Accounting MCP server: what it does and which ones exist
An accounting MCP server lets an AI app such as Claude or ChatGPT read, and sometimes change, your books through one standard connection. As of September 30, 2026, Intuit's QuickBooks connector can read and create invoices and transactions, Xero's and Digits' connectors are read-only, and Accountable's adds previews, approvals, undo and an audit log to every write.
Updated · 7 min read · By the Accountable team
The short version
- MCP (Model Context Protocol) is an open standard that connects AI apps like Claude and ChatGPT to outside data and tools, so one accounting server works in many AI apps.
- Xero's Claude connector and Digits' MCP server are read-only by design, so they answer questions but cannot change your books.
- Intuit's hosted QuickBooks connector in Claude and ChatGPT can also create and send invoices and categorize transactions, and asks for confirmation before destructive actions such as deleting an invoice.
- Intuit also publishes an open-source QuickBooks server with more than 140 tools that runs on your own computer, and Xero's developer organization publishes one with 50+ tools.
- A write-capable accounting server needs five controls: a preview, an approval the agent cannot grant itself, undo, an audit log, and locked closed months.
An MCP server is a standard plug between an AI app and your books
MCP stands for Model Context Protocol. Its own documentation describes it as an open standard for connecting AI applications to outside systems, and compares it to a USB-C port: one shape of plug that works with many devices. An accounting MCP server is the plug on the accounting side. It lists the things an AI app may do with your books, such as “run the profit and loss report” or “categorize these three transactions”, and does them when asked.
You add the server's web address to Claude, ChatGPT or another MCP app, sign in to your accounting system, and pick what the app may see. After that you can ask in plain English: “What did we spend on software in Q3?” The AI app calls the server, the server reads the books, and the answer comes back with real numbers instead of a guess.
Reading is safe and writing is where the risk sits
A read-only server can get an answer wrong, but it cannot change your books. A server that can write can post a wrong entry, recategorize a year of transactions, or send an invoice to a customer. Both OpenAI and Anthropic warn about this in their own help pages. OpenAI says write actions by default require confirmation in ChatGPT and that incorrect write actions can destroy, alter or share data. Claude's help center says to connect only to servers you trust and to disable tools that can take write actions when you run research.
The chat app's confirmation helps, but it is not a bookkeeping control. It asks “Allow this tool call?” and cannot know whether the entry balances, sits in a closed month or is larger than you would ever approve. Those checks belong in the accounting system, where they apply no matter which AI app made the call.
Four accounting MCP servers you can use today
These are the options from each company's own pages, checked on September 30, 2026. Each can change, so check the linked source before you connect.
| Server | Where it runs | Read | Write | Notes |
|---|---|---|---|---|
| QuickBooks connector (Intuit) | Hosted by Intuit, in Claude and ChatGPT | Yes: reports, business profile | Yes: invoices, estimates, customers, products, import and categorize transactions | US only at launch. Destructive actions such as deleting an invoice ask for your confirmation. The support page lists no undo or audit log. |
| QuickBooks Online MCP server (Intuit, open source) | Your own computer (a local process) | Yes: 11 financial reports and search across 29 entity types | Yes, and it can be switched off with a setting | Built for developers: you create an Intuit developer app and supply OAuth keys. |
| Xero connector and Xero MCP server | Connector: hosted, in Claude. Server: your own computer | Yes: profit and loss, cash, invoices, top customers | Connector: no, read-only. Open-source server: yes, invoices, contacts, payments and more | Connector is free with a Xero subscription and a Claude account. Server needs Node.js and API credentials. |
| Digits MCP server | Hosted at api.digits.com/mcp | Yes: transactions, categories, reconciliation status, ledger | No: read-only by design | Free on all plans. Works with Claude, ChatGPT, Cursor and other MCP apps. |
| Accountable MCP server | Hosted at accountable.im/mcp | Yes, on every plan including Free | Yes, on Pro and Holding, with preview, approval rules, undo and an audit log | 13 shared tools. You pick which companies the AI app can open and whether it can only read. |
QuickBooks has the widest official reach: a hosted connector for people who do not write code, and an open-source server that covers 29 kinds of records. If your books already live in QuickBooks, start there. Xero and Digits chose read-only, which is the safest choice if you only want answers. Accountable is the choice when you want an AI app to do the bookkeeping and still keep a person in charge of the big changes.
Five controls every write-capable accounting server needs
Before you let any AI app change your books, ask the vendor whether each of these exists. You can test most of them in ten minutes on a demo company.
Step 1: Preview before write. The AI app can see exactly what would change, line by line, before anything is saved.
Step 2: Approval the agent cannot give itself. Large or unusual changes wait for a named person, and no tool in the server can approve.
Step 3: Undo. Any change can be reversed, and the reversal is itself recorded.
Step 4: An audit log that names the AI app and the person whose connection it used, so you can answer “who changed this?” a year later.
Step 5: Closed months stay closed. A change to a locked month waits until a person reopens the month.
Accountable's server was built around these five. Its preview tool changes nothing, and run applies exactly the preview you saw. By default an AI app's changes apply at once but entries over your owner's limit (set at $5,000 until you change it), reopening a month and anything sent outside the company wait for a person. You can instead choose Full control, Every change waits for approval, or Read only. The audit log reads like “Claude via Maya's connection”, and every change can be undone. No tool can approve a change, send an email or move money.
What each plan and AI app lets you connect
- Claude: custom connectors work on Free, Pro, Max, Team and Enterprise plans. Free users can add one custom connector. On Team and Enterprise only an owner can add it.
- ChatGPT: developer mode, which lets you add your own MCP server, is available on Pro, Plus, Business, Enterprise and Education accounts on the web. You turn it on under Settings, then Security and login.
- Accountable: reading works on every plan. Writing needs Pro, at $149 a month for 2 companies, or Holding. Every new workspace gets a 14-day Pro trial with no card.
- Any MCP app, such as Cursor, connects with the same web address, or with a personal access token that is read-only or read and write for the companies you choose.
How to connect Claude or ChatGPT to Accountable in five minutes
Step 1: Open Settings, then AI and agents, in Accountable and copy the server URL.
Step 2: In Claude, go to Customize, then Connectors, press the plus button and choose Add custom connector. In ChatGPT, turn on developer mode and create a connector with OAuth.
Step 3: Paste the URL and sign in to Accountable when the app asks.
Step 4: On the consent screen, choose All my companies or Only these, then Read and make changes or Read only.
Step 5: Ask something that touches real numbers, such as “What are our burn and runway this month?”, and check the answer against the Home page.
The full guide is on the Accountable agents page. Step-by-step help for Claude and ChatGPT names every screen.
Questions founders ask
Does QuickBooks have an MCP server?
Yes, two. Intuit runs a hosted QuickBooks connector in Claude and ChatGPT that reads reports and creates invoices and transactions, and it publishes an open-source QuickBooks Online MCP server on GitHub that runs on your own computer and needs an Intuit developer app.
Does Xero have an MCP server?
Xero has a free, read-only connector in Claude for questions about profit, cash and invoices. Xero's developer organization also publishes an open-source MCP server on GitHub that can create invoices, contacts and payments.
Is it safe to give Claude or ChatGPT write access to my books?
It is safe only when the accounting system enforces the limits: previews, approvals the AI cannot grant itself, undo, an audit log and locked closed months. A confirmation popup in the chat app alone does not check your books.
Do I need to write code to use an accounting MCP server?
No for the hosted ones. You add a connector in Claude or ChatGPT and sign in. The open-source QuickBooks and Xero servers do need a developer setup with API keys.
What does an accounting MCP server cost?
Digits' MCP server is free on all plans, and Xero's Claude connector is free with a Xero subscription. Intuit's hosted connector works with existing QuickBooks subscriptions. Accountable's server reads on the free plan and writes on Pro at $149 a month.
An MCP server where big changes wait for you
Accountable's MCP server lets Claude or ChatGPT categorize, post entries and prepare the close. Every change shows a preview, is logged and can be undone, and large ones wait for your approval.
Connect your agentSources, checked September 30, 2026:
- Model Context Protocol: What is MCP?
- QuickBooks: QuickBooks expands into Claude and ChatGPT with new features
- QuickBooks Help: Use Claude to enter transactions and get insights in QuickBooks
- Intuit on GitHub: quickbooks-online-mcp-server
- Xero: Claude connector
- Claude connectors directory: Xero
- XeroAPI on GitHub: xero-mcp-server
- Digits: Digits MCP
- Digits press release, April 21, 2026 (Yahoo Finance copy)
- OpenAI: ChatGPT developer mode
- Claude Help Center: Get started with custom connectors using remote MCP