Public API & webhooks
AI that actually reads your books
A versioned REST API over 67 resources, signed outbound webhooks, and 153 MCP tools so Claude, ChatGPT or your own agents can work your books safely.
What it solves
Your books are the source of truth about your business, but most software keeps them locked behind an app you have to click through. Open them over a real, versioned API and signed webhooks — and over MCP, so an AI agent can answer 'who owes me the most?' or 'what's my GST this month?' from your actual data instead of a guess.
How we're different
Everything you can do in the app you can do over the API, and everything the API can read, an AI agent can read through the MCP endpoint — the same read layer, scope-enforced, powers all three. Private and ledger data is never exposed over the API, and every row is scoped by row-level security.


Inside Public API & webhooks
Public REST API v1 — 67 resources

AI over your books (MCP) — 153 tools

The tools it deliberately withholds
Public API & webhooks
The tools it deliberately withholds
The spec is checked against the code
Public API & webhooks
The spec is checked against the code
Signed outbound webhooks
Public API & webhooks
Signed outbound webhooks


Public API & webhooks
The tools it deliberately withholds
Public API & webhooks
The spec is checked against the code
Public API & webhooks
Signed outbound webhooks
More in Public API & webhooks
Secure by construction
Every row is scoped by Postgres row-level security, private and ledger data is never exposed over the API, and credentials are AES-256-GCM encrypted.
Works with the rest of Finocket
Part of Developer & AI. See how every module connects.
Questions
Can an AI assistant really read my books?
Yes — an MCP server exposes 153 scope-enforced tools over your invoices, payments, CRM, expenses, stock, assets, partners and financial reports, so you can point Claude, ChatGPT or your own agent at a company and get real answers from your data. Private and ledger data stays off-limits, and every read is scoped by row-level security.
Is there anything an AI agent deliberately can't do?
Yes, and the reasons are recorded. It cannot approve a growth campaign (that would let one model approve another model's outreach), change the AI autonomy dial (an agent could widen its own blast radius), approve a GST-notice reply (that step exists to evidence a named human read it), or reach the personal-tax screens (there is no tax scope, and attaching them to a reports scope would silently widen every existing third-party key to the owner's own income).
Is the API stable enough to build on?
It's a versioned REST v1 with an OpenAPI spec, a Scalar reference and OAuth clients, covering 67 resources — and the spec is guard-tested against the filesystem in both directions, so it can't drift from the code. It is the same data layer the app itself runs on — v1 is the contract, and a breaking change would mean v2, not a silent edit.
Ready to ditch the spreadsheet?
Free for solo users. No credit card. Your books stay yours.
