Claude and other AI apps (MCP)
GoRoute runs a remote MCP server at https://mcp.goroute.ai/mcp. Connect it to Claude, Claude Code or any other app that supports remote MCP servers with OAuth. You can then ask in plain language whether a customer is on Peppol, why an invoice was rejected or what arrived this week, and have invoices prepared, sent, resent or credited.
The connection has full access, as you. It can do what you can do in the GoRoute dashboard, in the organisation you belong to, and your role's permissions are the limit: a viewer's connection cannot send. Every tool that sends or changes something is marked as such, so Claude asks for your approval before using it unless you have chosen to always allow it.
Connectโ
Claude (web, desktop and mobile)โ
- In Claude, open Settings โ Connectors and choose Add custom connector.
- Name it GoRoute and paste
https://mcp.goroute.ai/mcpas the URL. - Press Connect. The GoRoute sign-in opens; sign in with your normal GoRoute login.
- On the consent screen, check the account and organisation shown, then press Allow.
On a Team or Enterprise plan, an owner may need to add the connector for the organisation first.
Claude Codeโ
claude mcp add --transport http goroute https://mcp.goroute.ai/mcp
Then run /mcp inside Claude Code and choose goroute to sign in. The browser sign-in and consent are the same as above.
Other MCP clientsโ
Any client that supports streamable HTTP and OAuth 2.1 works: it discovers the sign-in from the server on its own. Clients that need to be told can use:
| MCP endpoint | https://mcp.goroute.ai/mcp |
| Authorization server metadata | https://mcp.goroute.ai/.well-known/oauth-authorization-server |
| Protected resource metadata | https://mcp.goroute.ai/.well-known/oauth-protected-resource |
| Client registration | Dynamic registration or a client ID metadata document; PKCE (S256) is required |
What the connection can reachโ
Everything in the GoRoute API that your role allows, with these exceptions, which stay in the dashboard:
- API keys, sign-in sessions and store connection codes: credentials that would outlive the connection
- Other connected AI apps
- Payments and plan checkout
- Clearing all transactions at once
- Platform administration, which is for GoRoute's own staff rather than for your organisation
- The public endpoints that need no sign-in at all, such as receipt verification: the connection is signed in, so it uses the ordinary ones
Ask for one of these and the connector refuses with a message telling you to use the GoRoute dashboard instead.
Toolsโ
Thirty-four tools, read from the connector's own source on 24 September 2026. The newest is issue_einvoice_for_agent_order, for orders an AI agent placed for a business buyer โ see Agentic-commerce orders below.
Check what your own connection offers before you build on a tool. Ask your client to list GoRoute's tools โ in Claude Code, /mcp and then goroute; in Claude, the connector's entry under Settings โ Connectors. A tool listed here but missing there means the connector your account reaches does not have it yet: tell us, and do not work around it.
Look up and check
| Tool | What it does |
|---|---|
lookup_participant | Whether a company is on the Peppol network and which documents it can receive |
search_saved_parties | Search your saved customers and suppliers |
get_my_organization | Your organisation's own details: its profile, its seller party ready to use as the seller of an invoice, and its own Peppol participants |
validate_invoice | Validate an invoice in GoRoute's JSON format against its country's official rules |
validate_document | Validate a finished UBL XML document of any supported type |
get_invoice_format | The JSON schema of GoRoute's invoice format |
list_document_types | The business document types GoRoute validates and carries |
get_my_organization gathers its answer from three places. If the seller party or the participant list cannot be read, that part comes back empty and the rest still arrives, so do not assume all three are always there.
Sent and received
| Tool | What it does |
|---|---|
list_transactions, get_transaction | Your sent and received documents, delivery status and errors |
get_transaction_stats | Counts of sent and received documents by status for a date range. Reporting legs โ the extra copies sent to a tax authority โ are left out, so the counts match the documents you recognise |
get_invoice_pdf | A download link for the PDF of a sent or received document, in English or Arabic |
get_document_xml | The e-invoice XML of a document |
list_received_documents, get_received_document | Invoices and credit notes you received |
Send and change (marked as changing data)
| Tool | What it does |
|---|---|
send_invoice | Validate and send an invoice or credit note |
send_document | Send a finished UBL document to a participant |
send_credit_note_for_invoice | Credit an earlier invoice in full or in part |
issue_einvoice_for_agent_order | For an order an AI agent placed over UCP or ACP for a business: issue the e-invoice the merchant owes and return the ai.goroute.einvoice einvoice object |
create_draft_invoice, update_draft_invoice, send_draft, delete_draft, list_drafts | Work with drafts |
resend_transaction, email_document | Resend a failed document, or email it to the buyer |
list_participants, register_participant | Your own Peppol participants |
save_party | Save a customer or supplier |
Everything else
| Tool | What it does |
|---|---|
find_api_operations, describe_api_operation | Find any API operation (reports, VAT, webhooks, team, templates, bulk imports, Oman reporting and more) and its inputs |
api_read | Call any read operation |
api_create, api_update, api_delete | Call any create or send, update, or delete operation |
Agentic-commerce ordersโ
issue_einvoice_for_agent_order is the agent side of the ai.goroute.einvoice extension. Give it the order's reference, the buyer_business object the agent holds (legal_name, tax_id, scheme, peppol_id, order_reference, delivery), the order's lines in GoRoute's line format and its currency. The signed-in organisation is the seller; the invoice number defaults to INV-<order reference> and the issue date to today. It goes through the same send path as send_invoice and answers with the extension's einvoice object โ status, document_type, number, delivered_via, pdf_url, xml_url, network_message_id โ the two links lasting fifteen minutes like every other file link here. delivery: none issues and stores the document without sending it, which is what the law asks even when the buyer wants nothing.
PDF linksโ
get_invoice_pdf does not hand back the file itself; a tool result cannot carry one. It hands back a link on https://mcp.goroute.ai/files/pdf, and get_transaction returns the same link alongside the document it describes. The XML of a document issued for an agentic-commerce order comes the same way, on https://mcp.goroute.ai/files/xml.
Three things are worth knowing about that link:
- It lasts fifteen minutes. After that it answers with a message asking you to request the document again. Ask again and you get a fresh one.
- The link on its own opens the file. There is no second sign-in. Anyone holding it can read that invoice until it expires, so treat it as you would the invoice itself โ a shared channel keeps it long after the fifteen minutes have made it useless.
- Disconnecting stops it at once. The file is fetched as the person whose connection asked for it, so ending the connection ends its links, expired or not.
When an answer is too bigโ
A tool result larger than 100,000 characters comes back cut short, marked truncated, with a note saying so. Ask for a narrower date range, a filter or one page at a time and the whole answer fits. A year of transactions in one question will meet this; a month at a time will not.
Things to askโ
- Is 0192:910000047 on Peppol, and can it receive EHF invoices?
- Why did my last three invoices to Belgium fail?
- What did Fjord Supplies send us this month, and does anything need attention?
- Validate this XML and explain each error in plain English.
- Prepare a draft invoice to our saved customer Nordlys AS for 12 hours of consulting at 950 NOK.
- Resend every invoice that failed yesterday.
- Show last quarter's VAT report as a table.
Disconnectโ
In the GoRoute dashboard, open Settings โ Connected AI apps and press Disconnect next to the app. The connection stops working at once. Removing the connector inside Claude also ends it on Claude's side.
A connection also ends when your GoRoute sign-in is disabled, or when anything tries to reuse a spent sign-in code or refresh token.
Disconnect from the APIโ
If you want to automate this โ someone leaves, a laptop is lost โ two API calls do the same job as the dashboard.
| Call | What it does |
|---|---|
GET /api/v1/connected-apps | Lists the AI apps you have connected and not disconnected |
DELETE /api/v1/connected-apps/{connection_id} | Ends one connection |
The list returns, for each connection: its id (id), the name the app gave when it connected (app), the permissions you granted (permissions), when it was connected (connected_at) and when it was last used (last_used_at). Use the id as the connection_id in the second call.
Disconnecting takes effect immediately: the connection's tokens stop working and the app has to go through sign-in and consent again to come back. An id that is not one of your connections answers 404 with not_found โ including one you have already disconnected.
They need a signed-in person, not an API key, because a connection belongs to you rather than to your organisation โ you can only see and end your own. Send an API key and you get 401 with the message "A signed-in session is required for this action.", exactly as you would with no credential at all. Call them from a signed-in browser session, the same session the dashboard uses.
This also means there is no API way to end a colleague's connection. Disabling their GoRoute sign-in ends their connections, which is the route to take when someone leaves.
Data and privacyโ
- What the AI app receives: the connector sends it only the results of the tools it calls, and those results reach the AI provider.
- What GoRoute keeps: the name of the app you connected, the permissions you granted, when it was last used, and your sign-in tokens, encrypted.
- Revocation: disconnecting deletes nothing in your account, and GoRoute never stores the conversation.
See the privacy policy.