Atlas / MCP servers / promptpartner / Bexio

BexioCAUTION

mcp/promptpartner/bexio

Complete Swiss accounting integration for Bexio via MCP. Works with Claude Desktop, n8n, and any MCP client. 310 tools for invoices, contacts, projects & more. Created by Lukas Hertig.

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
200 170r · 76w · 30d
Transport
stdio
License
MIT
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Complete Swiss accounting integration for Bexio via the Model Context Protocol (MCP). Works with Claude Desktop, n8n, and any MCP-compatible client.

Manage invoices, contacts, projects, time tracking, and 300+ more tools through AI conversation or workflow automation.

⚠️ Early Release Software This project is under active development. While it's functional and tested, you may encounter bugs or unexpected behavior. Features will continue to be added and improved over time. Please report any issues you find!

Compatibility

Quick Start

For Claude Desktop

Option A: MCPB Bundle (Easiest)

  1. Download the latest .mcpb file from GitHub Releases
  2. Install it in Claude Desktop, either way works:
  3. Double-click the .mcpb file (or drag it onto the Claude Desktop window), or
  4. go to Settings → Extensions → Advanced settings, and under Extension Developer click Install Extension... and select the file
  5. Enter your Bexio API token when prompted. It is stored in your operating system's keychain.
  6. Optional: switch on Interactive panels in the extension's settings for invoice previews, contact cards and a dashboard.

No Node.js installation is needed: Claude Desktop runs extensions with its built-in Node.js. Updating from 2.6.1 or older? Re-enter your token if Claude Desktop asks for it.

Option B: npm (manual config)

Requires Node.js (LTS). In Claude Desktop, open Settings → Developer → Edit Config and add:

Read from source at commit 8b0d48f30c69OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add bexio-mcp-server -- npx -y @promptpartner/[email protected]
03

Exposed tools (200)

170 read · 76 write · 30 destructive. Blast radius: 30 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
accept_quotereadAccept a quote
advanced_search_contactsreadPerform advanced search on contacts using multiple criteria
archive_projectreadArchive a project in Bexio. Archived projects are hidden but not deleted.
bulk_create_contactswriteCreate multiple contacts in one call. Returns per-item results with success/failure status.
cancel_invoicereadCancel an invoice
copy_invoicereadCopy an invoice
copy_quotereadCopy/duplicate a quote
create_absencewriteCreate a new absence record (vacation, sick leave, etc.). Requires Bexio Payroll module subscription.
create_accountwriteCreate a new account in the chart of accounts
create_additional_addresswriteCreate an additional address for a contact
create_billwriteCreate a new bill (creditor invoice) from a supplier (Bexio v4.0). IMPORTANT field names: use supplier_id (NOT contact_id), line_items (NOT positions), and booking_account_id on each line (NOT account_id);
create_business_activitywriteCreate a new business activity (service type for time tracking)
create_commentwriteCreate a new comment on a document
create_contactwriteCreate a new contact in Bexio. Set contact_type to
create_contact_groupwriteCreate a new contact group for categorizing contacts
create_contact_relationwriteCreate a new contact relation
create_contact_sectorwrite[NOT SUPPORTED] Create a new contact sector (industry type). Note: Bexio API does not support creating contact sectors. This resource is read-only.
create_countrywriteCreate a new country entry
create_currencywriteCreate a new currency in Bexio. Swiss default: round_factor 0.05 (5 rappen). Common currencies: CHF, EUR, USD, GBP.
create_delivery_from_orderwriteCreate a delivery from an order
create_employeewriteCreate a new employee in the payroll system. Requires Bexio Payroll module subscription. Links a Bexio user to payroll.
create_expensewriteCreate a new expense record
create_fictional_userwriteCreate a new fictional user. Requires salutation_type, firstname, lastname, and email.
create_iban_paymentwrite⚠️ Creates a STANDALONE bank payment that is NOT linked to any supplier bill. To pay a supplier bill (and have it marked paid), use
create_invoicewriteCreate a new invoice in Bexio
create_invoice_from_orderwriteCreate an invoice from an order
create_invoice_from_quotewriteCreate an invoice from a quote
create_itemwriteCreate a new item in Bexio
create_languagewrite[NOT SUPPORTED] Create a new language entry. Note: Bexio API returns 501 Not Implemented for this endpoint. This resource is read-only.
create_manual_entrywriteCreate a manual journal entry (double-entry bookkeeping). Provide flat params; the handler transforms to nested entries array internally. Bexio validates that debits equal credits.
create_milestonewriteCreate a new milestone in a project. Milestones track key deadlines and deliverables.
create_notewriteCreate a new note attached to a resource (contact, invoice, quote, order, delivery, project, or bill)
create_orderwriteCreate a new order in Bexio
create_order_from_quotewriteCreate an order from a quote
create_paymentwriteCreate a new payment for an invoice
create_payment_typewriteCreate a new payment type for invoices and payments
create_projectwriteCreate a new project in Bexio. Requires user_id (owner) and name.
create_purchase_orderwriteCreate a new purchase order to a supplier
create_qr_paymentwrite⚠️ Creates a STANDALONE bank payment that is NOT linked to any supplier bill. To pay a supplier bill (and have it marked paid), use
create_quotewriteCreate a new quote (offer) for an existing contact
create_reminderwriteCreate a new reminder for an invoice
create_salutationwriteCreate a new salutation (e.g., Mr., Mrs., Dr.)
create_taskwriteCreate a new task with optional resource linking to a contact, invoice, quote, order, etc.
create_timesheetwriteCreate a new timesheet entry. Duration must be in HH:MM format (e.g.,
create_titlewriteCreate a new title (e.g., CEO, Manager, Director)
create_unitwriteCreate a new unit of measurement
create_work_packagewriteCreate a new work package in a project. Work packages organize deliverables and track estimated effort.
decline_quotereadDecline a quote
delete_absencedestructiveDelete an absence record. Requires Bexio Payroll module subscription.
delete_additional_addressdestructiveDelete an additional address from a contact
delete_billdestructiveDelete a bill (creditor invoice)
delete_contactdestructiveDelete a contact (soft delete -- moves to trash). Use restore_contact to recover.
delete_contact_groupdestructiveDelete a contact group by ID
delete_contact_relationdestructiveDelete a contact relation
delete_countrydestructiveDelete a country by ID
delete_currencydestructiveDelete a currency by ID. Cannot delete currencies in use by documents.
delete_expensedestructiveDelete an expense
delete_fictional_userdestructiveDelete a fictional user
delete_filedestructiveDelete a file from Bexio
delete_invoicedestructiveDelete an invoice
delete_itemdestructiveDelete an item
delete_manual_entrydestructiveDelete a manual entry
delete_milestonedestructiveDelete a milestone from a project in Bexio
delete_notedestructiveDelete a note by ID
delete_orderdestructiveDelete an order
delete_order_repetitiondestructiveDelete repetition settings for an order
delete_outgoing_paymentdestructiveDelete an outgoing payment
delete_paymentdestructiveDelete a payment
delete_projectdestructiveDelete a project from Bexio by ID. Consider using archive_project instead for data retention.
delete_purchase_orderdestructiveDelete a purchase order
delete_quotedestructiveDelete a quote
delete_reminderdestructiveDelete a reminder
delete_salutationdestructiveDelete a salutation by ID
delete_taskdestructiveDelete a task by ID
delete_timesheetdestructiveDelete a timesheet entry by ID
delete_titledestructiveDelete a title by ID
delete_unitdestructiveDelete a unit by ID
delete_work_packagedestructiveDelete a work package from a project in Bexio
download_filereadDownload a file
edit_invoicewriteEdit/update an existing invoice
edit_itemwriteEdit/update an existing item
edit_orderwriteEdit/update an existing order
edit_order_repetitionwriteEdit repetition settings for an order
edit_quotewriteEdit/update an existing quote
find_contact_by_namereadFind contacts by name (searches through all pages)
find_contact_by_numberreadFind a specific contact by its contact number (e.g.,
get_absencereadGet a specific absence record by ID. Requires Bexio Payroll module subscription.
get_accountreadGet a specific account by ID from the chart of accounts
get_additional_addressreadGet a specific additional address for a contact
get_bank_accountreadGet details of a specific bank account by ID
get_billreadGet a specific bill (creditor invoice) by UUID
get_business_activityreadGet a specific business activity by ID
get_calendar_yearreadGet a specific calendar year by ID
get_commentreadGet a specific comment by ID from a document
get_communication_typereadGet a specific communication type by ID
get_company_profilereadGet the company profile including name, address, and settings
get_contactreadGet a specific contact by ID
get_contact_groupreadGet a specific contact group by ID
get_contact_relationreadGet a specific contact relation by ID
get_contact_sectorreadGet a specific contact sector by ID
get_countryreadGet a specific country by ID
get_currencyreadGet details of a specific currency by ID
get_currency_exchange_ratesreadGet exchange rates for a specific currency (by ID, from list_currencies), optionally for a historical date. Useful for multi-currency reporting and conversions.
get_current_userreadGet the currently authenticated user
get_customer_revenue_reportreadGet customer revenue report for a specific period
get_deliveryreadGet a specific delivery by ID
get_employeereadGet a specific employee by ID. Requires Bexio Payroll module subscription.
get_employee_payslip_pdfreadFetch a single employee
get_expensereadGet a specific expense by UUID
get_fictional_userreadGet a specific fictional user by ID
get_filereadGet a specific file
get_iban_paymentreadGet details of an IBAN payment by ID
get_invoicereadGet a specific invoice by ID
get_invoice_pdfreadGet an invoice as PDF (returns base64-encoded content)
get_invoice_status_reportreadGet invoice status report for a specific period
get_itemreadGet a specific item by ID
get_languagereadGet a specific language by ID
get_manual_entryreadGet a specific manual entry by ID
get_milestonereadGet a specific milestone by ID from a project in Bexio
get_monthly_revenue_reportreadGet monthly revenue report for a specific month
get_notereadGet a specific note by ID
get_open_invoicesreadGet all open invoices (draft and sent/pending)
get_orderwriteGet a specific order by ID
get_order_pdfwriteGet an order as PDF (returns base64-encoded content)
get_order_repetitionwriteGet repetition settings for an order
get_outgoing_paymentreadGet a specific outgoing payment by UUID
get_overdue_invoicesreadGet all overdue invoices
get_overdue_invoices_reportreadGet overdue invoices report
get_paymentreadGet a specific payment by ID
get_payment_typereadGet a specific payment type by ID
get_projectreadGet a specific project by ID from Bexio
get_project_statusreadGet a specific project status by ID from Bexio
get_project_typereadGet a specific project type by ID from Bexio
get_purchase_orderwriteGet a specific purchase order by ID
get_qr_paymentreadGet details of a QR payment by ID
get_quotereadGet a specific quote by ID
get_quote_pdfreadGet a quote as PDF (returns base64-encoded content)
get_reminderreadGet a specific reminder by ID
get_reminder_pdfreadGet a reminder as PDF (returns base64-encoded content)
get_reminders_sent_this_weekreadGet all reminders sent this week
get_revenue_reportreadGet revenue report for a specific period
get_salutationreadGet a specific salutation by ID
get_taskreadGet a specific task by ID
get_tasks_due_this_weekreadGet all tasks due this week (invoices with due date this week)
get_taxreadGet a specific tax by ID
get_timesheetreadGet a specific timesheet entry by ID
get_titlereadGet a specific title by ID
get_top_customers_by_revenuereadGet top customers by revenue
get_unitreadGet a specific unit by ID
get_userreadGet a specific real Bexio user by ID
get_work_packagereadGet a specific work package by ID from a project in Bexio
issue_billreadFinalize (book) a DRAFT bill (creditor invoice): transitions it from DRAFT to BOOKED so it posts to the ledger and can be paid. Bexio v4.0 books bills via PUT /purchase/bills/{id}/bookings/BOOKED (there is no POST /issue endpoint).
issue_deliveryreadIssue a delivery
issue_invoicereadIssue an invoice
issue_quotereadIssue a quote
list_absencesreadList a specific employee
list_account_groupsreadList account groups (read-only hierarchy). Account groups organize the chart of accounts into categories.
list_accountsreadList chart of accounts with pagination. Returns all accounts in the chart of accounts.
list_additional_addressesreadList additional addresses for a contact
list_all_invoicesreadList every invoice in Bexio by paging automatically
list_all_statusesreadList all document statuses for invoices, quotes, and orders
list_bank_accountsreadList all configured bank accounts in Bexio. Returns account details including IBAN, bank name, and currency. Use this to get valid bank_account_id values before creating payments.
list_billsreadList all bills (creditor invoices) with optional pagination
list_business_activitiesreadList business activities (service types for time tracking). Used to categorize work.
list_business_yearsreadList business/fiscal years (read-only). Business years define fiscal periods for accounting.
list_calendar_yearsreadList calendar years defined in the system
list_commentswriteList all comments for a specific document (quote, order, invoice, or delivery)
list_communication_typesreadList all communication types (e.g., email, phone, meeting)
list_companiesreadList the Bexio companies (mandates) this server is configured for. Returns each company
list_contact_groupsreadList all contact groups for categorizing contacts
list_contact_relationsreadList all contact relations
list_contact_sectorsreadList all contact sectors (industry types for contacts)
list_contactsreadList contacts from Bexio with optional pagination and filtering
list_countriesreadList all countries available in Bexio
list_currenciesreadList all currencies configured in Bexio. Returns currency codes (CHF, EUR, USD, etc.) with their rounding factors for invoicing.
list_currency_codesreadList all ISO currency codes Bexio supports (for use when creating currencies).
list_deliveriesreadList deliveries from Bexio with optional pagination
list_document_settingsreadList all document settings (header/footer, number ranges, etc.)
list_document_templatesreadList all document templates available for generating documents
list_employeesreadList employees in the payroll system. Requires Bexio Payroll module subscription. Use to get employee IDs for timesheets and absences.
list_expensesreadList all expenses with optional pagination
list_fictional_usersreadList fictional users from Bexio with optional pagination
list_filesreadList files from Bexio with optional pagination
list_invoice_statusesreadList all available invoice statuses with their meanings
list_invoicesreadList invoices from Bexio with optional pagination
list_itemsreadList items from Bexio with optional pagination
list_languagesreadList all languages available in Bexio
list_manual_entriesreadList manual journal entries
list_milestonesreadList milestones for a specific project in Bexio
list_notesreadList notes from Bexio. Optionally filter by resource type and resource ID to get notes for a specific contact, invoice, quote, order, delivery, project, or bill.
list_ordersreadList orders from Bexio with optional pagination
list_outgoing_paymentsreadList outgoing payments for a specific bill. Bexio requires a bill_id (payments are listed per bill).
list_payment_typesreadList all payment types available for invoices and payments
list_paymentsreadList payments for a specific invoice
list_payroll_documentsreadList payroll documents (payslips, etc.). Requires Bexio Payroll module subscription. Optional employee filter.
list_permissionsreadList all available user permissions in the Bexio account (v3.0 API)
list_project_statusesreadList all project statuses available in Bexio (e.g., Active, Completed, On Hold)
list_project_typesreadList all project types available in Bexio (e.g., Internal, Customer Project)
list_projectsreadList all projects in Bexio with pagination support
list_purchase_ordersreadList all purchase orders with optional pagination
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (11)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/scripts/verify-ui-render.mjs:95
try { target = await (await fetch(`http://127.0.0.1:${port}/json/new?file://${hostFile}`, { method: "PUT" })).json(); }
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/transports/http-auth.test.ts:14
const TOKEN = "s3cret-token-for-tests-0123456789";
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_absence, delete_additional_address, delete_bill, delete_contact, delete_contact_group, delete_contact_relation, delete_country, delete_currency, delete_expense, delete_fictional_user, delete_fi
Why it matters. 30 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/shared/tempfile.test.ts:49
const p = await writeDownloadToTemp(bytes, "../../../etc/passwd");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/accounting/handlers.ts:9
import { BexioClient } from "../../bexio-client.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/accounting/handlers.ts:10
import { McpError } from "../../shared/errors.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/accounting/handlers.ts:37
} from "../../types/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/banking/handlers.ts:8
import { BexioClient } from "../../bexio-client.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/package.json
@fastify/cors, @modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, axios, dotenv, fastify, @types/node, concurrently
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
PRIVACY.md:25
- The server does not log, store, or transmit your token to any other party
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 8b0d48f30c69full audit observations/trust-audit/mcp-server/promptpartner__bexio.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-098b0d48f30c69CAUTIONB88first audit
06

Questions

What is the Bexio MCP server?

Complete Swiss accounting integration for Bexio via MCP. Works with Claude Desktop, n8n, and any MCP client. 310 tools for invoices, contacts, projects & more. Created by Lukas Hertig.

What tools does Bexio expose?

200 in total: 170 read-only, 76 that write, and 30 that can delete or overwrite (delete_absence, delete_additional_address, delete_bill, delete_contact, delete_contact_group). Every one is listed on this page with its risk.

Is Bexio safe to connect to an agent?

With care. The audit graded it B (88/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 30 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Bexio need?

It reads BEXIO_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Bexio run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @promptpartner/bexio-mcp-server at 2.6.2.

How current is this page?

The grade is for one exact copy of the source (8b0d48f30c69), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement