Skip to content
📢 Kafinea is a compatible solution for electronic invoicing! Learn more ➔
kafinea logo svg

Kafinea

  • Features
        • Finance
          • Accounting
          • Audits & KPIs
          • Invoicing
          • Purchases
        • Management
          • Documents
          • Inventory Management
          • Maintenance
          • Project Management
        • HR
          • Absence Management
          • Employees
          • Recruitment
          • Timesheets
        • Customer Service
          • Interventions
          • Service Contracts
          • Tickets
          • Warranty Tracking
        • Sales
          • CRM
          • Points of Sale
          • Sales Automation
          • Subscriptions
        • Cross-Features
          • API
          • Extranet
          • Electronic Signature
          • Workflows
  • Pricing
  • Login
  • Discover the demo
📢 Kafinea is electronic invoicing compatible! ➔
kafinea logo svg
Kafinea

Marketing

1
  • Leads

Sales

14
  • Customer purchase orders
  • Customer accounts
  • Customer Quotes
  • Customer credit notes
  • Company Search (Sirene)
  • Margins in quotes
  • Invoicing
    • Classic Invoicing
    • Progress Invoicing
    • Issue an electronic invoice
    • Recurring invoicing
    • Invoicing Article Consumption
  • Payments
    • Customer payments
    • Linking a payment to one or more invoices
  • Price list
    • Price list administrator guide

Purchases

5
  • Supplier invoices
  • Supplier Purchase Orders
  • Suppliers
  • Supplier Credits
  • Receiving an Electronic Invoice

Catalog

8
  • Units of measure
  • Products
  • Services
  • Sourcing Management
  • The Purchase Order Assistant
  • Generic products
  • Product kits
  • Catalog margin analysis

Finance

11
  • Bank Accounts
  • Manual entries
  • SEPA Mandates
  • Third-party bank accounts
  • Bank Transactions
  • Accounting
    • Accounting entries
    • Tools for Checking Your Accounting
    • Accounting
    • Financial statements
  • Fiscal years
    • Cash accounting
    • Fiscal years

Human Resources

5
  • Timesheets
  • Activities
  • Pay Slips
  • Employee Extranet
    • Leave Management
    • The employee portal card

Project management

2
  • Secure assignments using a people list
  • The responder area: view and accept my assignments

Customer Support

1
  • The Client Portal

Inventory management

4
  • Goods receipt notes
  • Delivery Notes
  • Stock movements
  • Inventory Valuation

Cash register

1
  • Cash Registers

Document management

3
  • Electronic signature
  • Templates
    • Email templates
    • Document templates

Automation

2
  • Forms
  • Workflows

Artificial intelligence

5
  • AI-assisted invoice OCR
  • Connect an External AI (MCP)
  • AI Chat
  • The AI Text Assistant
  • AI Workflows

Kafinea interface

8
  • Data Import/Export
  • Navigation
  • Lists
  • Records
  • The Layout Manager
  • Automatic saving
  • Document Lines
  • Links Between Elements

Settings

10
  • SMTP Settings
  • Access Rights
  • Numbering formats
  • Global search
  • User preferences
  • Permanent locking
  • Catalog popup filtering
  • Tax Configuration
  • The MCP Server
  • AI agents

Business Guides

2
  • Enable employees to complete their HR record independently
  • Mobilizing thousands of field workers at scale

API

7
  • REST API – Introduction
  • REST API – Entity Relationships
  • REST API – File Management
  • REST API – Requests and Querying
  • REST API – Drop-down lists (Picklist)
  • REST API – CRUD Operations
  • REST API – Authentication
  • Kafinea
  • Documentation
  • Settings
  • The MCP Server
View Categories

The MCP Server

3 minutes


Introduction #

The MCP server (Model Context Protocol) from Kafinea allows external AI clients (Claude Desktop, Cursor, Windsurf, VS Code, JetBrains…) to connect to the ERP instance to query data via a standardized protocol.

This page describes the technical architecture, security, and configuration of the MCP server for administrators.


1. Architecture #

The Kafinea MCP server is composed of several components:

Component Role
HTTP Entry Point Reception of MCP requests (Streamable HTTP protocol)
Tools Functions exposed to AI clients (search, read, navigation)
Resources Context data accessible by the AI client
Authentication Validation of user credentials for each request
Security Application of access rights and security controls
Configuration Server activation and limitation parameters

2. Authentication #

Authentication is performed via the HTTP header X-Kafinea-Credentials in the format:

X-Kafinea-Credentials: username:accesskey
  • The username is the Kafinea user name
  • The accesskey is the user’s access key (visible in My Preferences)

The server validates the credentials and establishes the user context for the request.


3. Security #

Access Rights #

Each MCP request is executed in the context of the authenticated user. Access rights to modules, records, and fields are respected.

Additional Security Controls #

In addition to user access rights, the MCP server applies additional controls:

  • Validation of input parameters
  • Filtering of sensitive modules and fields
  • Protection against injections

Recommendations #

  • Deploy the MCP server only over HTTPS connections
  • Never publish credentials in a public repository
  • Monitor access logs to detect abnormal usage
  • Use dedicated access keys for MCP integrations if possible

4. Exposed Tools #

The tools exposed by the MCP server allow AI clients to:

  • Search for records in Kafinea modules
  • Read the details of a specific record
  • Navigate relationships between records
  • List available modules and fields

Each tool respects the access rights of the connected user.


5. Exposed Resources #

Resources expose context data that the AI client can consult:

  • Information about the Kafinea instance
  • Structure of available modules
  • Field metadata

6. Configuration #

The MCP server configuration is managed by the server administrator. Parameters include:

  • Server activation/deactivation
  • List of exposed modules
  • Request limits

Note: Contact your server administrator if you wish to modify the list of exposed modules or request limits.


7. Activation #

The MCP server is activated via Kafinea feature flags. To activate it:

  1. Verify that the MCP feature flag is enabled in the configuration
  2. Ensure that the endpoint mcp/index.php is accessible from outside (or from the user network)
  3. Inform users that they can retrieve their configuration from My Preferences > MCP Configuration

8. Diagnostics #

In case of connection issues:

  1. Verify that the MCP endpoint is accessible from the user’s workstation
  2. Verify user credentials (valid username + accesskey)
  3. Verify that the MCP feature flag is properly enabled
  4. Consult the AI Agents Explorer to identify any errors

FAQ #

Is the MCP server compatible with all AI clients?
The server implements the standard MCP protocol (Streamable HTTP). Any MCP-compatible client can connect to it.

Can I limit the modules accessible via MCP?
Yes, via user profile access rights in Kafinea. The server administrator can also restrict the list of exposed modules at the server configuration level.

Are MCP requests logged?
Yes, MCP activity can be viewed from the AI Agents Explorer in Kafinea.


Related References #

  • Connect an External AI (MCP)
  • AI Agents
Index
  • Introduction
  • 1. Architecture
  • 2. Authentication
  • 3. Security
    • Access Rights
    • Additional Security Controls
    • Recommendations
  • 4. Exposed Tools
  • 5. Exposed Resources
  • 6. Configuration
  • 7. Activation
  • 8. Diagnostics
  • FAQ
  • Related References

An all-in-one software designed for SMEs. Take advantage of the automation capabilities and flexibility of our business management platform to make work easier for all your employees.

RESOURCES

Blog
Brand Guidelines
Distributors
Help
Security

Customer portal
ABOUT

About Us
Contact Us
Cookie Policy
FAQ
Legal Notice
Privacy Policy
Terms of Service

Electronic invoicing compatible solution
French Tech Grand Paris Logo
FINANCE

Accounting
Audits & KPIs
Invoicing
Purchases

MANAGEMENT

Documents
Inventory Management
Maintenance
Project Management

HR

Absence Management
Employees
Recruitment
Timesheets

CUSTOMER SERVICE

Interventions
Service Contracts
Tickets
Warranty Tracking

SALES

CRM
Points of Sale
Sales Automation
Subscriptions

© 2026 Madiasoft - Kafinea

24 rue Louis Blanc, 75010 PARIS, France

+33 1 70 06 05 41

Facebook Linkedin
kafinea logo svg
Gérer le consentement aux cookies
Pour offrir les meilleures expériences, nous utilisons des cookies pour stocker et/ou accéder aux informations des appareils. Le fait de consentir à ces cookies nous permettra de traiter des données telles que le comportement de navigation ou les ID uniques sur ce site. Le fait de ne pas consentir ou de retirer son consentement peut avoir un effet négatif sur certaines caractéristiques et fonctions.
Fonctionnel Always active
Le stockage ou l’accès technique est strictement nécessaire dans la finalité d’intérêt légitime de permettre l’utilisation d’un service spécifique explicitement demandé par l’abonné ou l’internaute, ou dans le seul but d’effectuer la transmission d’une communication sur un réseau de communications électroniques.
Préférences
Le stockage ou l’accès technique est nécessaire dans la finalité d’intérêt légitime de stocker des préférences qui ne sont pas demandées par l’abonné ou la personne utilisant le service.
Statistiques
Le stockage ou l’accès technique qui est utilisé exclusivement à des fins statistiques. Le stockage ou l’accès technique qui est utilisé exclusivement dans des finalités statistiques anonymes. En l’absence d’une assignation à comparaître, d’une conformité volontaire de la part de votre fournisseur d’accès à internet ou d’enregistrements supplémentaires provenant d’une tierce partie, les informations stockées ou extraites à cette seule fin ne peuvent généralement pas être utilisées pour vous identifier.
Marketing
Le stockage ou l’accès technique est nécessaire pour créer des profils d’internautes afin d’envoyer des publicités, ou pour suivre l’internaute sur un site web ou sur plusieurs sites web ayant des finalités marketing similaires.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Voir les préférences
  • {title}
  • {title}
  • {title}
  • Features
    • Finance
      • Accounting
      • Audits & KPIs
      • Invoicing
      • Purchases
    • Management
      • Documents
      • Interventions
      • Inventory Management
      • Project Management
    • HR
      • Absence Management
      • Employees
      • Recruitment
      • Timesheets
    • Customer Service
      • Maintenance
      • Service Contracts
      • Tickets
      • Warranty Tracking
    • Sales
      • CRM
      • Points of Sale
      • Sales Automation
      • Subscriptions
    • Cross-Features
      • API
      • Electronic Signature
      • Extranet
      • Workflows
  • Pricing
  • Login
  • Discover the demo