Atlas / MCP servers / dubbl-org / Dubbl

DubblBLOCK

mcp/dubbl-org/dubbl

A full-featured, open-source alternative to Xero and QuickBooks. It is API-first, developer-friendly, and built for teams that want full control over their financial data.

Verdict
BLOCK
Grade
F
Trust score
59 /100
Exposed tools
200 205r · 138w · 27d
Transport
streamable-http
License
Apache-2.0
Stars
52
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

dubbl Open source, double-entry bookkeeping for modern teams.

dubbl is a full-featured, open-source alternative to Xero and QuickBooks. It is API-first, developer-friendly, and built for teams that want full control over their financial data.

Features

  • Double-entry bookkeeping - Chart of accounts, journal entries, bank reconciliation
  • Invoicing and quotes - PDF generation, payment tracking, recurring invoices, credit notes
  • Bills and purchase orders - Accounts payable, purchase requisitions, landed costs
  • Banking - CSV import, bank reconciliation, scheduled transactions
  • Expense management - Claims, receipt OCR, approval workflows, recurring expenses
  • Inventory - Warehouses, stock takes, assembly/BOM, serial and lot tracking, valuation
  • Payroll - Employees, contractors, pay runs, tax forms, timesheets, leave management
  • Projects - Time tracking, milestones, tasks, billable hours
  • CRM - Pipeline management, deals, analytics
  • Fixed assets - Depreciation schedules, disposal tracking
  • Budgets - Budget creation, variance analysis, budget vs actual
  • Tax - Multi-jurisdiction tax rates, VAT returns, BAS, Schedule C, sales tax
  • 25+ financial reports - P&L, balance sheet, cash flow, aged receivables, and more
  • Multi-currency - Exchange rates, currency conversion
  • Documents - File management and storage
  • Audit trail - Full aud
Read from source at commit 0d7efda2f225OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add dubbl --env AUTH_APPLE_ID=${AUTH_APPLE_ID} --env AUTH_APPLE_KEY_BASE64=${AUTH_APPLE_KEY_BASE64} --env AUTH_APPLE_KEY_ID=${AUTH_APPLE_KEY_ID} --env AUTH_APPLE_SECRET=${AUTH_APPLE_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "dubbl": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AUTH_APPLE_ID": "${AUTH_APPLE_ID}",
        "AUTH_APPLE_KEY_BASE64": "${AUTH_APPLE_KEY_BASE64}",
        "AUTH_APPLE_KEY_ID": "${AUTH_APPLE_KEY_ID}",
        "AUTH_APPLE_SECRET": "${AUTH_APPLE_SECRET}"
      }
    }
  }
}
03

Exposed tools (200)

205 read · 138 write · 27 destructive. Blast radius: 27 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AdvisorreadFull access to every feature — intended for accountants and advisors.
BookkeeperreadCan manage day-to-day accounting tasks
EngineeringreadProduct engineering team
FinancereadFinance and accounting team
FreereadIncluded with every org
GrowthreadFor established businesses
Invoice-onlywriteLimited to creating invoices, quotes, credit notes and managing contacts and payments.
LeadershipreadExecutive leadership
Read-onlyreadView-only access to financial data with no ability to make changes.
ScalereadFor large organizations
StandardreadEveryday operational access without owner/admin-only powers (no posting, approvals or settings).
StarterreadFor growing teams
ViewerreadRead-only access to all financial data
accept_quotereadMark a sent sales quote/estimate as accepted by the customer. Only
add_consolidation_memberwriteAdd an organization as a member entity of a consolidation group. The current user must belong to the target organization. Optionally override the member
add_deal_activitywriteLog an activity (note, email, call, meeting or task) against a deal. The activity is attributed to the current user. Provide scheduledAt (ISO date-time) for upcoming tasks/meetings. Returns the created activity.
add_price_list_itemwriteAdd an item
adjust_inventory_stockwriteAdjust an inventory item and post the matching journal entry. Three kinds:
aged_payablesreadGenerate an aged payables report showing outstanding bills grouped by aging buckets (Current, 1-30, 31-60, 61-90, 90+ days). Amounts are in integer cents. Pass asAt (YYYY-MM-DD) for a historical snapshot: aging is measured from that date and each bill
aged_receivablesreadGenerate an aged receivables report showing outstanding invoices grouped by aging buckets (Current, 1-30, 31-60, 61-90, 90+ days). Amounts are in integer cents. Pass asAt (YYYY-MM-DD) for a historical snapshot: aging is measured from that date and each invoice
allocate_landed_costreadAllocate (capitalise) a DRAFT landed-cost allocation onto the inventory behind its purchase order. Spreads each cost component across the PO lines pro-rata by line value (or quantity when allocationMethod is
apply_bank_ruleswriteApply all active bank rules to uncategorized transactions. Matches rules against transaction descriptions/references and updates matching transactions with the rule
apply_credit_notewriteApply a customer credit note
apply_customer_creditwriteApply an open customer credit to an invoice. Moves the Customer Deposits 2410 liability onto the invoice: posts DR Customer Deposits 2410 / CR Accounts Receivable 1200, records the allocation, decrements the credit
apply_debit_notewriteApply a supplier debit note
apply_stock_takewrite
apply_tax_profilewriteApply a country tax profile to this organization: seeds the profile
approve_billreadApprove a draft or pending_approval bill. Changes status to
approve_expense_claimreadApprove a submitted expense claim. Posts the approval journal entry — DR each expense line to its account (falling back to Miscellaneous Expense 5990) / CR Employee Reimbursements Payable 2110 for the total — dated today, then flips status to
approve_invoicereadApprove an invoice that is pending approval. Records the approval action against the open approval request via the approval engine (enforcing approver-step validation and multi-step advance). Only returns the invoice to
approve_purchase_requisitionreadApprove a submitted purchase requisition. Sets status to
approve_requestreadApprove the current step of an approval request. You must be the assigned approver for the current step.
approve_timesheetreadApprove a submitted timesheet. Only timesheets in
assign_roledestructiveAssign a custom role to a member, or remove their custom role (pass null). Requires change:roles permission. The member
attach_file_to_entityreadAttach a file to any business entity (invoice, bill, payment, journal entry, bank transaction, contact, etc.). Returns the document record plus a presigned S3 upload URL the file bytes must be PUT to. File size in bytes.
attach_tagreadAttach a tag to a record (journal entry, invoice, bill, expense, contact, or project). The tag must belong to the caller
auto_reconcile_bank_transactionsreadAutomatically link unreconciled bank lines to ALREADY-POSTED cash journal entries (e.g. payments recorded manually) that move a bank ledger account and aren
balance_sheetreadGenerate a balance sheet report showing assets, liabilities, and equity with totals (cumulative balances as at a date). Only includes posted entries. Balances are decimal strings. Pass asAt to choose the point in time (defaults to today) and compareDates to add prior-date comparative columns.
budget_vs_actualreadBudget-vs-actual report for one budget. For each budget line it compares the budgeted amount against actual posted general-ledger activity for that account within the budget
build_assemblywriteComplete (build) a draft/in-progress assembly order: issues every BOM component at its current cost (incl. wastage), adds the BOM
bulk_cash_coderead
bulk_categorize_bank_transactionsread
bulk_delete_contactsdestructiveSoft-delete many contacts in one call (they move to trash and can be restored). Only contacts in THIS org are deleted; other-org ids are ignored. Each deletion is audited. Returns the number deleted.
bulk_mark_invoices_paidread
bulk_mark_invoices_sentread
bulk_send_invoice_reminderswrite
bulk_set_contacts_typewriteSet the TYPE (customer, supplier, or both) on many contacts in one call. This is the bulk equivalent of the
cancel_accrual_schedulewriteCancel an accrual schedule, setting its status to
cancel_revenue_schedulewriteCancel a revenue recognition schedule, setting its status to
capitalize_cwip_assetreadCapitalize a capital-work-in-progress (CWIP) asset into service: transfers the accumulated CWIP cost into the fixed-asset account and starts depreciation. Sums the asset
cash_flow_statementreadGenerate a cash flow statement using the indirect method. Shows operating, investing, and financing activities with opening/closing cash balances. Amounts in integer cents.
categorize_bank_transactionread
check_invoice_compliancereadCheck an invoice for compliance warnings based on the organization
close_fiscal_yearreadClose a fiscal year. Creates year-end closing journal entries (DR revenue, CR expense, net to Retained Earnings 3200), sets isClosed=true, and creates a period lock. Validates no draft entries exist first.
connect_stripereadGenerate a Stripe Connect OAuth URL to connect a Stripe account. Returns a URL that the user should open in their browser to authorize the connection.
convert_amountreadConvert a monetary amount (in integer minor units, e.g. cents) from one currency to another using the organization
convert_po_to_billwriteCreate a bill from a purchase order. Omit
convert_purchase_requisitionwriteConvert an APPROVED purchase requisition into a purchase order (PO). Copies the requisition
convert_quote_to_invoiceread
create_accountwriteCreate a new chart of accounts entry. Account code must be unique within the organization. Type determines the account
create_accrual_schedulewrite
create_approval_workflowwriteCreate an approval workflow with ordered steps. Each step specifies a member who must approve.
create_asset_categorywriteCreate a reusable asset category (asset class) holding default depreciation + posting settings that are copied onto each asset created in the category.
create_backupwriteCreate a manual backup of all organization data. Returns the backup record with status and entity counts.
create_bank_rulewriteCreate a new bank rule to auto-categorize imported bank transactions. Rules match on transaction description or reference fields.
create_billwriteCreate a new bill (accounts payable). Unit prices are decimal numbers (e.g. 12.50 for $12.50). The system calculates totals and assigns a bill number automatically. A line with inventoryItemId is a stock purchase: on posting it capitalises into the item
create_budgetwriteCreate a budget with one line per chart account. Each line is broken into time periods spanning the budget
create_consolidation_elimination_rulewriteCreate an intercompany elimination rule for a consolidation group. The rule nets matched balances when the consolidated report runs. kind is one of:
create_contactwriteCreate a new contact (customer, supplier, or both). Payment terms are in days (default 30).
create_cost_centerwriteCreate a cost center. The code must be unique within the organization. Optionally nest it under a parent cost center. New cost centers are active by default. Returns the created cost center.
create_credit_notewrite
create_customer_creditwriteRecord a customer prepayment, deposit, or overpayment received on account. The amount is in integer cents (e.g. 5000 = $50.00). Posts DR cash (the bank account
create_dealwriteCreate a new deal in a pipeline stage. valueCents is the deal value in integer cents (e.g. 1250 = $12.50), defaulting to 0. probability is a win likelihood 0-100. The deal starts active (not won/lost). Returns the created deal.
create_debit_notewrite
create_entrywriteCreate a new journal entry. Total debits must equal total credits. All amounts must be in integer cents (e.g. $12.50 = 1250). Minimum 2 lines required.
create_expense_claimwrite
create_fixed_assetwriteCreate a fixed asset. Monetary amounts are integer cents (purchasePrice, residualValue).
create_inventory_itemwrite
create_invoicewriteCreate a new invoice with line items. Unit prices are decimal numbers (e.g. 12.50 for $12.50). Quantities are decimal numbers. The system calculates totals and assigns an invoice number automatically.
create_landed_costwriteCreate a draft landed-cost allocation: a named bucket of additional costs (freight, duty, insurance, handling, etc.) to be spread onto a purchase order
create_loanwriteCreate a loan and generate its full amortization schedule. principalAmount is in INTEGER CENTS (e.g. 1000000 = $10,000.00) and is stored as-is. interestRate is the annual rate in basis points (500 = 5%). The monthly payment (PMT) and each period
create_paymentwriteRecord a standalone payment that settles one or more invoices (type
create_payroll_employeewriteCreate a payroll employee. Monetary amounts are integer cents:
create_payroll_runwrite
create_price_listwrite
create_purchase_orderwrite
create_purchase_requisitionwrite
create_quotewriteCreate a draft sales quote/estimate with line items. unitPrice is in integer cents (e.g. 1250 = $12.50) and is stored directly; quantity is a decimal number of units (e.g. 1.5). discountPercent is in basis points (1000 = 10%). Lines are tax-EXCLUSIVE — tax is added on top per line via the line
create_recurring_journalwriteCreate a recurring journal template that posts a balanced manual journal entry on a schedule. Provide at least two legs; each leg posts debitAmount OR creditAmount (integer cents) to accountId. Total debits must equal total credits and be non-zero. The first occurrence runs on startDate.
create_recurring_templatewrite
create_reminder_rulewriteCreate a payment-reminder rule. The rule decides when an automated email fires for a document: triggerType is
create_report_schedulewriteCreate a scheduled report that will be emailed to recipients on a recurring basis. Requires a saved report ID.
create_revenue_schedulewrite
create_rolewriteCreate a new custom role for the organization. Requires the change:roles permission. The permissions array must contain valid permission strings (e.g.
create_sales_receiptwrite
create_tagwriteCreate a new tag for the organization. name is required (1-50 chars) and must be unique within the org. color is a hex string (defaults to
create_tax_periodwriteCreate a VAT/GST tax period (a filing-tracking record for a date range). The period starts in
create_tax_ratewriteCreate a tax rate. The rate is in integer basis points (1000 = 10.00%). Set
create_time_entrywriteCreate a new time entry for the current user. Hourly rate is in integer cents (e.g. $50/hr = 5000). Minutes is the duration worked.
create_warehousewriteCreate a warehouse (physical stock location). name and code are required; code must be unique within the org. Optionally set an address and mark it as the default warehouse. There are no monetary fields on a warehouse. Returns the created warehouse.
create_webhookwriteCreate a new webhook for the current organization. A signing secret is automatically generated. Returns the created webhook including the secret.
decline_quotereadMark a sent sales quote/estimate as declined by the customer. Only
delete_accountdestructiveDelete an account. Fails if the account has any journal line entries, or if it is a system control account (AR/AP/bank/tax/retained earnings). This is a permanent deletion, not a soft delete.
delete_approval_workflowdestructiveSoft-delete an approval workflow.
delete_asset_categorydestructiveSoft-delete an asset category. The category is hidden from listings and new-asset selection but its row is retained; assets already created in the category keep their copied defaults and are not affected. Returns success.
delete_backupdestructiveDelete a backup. Moves to trash for 30 days before permanent removal.
delete_bank_ruledestructiveSoft-delete a bank rule by ID. The rule will no longer be applied to new transactions.
delete_budgetdestructiveSoft-delete a budget by ID (it stops appearing in lists/reports but is retained). Returns { success: true } on success.
delete_consolidation_elimination_ruledestructiveSoft-delete an intercompany elimination rule from a consolidation group. The rule will no longer be applied when consolidated reports run.
delete_contactdestructiveSoft-delete a contact by ID. The contact is marked deleted (not physically removed) and excluded from future listings. Requires the manage:contacts permission.
delete_cost_centerdestructiveSoft-delete a cost center. It is hidden from listings but historical journal-line tags referencing it are preserved. Returns success.
delete_exchange_ratedestructiveDelete a stored exchange rate by its id (requires the manage:tax-config role). Only deletes rates belonging to the organization. Returns { success: true } on success; errors if no matching rate exists.
delete_inventory_itemdestructiveSoft-delete an inventory item (sets deletedAt; the row and its history are retained). The item stops appearing in lists and lookups. Returns { success: true }.
delete_paymentdestructiveDelete (soft-delete) a standalone payment and fully UNWIND it: reverses every allocation on its invoices/bills (restoring amountDue / reducing amountPaid and reverting status), reverses the payment
delete_price_listdestructiveSoft-delete a price list. The list and its prices stop being available for pricing but the record is retained. Returns the deleted list ID.
delete_price_list_itemdestructiveRemove an item
delete_recurring_journaldestructiveSoft-delete a recurring journal template. Already-posted journal entries are unaffected.
delete_reminder_ruledestructiveSoft-delete a payment-reminder rule so it no longer fires. The rule is marked deleted (not physically removed) and stops appearing in listings. Only non-deleted rules in the org can be deleted. Returns success.
delete_report_scheduledestructiveSoft-delete a report schedule by ID. The schedule will no longer run but the record is preserved.
delete_tagdestructiveSoft-delete a tag (sets deletedAt) so it no longer appears in listings. The tag must belong to the caller
delete_time_entrydestructivePermanently delete a time entry owned by the current user.
delete_warehousedestructiveSoft-delete a warehouse (sets deletedAt; the row and its stock history are retained). The warehouse stops appearing in lists and lookups. Returns { success: true }.
delete_webhookdestructiveSoft-delete a webhook by ID. The webhook will no longer receive events.
detach_tagreadDetach a tag from a record (journal entry, invoice, bill, expense, contact, or project). The tag must belong to the caller
disconnect_stripereadDisconnect a specific Stripe account. Requires integrationId and confirm: true to proceed. This stops syncing and deauthorizes access.
dispose_fixed_assetread
exclude_bank_transactionreadToggle whether a bank transaction is EXCLUDED from reconciliation (e.g. a duplicate import or a personal line that should never hit the books). An unreconciled line becomes
executive_summaryread
export_csv_datareadExport organization data as CSV text. Amounts are exported as decimal strings (e.g.
export_financial_statementread
file_tax_periodreadFile an open VAT/GST tax period. Computes the box figures on the chosen basis (defaults to the org
file_vat_returnreadFile an open VAT return period. Computes the box figures on the chosen basis (defaults to the org
generate_payslipswriteGenerate payslips for every item in a COMPLETED payroll run, computing each employee
generate_remittancereadGenerate remittance advice for a payment batch: groups the batch
generate_tax_formsreadGenerate year-end tax forms for a tax year. formType
get_accountreadGet a single account by ID with its balance calculated from posted journal entries. Returns account details, total debits, total credits, and net balance in cents.
get_accrual_schedulewriteGet a single accrual schedule by ID, including its generated period entries (with each period
get_approval_requestreadGet full details of an approval request including all actions and workflow steps.
get_asset_categoryreadFetch a single asset category by its UUID, including its resolved default chart accounts (asset/depreciation/accumulated-depreciation/CWIP). Monetary defaults are integer cents and defaultDepreciationRateBp is in basis points. Returns the category, or an error if not found in the organization.
get_bank_rule_suggestionsreadAnalyze categorized bank transactions to suggest new rule patterns. Finds common description patterns among transactions that already have a category account assigned. Returns top suggestions sorted by frequency.
get_budgetreadGet a single budget by ID with its fiscal year and each budget line (with its chart account and the per-period breakdown). Line totals and period amounts are in integer cents.
get_consolidation_reportreadGet the consolidated P&L and balance sheet for a consolidation group over a date range. Each member entity
get_contactreadGet a single contact by ID with their details, default accounts, and contact people.
get_cost_centerreadGet a single cost center by ID, including its parent cost center (if any).
get_credit_notereadGet a single customer credit note by ID, including its line items (with account and tax rate) and customer contact. All amounts are in integer cents.
get_customer_creditreadGet a single customer credit by ID with contact and journal entry. Amounts are in integer cents.
get_dealreadGet a single deal by ID with its contact, assigned user, pipeline and activities. valueCents is in integer cents. Excludes deleted deals.
get_debit_notereadGet a single supplier debit note by ID, including its line items (with account and tax rate) and supplier contact. All amounts are in integer cents.
get_employee_leave_balancesreadGet an employee
get_entryreadGet a single journal entry by ID with all its line items. Line amounts are in integer cents. Exchange rate is stored as integer with 6 decimal places (1000000 = 1.0).
get_exchange_ratereadGet the effective exchange rate for a currency pair on or before a date, using the organization
get_expense_claimreadGet a single expense claim by ID with its line items (incl. mileage fields), the submitter, the approver, and each item
get_import_templatewriteGet expected CSV columns and their aliases for a source system and entity type. Use this to understand what columns are expected when importing data from a specific bookkeeping tool.
get_inventory_itemread
get_invoicereadGet a single invoice by ID with line items, contact, and payment history. All amounts are in integer cents.
get_invoice_pdfreadGet the download URL for an invoice PDF. Returns the URL path to download the generated PDF file.
get_invoice_signaturereadGet the e-signature status for an invoice. Returns all signature records associated with the invoice.
get_invoice_snapshotreadGet the frozen sender/recipient details for a finalized invoice. These are the org and contact details captured at send time. Returns null for draft invoices.
get_landed_costreadGet a single landed-cost allocation by ID with its cost components, any per-line allocations already computed, the linked bill, and the purchase order (with its lines). totalCostAmount and component/allocation amounts are integer cents; PO-line quantities are stored x100.
get_loanwriteGet a single loan by ID, including its full amortization schedule (period entries ordered by sort order). Amounts (principalAmount, monthlyPayment, and each schedule entry
get_match_suggestionsread
get_notification_preferencesreadGet the authenticated user
get_opening_balancesreadGet the current opening-balance journal entry for this organization, with its lines and the account on each line, or null if none has been set. The entry is the single posted journal entry with sourceType
get_organizationreadGet the current organization
get_paymentreadGet a single standalone payment record by ID, including its contact, bank account, and allocation rows (the invoices/bills it settled). The payment
get_pipelinereadGet a single sales pipeline by ID, including its stage configuration and all deals currently in it. Excludes deleted pipelines.
get_price_listreadGet a single price list by ID, including all of its item price rows. Each item row has a unitPrice (in integer cents of the list
get_procurement_settingsreadGet the org
get_project_profitabilityread
get_purchase_requisitionreadGet a single purchase requisition by ID, including its line items and contact. Amounts are integer cents; line quantities are stored x100 (5 units = 500).
get_purchasing_supplier_statementread
get_quotereadGet a single sales quote/estimate by ID, including its line items (each with account and tax rate) and the customer contact. All amounts are in integer cents; quantity is stored as units x 100 (1.00 = 100) and discountPercent is in basis points (1000 = 10%).
get_recurring_journalreadGet a single recurring journal template by id, including its legs (debit/credit in integer cents) and schedule.
get_recurring_templatereadGet a single recurring DOCUMENT template (invoice / bill / expense) by ID, including its contact and line items. Stored line unitPrice is in integer cents and quantity is the decimal x 100. Journal templates are not returned here.
get_reminder_rulereadGet a single payment-reminder rule by ID (excluding deleted ones). Returns its trigger settings, subject/body templates, target document type, and recipient configuration.
get_revenue_schedulewriteGet a single revenue recognition schedule by ID with its period entries (each showing periodDate, amount in integer cents, recognized flag, and the journal entry id once recognized).
get_rolereadGet a single custom role by ID with its permissions and member count.
get_running_timerreadGet the currently running timer for the current user. Returns null if no timer is running.
get_sales_receiptreadGet a single sales receipt by ID with line items, contact, bank/deposit account, and journal entry. All amounts are in integer cents.
get_special_category_accountreadResolve a plain-language money-movement behavior to the org
get_stripe_integration_statusreadGet the status of a specific Stripe Connect integration, or all integrations if no integrationId is provided. Returns connection status, account mappings, last sync time, and whether initial sync is completed.
get_stripe_webhook_healthreadGet webhook health metrics for a Stripe integration. Returns event counts for the last 24 hours, broken down by status.
get_tax_periodreadGet a single VAT/GST tax period by ID, including its frozen return lines (box figures). Tax-return line amounts are in integer cents. Returns the tax period.
get_warehousereadGet a single warehouse by ID. Returns the full warehouse: id, name, code, address, isDefault and isActive flags, and timestamps.
get_warehouse_stockread
impair_fixed_assetreadRecognize an impairment loss on a fixed asset under IAS 36, writing its carrying amount down to a lower recoverable amount.
import_csv_datawriteImport CSV data for a specific entity type. Parses CSV content, maps columns using source-specific aliases, validates, and imports rows. Amounts should be in decimal format (e.g.
import_journal_entrieswrite
import_stripe_csvwriteImport a Stripe CSV export file for a specific integration. Accepts raw CSV text content and type (
list_accountsreadList all chart of accounts (categories) for the organization. Returns account code, name, type (asset/liability/equity/revenue/expense), active status, and isSystem (true = a built-in default category that can
list_accrual_schedulesreadList accrual schedules (cost/income spread evenly across monthly periods) with their generated period entries. Optionally filter by status. totalAmount and each entry
list_approval_requestsreadList approval requests, optionally filtered by entity type and/or status.
list_approval_workflowsreadList approval workflows for the organization, optionally filtered by entity type.
list_asset_categoriesread
list_backupsreadList organization data backups. Returns backup metadata including type, status, size, and entity counts.
list_bank_rulesreadList bank rules for auto-categorizing imported transactions. Supports filtering by active status and pagination.
list_bank_transactionsreadList bank transactions for a bank account, optionally filtered by status. Use to find lines that still need to be categorized/matched (
list_billsreadList bills (accounts payable) with optional status filter. Amounts are in integer cents.
list_budgetsreadList budgets for the organization with pagination, newest first. Each budget includes its fiscal year (when set). Returns the budgets and the total count. The period amounts and line totals on budgets are in integer cents.
list_consolidation_elimination_rulesreadList the intercompany elimination rules for a consolidation group. Each rule matches account-code prefixes (debitAccountMatch / creditAccountMatch) to net out intercompany balances (e.g. AR vs AP, intercompany sales vs COGS) when the consolidated report is produced.
04

Trust audit

BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (21)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
lib/email/smtp-client.ts:52
tls: config.useTls ? { rejectUnauthorized: false } : undefined,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:12
# For Docker Compose: postgresql://dubbl:dubbl@localhost:5432/dubbl
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:13
DATABASE_URL="postgresql://dubbl:dubbl@localhost:5432/dubbl"
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
Dockerfile:26
ENV DATABASE_URL="postgresql://build:build@localhost:5432/build"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:72
DATABASE_URL: "postgresql://dubbl:dubbl@localhost:5432/dubbl"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
content/docs/self-hosting.mdx:21
DATABASE_URL: postgresql://dubbl:dubbl@db:5432/dubbl
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
assign_role, bulk_delete_contacts, delete_account, delete_approval_workflow, delete_asset_category, delete_backup, delete_bank_rule, delete_budget, delete_consolidation_elimination_rule, delete_contac
Why it matters. 27 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/(dashboard)/accounting/banking/[id]/(detail)/imports/page.tsx:7
import { ImportRow } from "../../_components";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/(dashboard)/accounting/banking/[id]/(detail)/settings/page.tsx:22
import { ACCOUNT_TYPE_LABELS, ACCOUNT_COLORS } from "../../_components";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/(dashboard)/accounting/banking/[id]/(detail)/transactions/page.tsx:25
import { TransactionRow, CashCodingGrid } from "../../_components";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/api/v1/bills/[id]/approve/route.ts:17
import { postBillReceipt, ProcurementBlockedError } from "../../_procurement";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/api/v1/bills/[id]/receive/route.ts:17
import { postBillReceipt, ProcurementBlockedError } from "../../_procurement";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@auth/drizzle-adapter, @aws-sdk/client-s3, @aws-sdk/s3-request-presigner, @dnd-kit/core, @dnd-kit/sortable, @dnd-kit/utilities, @paper-design/shaders-react, @react-email/components
Why it matters. 55 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
content/docs/guides/mcp.mdx:225
curl -X POST http://localhost:3000/api/mcp/oauth/token \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
public/og.png
public/og.png
Why it matters. 1276095 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
content/docs/guides/developer-guide.mdx:187
- `owner` - Full access
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
content/docs/guides/stripe-integration.mdx:195
Self-hosted instances can grant unlimited access to all features without Stripe by using admin overrides.
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
content/docs/settings/organization.mdx:39
| Owner | Full access, can delete the organization |
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
content/docs/settings/organization.mdx:40
| Admin | Full access except organization deletion |
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
<tool:Advisor>:1
Full access to every feature — intended for accountants and advisors.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0d7efda2f225full audit observations/trust-audit/mcp-server/dubbl-org__dubbl.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080d7efda2f225BLOCKF59first audit
06

Questions

What is the Dubbl MCP server?

A full-featured, open-source alternative to Xero and QuickBooks. It is API-first, developer-friendly, and built for teams that want full control over their financial data.

What tools does Dubbl expose?

200 in total: 205 read-only, 138 that write, and 27 that can delete or overwrite (assign_role, bulk_delete_contacts, delete_account, delete_approval_workflow, delete_asset_category). Every one is listed on this page with its risk.

Is Dubbl safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (59/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 27 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Dubbl need?

It reads AUTH_APPLE_ID, AUTH_APPLE_KEY_BASE64, AUTH_APPLE_KEY_ID, AUTH_APPLE_SECRET, AUTH_APPLE_TEAM_ID, AUTH_GOOGLE_ID, AUTH_GOOGLE_SECRET, EMAIL_ENCRYPTION_KEY, RESEND_API_KEY, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY and STRIPE_CONNECT_WEBHOOK_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Dubbl run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as dubbl at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (0d7efda2f225), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement