Skip to main content

Claude and other AI apps (MCP)

GoRoute runs a remote MCP server at https://mcp.goroute.ai/mcp. Connect it to Claude, Claude Code or any other app that supports remote MCP servers with OAuth. You can then ask in plain language whether a customer is on Peppol, why an invoice was rejected or what arrived this week, and have invoices prepared, sent, resent or credited.

The connection has full access, as you. It can do what you can do in the GoRoute dashboard, in the organisation you belong to, and your role's permissions are the limit: a viewer's connection cannot send. Every tool that sends or changes something is marked as such, so Claude asks for your approval before using it unless you have chosen to always allow it.

Connectโ€‹

Claude (web, desktop and mobile)โ€‹

  1. In Claude, open Settings โ†’ Connectors and choose Add custom connector.
  2. Name it GoRoute and paste https://mcp.goroute.ai/mcp as the URL.
  3. Press Connect. The GoRoute sign-in opens; sign in with your normal GoRoute login.
  4. On the consent screen, check the account and organisation shown, then press Allow.

On a Team or Enterprise plan, an owner may need to add the connector for the organisation first.

Claude Codeโ€‹

claude mcp add --transport http goroute https://mcp.goroute.ai/mcp

Then run /mcp inside Claude Code and choose goroute to sign in. The browser sign-in and consent are the same as above.

Other MCP clientsโ€‹

Any client that supports streamable HTTP and OAuth 2.1 works: it discovers the sign-in from the server on its own. Clients that need to be told can use:

MCP endpointhttps://mcp.goroute.ai/mcp
Authorization server metadatahttps://mcp.goroute.ai/.well-known/oauth-authorization-server
Protected resource metadatahttps://mcp.goroute.ai/.well-known/oauth-protected-resource
Client registrationDynamic registration or a client ID metadata document; PKCE (S256) is required

What the connection can reachโ€‹

Everything in the GoRoute API that your role allows, with these exceptions, which stay in the dashboard:

  • API keys, sign-in sessions and store connection codes: credentials that would outlive the connection
  • Other connected AI apps
  • Payments and plan checkout
  • Clearing all transactions at once
  • Platform administration, which is for GoRoute's own staff rather than for your organisation
  • The public endpoints that need no sign-in at all, such as receipt verification: the connection is signed in, so it uses the ordinary ones

Ask for one of these and the connector refuses with a message telling you to use the GoRoute dashboard instead.

Toolsโ€‹

Thirty-four tools, read from the connector's own source on 24 September 2026. The newest is issue_einvoice_for_agent_order, for orders an AI agent placed for a business buyer โ€” see Agentic-commerce orders below.

Check what your own connection offers before you build on a tool. Ask your client to list GoRoute's tools โ€” in Claude Code, /mcp and then goroute; in Claude, the connector's entry under Settings โ†’ Connectors. A tool listed here but missing there means the connector your account reaches does not have it yet: tell us, and do not work around it.

Look up and check

ToolWhat it does
lookup_participantWhether a company is on the Peppol network and which documents it can receive
search_saved_partiesSearch your saved customers and suppliers
get_my_organizationYour organisation's own details: its profile, its seller party ready to use as the seller of an invoice, and its own Peppol participants
validate_invoiceValidate an invoice in GoRoute's JSON format against its country's official rules
validate_documentValidate a finished UBL XML document of any supported type
get_invoice_formatThe JSON schema of GoRoute's invoice format
list_document_typesThe business document types GoRoute validates and carries

get_my_organization gathers its answer from three places. If the seller party or the participant list cannot be read, that part comes back empty and the rest still arrives, so do not assume all three are always there.

Sent and received

ToolWhat it does
list_transactions, get_transactionYour sent and received documents, delivery status and errors
get_transaction_statsCounts of sent and received documents by status for a date range. Reporting legs โ€” the extra copies sent to a tax authority โ€” are left out, so the counts match the documents you recognise
get_invoice_pdfA download link for the PDF of a sent or received document, in English or Arabic
get_document_xmlThe e-invoice XML of a document
list_received_documents, get_received_documentInvoices and credit notes you received

Send and change (marked as changing data)

ToolWhat it does
send_invoiceValidate and send an invoice or credit note
send_documentSend a finished UBL document to a participant
send_credit_note_for_invoiceCredit an earlier invoice in full or in part
issue_einvoice_for_agent_orderFor an order an AI agent placed over UCP or ACP for a business: issue the e-invoice the merchant owes and return the ai.goroute.einvoice einvoice object
create_draft_invoice, update_draft_invoice, send_draft, delete_draft, list_draftsWork with drafts
resend_transaction, email_documentResend a failed document, or email it to the buyer
list_participants, register_participantYour own Peppol participants
save_partySave a customer or supplier

Everything else

ToolWhat it does
find_api_operations, describe_api_operationFind any API operation (reports, VAT, webhooks, team, templates, bulk imports, Oman reporting and more) and its inputs
api_readCall any read operation
api_create, api_update, api_deleteCall any create or send, update, or delete operation

Agentic-commerce ordersโ€‹

issue_einvoice_for_agent_order is the agent side of the ai.goroute.einvoice extension. Give it the order's reference, the buyer_business object the agent holds (legal_name, tax_id, scheme, peppol_id, order_reference, delivery), the order's lines in GoRoute's line format and its currency. The signed-in organisation is the seller; the invoice number defaults to INV-<order reference> and the issue date to today. It goes through the same send path as send_invoice and answers with the extension's einvoice object โ€” status, document_type, number, delivered_via, pdf_url, xml_url, network_message_id โ€” the two links lasting fifteen minutes like every other file link here. delivery: none issues and stores the document without sending it, which is what the law asks even when the buyer wants nothing.

get_invoice_pdf does not hand back the file itself; a tool result cannot carry one. It hands back a link on https://mcp.goroute.ai/files/pdf, and get_transaction returns the same link alongside the document it describes. The XML of a document issued for an agentic-commerce order comes the same way, on https://mcp.goroute.ai/files/xml.

Three things are worth knowing about that link:

  • It lasts fifteen minutes. After that it answers with a message asking you to request the document again. Ask again and you get a fresh one.
  • The link on its own opens the file. There is no second sign-in. Anyone holding it can read that invoice until it expires, so treat it as you would the invoice itself โ€” a shared channel keeps it long after the fifteen minutes have made it useless.
  • Disconnecting stops it at once. The file is fetched as the person whose connection asked for it, so ending the connection ends its links, expired or not.

When an answer is too bigโ€‹

A tool result larger than 100,000 characters comes back cut short, marked truncated, with a note saying so. Ask for a narrower date range, a filter or one page at a time and the whole answer fits. A year of transactions in one question will meet this; a month at a time will not.

Things to askโ€‹

  • Is 0192:910000047 on Peppol, and can it receive EHF invoices?
  • Why did my last three invoices to Belgium fail?
  • What did Fjord Supplies send us this month, and does anything need attention?
  • Validate this XML and explain each error in plain English.
  • Prepare a draft invoice to our saved customer Nordlys AS for 12 hours of consulting at 950 NOK.
  • Resend every invoice that failed yesterday.
  • Show last quarter's VAT report as a table.

Disconnectโ€‹

In the GoRoute dashboard, open Settings โ†’ Connected AI apps and press Disconnect next to the app. The connection stops working at once. Removing the connector inside Claude also ends it on Claude's side.

A connection also ends when your GoRoute sign-in is disabled, or when anything tries to reuse a spent sign-in code or refresh token.

Disconnect from the APIโ€‹

If you want to automate this โ€” someone leaves, a laptop is lost โ€” two API calls do the same job as the dashboard.

CallWhat it does
GET /api/v1/connected-appsLists the AI apps you have connected and not disconnected
DELETE /api/v1/connected-apps/{connection_id}Ends one connection

The list returns, for each connection: its id (id), the name the app gave when it connected (app), the permissions you granted (permissions), when it was connected (connected_at) and when it was last used (last_used_at). Use the id as the connection_id in the second call.

Disconnecting takes effect immediately: the connection's tokens stop working and the app has to go through sign-in and consent again to come back. An id that is not one of your connections answers 404 with not_found โ€” including one you have already disconnected.

These two calls will not accept an API key

They need a signed-in person, not an API key, because a connection belongs to you rather than to your organisation โ€” you can only see and end your own. Send an API key and you get 401 with the message "A signed-in session is required for this action.", exactly as you would with no credential at all. Call them from a signed-in browser session, the same session the dashboard uses.

This also means there is no API way to end a colleague's connection. Disabling their GoRoute sign-in ends their connections, which is the route to take when someone leaves.

Data and privacyโ€‹

  • What the AI app receives: the connector sends it only the results of the tools it calls, and those results reach the AI provider.
  • What GoRoute keeps: the name of the app you connected, the permissions you granted, when it was last used, and your sign-in tokens, encrypted.
  • Revocation: disconnecting deletes nothing in your account, and GoRoute never stores the conversation.

See the privacy policy.