norman-mcp-server
AI-powered bookkeeping and tax filing automation for entrepreneurs at the heart of the European economy
Install
uvx norman-mcp-serverNORMAN_EMAILrequired — Your Norman account emailNORMAN_PASSWORDrequired · secret — Your Norman account passwordNORMAN_ENVIRONMENToptional — API environment: 'production' or 'sandbox'
Norman MCP Server
AI-powered bookkeeping, accounting, and taxes for European businesses, inside your AI assistant.
Norman connects invoicing, transactions, receipts, ledgers, reports, taxes, and company workflows to any MCP-compatible AI.
https://mcp.norman.finance/mcp
Claude · ChatGPT · Gemini · Grok · Perplexity · Cursor · Any MCP Client
What you can do
Invoicing — Create and edit invoices, quotes, and recurring schedules, including document templates, line discounts, units, service dates, payment links, and ZUGFeRD e-invoices; cancel an issued invoice with a Stornorechnung, credit part of it with a Rechnungskorrektur, or make a delivery note (Lieferschein) from an invoice or an approved quote
Client emails and reminders — Send invoices with the company's own email wording and CC recipients, see their delivery status, switch automatic payment reminders on for an invoice, and set the reminder rule (days and dunning fees per level)
Bookkeeping — Categorize transactions, match receipts, and verify entries
Automation rules — "Always book Telekom to Internet costs": preview, create, and manage rules that categorize matching transactions automatically
Workflows — "Close August for me": Norman runs month-end close, bank reconciliation, VAT-return readiness, invoice-to-payment and client document requests on its own servers, stops only to ask you something, and can run them by itself every month; answer its questions and see what the agents did this week from your AI client
Client Management — Maintain your client database and contact details
Products & Services — Keep a catalog of what you sell, with prices, VAT rates and units, and fill invoice lines from it
Tax Filing — Generate Finanzamt previews, file VAT returns, and track deadlines
Company Overview — Check your balance, revenue, and financial health at a glance
Company Formation — Found a German GmbH or UG: collect the founders' data, check the name against the Handelsregister, generate the founding documents (Musterprotokoll, Gesellschafterliste), match with a notary, and track every step through to registration
Documents — Upload and attach receipts, invoices, and supporting files
create_attachment.file_url, bulk file_urls, and structured document imports
accept HTTP(S) download links, including unexpired presigned S3 URLs with query
parameters. Pass the entire link unchanged; the file host must accept the request
without additional authorization headers. The URL downloader has no domain allowlist,
URL-length cap, or explicit file-size cap. Its connect/read timeout is 30 seconds
(not a total download deadline). The separate browser upload route defaults to
50 MiB, configurable with MCP_UPLOAD_MAX_SIZE; API file validation still applies.
URL download failures return an error message and code: download_http_error
(with http_status), download_timeout, download_network_error,
download_storage_error, or download_error. A 403 from the file host can mean an
expired or rejected signature; obtain a fresh link and check the host response.
Bulk uploads include download_errors for failed URLs, indexed within file_urls
followed by URL entries from the deprecated file_paths alias; successfully fetched
files are still uploaded. Structured imports report errors per document. Download
errors omit signed URLs, and temporary downloads are cleaned up after use or cancellation.
Norman is built as a multi-market European accounting platform. Market-specific capabilities are added as Norman expands; current German coverage includes SKR03/SKR04, DATEV, ELSTER, ZUGFeRD, and GmbH/UG workflows.
Invoice appearance and updates
Use list_invoice_templates to discover the templates, appearance controls and the active company's plan access. Use get_invoice_settings to read its logo and saved defaults.
create_invoice, create_recurring_invoice and create_offer accept document_design, for example:
{"template": "sovereign", "logoSize": 75, "textSize": "medium", "spacing": "compact", "tableBorders": "grid"}
Omit document_design, font, and color_schema to inherit saved branding. On create, a partial design uses that template's defaults. Paid templates require an active subscription.
Use update_invoice for an invoice or quote, update_recurring_invoice for a schedule, and update_invoice_settings for future document defaults. Their typed changes object accepts camelCase or snake_case field names. Unset fields stay unchanged; explicit false, 0, empty strings and valid nulls keep their meaning. A partial document design keeps the document's other saved controls; changing its template starts from that template's defaults. Keep existing line IDs when editing lines. Rates use minor currency units; the API calculates totals. Only set isToSend when sending is intended.
Use cancel_invoice, create_credit_note and create_delivery_note for documents derived from an existing invoice or an approved quote; each links back to its source, and a cancelled invoice is read-only afterwards. duplicate_invoice copies an invoice or quote into a fresh draft without a link. API keys need read_invoices for template/settings reads and write_invoices for edits. Settings updates use the invoice-specific endpoint and cannot edit other company fields. Deploy the matching invoice API endpoints before deploying this MCP version.
Client emails and payment reminders
send_invoice and send_invoice_overdue_reminder use the company's email template when subject and body are left out; additional_emails go out as CC, and the company's own copy follows its setting unless is_send_to_company is given. list_invoice_emails returns every email about a document with its delivery status and the reminder the rule sends next. A send that fails at once returns an error with the reason; otherwise email.status is sent, or queued while Norman retries. A dunning fee is shown in the reminder with the total and is paid by bank transfer: a reminder with a fee has no online payment button.
Automatic reminders are off until autoReminders is true on the invoice (create_invoice, create_recurring_invoice, or update_invoice, also after the invoice was issued); remindersPaused stops them for one invoice and skip_invoice_reminder stops one planned reminder. remindersActive on an invoice says whether Norman reminds by itself right now. The company's rule and wording live in get_invoice_email_settings / update_invoice_email_settings and list_invoice_email_templates / save_invoice_email_template / reset_invoice_email_template. settings_on_overdue is kept for older integrations and sends nothing. These tools need the invoice email endpoints of the API to be live before this MCP version is deployed.
💬 Try asking
Once connected, talk to your books in plain language:
- "Prepare and file my UStVA for last month."
- "Send a €1,200 invoice to ACME for consulting."
- "What did I spend on software this quarter?"
- "Find tax deductions I might have missed."
- "Which invoices are overdue? Send reminders."
Interactive UI inside your AI assistant
Norman is more than a collection of background tools. In MCP Apps-compatible ChatGPT and Claude clients, Norman can render focused accounting workspaces directly inside the conversation. You can filter and inspect the underlying data, move between related views, and use Ask AI to continue the discussion with the current accounting context.
| Interactive workspace | Use case |
|---|---|
| Norman Inbox | Review blocked workflows and pending automation approvals. Inspect current values and the complete planned action list, then explicitly approve or dismiss. |
| Document Review | Review uploaded invoices and receipts, find documents that still need a transaction match, and inspect linked records. |
| Reconciliation Cockpit | Find transactions with missing documents, missing categories, or accounts from a previous SKR before month-end or year-end close. |
| Ledger Explorer | Browse the chart of accounts, inspect balances, and drill into the postings behind an account. |
| Tax Preview & Submission | Review the Finanzamt test PDF, tax lines, period, total, and readiness checks before filing. Submission is a separate explicit action and stays disabled until the user confirms the preview. |
Try prompts such as:
- "Open my Norman Inbox and show what needs my attention."
- "Open my Document Review for the last 60 days."
- "Show my Reconciliation Cockpit and highlight missing documents or categories."
- "Open the Ledger Explorer and show the postings for account 1200."
- "Open my VAT return for July, generate the Finanzamt test preview, and explain anything I should review before submission."
The Norman API remains the source of truth. Opening or filtering a workspace does not change accounting data. Binding actions, including tax submission, remain separate MCP tool calls with their normal confirmation and permission checks. Clients without MCP Apps support receive the same underlying results as structured or text tool output.
The SDK 2 HTTP transport limits MCP JSON request bodies to 4 MiB. Send larger
documents through file_url or the upload page's file_ref, rather than inline
base64. The separate multipart upload route keeps its own 50 MiB default,
configurable with MCP_UPLOAD_MAX_SIZE.
🏢 Starting a company
Found a German GmbH or UG (haftungsbeschränkt) end-to-end — Norman collects the data, prepares the documents, and hands off to a notary:
- "I want to start a GmbH in Berlin — walk me through it."
- "Found a UG for me and two co-founders, split the shares 60/40."
- "Is 'Wunderbar Robotics' still free in the Handelsregister?"
- "Reword my business purpose so it's ready for the register."
- "Generate the Musterprotokoll and find me a notary who does online notarization."
- "What's left before my company is officially registered?"
Choosing GmbH/UG also sets your Norman account to the corporate SKR04 chart of accounts, so bookkeeping and taxes are ready from day one. The documents are drafts to prepare the notary appointment — not legal advice.
👀 See it in action
|
Filing a VAT return |
Transaction insights |
|
Syncing Stripe payments |
Receipts from Gmail |
|
Chasing overdue invoices |
Sending payment reminders |
🚀 Get Started
Before connecting, create a free Norman account if you don't have one yet. Log in with your Norman credentials via OAuth — your password never touches the AI.
Claude Connectors- Go to Claude Connectors
- Click Add
- Find and connect: Norman Finance
MCP Apps-compatible Claude hosts can open Norman's interactive accounting workspaces directly in the conversation. Other Claude clients receive the same data as normal tool output.
Claude CodeNorman is available as a Claude Code plugin with built-in skills.
/plugin marketplace add norman-finance/norman-mcp-server
/plugin install norman-finance@norman-finance
Or install directly from GitHub:
claude /plugin install github:norman-finance/norman-mcp-server
ChatGPT Plugins
- Install it from the official ChatGPT Plugins Directory.
The plugin includes Norman's interactive accounting workspaces, including Document Review, Reconciliation, Ledger Explorer, and the explicit tax preview and submission flow.
GeminiGemini CLI extension
gemini extensions install https://github.com/norman-finance/norman-mcp-server
Start Gemini CLI and authenticate the remote server when prompted, or run:
/mcp auth norman-finance
Gemini Spark custom app
Create a Spark, add a custom app, and use
https://mcp.norman.finance/mcp as its MCP server URL. Availability depends on
your Gemini account and region. See Google's custom app
guide.
- Open Account settings → Connectors
- Click + Custom Connector and select Remote
- Enter Norman Finance and
https://mcp.norman.finance/mcp - Save the connector and complete Norman OAuth
Organization administrators can share the remote connector with their team.
GrokGrok web
- Go to Grok Connectors
- Click New Connector → Custom
- Enter
https://mcp.norman.finance/mcpand complete Norman OAuth
Grok CLI
grok mcp add --transport http norman-finance https://mcp.norman.finance/mcp
Grok CLI also discovers this repository's .mcp.json automatically.
Replit
OpenClaw
Option 1 — Remote with OAuth
Run in OpenClaw:
mcp add https://mcp.norman.finance/mcp
You'll be prompted to log in with your Norman account on first use.
Option 2 — Skills only
git clone https://github.com/norman-finance/norman-mcp-server.git
cp -r norman-mcp-server/skills/* ~/.openclaw/skills/
openclaw gateway restart
Option 3 — Local stdio
pip install norman-mcp-server
openclaw mcp add norman -- norman-mcp --transport stdio
Set your credentials as environment variables (NORMAN_EMAIL, NORMAN_PASSWORD) before starting the gateway.
- Create an MCP OAuth2 API credential
- Enable Dynamic Client Registration
- Set Server URL:
https://mcp.norman.finance/ - Click Connect my account and log in with Norman
- Add an MCP Client Tool node to your AI Agent workflow
- Set the URL to
https://mcp.norman.finance/mcpand select the credential
Add a remote HTTP MCP server with URL:
https://mcp.norman.finance/mcp
Skills
Ready-to-use skills compatible with Claude Code, OpenClaw, and the Agent Skills standard.
| Skill | What it does |
|---|---|
financial-overview |
Full dashboard — balance, transactions, invoices, and tax status |
create-invoice |
Step-by-step invoice creation and sending |
manage-clients |
List, create, and update client records |
manage-products |
List, create, update, and archive catalog products; fill invoice lines from them |
tax-report |
Review, preview, and file tax reports with the Finanzamt |
categorize-transactions |
Categorize and verify bank transactions |
find-receipts |
Find missing receipts from Gmail or email and attach them |
overdue-reminders |
Identify overdue invoices and send payment reminders |
expense-report |
Expense breakdown by category, top vendors, and trends |
tax-deduction-finder |
Scan transactions for missed deductions and suggest fixes |
monthly-reconciliation |
Full monthly close — transactions, invoices, receipts, and taxes |
run-workflow |
Start a Norman workflow, answer its questions, and schedule it to run by itself |
company-incorporation |
Found a German GmbH/UG — data, documents, name check, and notary hand-off |
Claude Code —
/plugin marketplace add norman-finance/norman-mcp-serverClaude Code (local) —
claude --plugin-dir ./norman-mcp-serverOpenClaw —
cp -r skills/* ~/.openclaw/skills/ && openclaw gateway restart
Have a feature idea? Share your suggestion →
Mixed VAT and documented input tax
See the VAT item workflow for item-level treatments, fixed documented EUR input VAT, refunds and manual VAT-only corrections. Requires the corresponding API migrations and calculation updates.
Norman Inbox and MCP Events (development)
open_norman_inbox declares global/sidebar and thread entrypoints for hosts that
support plugin extensions.
MCP Apps hosts can render the same self-contained UI; other clients can call
get_norman_inbox_data and get_norman_approval_data for structured results.
Workflow questions use actual blocking state. Pending approval totals include all
pages; tax reviews are a bounded list. Source failures are shown as unavailable.
The review card uses existing approve/dismiss/undo tools and refreshes actual
results. Approval requires a checkbox and re-reads current values and planned
actions immediately before executing. A changed review requires confirmation
again. The backend remains responsible for atomic execution and permissions.
Non-transaction approvals whose current target is unavailable can be discussed or
dismissed; they cannot be approved from this card.
The visible Inbox refreshes through get_norman_inbox_data 30 seconds after a
completed read and backs off to 60, 120 and at most 300 seconds while nothing on
screen changes; any interaction or change resets it to 30. Focus or becoming
visible refreshes only once half the current interval has passed. It pauses while
hidden/offscreen, during actions, on teardown, and after an expired session until
the user acts. It keeps the selected page and typed workflow answer (a draft is
bound to its question; if the question changes, sending needs confirmation); an
unchanged approval keeps explicit consent, while changed current values or
planned actions clear it. This uses the portable Apps tools/call bridge: iframe support for
SDK 2 resource subscriptions is not assumed.
Hosted SDK 2 clients can separately opt into resource invalidations by setting
NORMAN_MCP_INBOX_LIVE=1 on a single-process MCP deployment using the
streamable-http transport (SSE starts one lifespan per connection, so the flag is
ignored there with a warning). Credential-only stdio does not enable this feature. Existing tools and legacy refresh continue
working when the setting is absent.
- Call
watch_norman_inboxwith an approvalpage(default 1). It returns an opaqueresourceUri,expiresAt(Unix seconds), and observation interval. - Open SDK 2
subscriptions/listenfor that exact URI. After acknowledgment, callresources/readfor the current snapshot; refetch on eachnotifications/resources/updated. Events contain only the opaque URI. - Reopen the watch after expiry, reconnect, token refresh, restart, or an
attempted
switch_company. Watches last at most five minutes and never outlive their MCP bearer token. There is no replay; always refetch on reconnect.
Read and listen both check the exact OAuth grant, client and selected company. Observers resolve only that grant's current Norman token and pin its company. An expired Norman token (one hour) is refreshed through that grant; a 401 that survives the refresh, or a 403, closes the watch. Local grant revocation, company changes and expiry end its stream within one second. The observer reads only while a stream is connected, with 30 seconds between observation cycles. Each watch observes one approval page, workflow state and bounded tax reviews; it is not a complete company event log and may miss intermediate changes. Financial snapshots are never cached in the change bus. There are at most 128 leases/streams, four leases and four open streams per OAuth grant, four concurrent snapshot reads (three API sources per snapshot) and two per grant. Tokens refreshed from one authorization share its grant, so refreshing does not raise these limits.
Leases and the SDK subscription bus are in memory. Use one process/replica; multiple replicas require shared lease state, OAuth state and a distributed subscription bus before this feature can be enabled reliably. This read-only feed is separate from the durable webhook events below.
The opt-in workflow.attention_required event implements the
draft MCP Events contract
on SDK 2 / protocol 2026-07-28. It watches one explicitly selected company and
workflow through the Norman API and sends signed webhooks when the active run
becomes blocked. It does not advance workflows, send invoice reminders or file
taxes. Current delivery waits 30 seconds between source observation cycles; it does not yet
consume a backend event stream and can miss transitions between observations.
To enable events on a hosted single-worker Streamable HTTP deployment, set:
NORMAN_MCP_EVENTS_DB: an absolute SQLite path on a persistent private volume.NORMAN_MCP_EVENTS_KEY: a Fernet encryption key from your secret manager. Keep the same key across restarts; changing it makes stored subscriptions unreadable.
Start with norman-mcp --transport streamable-http --public-url https://your-host.
Both settings are required. Without them, events are not advertised. SQLite state
contains encrypted authentication references, callback URLs, signing keys and
pending payloads. Persist the existing MCP_OAUTH_STATE_FILE on a private volume
as well: delivery after restart needs valid OAuth tokens and Norman token mappings.
The worker reads each run with the subscriber's own grant and company; an
expired Norman access token (one hour) is refreshed through that grant, and a
grant that cannot be refreshed suspends delivery until the client refreshes the
subscription. Nothing falls back to other credentials. Multiple worker
processes/replicas require coordinated OAuth storage and a distributed delivery
lease before enabling events.
Subscriptions use events/list, events/subscribe and events/unsubscribe, with
arguments { "company_id": "UUID", "run_id": "UUID" } and webhook delivery
{ "mode": "webhook", "url": "https://public-callback", "secret": "whsec_…" }.
The receiver must echo the signed verification challenge. Subscription lifetime
is capped at one hour and authentication expiry; renew before refreshBefore.
Secret rotation accepts the previous signing key for five minutes. Each retry
keeps the same eventId; receivers should deduplicate by it. Permanent callback
failures stop retries until the subscription is renewed, and HTTP 410 removes
the subscription. Callback addresses are validated and DNS-pinned to public HTTPS
endpoints; redirects are not followed. Each callback, verification included, has
15 seconds in total and runs in a small dedicated pool.
Host support, plugin submission and production activation need separate verification. Local protocol and browser fixtures do not establish ChatGPT catalog availability or a successful production OAuth/webhook connection.