Connect an AI agent
Give Claude, Codex or any other MCP client access to your purchase orders and invoices.
What your agent can and can't do
- It acts as the person the token is bound to, with exactly that person's permissions. Change their permissions and the agent's change with them, immediately.
- It can read, create and edit POs and invoices, and approve, reject or mark paid — whatever that person could do in the web app.
- It can never reach admin functions — companies, permissions, tokens, the global audit log — and it can never delete anything. That holds even for a token bound to an administrator.
- Every action it takes is recorded and attributed, reading like “Approved by Yuriy Srybnik via MCP (Claude Desktop)” — in the audit trail, in notifications, and in the daily digest.
Step 1 —Get a token
Tokens are minted by an administrator and shown once.
Ask an administrator to mint one for you. Tell them which client it's for, so the token can be named after it — that name appears in the audit trail every time your agent does something.
They'll send you a token starting with itk_. It's shown once on their screen, so store it somewhere safe when you get it. Treat it like a password: it can approve invoices as you.
Step 2 —Point your agent at the server
Pick your client. Replace itk_YOUR_TOKEN with the token from step 1.
First, install Node.js 18 or newer (nodejs.org) if you don't have it. Claude Desktop talks to local programs, so a small bridge does the HTTP part.
Then open Settings → Developer → Edit Config. That opens claude_desktop_config.json. Paste this in, replacing the whole file if it's empty:
{
"mcpServers": {
"itracker": {
"command": "npx",
"args": [
"mcp-remote",
"https://itracker.bellridgemg.com/api/mcp",
"--transport",
"http-only",
"--header",
"Authorization:${AUTH_HEADER}"
],
"env": {
"AUTH_HEADER": "Bearer itk_YOUR_TOKEN"
}
}
}
}The token goes in the env block, and there is deliberately no space after Authorization: — on Windows, Claude Desktop mangles arguments containing spaces, so the space has to live inside the variable instead. It works the same way on a Mac, so this one snippet is fine for everyone.
Save the file, then quit Claude Desktop completely and reopen it — closing the window isn't enough. You should see itracker's tools listed under the tools icon in the message box.
Step 3 —Check it worked
Two questions that prove the connection end to end.
Ask your agent:
Who am I in Invoice Tracker, and what can I do?
It should come back with your name, your email, and your permissions. If it does, the token is valid and bound to the right person.
List the invoices waiting on my approval.
That confirms it can actually read your data, not just authenticate. From there it can create POs and invoices, add notes, ask people for information, and approve or reject — all in plain language.
Where this won't work
Use the desktop apps, not the browser.
This server authenticates with a token in a header. A few places only accept a server URL and expect the server to run an OAuth sign-in flow, which this one doesn't:
- Claude's Connectors screen — in the browser, on mobile, in Cowork, and in the desktop app. It takes a URL and optional OAuth credentials, with nowhere to put a token, and it connects from Anthropic's cloud rather than from your machine. On desktop, use the Developer config above instead; the two are separate systems.
- ChatGPT in a web browser, including developer-mode connectors. They require a full OAuth 2.1 flow with dynamic client registration and reject plain bearer tokens. The ChatGPT desktop app has no such limit — use that.
Both come down to the same thing: an agent that runs on your computer can hold your token, and one that runs in someone else's cloud can't.
Worth knowing
- Restart your client after an update to this app. MCP clients ask for the tool list once when they connect and cache it. If new tools ship, your agent won't see them until it reconnects.
- Approved and paid invoices are frozen. Neither their fields nor their document can be changed, by an agent or by a person. Notes can still be added at any status.
- Attaching a document needs an agent that can make HTTP requests. The file is uploaded straight to storage through a signed URL rather than passed through the agent's connection, so a client with no shell or fetch capability can't do it.
- Revoking is immediate. A revoked token fails on its next request. A token also stops working the moment the person it's bound to loses access to this app.