The KikoBooks MCP server is an open-source Model Context Protocol server that gives Claude, ChatGPT, and GitHub Copilot secure, governed access to a KikoBooks organization — 116 tools across bookkeeping, reports, banking, CRM, proposals and workflow. Read-only by default, scoped write when you approve it, and secrets are never exposed.
Your assistant talks to KikoBooks through the MCP server. Reads flow freely; writes stop at the approval gate until you say go.
Ask a question or request work in plain language.
Claude, ChatGPT, or Copilot picks the right tools.
116 governed tools over the KikoBooks API.
Reads pass through; writes wait for your sign-off.
Changes land in KikoBooks with a full audit trail.
Read-only by default. Scope tiers and the approval gate are yours to set — and revoke anytime.
Grab an API key from your KikoBooks organization settings, add one block to your assistant's config, and
start asking. The server is published on npm — npx pulls it
automatically.
{
"mcpServers": {
"kikobooks": {
"command": "npx",
"args": ["-y", "@agentkiko/kikobooks-mcp-server@latest"],
"env": {
"KIKOBOOKS_BASE_URL": "https://ai.kikobooks.com",
"KIKOBOOKS_API_KEY": "your_api_key"
}
}
}
}
{
"servers": {
"kikobooks": {
"command": "npx",
"args": ["-y", "@agentkiko/kikobooks-mcp-server@latest"],
"env": {
"KIKOBOOKS_BASE_URL": "https://ai.kikobooks.com",
"KIKOBOOKS_API_KEY": "your_api_key"
}
}
}
}
Read tools always load. Mutating tools are grouped into scope tiers you can suppress at startup — so you can hand an assistant read-only analysis, or let it draft changes while holding writes for your approval. Authenticate with an org API key (auto-exchanged for short-lived JWTs); the key itself is never written to disk or returned to the model.
| Tier | Environment flag | What it gates |
|---|---|---|
| Read Always on | — | Every get_* and search_* tool — reporting, analysis, discovery. |
| Write | KIKOBOOKS_DISABLE_WRITE | create_*, post_*, reverse_*, move_*, promote_*, copy_*, generate_* |
| Update | KIKOBOOKS_DISABLE_UPDATE | update_* tools |
| Delete | KIKOBOOKS_DISABLE_DELETE | delete_*, void_* tools |
The full KikoBooks org — core bookkeeping, practice management, banking, and analytics — exposed as typed MCP tools over the public REST API.
Plus connection & discovery tools (get_connection_status, get_enabled_modules) and
lifecycle bridges: CRM deal → proposal → job → invoice, end to end.
See the full list →
The MCP server is a client of KikoBooks — it inherits the platform's approval-aware controls, not a side door around them.
The questions developers and finance teams ask before connecting an assistant to their books.
get_*, search_*) always load. Writes are grouped into scope tiers you switch on with KIKOBOOKS_DISABLE_WRITE, _UPDATE, and _DELETE — so you can start read-only for analysis and enable scoped writes when you’re ready. Every write is read back and surfaced for approval.npx pulls it automatically — you just paste one config block into your assistant and add your API key. No build step, no server to host.get_enabled_modules to check.Start free, grab an API key, and connect Claude, ChatGPT, or Copilot in minutes — with read-only analysis today and approval-gated writes when you're ready.