Pacioli — the ERPNext broker you can hand the books runs on your own machine — the client starts it, so there is no endpoint to ping. 580 installs a week from pypi. Last commit 2 Sep 2026.
Governed agent access to ERPNext — MCP + A2A doors, one spine. No debit without a credit.
We read the source, 10 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
token = _resolve_transport_token(auth, env if env is not None else dict(os.environ))
Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.
s.verb_read = 1; s.verb_create = 1; s.verb_write = 0; s.verb_delete = 0
for m in methods: s.append("methods", {"pattern": m})
for d in doctypes + graph: s.append("resource_doctypes", {"ref_doctype": d})
USER root # This entrypoint script link build assets of the image to the mounted sites volume at container initialization
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add pacioli -- uvx pacioli
{
"mcpServers": {
"pacioli": {
"args": [
"pacioli"
],
"command": "uvx"
}
}
}
[mcp_servers.pacioli]
command = "uvx"
args = ["pacioli"]
{
"mcpServers": {
"pacioli": {
"args": [
"pacioli"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"pacioli": {
"args": [
"pacioli"
],
"command": "uvx"
}
}
}
Prove your books balance: every debit and credit for a month, to the minor unit.
AI agent access to your Searcher OS deal feed, pipeline, buy boxes, CIM analysis, and broker CRM.
Credential broker that signs your AI agent up to SaaS dev tools, within a signed spending mandate.
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
SSH & Kubernetes access broker for AI agents; the model never touches a credential.
Give AI agents secure access to ZERNO project briefs, tasks, and context over remote MCP.
Standards-based A2A hub. One MCP connection to thousands of agents, with shared persistent memory.
Credential broker for AI agents: scoped, revocable API access with policy enforcement and audit.
Answers built from our own checks of this server.