API keys & MCP
Connect AI assistants and automations to PaidFast through the MCP endpoint and organization API keys.
PaidFast can be driven by AI assistants and your own scripts through a built-in MCP (Model Context Protocol) server, authenticated with organization API keys. This lets an assistant answer questions about your business and take safe actions — all scoped to your organization.
#Connect with a sign-in (no key needed)
Assistants that support OAuth, such as Claude's custom connectors, can connect by signing in instead of using a key:
- Add a custom connector in your assistant with the URL
https://paidfast.online/api/mcp. Leave any client ID and secret blank. - When the assistant asks, sign in to PaidFast. A consent screen shows which app is asking, where you'll be sent back to, and what it will be able to do.
- Untick anything you don't want to allow, then choose Allow.
Things to know:
- The consent screen names the app. An app that PaidFast could verify is shown by the website that publishes it, for example
claude.ai. An app that registered itself is marked unverified: only continue if you just started connecting it yourself. - Viewing is always included. Drafting invoices and asking to send them are ticked by default. Sending due reminders is only offered when the app asks for it, and starts unticked.
- It can't send invoices by itself. Sending still needs an owner's approval in PaidFast, exactly as with a key.
- Connections show under Settings → Integrations alongside your API keys, labelled Connected app. Revoke one there, or with Reject & revoke key on an approval request, and it stops working immediately.
- A connection stays signed in for up to 30 days of inactivity; after that, the assistant asks you to sign in again.
#API keys
An API key authenticates calls to PaidFast on behalf of your organization.
- Keys are created under Settings → Integrations (API keys).
- They begin with the prefix
pf_live_. - A key is shown once at creation — copy and store it securely; PaidFast keeps only a hashed version.
- Keys are scoped to your organization and can be revoked instantly if one is ever exposed.
Keep keys secret. Treat an API key like a password. Never paste it into a public place, and revoke and replace any key you think may have leaked.
#The MCP endpoint
Assistants connect to the PaidFast MCP server at:
https://paidfast.online/api/mcp
This is the same endpoint for every organization — it isn't tied to your account or a per-customer domain. Which organization a request acts on is determined entirely by the API key you present, so the URL doesn't change from one business to the next.
Authenticate by presenting your API key as a bearer token:
Authorization: Bearer pf_live_xxxxxxxx
The connection uses the standard MCP Streamable HTTP transport, so any MCP-compatible assistant can discover and call the available tools.
#Available tools
The MCP server exposes a focused, mostly read-only tool set, each governed by a scope:
| Tool | Scope | Purpose |
|---|---|---|
get_business_summary |
— | Snapshot of your receivables |
list_invoices / get_invoice |
invoices:read |
Read invoices |
list_customers |
customers:read |
Read customers |
list_quotations |
quotations:read |
Read quotations |
get_statement |
statements:read |
Read a customer statement |
list_items / list_units_of_measure |
items:read |
Read your price list |
list_due_reminders |
invoices:read |
See what's due to be chased |
create_draft_invoice / update_draft_invoice |
invoices:write |
Draft invoices (never auto-sent) |
duplicate_invoice_as_draft / delete_draft_invoice |
invoices:write |
Manage drafts |
request_invoice_approval |
invoices:submit |
Ask an owner to approve sending a draft |
get_approval_status / cancel_approval_request |
invoices:submit |
Follow up on, or withdraw, a request |
run_due_reminders |
reminders:run |
Trigger due reminders |
Write actions are deliberately limited to drafts and reminders. An assistant can prepare an invoice and ask for it to be sent, but only a person approves it. Tools outside a key's scopes are refused.
#Approving invoices an assistant wants to send
With the Allow requesting approval to send invoices permission, an assistant can put a draft in front of you instead of asking you to finish it in the dashboard:
- The assistant drafts the invoice, shows it to you, and calls
request_invoice_approval. - It tells you a short match code, like
K7-42. Every owner of the organization gets an email with a link, and the request also shows on the Documents page. - Open the link while signed in to PaidFast. The review page shows exactly what will go out: the customer, lines, totals, and the email address or WhatsApp number it will be sent to. Check that it shows the same match code the assistant gave you.
- Choose Approve & send. PaidFast assigns the invoice number, runs compliance where enabled, and sends it. The assistant can then confirm the invoice number with
get_approval_status.
Things to know:
- Nothing is sent until an owner approves. The API key can't approve its own requests; there is no tool for it.
- If you signed in more than 15 minutes ago, PaidFast emails you a 6-digit code to enter on the review page. Enter it only in PaidFast. PaidFast never needs a code relayed through an assistant, so an assistant that asks you for one is not working as intended.
- What you review is what gets sent. While a request is pending, the assistant can't edit that draft. If the draft or the customer's contact details change, the request is withdrawn and nothing is sent.
- Requests expire after 24 hours. Each key can have up to 10 waiting at once and make 50 a day.
- If you didn't ask for a request, choose Reject, then Reject & revoke key. The key stops working immediately and its other requests are cancelled.
#Safe by design
- Every call is scoped to your organization — an assistant can never see another business's data.
- Keys are hashed at rest and instantly revocable.
- Write operations create drafts, not sent documents, so nothing goes to a customer without your action. Sending an assistant's draft always needs an owner's approval in PaidFast.
#Getting started
- Go to Settings → Integrations and create an API key.
- Copy the
pf_live_…value somewhere safe. - Point your MCP-compatible assistant at
https://paidfast.online/api/mcpwith the key as a bearer token. - Ask it to list your invoices or draft one to confirm the connection.