Bonsai MCP server icon

Bonsai

by Bonsai

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity39 tools

Run a consulting business from a conversation: CRM, deals, projects, tasks, time tracking and invoices. 39 tools, OAuth sign-in with no API key, and four tools that delete.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Bonsai via MCP

https://mcp.hellobonsai.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Use in Agentman

Connect Bonsai once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Bonsai Tools & Capabilities (39)

create_comment
create_company
create_contact
create_deal
create_invoice
create_invoice_item
create_note
create_note_link
create_project
create_task
create_time_entry
destroy_invoice_item
destroy_note
destroy_note_link
destroy_task
get_note
get_task
list_board_groups
list_comments
list_companies
list_company_tags
list_contacts
list_deals
list_invoices
list_notes
list_projects
list_subtasks
list_task_statuses
list_tasks
list_team_members
list_time_entries
update_company
update_contact
update_deal
update_invoice
update_invoice_item
update_note
update_task
update_time_entry

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • It is beta. Bonsai's own documentation says the server is live in beta at this endpoint. Treat the surface as subject to change.
  • No payments, no reports. Bonsai names both as planned for later milestones. An agent cannot record a payment, reconcile one, or pull a business report through this connector today.
  • Four tools delete, and one of them is not idempotent. destroy_note_link returns 404 on a repeat call, so an automatic retry after a network timeout fails rather than silently repeating.
  • Paid invoices are closed. An invoice that is paid, partially paid or has a payment in progress returns 403 to edits and line-item removals, per Bonsai's API reference. That is a guard rail, but it also means an agent cannot correct a billing mistake after payment starts.
  • We could not read tool safety annotations. The server requires authentication, so no readOnlyHint or destructiveHint values were observable. Every safety statement on this page comes from Bonsai's documentation, not from server metadata.
  • The two documented rate limits disagree. Bonsai's MCP page gives 10,000 requests per 10 minutes per IP; its REST API reference gives 600 per minute and 10,000 per hour per credential, with a separate 120-per-minute write cap. We did not test either.
  • Your data goes to your AI provider. Bonsai states this plainly: whatever you ask about is sent to whichever AI client and model you use. Bonsai's guidance is to review that provider's data handling before connecting a sensitive account.
  • Permissions narrow answers, not just tools. Bonsai documents that asking for time entries by billing status without billing access is refused rather than answered, because answering would reveal the hidden field. Expect refusals, not empty results, on restricted queries.
  • Parameter-level detail is not on the MCP page. Bonsai directs readers to its REST API reference for every field, type and filter, so the MCP documentation describes capabilities rather than schemas.

Frequently asked questions

No. Bonsai's documentation states there are no API keys to create, copy or paste. The server uses OAuth 2.1 with the authorization code flow and PKCE, and your AI client runs the login in a browser. Most clients register themselves automatically because Bonsai supports dynamic client registration, so setup is one command with no developer-portal step.

Yes. Four of the 39 tools delete: destroy_task, destroy_note, destroy_note_link and destroy_invoice_item. Bonsai's API reference says a deleted task or note stops appearing in every subsequent read, and that detaching a note link is not idempotent, so a repeat call returns 404. Ask your assistant to confirm before it deletes anything.

No. Bonsai's API reference states an invoice is created as a draft and nothing is sent to your client at that point; you send it from Bonsai when you are ready. The MCP server can create the invoice, add and remove its line items, and change its title, currency, billing contact and due terms.

Only what your own Bonsai role can already see. Bonsai's documentation says there are no scopes to pick, and every call is re-checked against your permissions on the server. Tools you are not allowed to use never appear, and a role without financial access gets time entries and tasks with the money fields left out.

Yes. Bonsai documents setup for Claude Desktop, Claude Code, Cursor and Codex, and says any client supporting remote MCP servers over HTTP can connect. The only requirement is that your client can run an OAuth login flow for MCP, because there is no API key path into the server.

Yes, and Bonsai documents two different figures. Its MCP page states 10,000 requests every 10 minutes per IP address. Its REST API reference states 600 requests per minute and 10,000 per hour, counted per credential rather than per IP, with writes capped at 120 per minute. Normal conversational use stays well inside either.

Sources

Server Info

Category
Productivity
Developer
Bonsai
Tools
39
Domain
mcp.hellobonsai.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.

Ready to connect Bonsai?

Connect Bonsai once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.