Skip to content

AI assistants

AI assistants

MetroPay has a Model Context Protocol server. Connect Claude, ChatGPT, Cursor or Claude Code to one workspace and it works there as you — reading, drafting or, if you allow it, sending and recording — under your own role, with every action recorded in your name.

You decide how much

Three levels, chosen when you connect

The consent screen asks which workspace and how much. Owners can cap what any member may grant, and can end any connection.

  • Read only

    See customers, invoices, payments, items, estimates, the dashboard figures, receivables aging and customer statements — and fetch an invoice PDF.

    Cannot: Create, change or send anything.

  • Read and draft

    Also create and edit customers and items, and create, edit or duplicate DRAFT invoices — under the same rules and the same Free-plan limit as the forms.

    Cannot: Email anyone, record money, or touch a sent invoice.

  • Full access

    Also email an invoice to the customer, record a payment, create a payment link, void or write off an invoice, convert an accepted estimate, and archive customers or items — each only as far as your own role allows, and each irreversible.

    Cannot: Delete anything, change settings or members, or email anyone but the customer's own addresses.

Connecting

One address, your ordinary sign-in

Every assistant uses the same address, shown on Settings → AI assistants once an owner turns the module on. There is no key to copy; the assistant sends you to MetroPay to sign in and choose.

  • Claude (web, desktop, mobile)

    1. Settings → Connectors → Add custom connector.
    2. Paste the workspace's MCP address.
    3. Sign in to MetroPay when the browser opens; choose the workspace and a level; Allow.
  • ChatGPT

    1. Settings → Connectors: create a connector with the address and OAuth.
    2. Sign in to MetroPay; choose the workspace and a level; Allow.
    3. Turn the connector on in a chat.
  • Claude Code

    1. Run `claude mcp add --transport http metropay <address>` once.
    2. Type /mcp, pick metropay, follow the sign-in link.
    3. Choose the workspace and a level; Allow.
  • Cursor

    1. Settings → MCP → add an HTTP server with the address.
    2. Sign in to MetroPay when asked; choose the workspace and a level; Allow.

What leaves MetroPay

Only what you ask the assistant to read, to the company that runs it

  • The assistant reads what you ask it to read — a customer, an invoice, the dashboard figures — and that content goes to the company that runs the assistant, under its terms, at your direction. That company is not a MetroPay sub-processor: we do not choose it and cannot delete what it keeps.
  • Every call is recorded in your workspace's activity, in your name: which tool, on which record by its number, and whether MetroPay refused. The contents an assistant passed to us are never recorded.
  • Sending an invoice through an assistant reaches only the customer's own email address or a contact person's, uses your workspace's own email template, is refused within ten minutes of the last send unless the assistant insists, and counts against a daily limit owners set per assistant.
  • Nothing here is a REST API or a webhook: the server speaks the Model Context Protocol, behind OAuth 2.1, and only to a signed-in member of a workspace that has turned the module on.

Ending it

Revoke in one click, from Settings → AI assistants

Revoking signs the assistant out at its next request. You may revoke your own connections; owners and admins may revoke anyone's. Turning the module off for the workspace revokes them all. A connection unused for fifteen days expires on its own.

Next best action

Want to try it?

An owner turns AI assistants on under Settings → Modules, sets the three limits, and the address appears under Settings → AI assistants for every member. If your assistant is not on the list above, tell us which one.