DubblBLOCK
A full-featured, open-source alternative to Xero and QuickBooks. It is API-first, developer-friendly, and built for teams that want full control over their financial data.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
dubbl Open source, double-entry bookkeeping for modern teams.
dubbl is a full-featured, open-source alternative to Xero and QuickBooks. It is API-first, developer-friendly, and built for teams that want full control over their financial data.
Features
- Double-entry bookkeeping - Chart of accounts, journal entries, bank reconciliation
- Invoicing and quotes - PDF generation, payment tracking, recurring invoices, credit notes
- Bills and purchase orders - Accounts payable, purchase requisitions, landed costs
- Banking - CSV import, bank reconciliation, scheduled transactions
- Expense management - Claims, receipt OCR, approval workflows, recurring expenses
- Inventory - Warehouses, stock takes, assembly/BOM, serial and lot tracking, valuation
- Payroll - Employees, contractors, pay runs, tax forms, timesheets, leave management
- Projects - Time tracking, milestones, tasks, billable hours
- CRM - Pipeline management, deals, analytics
- Fixed assets - Depreciation schedules, disposal tracking
- Budgets - Budget creation, variance analysis, budget vs actual
- Tax - Multi-jurisdiction tax rates, VAT returns, BAS, Schedule C, sales tax
- 25+ financial reports - P&L, balance sheet, cash flow, aged receivables, and more
- Multi-currency - Exchange rates, currency conversion
- Documents - File management and storage
- Audit trail - Full aud
0d7efda2f225OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add dubbl --env AUTH_APPLE_ID=${AUTH_APPLE_ID} --env AUTH_APPLE_KEY_BASE64=${AUTH_APPLE_KEY_BASE64} --env AUTH_APPLE_KEY_ID=${AUTH_APPLE_KEY_ID} --env AUTH_APPLE_SECRET=${AUTH_APPLE_SECRET} -- npx -y [email protected]{
"mcpServers": {
"dubbl": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"AUTH_APPLE_ID": "${AUTH_APPLE_ID}",
"AUTH_APPLE_KEY_BASE64": "${AUTH_APPLE_KEY_BASE64}",
"AUTH_APPLE_KEY_ID": "${AUTH_APPLE_KEY_ID}",
"AUTH_APPLE_SECRET": "${AUTH_APPLE_SECRET}"
}
}
}
}Exposed tools (200)
205 read · 138 write · 27 destructive. Blast radius: 27 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Advisor | read | Full access to every feature — intended for accountants and advisors. |
Bookkeeper | read | Can manage day-to-day accounting tasks |
Engineering | read | Product engineering team |
Finance | read | Finance and accounting team |
Free | read | Included with every org |
Growth | read | For established businesses |
Invoice-only | write | Limited to creating invoices, quotes, credit notes and managing contacts and payments. |
Leadership | read | Executive leadership |
Read-only | read | View-only access to financial data with no ability to make changes. |
Scale | read | For large organizations |
Standard | read | Everyday operational access without owner/admin-only powers (no posting, approvals or settings). |
Starter | read | For growing teams |
Viewer | read | Read-only access to all financial data |
accept_quote | read | Mark a sent sales quote/estimate as accepted by the customer. Only |
add_consolidation_member | write | Add an organization as a member entity of a consolidation group. The current user must belong to the target organization. Optionally override the member |
add_deal_activity | write | Log an activity (note, email, call, meeting or task) against a deal. The activity is attributed to the current user. Provide scheduledAt (ISO date-time) for upcoming tasks/meetings. Returns the created activity. |
add_price_list_item | write | Add an item |
adjust_inventory_stock | write | Adjust an inventory item and post the matching journal entry. Three kinds: |
aged_payables | read | Generate an aged payables report showing outstanding bills grouped by aging buckets (Current, 1-30, 31-60, 61-90, 90+ days). Amounts are in integer cents. Pass asAt (YYYY-MM-DD) for a historical snapshot: aging is measured from that date and each bill |
aged_receivables | read | Generate an aged receivables report showing outstanding invoices grouped by aging buckets (Current, 1-30, 31-60, 61-90, 90+ days). Amounts are in integer cents. Pass asAt (YYYY-MM-DD) for a historical snapshot: aging is measured from that date and each invoice |
allocate_landed_cost | read | Allocate (capitalise) a DRAFT landed-cost allocation onto the inventory behind its purchase order. Spreads each cost component across the PO lines pro-rata by line value (or quantity when allocationMethod is |
apply_bank_rules | write | Apply all active bank rules to uncategorized transactions. Matches rules against transaction descriptions/references and updates matching transactions with the rule |
apply_credit_note | write | Apply a customer credit note |
apply_customer_credit | write | Apply an open customer credit to an invoice. Moves the Customer Deposits 2410 liability onto the invoice: posts DR Customer Deposits 2410 / CR Accounts Receivable 1200, records the allocation, decrements the credit |
apply_debit_note | write | Apply a supplier debit note |
apply_stock_take | write | |
apply_tax_profile | write | Apply a country tax profile to this organization: seeds the profile |
approve_bill | read | Approve a draft or pending_approval bill. Changes status to |
approve_expense_claim | read | Approve a submitted expense claim. Posts the approval journal entry — DR each expense line to its account (falling back to Miscellaneous Expense 5990) / CR Employee Reimbursements Payable 2110 for the total — dated today, then flips status to |
approve_invoice | read | Approve an invoice that is pending approval. Records the approval action against the open approval request via the approval engine (enforcing approver-step validation and multi-step advance). Only returns the invoice to |
approve_purchase_requisition | read | Approve a submitted purchase requisition. Sets status to |
approve_request | read | Approve the current step of an approval request. You must be the assigned approver for the current step. |
approve_timesheet | read | Approve a submitted timesheet. Only timesheets in |
assign_role | destructive | Assign a custom role to a member, or remove their custom role (pass null). Requires change:roles permission. The member |
attach_file_to_entity | read | Attach a file to any business entity (invoice, bill, payment, journal entry, bank transaction, contact, etc.). Returns the document record plus a presigned S3 upload URL the file bytes must be PUT to. File size in bytes. |
attach_tag | read | Attach a tag to a record (journal entry, invoice, bill, expense, contact, or project). The tag must belong to the caller |
auto_reconcile_bank_transactions | read | Automatically link unreconciled bank lines to ALREADY-POSTED cash journal entries (e.g. payments recorded manually) that move a bank ledger account and aren |
balance_sheet | read | Generate a balance sheet report showing assets, liabilities, and equity with totals (cumulative balances as at a date). Only includes posted entries. Balances are decimal strings. Pass asAt to choose the point in time (defaults to today) and compareDates to add prior-date comparative columns. |
budget_vs_actual | read | Budget-vs-actual report for one budget. For each budget line it compares the budgeted amount against actual posted general-ledger activity for that account within the budget |
build_assembly | write | Complete (build) a draft/in-progress assembly order: issues every BOM component at its current cost (incl. wastage), adds the BOM |
bulk_cash_code | read | |
bulk_categorize_bank_transactions | read | |
bulk_delete_contacts | destructive | Soft-delete many contacts in one call (they move to trash and can be restored). Only contacts in THIS org are deleted; other-org ids are ignored. Each deletion is audited. Returns the number deleted. |
bulk_mark_invoices_paid | read | |
bulk_mark_invoices_sent | read | |
bulk_send_invoice_reminders | write | |
bulk_set_contacts_type | write | Set the TYPE (customer, supplier, or both) on many contacts in one call. This is the bulk equivalent of the |
cancel_accrual_schedule | write | Cancel an accrual schedule, setting its status to |
cancel_revenue_schedule | write | Cancel a revenue recognition schedule, setting its status to |
capitalize_cwip_asset | read | Capitalize a capital-work-in-progress (CWIP) asset into service: transfers the accumulated CWIP cost into the fixed-asset account and starts depreciation. Sums the asset |
cash_flow_statement | read | Generate a cash flow statement using the indirect method. Shows operating, investing, and financing activities with opening/closing cash balances. Amounts in integer cents. |
categorize_bank_transaction | read | |
check_invoice_compliance | read | Check an invoice for compliance warnings based on the organization |
close_fiscal_year | read | Close a fiscal year. Creates year-end closing journal entries (DR revenue, CR expense, net to Retained Earnings 3200), sets isClosed=true, and creates a period lock. Validates no draft entries exist first. |
connect_stripe | read | Generate a Stripe Connect OAuth URL to connect a Stripe account. Returns a URL that the user should open in their browser to authorize the connection. |
convert_amount | read | Convert a monetary amount (in integer minor units, e.g. cents) from one currency to another using the organization |
convert_po_to_bill | write | Create a bill from a purchase order. Omit |
convert_purchase_requisition | write | Convert an APPROVED purchase requisition into a purchase order (PO). Copies the requisition |
convert_quote_to_invoice | read | |
create_account | write | Create a new chart of accounts entry. Account code must be unique within the organization. Type determines the account |
create_accrual_schedule | write | |
create_approval_workflow | write | Create an approval workflow with ordered steps. Each step specifies a member who must approve. |
create_asset_category | write | Create a reusable asset category (asset class) holding default depreciation + posting settings that are copied onto each asset created in the category. |
create_backup | write | Create a manual backup of all organization data. Returns the backup record with status and entity counts. |
create_bank_rule | write | Create a new bank rule to auto-categorize imported bank transactions. Rules match on transaction description or reference fields. |
create_bill | write | Create a new bill (accounts payable). Unit prices are decimal numbers (e.g. 12.50 for $12.50). The system calculates totals and assigns a bill number automatically. A line with inventoryItemId is a stock purchase: on posting it capitalises into the item |
create_budget | write | Create a budget with one line per chart account. Each line is broken into time periods spanning the budget |
create_consolidation_elimination_rule | write | Create an intercompany elimination rule for a consolidation group. The rule nets matched balances when the consolidated report runs. kind is one of: |
create_contact | write | Create a new contact (customer, supplier, or both). Payment terms are in days (default 30). |
create_cost_center | write | Create a cost center. The code must be unique within the organization. Optionally nest it under a parent cost center. New cost centers are active by default. Returns the created cost center. |
create_credit_note | write | |
create_customer_credit | write | Record a customer prepayment, deposit, or overpayment received on account. The amount is in integer cents (e.g. 5000 = $50.00). Posts DR cash (the bank account |
create_deal | write | Create a new deal in a pipeline stage. valueCents is the deal value in integer cents (e.g. 1250 = $12.50), defaulting to 0. probability is a win likelihood 0-100. The deal starts active (not won/lost). Returns the created deal. |
create_debit_note | write | |
create_entry | write | Create a new journal entry. Total debits must equal total credits. All amounts must be in integer cents (e.g. $12.50 = 1250). Minimum 2 lines required. |
create_expense_claim | write | |
create_fixed_asset | write | Create a fixed asset. Monetary amounts are integer cents (purchasePrice, residualValue). |
create_inventory_item | write | |
create_invoice | write | Create a new invoice with line items. Unit prices are decimal numbers (e.g. 12.50 for $12.50). Quantities are decimal numbers. The system calculates totals and assigns an invoice number automatically. |
create_landed_cost | write | Create a draft landed-cost allocation: a named bucket of additional costs (freight, duty, insurance, handling, etc.) to be spread onto a purchase order |
create_loan | write | Create a loan and generate its full amortization schedule. principalAmount is in INTEGER CENTS (e.g. 1000000 = $10,000.00) and is stored as-is. interestRate is the annual rate in basis points (500 = 5%). The monthly payment (PMT) and each period |
create_payment | write | Record a standalone payment that settles one or more invoices (type |
create_payroll_employee | write | Create a payroll employee. Monetary amounts are integer cents: |
create_payroll_run | write | |
create_price_list | write | |
create_purchase_order | write | |
create_purchase_requisition | write | |
create_quote | write | Create a draft sales quote/estimate with line items. unitPrice is in integer cents (e.g. 1250 = $12.50) and is stored directly; quantity is a decimal number of units (e.g. 1.5). discountPercent is in basis points (1000 = 10%). Lines are tax-EXCLUSIVE — tax is added on top per line via the line |
create_recurring_journal | write | Create a recurring journal template that posts a balanced manual journal entry on a schedule. Provide at least two legs; each leg posts debitAmount OR creditAmount (integer cents) to accountId. Total debits must equal total credits and be non-zero. The first occurrence runs on startDate. |
create_recurring_template | write | |
create_reminder_rule | write | Create a payment-reminder rule. The rule decides when an automated email fires for a document: triggerType is |
create_report_schedule | write | Create a scheduled report that will be emailed to recipients on a recurring basis. Requires a saved report ID. |
create_revenue_schedule | write | |
create_role | write | Create a new custom role for the organization. Requires the change:roles permission. The permissions array must contain valid permission strings (e.g. |
create_sales_receipt | write | |
create_tag | write | Create a new tag for the organization. name is required (1-50 chars) and must be unique within the org. color is a hex string (defaults to |
create_tax_period | write | Create a VAT/GST tax period (a filing-tracking record for a date range). The period starts in |
create_tax_rate | write | Create a tax rate. The rate is in integer basis points (1000 = 10.00%). Set |
create_time_entry | write | Create a new time entry for the current user. Hourly rate is in integer cents (e.g. $50/hr = 5000). Minutes is the duration worked. |
create_warehouse | write | Create a warehouse (physical stock location). name and code are required; code must be unique within the org. Optionally set an address and mark it as the default warehouse. There are no monetary fields on a warehouse. Returns the created warehouse. |
create_webhook | write | Create a new webhook for the current organization. A signing secret is automatically generated. Returns the created webhook including the secret. |
decline_quote | read | Mark a sent sales quote/estimate as declined by the customer. Only |
delete_account | destructive | Delete an account. Fails if the account has any journal line entries, or if it is a system control account (AR/AP/bank/tax/retained earnings). This is a permanent deletion, not a soft delete. |
delete_approval_workflow | destructive | Soft-delete an approval workflow. |
delete_asset_category | destructive | Soft-delete an asset category. The category is hidden from listings and new-asset selection but its row is retained; assets already created in the category keep their copied defaults and are not affected. Returns success. |
delete_backup | destructive | Delete a backup. Moves to trash for 30 days before permanent removal. |
delete_bank_rule | destructive | Soft-delete a bank rule by ID. The rule will no longer be applied to new transactions. |
delete_budget | destructive | Soft-delete a budget by ID (it stops appearing in lists/reports but is retained). Returns { success: true } on success. |
delete_consolidation_elimination_rule | destructive | Soft-delete an intercompany elimination rule from a consolidation group. The rule will no longer be applied when consolidated reports run. |
delete_contact | destructive | Soft-delete a contact by ID. The contact is marked deleted (not physically removed) and excluded from future listings. Requires the manage:contacts permission. |
delete_cost_center | destructive | Soft-delete a cost center. It is hidden from listings but historical journal-line tags referencing it are preserved. Returns success. |
delete_exchange_rate | destructive | Delete a stored exchange rate by its id (requires the manage:tax-config role). Only deletes rates belonging to the organization. Returns { success: true } on success; errors if no matching rate exists. |
delete_inventory_item | destructive | Soft-delete an inventory item (sets deletedAt; the row and its history are retained). The item stops appearing in lists and lookups. Returns { success: true }. |
delete_payment | destructive | Delete (soft-delete) a standalone payment and fully UNWIND it: reverses every allocation on its invoices/bills (restoring amountDue / reducing amountPaid and reverting status), reverses the payment |
delete_price_list | destructive | Soft-delete a price list. The list and its prices stop being available for pricing but the record is retained. Returns the deleted list ID. |
delete_price_list_item | destructive | Remove an item |
delete_recurring_journal | destructive | Soft-delete a recurring journal template. Already-posted journal entries are unaffected. |
delete_reminder_rule | destructive | Soft-delete a payment-reminder rule so it no longer fires. The rule is marked deleted (not physically removed) and stops appearing in listings. Only non-deleted rules in the org can be deleted. Returns success. |
delete_report_schedule | destructive | Soft-delete a report schedule by ID. The schedule will no longer run but the record is preserved. |
delete_tag | destructive | Soft-delete a tag (sets deletedAt) so it no longer appears in listings. The tag must belong to the caller |
delete_time_entry | destructive | Permanently delete a time entry owned by the current user. |
delete_warehouse | destructive | Soft-delete a warehouse (sets deletedAt; the row and its stock history are retained). The warehouse stops appearing in lists and lookups. Returns { success: true }. |
delete_webhook | destructive | Soft-delete a webhook by ID. The webhook will no longer receive events. |
detach_tag | read | Detach a tag from a record (journal entry, invoice, bill, expense, contact, or project). The tag must belong to the caller |
disconnect_stripe | read | Disconnect a specific Stripe account. Requires integrationId and confirm: true to proceed. This stops syncing and deauthorizes access. |
dispose_fixed_asset | read | |
exclude_bank_transaction | read | Toggle whether a bank transaction is EXCLUDED from reconciliation (e.g. a duplicate import or a personal line that should never hit the books). An unreconciled line becomes |
executive_summary | read | |
export_csv_data | read | Export organization data as CSV text. Amounts are exported as decimal strings (e.g. |
export_financial_statement | read | |
file_tax_period | read | File an open VAT/GST tax period. Computes the box figures on the chosen basis (defaults to the org |
file_vat_return | read | File an open VAT return period. Computes the box figures on the chosen basis (defaults to the org |
generate_payslips | write | Generate payslips for every item in a COMPLETED payroll run, computing each employee |
generate_remittance | read | Generate remittance advice for a payment batch: groups the batch |
generate_tax_forms | read | Generate year-end tax forms for a tax year. formType |
get_account | read | Get a single account by ID with its balance calculated from posted journal entries. Returns account details, total debits, total credits, and net balance in cents. |
get_accrual_schedule | write | Get a single accrual schedule by ID, including its generated period entries (with each period |
get_approval_request | read | Get full details of an approval request including all actions and workflow steps. |
get_asset_category | read | Fetch a single asset category by its UUID, including its resolved default chart accounts (asset/depreciation/accumulated-depreciation/CWIP). Monetary defaults are integer cents and defaultDepreciationRateBp is in basis points. Returns the category, or an error if not found in the organization. |
get_bank_rule_suggestions | read | Analyze categorized bank transactions to suggest new rule patterns. Finds common description patterns among transactions that already have a category account assigned. Returns top suggestions sorted by frequency. |
get_budget | read | Get a single budget by ID with its fiscal year and each budget line (with its chart account and the per-period breakdown). Line totals and period amounts are in integer cents. |
get_consolidation_report | read | Get the consolidated P&L and balance sheet for a consolidation group over a date range. Each member entity |
get_contact | read | Get a single contact by ID with their details, default accounts, and contact people. |
get_cost_center | read | Get a single cost center by ID, including its parent cost center (if any). |
get_credit_note | read | Get a single customer credit note by ID, including its line items (with account and tax rate) and customer contact. All amounts are in integer cents. |
get_customer_credit | read | Get a single customer credit by ID with contact and journal entry. Amounts are in integer cents. |
get_deal | read | Get a single deal by ID with its contact, assigned user, pipeline and activities. valueCents is in integer cents. Excludes deleted deals. |
get_debit_note | read | Get a single supplier debit note by ID, including its line items (with account and tax rate) and supplier contact. All amounts are in integer cents. |
get_employee_leave_balances | read | Get an employee |
get_entry | read | Get a single journal entry by ID with all its line items. Line amounts are in integer cents. Exchange rate is stored as integer with 6 decimal places (1000000 = 1.0). |
get_exchange_rate | read | Get the effective exchange rate for a currency pair on or before a date, using the organization |
get_expense_claim | read | Get a single expense claim by ID with its line items (incl. mileage fields), the submitter, the approver, and each item |
get_import_template | write | Get expected CSV columns and their aliases for a source system and entity type. Use this to understand what columns are expected when importing data from a specific bookkeeping tool. |
get_inventory_item | read | |
get_invoice | read | Get a single invoice by ID with line items, contact, and payment history. All amounts are in integer cents. |
get_invoice_pdf | read | Get the download URL for an invoice PDF. Returns the URL path to download the generated PDF file. |
get_invoice_signature | read | Get the e-signature status for an invoice. Returns all signature records associated with the invoice. |
get_invoice_snapshot | read | Get the frozen sender/recipient details for a finalized invoice. These are the org and contact details captured at send time. Returns null for draft invoices. |
get_landed_cost | read | Get a single landed-cost allocation by ID with its cost components, any per-line allocations already computed, the linked bill, and the purchase order (with its lines). totalCostAmount and component/allocation amounts are integer cents; PO-line quantities are stored x100. |
get_loan | write | Get a single loan by ID, including its full amortization schedule (period entries ordered by sort order). Amounts (principalAmount, monthlyPayment, and each schedule entry |
get_match_suggestions | read | |
get_notification_preferences | read | Get the authenticated user |
get_opening_balances | read | Get the current opening-balance journal entry for this organization, with its lines and the account on each line, or null if none has been set. The entry is the single posted journal entry with sourceType |
get_organization | read | Get the current organization |
get_payment | read | Get a single standalone payment record by ID, including its contact, bank account, and allocation rows (the invoices/bills it settled). The payment |
get_pipeline | read | Get a single sales pipeline by ID, including its stage configuration and all deals currently in it. Excludes deleted pipelines. |
get_price_list | read | Get a single price list by ID, including all of its item price rows. Each item row has a unitPrice (in integer cents of the list |
get_procurement_settings | read | Get the org |
get_project_profitability | read | |
get_purchase_requisition | read | Get a single purchase requisition by ID, including its line items and contact. Amounts are integer cents; line quantities are stored x100 (5 units = 500). |
get_purchasing_supplier_statement | read | |
get_quote | read | Get a single sales quote/estimate by ID, including its line items (each with account and tax rate) and the customer contact. All amounts are in integer cents; quantity is stored as units x 100 (1.00 = 100) and discountPercent is in basis points (1000 = 10%). |
get_recurring_journal | read | Get a single recurring journal template by id, including its legs (debit/credit in integer cents) and schedule. |
get_recurring_template | read | Get a single recurring DOCUMENT template (invoice / bill / expense) by ID, including its contact and line items. Stored line unitPrice is in integer cents and quantity is the decimal x 100. Journal templates are not returned here. |
get_reminder_rule | read | Get a single payment-reminder rule by ID (excluding deleted ones). Returns its trigger settings, subject/body templates, target document type, and recipient configuration. |
get_revenue_schedule | write | Get a single revenue recognition schedule by ID with its period entries (each showing periodDate, amount in integer cents, recognized flag, and the journal entry id once recognized). |
get_role | read | Get a single custom role by ID with its permissions and member count. |
get_running_timer | read | Get the currently running timer for the current user. Returns null if no timer is running. |
get_sales_receipt | read | Get a single sales receipt by ID with line items, contact, bank/deposit account, and journal entry. All amounts are in integer cents. |
get_special_category_account | read | Resolve a plain-language money-movement behavior to the org |
get_stripe_integration_status | read | Get the status of a specific Stripe Connect integration, or all integrations if no integrationId is provided. Returns connection status, account mappings, last sync time, and whether initial sync is completed. |
get_stripe_webhook_health | read | Get webhook health metrics for a Stripe integration. Returns event counts for the last 24 hours, broken down by status. |
get_tax_period | read | Get a single VAT/GST tax period by ID, including its frozen return lines (box figures). Tax-return line amounts are in integer cents. Returns the tax period. |
get_warehouse | read | Get a single warehouse by ID. Returns the full warehouse: id, name, code, address, isDefault and isActive flags, and timestamps. |
get_warehouse_stock | read | |
impair_fixed_asset | read | Recognize an impairment loss on a fixed asset under IAS 36, writing its carrying amount down to a lower recoverable amount. |
import_csv_data | write | Import CSV data for a specific entity type. Parses CSV content, maps columns using source-specific aliases, validates, and imports rows. Amounts should be in decimal format (e.g. |
import_journal_entries | write | |
import_stripe_csv | write | Import a Stripe CSV export file for a specific integration. Accepts raw CSV text content and type ( |
list_accounts | read | List all chart of accounts (categories) for the organization. Returns account code, name, type (asset/liability/equity/revenue/expense), active status, and isSystem (true = a built-in default category that can |
list_accrual_schedules | read | List accrual schedules (cost/income spread evenly across monthly periods) with their generated period entries. Optionally filter by status. totalAmount and each entry |
list_approval_requests | read | List approval requests, optionally filtered by entity type and/or status. |
list_approval_workflows | read | List approval workflows for the organization, optionally filtered by entity type. |
list_asset_categories | read | |
list_backups | read | List organization data backups. Returns backup metadata including type, status, size, and entity counts. |
list_bank_rules | read | List bank rules for auto-categorizing imported transactions. Supports filtering by active status and pagination. |
list_bank_transactions | read | List bank transactions for a bank account, optionally filtered by status. Use to find lines that still need to be categorized/matched ( |
list_bills | read | List bills (accounts payable) with optional status filter. Amounts are in integer cents. |
list_budgets | read | List budgets for the organization with pagination, newest first. Each budget includes its fiscal year (when set). Returns the budgets and the total count. The period amounts and line totals on budgets are in integer cents. |
list_consolidation_elimination_rules | read | List the intercompany elimination rules for a consolidation group. Each rule matches account-code prefixes (debitAccountMatch / creditAccountMatch) to net out intercompany balances (e.g. AR vs AP, intercompany sales vs COGS) when the consolidated report is produced. |
Trust audit
BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (21)
tls: config.useTls ? { rejectUnauthorized: false } : undefined,# For Docker Compose: postgresql://dubbl:dubbl@localhost:5432/dubbl
DATABASE_URL="postgresql://dubbl:dubbl@localhost:5432/dubbl"
ENV DATABASE_URL="postgresql://build:build@localhost:5432/build"
DATABASE_URL: "postgresql://dubbl:dubbl@localhost:5432/dubbl"
DATABASE_URL: postgresql://dubbl:dubbl@db:5432/dubbl
assign_role, bulk_delete_contacts, delete_account, delete_approval_workflow, delete_asset_category, delete_backup, delete_bank_rule, delete_budget, delete_consolidation_elimination_rule, delete_contac
CLAUDE.md
import { ImportRow } from "../../_components";import { ACCOUNT_TYPE_LABELS, ACCOUNT_COLORS } from "../../_components";import { TransactionRow, CashCodingGrid } from "../../_components";import { postBillReceipt, ProcurementBlockedError } from "../../_procurement";import { postBillReceipt, ProcurementBlockedError } from "../../_procurement";@auth/drizzle-adapter, @aws-sdk/client-s3, @aws-sdk/s3-request-presigner, @dnd-kit/core, @dnd-kit/sortable, @dnd-kit/utilities, @paper-design/shaders-react, @react-email/components
curl -X POST http://localhost:3000/api/mcp/oauth/token \
public/og.png
- `owner` - Full access
Self-hosted instances can grant unlimited access to all features without Stripe by using admin overrides.
| Owner | Full access, can delete the organization |
| Admin | Full access except organization deletion |
Full access to every feature — intended for accountants and advisors.
Gates applied: no_behavioural_pass.
0d7efda2f225full audit observations/trust-audit/mcp-server/dubbl-org__dubbl.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0d7efda2f225 | BLOCK | F | 59 | first audit |
Questions
What is the Dubbl MCP server?
A full-featured, open-source alternative to Xero and QuickBooks. It is API-first, developer-friendly, and built for teams that want full control over their financial data.
What tools does Dubbl expose?
200 in total: 205 read-only, 138 that write, and 27 that can delete or overwrite (assign_role, bulk_delete_contacts, delete_account, delete_approval_workflow, delete_asset_category). Every one is listed on this page with its risk.
Is Dubbl safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (59/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 27 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Dubbl need?
It reads AUTH_APPLE_ID, AUTH_APPLE_KEY_BASE64, AUTH_APPLE_KEY_ID, AUTH_APPLE_SECRET, AUTH_APPLE_TEAM_ID, AUTH_GOOGLE_ID, AUTH_GOOGLE_SECRET, EMAIL_ENCRYPTION_KEY, RESEND_API_KEY, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY and STRIPE_CONNECT_WEBHOOK_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Dubbl run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as dubbl at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (0d7efda2f225), read on 2026-10-08. The repository is watched and re-audited when it changes.