Affinity
Search your CRM, prep for meetings and update deal records from your AI assistant.
Query a live general ledger and post to it.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Rillet MCP server connects Rillet's AI-native ERP to Claude, ChatGPT or any MCP-compatible agent, so a general ledger can be queried in plain English. It is not read-only. Of the 81 tool names Anthropic's directory publishes, 43 write — creating invoices and bills, recording payments, and deleting records across every subledger Rillet keeps.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
readOnlyHint and destructiveHint values — the fields a client uses to prompt for confirmation — are unverified for every one of the 81 tools. The read/write split published above is inferred from verb prefixes and Rillet's own endpoint documentation, not from annotations.write covers creating invoices, recording payments and deleting records with one grant; read covers every report and subledger with the other. There is no per-domain or per-destructiveness split of the kind some connectors publish.X-Rillet-API-Version as the way to pin behaviour and warns that the no-header default moved from version 1 to the latest version on 1 August 2026. It is not documented whether the MCP server pins a version on your behalf.Idempotency-Key header on POST requests and stores the response for 24 hours, but nothing states that the MCP server sets one — so a retried create is not automatically safe from duplicating a record.book_id values work with report and journal-entry endpoints, and that multi-book support applies to v4 only.It changes them. Anthropic's directory publishes the permission label Read and write, and 43 of the 81 listed tool names are mutating verbs — 12 create, 13 update, 13 delete, plus five one-off actions. Only 38 read. Every financial subledger Rillet exposes has a delete tool attached to it, so this is not a reporting connector with a few writes bolted on.
The directory listing does not include one, but Rillet's own API does. Anthropic's snapshot names only list_all_journal_entries, a read. Rillet's published v4 OpenAPI specification documents POST, PUT and DELETE on /journal-entries, and Rillet's connector description advertises creating journal entries by prompt. Treat GL posting as reachable and gate it deliberately.
Anthropic's directory lists 81 tool names, but that is a floor rather than a total. Rillet documents the MCP server as implementing the same features as its Public API, whose v4 specification defines 117 operations. Rillet also states an agent only sees tools the signed-in Rillet user can reach, so the real surface varies per user.
Yes, in principle. Rillet's RFC 9728 resource descriptor advertises exactly two scopes, read and write, so a token can carry read without write. Whether your MCP client lets you decline the write scope at the consent screen is a client question, not a Rillet one. The scopes are coarse: read covers every report and subledger at once.
You may silently erase fields you never mentioned. Rillet marks its update endpoints as full-replace PUT semantics and warns that omitting any field sets it to null, wiping existing data. Its documented remedy is to retrieve the record first and resend every existing field alongside the change. An agent that patches conversationally will not do that by default.
You need a Rillet account, and API access is not self-serve. Rillet's setup page lists a valid Rillet account as the only stated prerequisite for MCP. Its getting-started guide adds that you contact your Rillet team to enable API access before keys can be created. Authorisation is per organisation — you pick one during the OAuth redirect.
Yes. Rillet documents a maximum of 60 API requests over a rolling one-minute window, with requests above that threshold failing with HTTP 429. That budget is shared with any other integration using the same credentials. Agents that fan out across subsidiaries or paginate long ledgers can exhaust it quickly, since list responses default to 25 records per page.
robots.txt allows crawling and names this file itself; no llms-full.txt exists (HTTP 404) · retrieved 2026-08-20initialize to the endpoint returned HTTP 401 with a www-authenticate challenge naming resource_metadata; RFC 9728 descriptor at api.rillet.com/.well-known/oauth-protected-resource returned scopes read and write (2026-08-20) · retrieved 2026-08-20Connect Rillet once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.