Skip to main content

invoice-intake-mcp

Reference implementation of the tool-design rules in Designing MCP servers and tools that agents can use safely, on a real back-office process: supplier invoice intake.

It is small on purpose. The fake ERP is a JSON file; everything else is the shape we use in production systems.

What it shows

Rule Where
Model the business operation, not the API erp_match_po, erp_stage_invoice, not PATCH /invoices
Separate reads, drafts and commits --role read server (reads + reversible staging) vs --role commit server (irreversible post)
Strict schemas Literal enums for currency, ids not names, found=false as a valid empty result
Permissions on the server and credential specialist agents get read; only the orchestrator connects to commit
Tool results are untrusted input invoices_extract says so in its description; the eval set includes a prompt-injection case
Typed errors {"error": "approval_required" | "validation_failed" | "business_rule" | "not_found", "retryable": bool, ...}
Log for the auditor audit.jsonl: actor, tool, ids, approval reference
Human checkpoint enforced server-side erp_post_invoice refuses without a recorded approval, whatever the client believes

Run it

python -m venv .venv && . .venv/bin/activate
pip install -e ".[dev]"

python -m invoice_intake_mcp.orchestrator            # process the inbox
python -m invoice_intake_mcp.approve list            # see what is waiting
python -m invoice_intake_mcp.approve APR-xxxx approved --by cfo
python -m invoice_intake_mcp.orchestrator --resume   # post the approved item
cat audit.jsonl

Expected first run:

plan: 4 new invoices -> extract, resolve vendor, match, stage, post-or-approve
  invoice_2291.pdf: staged STG-… -> WAITING for APR-…        (7,420 EUR > 5,000 limit)
  invoice_2292.pdf: match=goods_not_received -> REVIEW
  invoice_2293.pdf: match=variance {"variance_pct": 2.34} -> REVIEW
  invoice_2294.pdf: no PO reference -> REVIEW (ask requester)

The orchestrator is deterministic so the flow replays without an API key. An LLM belongs in the places marked in orchestrator.py (ambiguous vendor candidates, free-text remarks, the note back to the requester), not in the match rule, the tolerance or the approval limit.

Use the servers from an MCP client

{
  "mcpServers": {
    "invoice-intake-read":   { "command": "uvx", "args": ["invoice-intake-mcp", "--role", "read"] },
    "invoice-intake-commit": { "command": "uvx", "args": ["invoice-intake-mcp", "--role", "commit"] }
  }
}

Give an agent only the read server unless it is the orchestrator.

Tests and evals

pytest                 # unit tests on the core operations and the gate
python evals/run.py    # replayable decision cases, run on every change

Layout

invoice_intake_mcp/
  core.py          business operations + policy (tolerance, approval limit), pure functions
  server.py        the two MCP servers and their tool descriptions
  orchestrator.py  minimal hub over MCP stdio: read server for work, commit server for posting
  approve.py       the human decision, as a CLI
  audit.py         append-only JSONL audit log
  erp.py           fake ERP / inbox state (JSON file)
tests/             pytest
evals/             cases.jsonl + run.py

MIT. Built by JustDukkan, AI solutions architecture.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

invoice_intake_mcp-0.1.1.tar.gz (13.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

invoice_intake_mcp-0.1.1-py3-none-any.whl (14.0 kB view details)

Uploaded Python 3

File details

Details for the file invoice_intake_mcp-0.1.1.tar.gz.

File metadata

  • Download URL: invoice_intake_mcp-0.1.1.tar.gz
  • Upload date:
  • Size: 13.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.13

File hashes

Hashes for invoice_intake_mcp-0.1.1.tar.gz
Algorithm Hash digest
SHA256 db44250600f21df1604bc85f12d59d3d169f9f3d180e74f4172d2d7311d6f7ee
MD5 54ba624c92b747b258b7a1d9035377ef
BLAKE2b-256 184487654a2d1041784ce52cae7e04f0a6bd04b95b198466cd983d7f6673026a

See more details on using hashes here.

File details

Details for the file invoice_intake_mcp-0.1.1-py3-none-any.whl.

File metadata

File hashes

Hashes for invoice_intake_mcp-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 8d949d1a045b35a60dacdecb88384142cb812b7b28e58d50830f6fb4aec8a415
MD5 2625bd89f0aad0ca8b2198cddbad409d
BLAKE2b-256 a0f52f6dd283b8ca337228c24db7ced78ae06dd3cf9d636089085b50419981b6

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page