Connect an AI assistant (MCP)

Ask your AI assistant about your company's spend, invoices and accounting — and act on them — through the Spendesk MCP server.

The Spendesk MCP server lets an AI assistant work with your Spendesk data. Once connected, you can ask it questions in plain language — "Which supplier invoices are overdue?", "How much did each cost center spend this quarter compared with last?" — and, if you allow it, ask it to act: create a purchase order, update a supplier, mark a payable as exported.

It uses the Model Context Protocol, an open standard for connecting AI assistants to business systems. The server and its tools evolve regularly: reconnect your assistant to pick up new tools, and send questions or feedback to [email protected]. The assistant never sees your password: you sign in to Spendesk and approve what it may do.

Who can use it

  • Admins and Account Owners set the assistant up for the organisation, once (see Set up the assistant).
  • Controllers and Account Owners can then connect and use it.
  • Admins can approve a connection, but the assistant cannot use it on their behalf.
  • Requesters cannot connect.

Each connection works for one company, or for every company of your organisation if you approve it at organisation level — see Several companies.

Set up the assistant

An Admin or Account Owner does this once for the organisation, for each assistant — Claude, ChatGPT or Dust:

  1. In Spendesk, open Settings → Integrations → MCP. For an organisation with several entities, the MCP tab of the multi-entity hub leads to the same page.
  2. Choose the assistant, and confirm with your second factor.
  3. Spendesk shows the connection details straight away: the server URL, a client ID and a client secret, and the authorization and token endpoints.
  4. Give them to the administrator of your Claude, ChatGPT or Dust workspace, who adds Spendesk as a custom connector (below).

One connector serves the whole organisation; each person then signs in with their own Spendesk account and approves their own access. The Admin can change the permissions the connector may request later, from its detail page in Spendesk (Permissions tab, with a new second-factor check).

The server URL is:

EnvironmentServer URL
Productionhttps://public-api.spendesk.com/v1/mcp
Demohttps://public-api.demo.spendesk.com/v1/mcp

Connect your assistant

Claude

  1. In Claude, open Customize → Connectors and choose Add custom connector.
  2. Enter the server URL, then open Advanced settings and paste the client ID and client secret.
  3. Connect, and approve the access in Spendesk (see Approve the access).

On Claude Team and Enterprise plans, an organisation Owner first adds the connector under Organization settings → Connectors. Claude then asks your permission the first time it uses each Spendesk tool: allow it once, always, or refuse.

ChatGPT

  1. In ChatGPT, open Settings → Apps → Advanced settings and turn on Developer mode.
  2. Choose Create app, enter the server URL, and fill in the client ID and client secret under Advanced OAuth settings.
  3. Connect, and approve the access in Spendesk.

Dust and Langdock

Dust can use the connection details from Spendesk like Claude and ChatGPT. Dust and Langdock can also register themselves: add a remote MCP server with the Spendesk server URL, and the assistant opens the approval page.

Approve the access

When you connect, Spendesk opens in your browser:

  1. Sign in, with your usual second factor.
  2. Choose what to connect: one company, or your whole organisation.
  3. Choose what the assistant may do. Permissions are split into Read and Write, each with its sensitivity. Read permissions are ticked by default; write permissions are not — tick only those for the actions you want the assistant to carry out. You can untick anything.

The assistant only sees the tools your permissions allow, and your Spendesk role still applies to every action. To change your permissions, reconnect. Some actions cannot be undone — cancelling a purchase order, or committing an accounting export — and the assistant asks for your confirmation before an action.

Check the connection

Once connected, try these questions — they only read data:

  • "Which Spendesk companies can I access?"
  • "What did we spend this quarter, by supplier? Top 5."
  • "Which supplier invoices are overdue as of today?"

The assistant should list your companies, then answer with the dates it used and the tools it called. If a company is missing, check that you are a Controller or Account Owner there.

What the assistant can do

  • Analyse spend and cash — spend by cost center, supplier, employee or month, compared with the previous period; cash movements; the workload of spend requests.
  • Follow invoices and suppliers — overdue invoices by age, supplier invoices and the invoice inbox, supplier details; with permission, create, update or archive suppliers.
  • Prepare the accounting close — read payables and their receipts, settlements, the chart of accounts; with permission, fix accounting fields, mark payables ready or exported, maintain accounts, and generate journal exports.
  • Manage purchase orders — list them; with permission, create, cancel or close them.
  • Keep reference data tidy — analytical fields, expense categories and cost centers; with permission, create, update or delete them.
  • Look up cards and card spend — cards and their orders, requests, settled and declined transactions.

In detail:

AreaReadAct (needs the matching permission)
Spend analysisspend by cost center, supplier, employee, month…; cash movements; request workload; overdue invoices by age—
Payableslist, search, details, receiptsupdate accounting fields, mark as ready, mark as exported
Settlementslist payments and refundsmark as exported
Supplierslist and detailscreate, update, archive
Purchase orderslistcreate, cancel, close
Accountingchart of accountscreate, update and archive accounts; list journal templates, generate and download journal exports — all with the Manage accounting exports permission today
Analytical fields and expense categoriesfields, values, categories, cost centerscreate, update, delete
Cards, requests and transactionscards, card orders, requests, settled and failed transactions—
Invoices and invoice intakeinvoices, invoice summaries, inbox documents—
Companycompanies you can access, users, wallet balance and top-ups—

Several companies

With an organisation-level connection, the assistant can work across the companies of your group. It first lists them, then works on one company at a time: tell it which one — "for the German entity" — or ask for a comparison, and it will go through each company in turn. It only sees companies where you are a Controller or Account Owner.

Getting good answers

The server gives the assistant rules to follow. Knowing them helps you read its answers:

  • Dates. The assistant states the exact dates it uses ("from 2026-07-01 to 2026-09-30"). If your question is ambiguous — "last quarter", a fiscal year — it asks. When the day matters, say it ("overdue as of 30 September"): around midnight, the server's "today" may differ from yours.
  • Complete figures only. Totals and rankings come from the analysis tools, which always cover all the data. The assistant does not total a partial list.
  • Amounts are shown as Spendesk formats them, in their own currency. Amounts in different currencies are never added together.
  • Links to Spendesk pages come from Spendesk itself; the assistant does not build them.
  • Actions happen only when you ask for them. Some cannot be undone: cancelling a purchase order, marking entries as exported, or generating an accounting export that marks entries as exported. Export previews are the default.

Troubleshooting

What you seeWhat it meansWhat to do
The assistant says a tool does not existThe connection lacks the permission for itReconnect and tick the permission
"Insufficient role"You are not a Controller or Account Owner of that companyAsk for the role, or use another company
"This tool requires a companyId"Organisation-level connection, no company chosenTell the assistant which company
The connection asks you to sign in againThe connection was unused for more than 30 daysReconnect
The connection fails or new tools do not appearThe assistant kept an old session or tool listClaude: in Customize → Connectors, open the Spendesk connector, disconnect and connect again. ChatGPT: disconnect and reconnect the app in Settings → Apps. Dust, Langdock: remove and add the server again. Check you sign in to the right Spendesk account
Too many requestsMore than 100 simultaneous requests for a company, or 200 for an organisationWait a moment and retry

For developers: how the connection works

The server implements the MCP Streamable HTTP transport on POST, GET and DELETE /v1/mcp, and exposes tools only (no resources or prompts).

  • Clients: Claude, ChatGPT and Dust clients are created in the Spendesk app (see above). Dust and Langdock can use dynamic client registration. For any other client — VS Code, for instance — contact your Spendesk account team.
  • Authorization is OAuth 2.0 authorization code with PKCE (S256). Public API keys are refused. An unauthenticated call returns 401 with a WWW-Authenticate header pointing to the metadata.
  • Discovery: protected resource metadata at /.well-known/oauth-protected-resource/v1/mcp, and authorization server metadata at /.well-known/oauth-authorization-server.
  • Endpoints: authorize, token (code exchange and refresh), and dynamic client registration, which is open to supported partners only.
  • Resource: send resource=<server URL> (RFC 8707) when you request the token.
  • Tokens: access tokens last one hour. Refresh tokens rotate on each use and expire after 30 days without use.
  • Permissions: the token's scopes decide which tools tools/list returns; calling a tool outside them returns JSON-RPC error -32601. Tool errors come back as results with isError: true.
  • Limits: 100 concurrent requests per company and 200 per organisation, on top of the rate limits of the API.

An MCP server for this documentation

A second, public MCP server gives coding assistants access to this documentation and the API reference — no Spendesk account or sign-in needed. Add https://developer.spendesk.com/mcp to your editor's assistant to let it list and search the endpoints and read their parameters and schemas while you build.

See also How to Authenticate and Organisation-level access.