Wafeq accounting API: all 251 endpoints as safety-categorized MCP tools, over stdio or HTTP.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Run your Wafeq books in plain language from AI assistants like Claude, Cursor, and any other MCP client.
This Model Context Protocol server exposes the Wafeq Public API β all 251 endpoints, generated straight from the OpenAPI spec into MCP tools, plus two hand-written ones. Every tool carries a safety category (π’ read-only / π‘ write / π state change / π΄ irreversible or destructive) so your assistant knows what an action does before it calls it β including the difference between saving an invoice and filing it with a tax authority, which no CRUD-shaped wrapper can tell you. It runs over stdio (Claude Desktop and other local launchers) or Streamable HTTP (hosted in Docker), and ships with retries, client-side rate limiting, request timeouts, idempotency keys, multipart upload and binary PDF handling so it holds up against a live book.
Some MCP servers just forward an API. This one is built to be safe to hand to an LLM and easy to run against real accounting data:
| What you get | Why it matters |
|---|---|
| All 251 endpoints, spec-driven | Full coverage of invoices, bills, quotes, credit and debit notes, payments, banking, journals, payroll, projects, inventory and reports β nothing hand-picked or left behind. |
| Nine safety categories, not four π’ / π‘ / π / π΄ | A dozen of Wafeq's POSTs are not creates. Previews write nothing; ending an amortization early posts to the ledger with no undo; reporting an invoice to a tax authority leaves your organization permanently. Each gets its own banner instead of being lumped in with "create". |
| Server instructions sent on connect | The client is told how to read the safety banners and the handful of Wafeq conventions β date format, decimal separator, whole-period report ranges β up front, instead of discovering them by getting a call wrong first. |
Machine-readable MCP annotations (readOnlyHint, destructiveHint) | Hosts that honor annotations (Claude included) can auto-trust the 98 read-only tools and demand confirmation before any of the 44 that delete or cannot be undone. |
| Correct report parameters, per report | Each of the four reports gets its own schema: balance sheet takes date + period_count; profit-and-loss and cash flow take date_after + date_before; trial balance takes from_date + to_date. Wafeq silently ignores misspelled query parameters, so a wrong name looks like a working call. |
| Whole-period validation before sending | Profit-and-loss and cash flow reject ranges that don't align to whole months or years. The server checks locally and replies with the nearest valid range instead of spending a round trip on an HTTP 400. |
| Automatic idempotency keys | Every one of the 146 write endpoints that supports X-Wafeq-Idempotency-Key gets a UUID v4 automatically, reused across retries β so a network hiccup can never duplicate an invoice. Supply your own to make a deliberate re-run safe too. |
| File uploads that actually work | POST /files/ is multipart-only and POST /files/raw/ needs a Content-Disposition header. Both are handled; you pass base64 content and a filename. |
| Binary PDFs handled as bytes | The nine PDF endpoints are base64-encoded into a small envelope with size and content type, instead of being read as text and corrupted. |
| Automatic retries with backoff | Transient 429 / 5xx responses are retried with jittered exponential backoff, honoring Retry-After β with the same idempotency key, exactly as Wafeq's integration guide requires. |
| Built-in rate limiting | Self-throttles so a burst of tool calls doesn't trip a 429. Wafeq publishes no numeric limit, so the default is deliberately conservative and configurable. |
| Tenant verified at startup | A Wafeq API key is organization-scoped. The server calls GET /organization/ before serving and publishes the result on /health, so a mis-set key shows up as a name you can check rather than as writes against the wrong company's books. |
| Two transports: stdio and Streamable HTTP | Use it locally in Claude Desktop, or run one always-on server that any number of MCP clients reach over HTTP. |
| Docker + docker-compose, health check, auto-restart | docker compose up and it stays up, bound to localhost only. |
| Optional bearer-token auth on the HTTP endpoint | Put the server behind a shared secret the moment it's reachable beyond localhost. |
| Your secrets never reach the model | Credentials live in the server's environment and are injected on every request. The passthrough tool cannot override Authorization or point the credential at another host. |
| Drop-in spec updates | Wafeq ships a newer spec? Replace one file and rebuild β new endpoints become new tools automatically, no code changes. |
| Capability | This project | Generic OpenAPIβMCP wrapper* |
|---|---|---|
| All 251 Wafeq endpoints as tools | β | β |
| Per-tool safety category + banner | β | β |
| Tax-authority filing flagged as irreversible, not "create" | β | β |
readOnlyHint / destructiveHint MCP annotations | β | β |
| Read-only fields stripped from create/update bodies | β | β |
| Duplicated enum prose compacted out of schemas | β | β |
| Correct, per-report date parameters | β | β |
| Whole-period range validated before sending | β | β |
Automatic X-Wafeq-Idempotency-Key, stable across retries | β | β |
| Multipart + raw-binary file upload | β | β |
| Binary PDF responses base64-encoded, not mangled | β | β |
| Transaction dates recovered for journal line items | β | β |
Automatic retries on 429 / 5xx (honors Retry-After) | β | β |
| Client-side rate limiting | β | β |
| Organization identity verified at startup | β | β |
stdio transport | β | β |
| Streamable-HTTP transport | β | β |
| Docker + docker-compose, health check, auto-restart | β | β |
| Optional bearer-token auth on the endpoint | β | β |
| License | MIT | varies |
*Generic OpenAPIβMCP wrappers turn any spec into MCP tools. They can reach the same endpoints, but treat every operation identically β and against Wafeq's spec specifically they inherit the read-only-required-field problem described in MIGRATION.md. "β" = varies by tool / not guaranteed.
Once it's connected, ask your assistant things like:
At startup the server parses the bundled OpenAPI spec into MCP tools β resolving
$refs, guarding against recursive schemas, and stripping server-assigned
(readOnly) fields out of request bodies β tags each tool with its safety category,
verifies which Wafeq organization the credentials belong to, and then injects your
credential on every outgoing request. Your key stays in the server's environment; the
model never sees or handles it.
1. Add your credentials. Copy the example config and fill it in:
Then edit .env and set WAFEQ_API_KEY. Unless HOST is a loopback address the
server also requires MCP_AUTH_TOKEN and refuses to start without one, so set it
to a long random string: MCP_AUTH_TOKEN=$(openssl rand -hex 32).
2. Start the server:
docker-compose.yml binds to 127.0.0.1:8765 only, so the server is reachable from
your machine but not from the network.
3. Confirm it's running β and that it's pointed at the right books:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/wafeq)<a href="https://allmcps.com/mcp/wafeq"><img src="https://allmcps.com/api/badge/wafeq?style=directory" alt="Wafeq on AllMCPs" /></a>