Skip to main content

invoice-intake-mcp

Reference implementation of the tool-design rules in Designing MCP servers and tools that agents can use safely, on a real back-office process: supplier invoice intake.

It is small on purpose. The fake ERP is a JSON file; everything else is the shape we use in production systems.

What it shows

Rule Where
Model the business operation, not the API erp_match_po, erp_stage_invoice, not PATCH /invoices
Separate reads, drafts and commits --role read server (reads + reversible staging) vs --role commit server (irreversible post)
Strict schemas Literal enums for currency, ids not names, found=false as a valid empty result
Permissions on the server and credential specialist agents get read; only the orchestrator connects to commit
Tool results are untrusted input invoices_extract says so in its description; the eval set includes a prompt-injection case
Typed errors {"error": "approval_required" | "validation_failed" | "business_rule" | "not_found", "retryable": bool, ...}
Log for the auditor audit.jsonl: actor, tool, ids, approval reference
Human checkpoint enforced server-side erp_post_invoice refuses without a recorded approval, whatever the client believes

Run it

python -m venv .venv && . .venv/bin/activate
pip install -e ".[dev]"

python -m invoice_intake_mcp.orchestrator            # process the inbox
python -m invoice_intake_mcp.approve list            # see what is waiting
python -m invoice_intake_mcp.approve APR-xxxx approved --by cfo
python -m invoice_intake_mcp.orchestrator --resume   # post the approved item
cat audit.jsonl

Expected first run:

plan: 4 new invoices -> extract, resolve vendor, match, stage, post-or-approve
  invoice_2291.pdf: staged STG-… -> WAITING for APR-…        (7,420 EUR > 5,000 limit)
  invoice_2292.pdf: match=goods_not_received -> REVIEW
  invoice_2293.pdf: match=variance {"variance_pct": 2.34} -> REVIEW
  invoice_2294.pdf: no PO reference -> REVIEW (ask requester)

The orchestrator is deterministic so the flow replays without an API key. An LLM belongs in the places marked in orchestrator.py (ambiguous vendor candidates, free-text remarks, the note back to the requester), not in the match rule, the tolerance or the approval limit.

Use the servers from an MCP client

{
  "mcpServers": {
    "invoice-intake-read":   { "command": "uvx", "args": ["invoice-intake-mcp", "--role", "read"] },
    "invoice-intake-commit": { "command": "uvx", "args": ["invoice-intake-mcp", "--role", "commit"] }
  }
}

Give an agent only the read server unless it is the orchestrator.

Tests and evals

pytest                 # unit tests on the core operations and the gate
python evals/run.py    # replayable decision cases, run on every change

Layout

invoice_intake_mcp/
  core.py          business operations + policy (tolerance, approval limit), pure functions
  server.py        the two MCP servers and their tool descriptions
  orchestrator.py  minimal hub over MCP stdio: read server for work, commit server for posting
  approve.py       the human decision, as a CLI
  audit.py         append-only JSONL audit log
  erp.py           fake ERP / inbox state (JSON file)
tests/             pytest
evals/             cases.jsonl + run.py

MIT. Built by JustDukkan, AI solutions architecture.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

invoice_intake_mcp-0.1.0.tar.gz (13.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

invoice_intake_mcp-0.1.0-py3-none-any.whl (14.0 kB view details)

Uploaded Python 3

File details

Details for the file invoice_intake_mcp-0.1.0.tar.gz.

File metadata

  • Download URL: invoice_intake_mcp-0.1.0.tar.gz
  • Upload date:
  • Size: 13.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.13

File hashes

Hashes for invoice_intake_mcp-0.1.0.tar.gz
Algorithm Hash digest
SHA256 7924cb4c5a931621fa5f79a8bd3fb9d0dc29ae2619f66d4c760f8283eed2a413
MD5 36c906ed23023a3d2516832d64255252
BLAKE2b-256 595e900c08ea4b331a60153a978a36484a959bececc9894e02eb6bdbadee73b3

See more details on using hashes here.

File details

Details for the file invoice_intake_mcp-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for invoice_intake_mcp-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 263fd1c2a512a4b16c80f087642ed890910cb30041ccf1ab23fe35117ef4a791
MD5 a6560606f4ebbd46d792d0c7c09f392c
BLAKE2b-256 69b2c65532301f247d5e1cdff1959d0416b230931b37ba8319ef73c53154ac98

See more details on using hashes here.

Release history Release notifications | RSS feed

0.1.1

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page