---
updatedAt: 2026-10-01T13:30:58.000Z
agentTools:
  projectIndex: https://developer.spendesk.com/llms.txt
---

# Connect an AI assistant (MCP)

Ask your AI assistant about your company's spend, invoices and accounting — and act on them — through the Spendesk MCP server.

The Spendesk MCP server lets an AI assistant work with your Spendesk data. Once connected, you can ask it questions in plain language — *"Which supplier invoices are overdue?"*, *"How much did each cost center spend this quarter compared with last?"* — and, if you allow it, ask it to act: create a purchase order, update a supplier, mark a payable as exported.

It uses the [Model Context Protocol](https://modelcontextprotocol.io), an open standard for connecting AI assistants to business systems. The server and its tools evolve regularly: reconnect your assistant to pick up new tools, and send questions or feedback to <support-public-api@spendesk.com>. The assistant never sees your password: you sign in to Spendesk and approve what it may do — see [Using the AI assistant safely](https://developer.spendesk.com/reference/mcp-using-the-assistant-safely) for what protects you and what to know before allowing it to act.

# Who can use it

* **Admins and Account Owners** set the assistant up for the organisation, once (see [Set up the assistant](#set-up-the-assistant)).
* **Controllers and Account Owners** can then connect and use it.
* **Admins** can approve a connection, but the assistant cannot use it on their behalf.
* **Requesters** cannot connect.

Each connection works for one company, or for every company of your organisation if you approve it at organisation level — see [Several companies](#several-companies).

# Set up the assistant

An Admin or Account Owner does this once for the organisation, for each assistant — Claude, ChatGPT or Dust:

1. In Spendesk, open **Settings → Integrations → MCP**. For an organisation with several entities, the **MCP** tab of the multi-entity hub leads to the same page.
2. Choose the assistant, and confirm with your second factor.
3. Spendesk shows the connection details straight away: the server URL, a **client ID** and a **client secret**, and the authorization and token endpoints.
4. Give them to the administrator of your Claude, ChatGPT or Dust workspace, who adds Spendesk as a custom connector (below).

Step-by-step admin instructions for each assistant, including ChatGPT's publishing and Claude Team and Enterprise: [Set up Claude, ChatGPT or Dust](https://developer.spendesk.com/reference/mcp-set-up-claude-chatgpt-dust).

One connector serves the whole organisation; each person then signs in with their own Spendesk account and approves their own access. An Admin or Account Owner can change the permissions the connector may request later, from its detail page in Spendesk (**Permissions** tab, with a new second-factor check).

The server URL is:

| Environment | Server URL                                    |
| :---------- | :-------------------------------------------- |
| Production  | `https://public-api.spendesk.com/v1/mcp`      |
| Demo        | `https://public-api.demo.spendesk.com/v1/mcp` |

# Connect your assistant

## Claude

1. In Claude, open **Customize → Connectors** and choose **Add custom connector**.
2. Enter the server URL, then open **Advanced settings** and paste the client ID and client secret.
3. Connect, and approve the access in Spendesk (see [Approve the access](#approve-the-access)).

On Claude Team and Enterprise plans, an organisation Owner first adds the connector under **Organization settings → Connectors**. Claude then asks your permission the first time it uses each Spendesk tool: allow it once, always, or refuse.

## ChatGPT

1. In ChatGPT, open **Settings → Apps → Advanced settings** and turn on **Developer mode**.
2. Choose **Create app**, enter the server URL, and fill in the client ID and client secret under **Advanced OAuth settings**.
3. Connect, and approve the access in Spendesk.

## Dust and Langdock

Dust can use the connection details from Spendesk like Claude and ChatGPT. Dust and Langdock can also register themselves: add a remote MCP server with the Spendesk server URL, and the assistant opens the approval page.

## Approve the access

When you connect, Spendesk opens in your browser:

1. **Sign in**, with your usual second factor.
2. **Choose what to connect**: one company, or your whole organisation.
3. **Choose what the assistant may do.** Permissions are split into **Read** and **Write**, each with its sensitivity. Read permissions are ticked by default; write permissions are not — tick only those for the actions you want the assistant to carry out. Write actions are in **Beta**: a write permission only appears once an Account Owner or Admin has enabled it on the connection. You can untick anything.

The assistant only sees the tools your permissions allow, and your Spendesk role still applies to every action. To change your permissions, reconnect. Some actions cannot be undone — cancelling a purchase order or committing an accounting export, for example; the full list is in the page below. Spendesk instructs the assistant to ask for your confirmation before an action, but does not enforce it: keep your assistant's own approval on for write actions (in Claude, *Allow once*). Before ticking a write permission, read [Assistant actions and safety](https://developer.spendesk.com/reference/mcp-actions-and-safety): every action, what can be undone, and what keeps the assistant in check.

# Check the connection

Once connected, try these questions — they only read data:

* *"Which Spendesk companies can I access?"*
* *"What did we spend this quarter, by supplier? Top 5."*
* *"Which supplier invoices are overdue as of today?"*

The assistant should list your companies, then answer with the dates it used and the tools it called. If a company is missing, check that you are a Controller or Account Owner there.

# What the assistant can do

* **Analyse spend and cash** — spend by cost center, supplier, employee or month, compared with the previous period; cash movements; the workload of spend requests.
* **Follow invoices and suppliers** — overdue invoices by age, supplier invoices and the invoice inbox, supplier details; with permission, create, update or archive suppliers.
* **Prepare the accounting close** — read payables and their receipts, settlements, the chart of accounts; with permission, fix accounting fields, mark payables ready or exported, maintain accounts, and generate journal exports.
* **Manage purchase orders** — list them; with permission, create, cancel or close them.
* **Keep reference data tidy** — analytical fields, expense categories and cost centers; with permission, create, update or delete them.
* **Look up cards and card spend** — cards and their orders, requests, settled and declined transactions.

In detail — and tool by tool, with the permission each needs, in the [MCP tool reference](https://developer.spendesk.com/reference/mcp-tool-reference):

| Area                                     | Read                                                                                                        | Act (needs the matching permission)                                                                                                                            |
| :--------------------------------------- | :---------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Spend analysis                           | spend by cost center, supplier, employee, month…; cash movements; request workload; overdue invoices by age | —                                                                                                                                                              |
| Payables                                 | list, search, details, receipts                                                                             | update accounting fields, mark as ready, mark as exported                                                                                                      |
| Settlements                              | list payments and refunds                                                                                   | mark as exported                                                                                                                                               |
| Suppliers                                | list and details                                                                                            | create, update, archive                                                                                                                                        |
| Purchase orders                          | list                                                                                                        | create, cancel, close                                                                                                                                          |
| Accounting                               | chart of accounts                                                                                           | create, update and archive accounts; list journal templates, generate and download journal exports — all with the *Manage accounting exports* permission today |
| Analytical fields and expense categories | fields, values, categories, cost centers                                                                    | create, update, delete                                                                                                                                         |
| Cards, requests and transactions         | cards, card orders, requests, settled and failed transactions                                               | —                                                                                                                                                              |
| Invoices and invoice intake              | invoices, invoice summaries, inbox documents                                                                | —                                                                                                                                                              |
| Company                                  | companies you can access, users, wallet balance and top-ups                                                 | —                                                                                                                                                              |

## What the assistant cannot do

There is no tool to:

* **approve or reject** a request or an invoice — *Mark a payable as ready* means ready for accounting export, it is not an approval;
* **pay** an invoice or schedule a payment;
* **create or change** cards, users or cost centers;
* **read budgets** — the assistant analyses spend, it cannot compare it with a budget;
* **delete** a purchase order: it can only be cancelled.

For these, use Spendesk itself.

**The assistant does not receive events.** It reads and acts when you ask, not when something happens in Spendesk, so it cannot alert you on its own. To be told when something changes, use the API's [webhooks](https://developer.spendesk.com/reference/using-webhooks) (experimental); to check on demand, ask a question such as *"Which supplier invoices are due this week?"* or follow the recipe [List the invoices due this week](https://developer.spendesk.com/reference/list-the-invoices-due-this-week).

# Questions to try

Questions finance teams ask, tested on a Spendesk demo account: the assistant's answers matched the API figure for figure. They only read data. With several companies, name the one you mean — *"For our French entity: …"*.

| Job             | Ask                                                                                                                                                                     | Good to know                                                                                                                                      |
| :-------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------ |
| Spend analysis  | *"How much did we spend last quarter by cost center, compared with the quarter before?"*                                                                                | Amounts include VAT and follow the expense date, not the accounting date — ask for accounting dates when you reconcile with the ledger.           |
| Suppliers       | *"Which 5 suppliers did we spend the most with this year, and how much with each?"*                                                                                     | Credit notes are netted in.                                                                                                                       |
| Month export    | *"List all our spend for August 2026 with the supplier or employee, amount, cost center and whether a receipt is attached, as a table I can paste into a spreadsheet."* | For large months, ask for the total first. The [monthly spend recipe](https://developer.spendesk.com/reference/export-a-month-of-spend-to-a-spreadsheet) gives the same file as a CSV. |
| Month-end close | *"For August 2026: how many expenses are missing a receipt, how many are not exported to accounting yet, and which supplier invoices are still waiting for approval?"*  | The assistant cannot tell a failed export from one still waiting — see the [month-end close checklist](https://developer.spendesk.com/reference/month-end-close-checklist).            |
| Invoices to pay | *"Which approved supplier invoices are due in the next 7 days or already overdue? Give the supplier, the amount still due and the total per currency."*                 | The assistant works from payables; [List the invoices due this week](https://developer.spendesk.com/reference/list-the-invoices-due-this-week) reads the invoices themselves.          |
| Purchase orders | *"Which purchase orders are still open, for which supplier, and for what amount?"*                                                                                      | Shows the committed amount and what has been billed so far.                                                                                       |
| Approvals       | *"How many spend requests are waiting for approval, how long have they been waiting, and who requested them?"*                                                          | Covers card requests (single purchase, subscription, multi-use, physical card loads), not supplier invoices or expense claims.                    |
| Cash            | *"What is our Spendesk wallet balance, how much is still available, and which wallet loads did we receive in the last 30 days?"*                                        | Answered per company. See also [Check the wallet balance](https://developer.spendesk.com/reference/check-the-wallet-balance).                                                          |

Follow-up questions work too: *"Break that down by supplier"*, *"Same for the other entity"*, *"Which of these are still unpaid?"*.

# Several companies

With an organisation-level connection, the assistant can work across the companies of your group. It first lists them, then works on one company at a time: tell it which one — *"for the German entity"* — or ask for a comparison, and it will go through each company in turn. It only sees companies where you are a Controller or Account Owner.

# Getting good answers

The server gives the assistant rules to follow. Knowing them helps you read its answers:

* **Dates.** The assistant states the exact dates it uses (*"from 2026-07-01 to 2026-09-30"*). If your question is ambiguous — *"last quarter"*, a fiscal year — it asks. When the day matters, say it (*"overdue as of 30 September"*): around midnight, the server's "today" may differ from yours.
* **Complete figures only.** Totals and rankings come from the analysis tools, which always cover all the data. The assistant does not total a partial list.
* **Amounts** are shown as Spendesk formats them, in their own currency. Amounts in different currencies are never added together.
* **Links** to Spendesk pages come from Spendesk itself; the assistant does not build them.
* **Actions** happen only when you ask for them. Some cannot be undone: cancelling a purchase order, marking entries as exported, or generating an accounting export that marks entries as exported. Export previews are the default.

# Troubleshooting

| What you see                                                                 | What it means                                                                 | What to do                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| :--------------------------------------------------------------------------- | :---------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| The assistant says a tool does not exist                                     | The permission is not enabled on the connection, or you did not tick it       | An Account Owner or Admin enables it (**Permissions** tab); then disconnect, connect again and tick it — refreshing the tool list is not enough                                                                                                                                                                                                                                                                                                    |
| "Insufficient role"                                                          | You are not a Controller or Account Owner of that company                     | Ask for the role, or use another company                                                                                                                                                                                                                                                                                                                                                                                                           |
| "This tool requires a companyId"                                             | Organisation-level connection, no company chosen                              | Tell the assistant which company                                                                                                                                                                                                                                                                                                                                                                                                                   |
| The connection asks you to sign in again                                     | The connection was unused for more than 30 days                               | Reconnect                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| The connection fails or new tools do not appear                              | The assistant kept an old session or tool list                                | **Claude**: in **Customize → Connectors**, open the Spendesk connector, disconnect and connect again. **ChatGPT**: disconnect and reconnect the app in **Settings → Apps**; in a Business or Enterprise workspace, an admin also has to refresh the published app (see [Set up Claude, ChatGPT or Dust](https://developer.spendesk.com/reference/mcp-set-up-claude-chatgpt-dust)). **Dust, Langdock**: remove and add the server again. Check you sign in to the right Spendesk account |
| Too many requests                                                            | More than 100 simultaneous requests for a company, or 200 for an organisation | Wait a moment and retry                                                                                                                                                                                                                                                                                                                                                                                                                            |
| A client secret was exposed (pasted in a chat, a ticket, an AI conversation) | Anyone holding it could start a sign-in for your connector                    | An Account Owner or Admin removes the connection (**Remove**) and creates a new one: a secret cannot be regenerated. Users then connect again                                                                                                                                                                                                                                                                                                      |

For every error message and what to do, see [MCP errors and limits](https://developer.spendesk.com/reference/mcp-errors-and-limits).

# For developers: how the connection works

The server implements the MCP Streamable HTTP transport on `POST`, `GET` and `DELETE` `/v1/mcp`, and exposes tools only (no resources or prompts).

* **Clients**: Claude, ChatGPT and Dust clients are created in the Spendesk app (see above). Dust and Langdock can use dynamic client registration. For any other client — VS Code, for instance — contact your Spendesk account team.
* **Authorization** is OAuth 2.0 authorization code with PKCE (`S256`). Public API keys are refused. An unauthenticated call returns `401` with a `WWW-Authenticate` header pointing to the metadata.
* **Discovery**: [protected resource metadata](https://developer.spendesk.com/reference/mcp-protected-resource-metadata-mcp) at `/.well-known/oauth-protected-resource/v1/mcp`, and [authorization server metadata](https://developer.spendesk.com/reference/mcp-authorization-server-metadata) at `/.well-known/oauth-authorization-server`.
* **Endpoints**: [authorize](https://developer.spendesk.com/reference/v1-request-authorization), [token](https://developer.spendesk.com/reference/v1-create-oauth2-token) (code exchange and refresh), and [dynamic client registration](https://developer.spendesk.com/reference/v1-register-oauth2-client), which is open to supported partners only.
* **Resource**: send `resource=<server URL>` (RFC 8707) when you request the token.
* **Tokens**: access tokens last one hour. Refresh tokens rotate on each use and expire after 30 days without use.
* **Permissions**: the token's scopes decide which tools `tools/list` returns; calling a tool outside them returns JSON-RPC error `-32601`. Tool errors come back as results with `isError: true` — every error is explained in [MCP errors and limits](https://developer.spendesk.com/reference/mcp-errors-and-limits).
* **Limits**: 100 concurrent requests per company and 200 per organisation, on top of the [rate limits](https://developer.spendesk.com/reference/rate-limiting) of the API.

## An MCP server for this documentation

A second, public MCP server gives coding assistants access to this documentation and the API reference — no Spendesk account or sign-in needed. Add `https://developer.spendesk.com/mcp` to your editor's assistant to let it list and search the endpoints and read their parameters and schemas while you build.

See also [How to Authenticate](https://developer.spendesk.com/reference/how-to-authenticate) and [Organisation-level access](https://developer.spendesk.com/reference/organisation-level-access).