Guides · August 28, 2026 · By João Pereira, Founder, Build Up Labs · Updated August 28, 2026 · 8 min

Claude for Accountants: Query TOConline Invoices with MCP

Claude can query TOConline documents, customers, account status, and PDF links through MCP with read-only, revocable OAuth access.

An accountant can use Claude to query TOConline accounts, sales documents, customers, and PDF links through a read-only MCP server. Access requires OAuth authorization, is limited to the companies selected, and can be changed or revoked in the dashboard. The assistant receives no TOConline API credentials and performs no fiscal actions.

How does Claude for accountants work with TOConline MCP?

Model Context Protocol, or MCP, allows Claude to request data from an external tool during a conversation. Here, the MCP client talks to a hosted bridge, the bridge validates the authorization, and it queries the TOConline API for the specified account. The response returns to the conversation in a structured format.

This is not the same as giving the assistant full TOConline access. Every query for company data includes an explicit account ID, and the server confirms that the account is in the authorized set. For example, an accounting firm can allow queries for company Alpha without sharing company Beta through the same Claude connection.

The TOConline MCP page provides the endpoint and connection process. This integration is intended to answer operational questions about existing information, not replace the invoicing application or the accountant's professional review.

The MCP integrations hub lists the available connections. Firms that use another provider can also review the InvoiceXpress MCP page.

Which TOConline data can an accountant query?

The current set contains eight tools. Every tool is marked as read-only. Three identify the available accounts and their status; the other five query sales documents, customers, and PDF links.

RequestAvailable toolExpected response
List authorized accountsprovider_accounts_listIdentifier, name, provider, and status, without credentials
Show an account or its stored statusprovider_account_show and provider_account_statusConnection summary and whether attention is required
List or open sales documentstoconline_list_sales_documents and toconline_get_sales_documentNumber, type, date, amount, and other available fields
Search or open customerstoconline_search_customers and toconline_get_customerMatches and the customer record returned by the provider
Get a document PDFtoconline_download_pdfA provider link to the PDF, when available

The document list supports pagination and filters for FT or FR document type and status. Document detail can include totals, VAT, due date, currency, and customer data when TOConline returns them. For example, an accountant can list the first page of FT documents and then open one document by its ID.

Which practical questions can an accountant ask?

The following examples are prompt templates, not simulated answers. The names, numbers, and amounts presented by Claude will always depend on the authorized accounts and the real data returned by TOConline.

Question for ClaudeWhat the answer can confirm
Which TOConline accounts can I query?The accounts visible to this authorization and their IDs
What is the stored status of the account with this ID?Whether the connection is active, invalid, or needs reauth
List the first page of invoice-receipts for this account.FR rows with number, date, total, and available fields
Search for customers containing this VAT number or name.Matches found and any search-truncation warning
Get the PDF link for the document with this ID.The print URL returned by TOConline or an explicit error

A question is easier to verify when it includes the company, document type, page, or required ID. “Show document 8472 from account Alpha” defines the request better than “find that invoice from last month.” The result should retain the ID used so that the team can check the document in the source system.

How do you connect TOConline to Claude?

  1. Create or select the workspace in the dashboard and add the company's TOConline connection. The API details are obtained in TOConline under Empresa, Configurações, Dados API.

  2. Test and save the connection. TOConline API authentication uses the identifier, secret, OAuth address, and API base address; these details must not be pasted into a conversation.

  3. In the TOConline profile setup wizard, continue to the AI assistant connection and copy the MCP server URL shown in the interface.

  4. In Claude, follow the flow for the relevant plan. On an individual plan, add the URL as a custom connector. On Team or Enterprise, an Owner or Primary Owner first adds the connector, after which each member establishes their own connection. The sign-in process opens in the browser.

  5. Choose the workspace and only the accounting connections required. After authorizing, start by requesting the account list and confirm the IDs before querying documents.

For example, a firm with ten companies can first grant the connector access to one test company. Access can be expanded later without giving Claude the identifier, secret, or tokens used by the TOConline API.

How does TOConline OAuth differ from Claude access?

There are two separate connections. The first authenticates the service with the TOConline commercial API. The official documentation describes an authorization code, an access token, and token renewal. Those elements remain on the server side that communicates with the provider.

The second connection authorizes the MCP client. During that OAuth flow, the person signs in to the dashboard, chooses a workspace, and selects the accounts that the assistant may read. That selection becomes a grant. A company added later is not automatically included in the existing grant.

An administrator can open AI assistants, edit the selection, or revoke access. An edit applies the new list to subsequent calls. Revocation invalidates the assistant's authorization, including the associated access and refresh tokens. For example, when an engagement ends, the administrator can first remove the company from the grant or revoke the entire connector.

Is access really read-only?

Yes, for the TOConline MCP profile described here. The official TOConline API supports more operations, but this server publishes only the query subset listed above. A capability available from the provider does not automatically become available to Claude.

  • It cannot create sales documents.
  • It cannot edit, finalize, or cancel documents.
  • It cannot send documents by email.
  • It cannot create fiscal previews.
  • It cannot add, change, revoke, or reveal TOConline credentials.

“Download PDF” does not change the document either: the tool asks the provider for a print link and returns that address. The official documentation says that the PDF is available for finalized documents. If a document does not yet meet that condition, expect an error, not automatic finalization.

Which limits matter before relying on an answer?

The status shown by provider_account_status is the stored connection status. The operation does not run a new test, refresh tokens, or correct credentials. When it reports that reauthentication or other attention is required, the correction belongs in the dashboard, not in the conversation.

Lists are paginated. Customer search scans pages and can return a warning when it reaches its search limit before completion. That warning must not be turned into “does not exist.” For example, no matches in a truncated result calls for a narrower query or direct confirmation in TOConline.

MCP also does not certify that a document is correct for accounting purposes, that the right VAT rate was selected, or that a period is closed. It shows provider data to support the work. A tax conclusion still requires the document, the transaction context, and the applicable professional controls.

How should customer data be protected during a query?

Read-only does not mean free of personal data. A customer search can return a name, VAT number, email, address, city, postal code, or phone number when those fields exist in TOConline. Access should cover only the company required, and prompts should not retrieve data that is irrelevant to the task.

The account tools return summaries, not the secret, access token, or refresh token. Every business tool also requires the account ID. For example, knowing a document ID does not grant access if the account containing that document is outside the grant.

The recipient should be checked before copying an answer into a message or report. If the request is only “is the PDF available?”, there is no need to reproduce the complete customer record. Data minimization should apply to the authorization, the prompt, and the later use of the answer.

Which accounting workflows suit this MCP?

The first workflow is connection triage. List the authorized set, query each account's status, and route connections that need attention to the dashboard. This avoids beginning a document search against an unavailable account.

The second is document retrieval. An accountant can list a page of FT or FR documents, open the relevant IDs, and obtain a PDF link for a finalized document. This is useful, for example, when a client asks for another copy and the company and approximate period are known, but pagination must continue until the required range has been covered.

The third is checking a customer record. Search by name, VAT number, or another available term, open the correct customer by ID, and check the returned record. Any change must still be made in TOConline. To choose between providers and understand their integration differences, see the TOConline and InvoiceXpress comparison.

When should payment remain separate from the accounting query?

MCP queries what already exists in TOConline. It does not turn a charge into a fiscal document, select FT or FR, or reconcile the payment with the invoice by itself. A payment result and a sales document are different records even when they share a reference.

Automating issue after a Stripe payment requires a separate workflow with rules, validation, and failure handling. That process is described in the guide to automating Stripe invoicing in Portugal. MCP remains a query interface for concrete questions, with limited and revocable access.

Frequently asked questions

What TOConline data can Claude query?

The connector provides read operations to list authorised accounts and their status, list or retrieve sales documents, search or retrieve customers, and generate a document PDF download link.

Can Claude create, change, or send TOConline invoices?

No. The current tools are read-only. They do not create, edit, finalise, cancel, or send documents, and they do not provide a change preview.

Are TOConline credentials shared with Claude?

No. The connection uses OAuth authorisation, and the assistant receives only access to tools exposed by the MCP server. Provider tokens and credentials are not returned in tool responses.

Does an MCP authorisation automatically cover every account?

No. Authorisation is limited to the accounts selected during consent. An account added later is not shared automatically and requires editing the existing grant or repeating consent.

How is Claude access revoked?

An administrator can edit or revoke the grant in the dashboard. Revocation invalidates the associated tokens, so later calls no longer have access to the covered accounts.

Sources

Automate Stripe invoicing with Faturado

Connect Stripe, TOConline, or InvoiceXpress and validate the flow with usage-based pricing.