Skip to main content

AI & integrations

Connect your AI assistant

Connect Claude, ChatGPT, Cursor, or any MCP client to your books — what the connection can do, what it never can, and how to control it.

PulseBooks runs a Model Context Protocol (MCP) server, so an AI assistant can work inside your real books: capture income and expenses with their receipts, draft invoices and credit notes, reconcile a bank statement, keep supplier and bill records, post journal entries, and read every report the app can run. It is included on every plan.

Connecting

  1. In Claude, ChatGPT, Cursor, or any MCP client, add PulseBooks as a connector with this address:
https://pulsebooks.app/api/mcp
  1. Your client opens a PulseBooks sign-in and consent screen. If you belong to more than one organisation, you choose which one the connection may touch — a connection is bound to exactly one organisation.
  2. The consent screen spells out every permission the connection will hold. Nothing is granted until you approve, and approving is all-or-nothing for that connection: if the list is more than you want to grant, deny it.
  3. Ask for something. "What's overdue?" is a good first question. So is handing it a photo of a receipt.

Each assistant is its own connection with its own grant. Claude on your laptop and an agent in your editor are separate, and each can be revoked on its own.

What a connection can do

Around a hundred tools, covering six jobs: capturing transactions and receipts, drafting sales documents, keeping purchase records, reconciling banking, posting accounting entries, and reading reports. The exact capabilities depend on the permissions in the connection's grant, and every call re-checks that grant — plus your live membership and role — at the moment it runs.

Your role applies to the assistant too: a connection authorised by an accountant (a read-only role) cannot write, whatever its grant says.

What a connection can never do

Some limits are structural — no permission in the catalogue reaches them:

  • Nothing is ever sent to anyone. No invoice, quote, statement, receipt, reminder or agreement leaves the server. The assistant prepares drafts; a signed-in human reviews the recipient and sends from PulseBooks.
  • Issuing stays with you. An assistant can create and edit invoice drafts, but only a person can move an invoice out of draft or pass on its payment link.
  • Almost nothing can be deleted. Documents a person created — invoices, credit notes, bills, clients, products, assets, agreements — are archived, voided or cancelled, never deleted, which keeps the audit trail. The narrow permanent removals that do exist (a still-draft invoice, a duplicate income or expense entry, unmatching a reconciled line) each ask you first, name what they are about to remove, and cannot be undone.
  • Sensitive actions pause for your yes. High-impact operations require an explicit confirmation token before they run — the assistant has to show you what it is about to do and get your approval in the conversation.

Managing and revoking connections

Settings → Developer lists every connection to your organisation: which client, which permissions, and when it was last used. Revoking one takes effect on the assistant's very next request — tokens are re-validated on every call, so there is no waiting for an expiry. Removing a member from the organisation revokes their connections the same way.

Your own connections (across organisations) are also listed under your profile's connected apps.

Auditing what an assistant did

Everything a connection writes lands in the same audit log as your team's work, attributed to the connection. If an assistant files something wrongly, correct it the way you would correct anyone's entry — the history stays.