Affinity
Search your CRM, prep for meetings and update deal records from your AI assistant.
Query and change a Kick bookkeeping ledger: categorize transactions, post journal entries, edit accounts, run reports.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Kick MCP server connects a Kick bookkeeping ledger to Claude, ChatGPT and any MCP client. An agent can search transactions, run financial statements, and — with your approval — recategorize transactions, post journal entries and edit the chart of accounts. Twenty of its 39 tools write to live books, each gated behind a preview you confirm before anything saves.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
tools/list regardless of plan and return a plan-capability error only at execution, so an agent discovers the gate by hitting it.It can change them. Twenty of Kick's 39 documented tools are writes, and they reach the ledger itself — transaction categories, journal entries, the chart of accounts and opening balances. Kick gates each one behind a preview: the first call returns a summary and a confirmation token, and nothing is saved until a second call repeats the same input with that token attached.
Yes, directly. The journals tool creates single and bulk manual journal entries with debit and credit lines against a named entity and ledger, and can also update and delete them. Kick documents the same tool as write and destructive. The entry lands in the ledger once you confirm the preview — there is no separate draft or approval queue behind it.
No. Kick connects banks through Plaid, and no tool in Kick's 39-tool reference reaches that connection — the words Plaid, reconcile and import appear nowhere in it. The one accounts tool, financial accounts query, is documented read-only and lists connected accounts. Adding, removing or repairing a bank feed stays in the Kick web app.
Kick advertises exactly two scopes, mcp:read and mcp:write, and both its protected-resource and authorization-server documents agree on that pair. So read-only access is expressible here, which is unusual — most connectors in this catalogue offer a single all-or-nothing grant. Kick also documents read-only personal access tokens as the safer credential for lookup and reporting work.
That is the designed behaviour, not a failure. Kick's write tools are preview-first: calling one without a confirmation token returns a summary of the pending action plus a fresh token bound to that exact input. Kick tells users to check the workspace, resource IDs, dates and amounts against the preview, and to confirm only when they match.
Usually the authorization did not finish. Kick's fix is to disconnect Kick on the Claude connectors page and reconnect, completing the flow. Kick also lists four other causes: the credential cannot reach the workspace, the token lacks the mcp:read scope, the relevant Kick feature is off for that workspace, or the client was not restarted after a config change.
Not for the core tools, but two toolsets are plan-gated. Kick documents class tools as requiring the Classes capability and invoice and bill tools as requiring the Accrual Ledger capability — both sit on the Plus plan at $100 a month. Gated tools still appear in the tool list and fail at execution with a plan-capability error rather than being hidden.
Yes, and that is the intended shape. Kick gives each client its own workspace, and at authorization you choose either all workspaces or a named subset. Access never exceeds your own Kick permissions. Because one connection can span several clients' books, Kick tells agents to confirm the active workspace before reading or changing any client data.
documentation URL; fetched 2026-08-21 as Markdown via the .md suffix, HTTP 200, no redirect) · retrieved 2026-08-21docs.kick.co/robots.txt (fetched 2026-08-21) allows all crawlers and carries Content-Signal: ai-train=yes, search=yes, ai-input=yes — the publisher expressly permits AI synthesis of this content · retrieved 2026-08-21resource, authorization_servers and scopes_supported of mcp:read and mcp:write). The path-append and path-insert forms both return HTTP 200 serving an identical SPA HTML shell, not metadata — only the root form is real · retrieved 2026-08-21S256, dynamic registration, one-hour token lifetime) · retrieved 2026-08-21www-authenticate Bearer challenge naming resource_metadata and pointing at the root descriptor. No tool was ever called and no authentication was attempted · retrieved 2026-08-21permissions value, the sensitive-data types, and an empty prompt list) · retrieved 2026-08-16Connect Kick once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.