound email |
STRIPE_SECRET_KEY | no | Enables billing checkout and invoice payment links |
STRIPE_WEBHOOK_SECRET | no (required if STRIPE_SECRET_KEY is set) | Verifies /webhooks/stripe payloads |
STRIPE_PRICE_PRO / STRIPE_PRICE_TEAM | no | Price IDs for the paid plans |
STRIPE_CONNECT_FEE_BPS | no (default 0) | Optional platform fee, in basis points, on Connect payment links |
PRODUCT_NAME | no (default Tallied) | Used in emails, docs pages, and MCP server metadata |
SUPPORT_EMAIL | no (default support@localhost) | Shown in docs and consent screens |
See .env.example for the same list with inline comments.
@modelcontextprotocol/sdk router (mcpAuthRouter) provides the protocol surface: dynamic client registration, PKCE (S256), a form-encoded token endpoint, and RFC 8414 + RFC 9728 discovery metadata. src/http/app.ts mounts it at AUTH_ISSUER_URL and wires it to TallyOAuthProvider (src/auth/provider.ts), which persists clients, codes, and tokens in Postgres.src/auth/routes.ts.TallyOAuthProvider, replace it with the SDK's ProxyOAuthServerProvider, which delegates the same protocol surface to an upstream authorization server.Tallied runs on any host that gives you a stable HTTPS origin — Fly.io, Railway, Render, or similar.
BASE_URL to your public origin. Set MCP_URL, AUTH_ISSUER_URL, and/or APP_URL only if you're splitting those surfaces across subdomains.npm run build (runs build:app then tsc), then npm start.DATABASE_URL and run npm run db:migrate.${BASE_URL}/webhooks/stripe subscribed to checkout.session.completed, payment_intent.succeeded, customer.subscription.updated, and customer.subscription.deleted.${BASE_URL}/oauth/google/callback as an authorized redirect URI in the Google OAuth client.npm test — unit tests (vitest).test/golden-prompts.json — a hand-curated set of prompts and expected tool-call behavior. It's run manually, in both Claude and ChatGPT, before any change to tool names, descriptions, or input schemas — those are effectively a public API for the model and regressions there don't show up in unit tests.Before submitting to a connector directory, see docs/listing.md for store-listing copy and screenshots, and the product spec's submission checklist for the full requirements. Note that Claude's connector directory requires the submitting organization to be on a Team (or Enterprise) plan.