braatzledger

Your books, as tools an assistant can use.

An MCP server exposes your ledger to the AI assistant you already use: read the close, search transactions, open a line and its provenance, categorise a line, turn an exception into a rule, run the rules — by asking, under a token you minted.

Its tools are generated from the API's own index at startup, so the assistant's view and the API's are one list, never two. It runs on your machine with one personal access token from Settings and nothing else installed.

The permission model is the app's, not a second one: every MCP tool call passes the same per-tenant capability checks as a page load, so an assistant can reach exactly what its tenant granted and nothing else. Read, write, and destructive scopes are separate grants, revocable per row, effective on the next call — no deploy, no support ticket.

The bar we are building to is public and measured: parity with the strongest bookkeeping MCP surface in the wild — a 42-tool server mirroring its API one to one — at the scope a working business actually uses. Reads and writes have landed; the destructive verbs (retiring a rule) are withheld by a ruling, not by a schedule.