10 MCP servers accountants can connect to AI today
Ten MCP servers an accounting firm can connect to Claude, ChatGPT or another AI assistant as at September 2026, grouped by the job they do: ledger, practice data, proposals and billing, payments, CRM and the inbox. Each entry says what the AI can read and change, how hard it is to set up, and the permission to check before you switch it on.
Part of our AI in accounting coverage. See the full AI for accountants guide →
MCP (Model Context Protocol) is the plug that lets an AI assistant such as Claude or ChatGPT reach into another app, read what is there and, if you allow it, change things. If the idea is new, start with MCP for accountants, explained without jargon, then come back.
This list covers ten servers an accounting firm can connect as at September 2026. Every one is confirmed from the vendor’s own site, docs or code repository, linked in each entry. They are numbered for scanning, in no particular order; grouped by the work they touch. For each: what the AI can do, which assistants it works with, how much setup it takes, and the risk to check first.
The ten at a glance, in the same order as below and in no particular order of merit. Details and sources are in each entry.
| Server | What the AI can do | Setup |
|---|---|---|
| 1. Xero | Connector: read-only. Developer server: read and write | Minutes (connector); config file (developer) |
| 2. QuickBooks Online | Read, plus create or update invoices, estimates and customers | Sign in with Intuit (US customers only) |
| 3. Meridian | Read and write Xero transactions, set per company | Sign in, no install |
| 4. XBert | Read-only practice view | Custom connector |
| 5. Zapier MCP | The actions you choose in Karbon, FYI, Financial Cents and more | Pick apps and actions |
| 6. Ignition | Read and write; invoices created as drafts | Server address, sign in |
| 7. Anchor | Read, draft and publish proposals; cannot charge clients | Connector URL, per-user login |
| 8. Stripe | Read and write much of the Stripe API | OAuth or agent API keys |
| 9. HubSpot | Read and write CRM records | Admin authorises first |
| 10. Microsoft 365 | Search; write tools optional | Global Administrator authorises once |
Ledger and bookkeeping
1. Xero
Xero offers two different things, and the difference matters. The Xero connector for Claude is read-only: Xero says Claude can answer questions on profit, cash flow, overdue invoices and top customers but cannot edit invoices or post transactions. The open-source Xero MCP server on GitHub is a developer tool that can also create and update contacts, invoices, bank transactions, manual journals and more.
Xero offers two different things, and the difference matters.
- Works with: the connector is documented for Claude; the developer server works with any MCP client you configure.
- Setup: connector, a few minutes with your Xero login; developer server, a Xero custom connection and a config file.
- Check: which organisation you authorised, and whether anyone has quietly swapped the read-only connector for the write-capable server.
2. QuickBooks Online
Intuit runs a hosted QuickBooks connector for Claude that reads reports and transactions and can create or update invoices, estimates and customers. In July 2026 Intuit extended it into ChatGPT as well, adding invoicing and payroll lookups. Developers can also run Intuit’s open-source QuickBooks Online MCP server locally.
- Works with: Claude and ChatGPT (hosted); any MCP client (open-source server).
- Setup: hosted connector, sign in with Intuit. Intuit’s help article says it is currently available to US customers only.
- Check: write access to invoices means an assistant can send one to a client. Decide who in the firm may connect a client file at all.
3. Meridian connector for Xero and QuickBooks Online
Launched on 22 September 2026 by Pilot, the AI Agent Connector by Meridian is a free, hosted server that reads and writes Xero transactions, including manual journals, across several organisations. A QuickBooks Online version sits alongside it. It fills the gap between Xero’s read-only connector and the developer server.
- Works with: Claude, ChatGPT and Codex, per Meridian’s own page.
- Setup: sign in, connect organisations, add the server to your assistant. No install.
- Check: it is an independent service, not endorsed by Xero. You set read-only or read-write per company, so start every client file on read-only.
4. XBert
XBert’s MCP gateway lets an assistant query XBert’s view of your practice: client data health alerts, practice analytics and team capacity and job progress drawn from Xero Practice Manager (XPM). XBert describes it as read-only, and says it is included in an existing XBert subscription.
- Works with: Claude, ChatGPT, Microsoft Copilot, Google Gemini and Perplexity, per XBert.
- Setup: add XBert’s gateway as a custom connector, following XBert’s support guide.
- Check: read-only removes the risk of bad writes, not the privacy question. Practice-wide data reaches the assistant, so confirm your AI provider’s data terms first.
Practice-wide data reaches the assistant, so confirm your AI provider’s data terms first.
Practice management and workflow
5. Zapier MCP (the bridge to Karbon, FYI and Financial Cents)
Most practice management platforms do not yet have an official server. Karbon announced a public MCP server in June 2026, marked coming soon, and as at September 2026 it is not published. Until it is, Zapier MCP is the practical route: it exposes chosen actions in Karbon, FYI, Financial Cents and thousands of other apps to your assistant.
- Works with: Claude, ChatGPT, Cursor and other MCP clients.
- Setup: pick the apps and the exact actions the assistant may use. Zapier says each tool call uses two tasks from your plan.
- Check: you are adding a middleman that holds your credentials. Zapier keeps a full action history; review it.
Proposals, engagement and billing
6. Ignition
The Ignition MCP reads and writes across most of Ignition: look up clients, invoices and proposals; create and edit clients, proposals, deals and forms. Invoices are created as drafts, and Ignition says nothing is issued automatically. We covered the workflow in Ignition MCP: from discovery call to proposal.
- Works with: Claude, ChatGPT and other MCP-compatible apps.
- Setup: add the server address from Ignition’s help article, sign in, approve.
- Check: the assistant inherits your Ignition role, so an Admin login gives it Admin reach.
7. Anchor
Anchor’s Claude connector reads contacts, proposals, agreements, invoices and payouts, and can draft and publish proposals and change services on agreements. It cannot charge clients or add credit. Anchor also documents a ChatGPT route.
- Works with: Claude (Anchor lists Pro, Team and Enterprise plans or Claude Desktop) and ChatGPT.
- Setup: add the connector URL, sign in, authorise. Each team member connects with their own login.
- Check: publishing a proposal asks for confirmation. Keep it that way.
Vinyl (The Firm partner) records client meetings and files the notes into Karbon, FYI, Xero Practice Manager and Ignition, where the servers above can reach them. Its Ignition integration turns a discovery meeting into a draft proposal.
Payments and CRM
8. Stripe
Stripe’s MCP server gives an assistant read and write access to much of the Stripe API: customers, invoices, subscriptions, payment links, refunds and payouts. Useful for a firm that bills through Stripe, or for advisory clients who do.
- Works with: Claude, ChatGPT, Codex, Cursor and VS Code, per Stripe’s docs.
- Setup: OAuth from the Claude directory or ChatGPT; agent API keys for unattended use.
- Check: Stripe asks for human confirmation on some writes, such as refunds. From 31 October 2026 it stops accepting full-access secret keys over MCP, so replace any old key.
9. HubSpot
HubSpot’s remote MCP server reads and writes contacts, companies, deals, tickets, quotes and logged activity, and reads campaigns and web pages. For a firm running its pipeline in HubSpot, that means asking which prospects went quiet after a proposal.
- Works with: any MCP-compatible assistant; there is a HubSpot connector in Claude’s directory.
- Setup: an account admin authorises first, then users connect.
- Check: access follows the user’s HubSpot permissions and the app’s scopes. A CRM holds client personal data, so check scopes.
Email, calendar and files
10. Microsoft 365
Anthropic’s Microsoft 365 connector lets Claude search Outlook, SharePoint, OneDrive and Teams, and, if you enable write tools, send email, manage calendar events and create files. For most firms this is where client correspondence and workpapers already live.
- Works with: Claude, on every plan.
- Setup: a Microsoft Entra Global Administrator authorises it once for the tenant.
- Check: write tools are optional and can be switched off per member. Start with read only.
Before you connect anything
An MCP server is a new door into client data. Work through this list once, write down the answers and put them in your firm’s AI policy.
An MCP server is a new door into client data.
- Data security. Read the AI provider’s terms on retention and training, and your professional obligations on confidentiality. Our guide on whether AI is safe for client data covers the questions to ask.
- Least privilege. Connect with the narrowest role, one organisation at a time, read-only first.
- Confirmation on writes. Keep every “ask before acting” setting on, especially for anything that sends, publishes or moves money.
- Audit trail. Know where the log of assistant actions lives in each app, and who reviews it.
- Revocation. Know how to disconnect each server in under a minute, and do it when someone leaves.
- Prompt injection. Content an assistant reads, such as an email or a PDF, can carry instructions. Stripe’s own docs warn about combining servers for this reason.
Content an assistant reads, such as an email or a PDF, can carry instructions.
This is general information, not legal or security advice; check your obligations with your professional body. For where each of these tools fits in a wider AI stack, see our guide to AI for accounting firms.
Frequently asked questions
Is an MCP server the same as a connector?
Mostly. “Connector” is what Claude and ChatGPT call an MCP server once it is packaged for one-click setup. The same vendor may offer both a polished connector and a rawer server for developers, and the two can have very different permissions, as Xero’s do.
Do I need to be technical to set these up?
Not for the hosted ones. Ignition, Anchor, Stripe, HubSpot, XBert, Meridian and the Xero and QuickBooks Online connectors all use a sign-in and approve flow. The open-source Xero and QuickBooks Online servers need someone comfortable with config files and developer credentials.
Does Karbon have an MCP server?
Karbon announced one in June 2026 and lists it as coming soon. As at September 2026 there is no published endpoint from Karbon itself. Community-built servers exist on GitHub, but they are not supported by Karbon, so treat them with the same caution as any unvetted software touching client data.
Can I connect a client’s Xero or QuickBooks Online file, or only my firm’s?
Technically you can connect any file your login can open. Whether you should is a question for your engagement letter and privacy notice: some clients will expect to be told before their books are read by an AI service. Decide the firm’s position before a staff member decides it for you.
Which one should a firm connect first?
Pick the job, not the tool. If partners spend hours building proposals, the proposal servers pay back fastest. If the pain is chasing data quality across a client base, a read-only practice view is lower risk. Starting read-only anywhere is the safest way to learn how your team actually uses it.
MCPAI ToolsXeroQuickBooksIgnitionData Security