mcp-malt
Provides access to the Malt API for managing invoices issued to clients, Malt commission fee invoices, received payments, and SCIM user provisioning for Malt organization accounts.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-maltReconcile my Malt revenue for Q1 2026"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-malt
An MCP server for the Malt API. It covers all 13 operations Malt publishes: the invoices you issue, the commission Malt bills you, the payments you receive, and SCIM user provisioning for organization accounts.
What this does and does not cover
Malt's API is smaller than most people expect. It covers back office billing and enterprise user provisioning, and nothing else:
Toolset | Tools | What it reaches |
| 3 | Invoices you issued to clients, including the PDF |
| 1 | Payments received, with the invoices each one settles |
| 3 | Malt's commission invoices to you, including the PDF |
| 2 read, 4 write | SCIM 2.0 user provisioning for an organization account |
There is no talent search, no profiles, no missions, no offers, and no messaging. Those are what Malt is known for, and none of them are in the public API. If that is what you came for, this server cannot give it to you, and neither can anything else built on the documented API.
Two community MCP servers for Malt do reach that data, by driving the web app with browser automation and scraping the DOM. Their own documentation warns that automating profile edits may breach Malt's terms of service. This server only calls the documented API.
Related MCP server: fintaro-mcp
Getting a token
Create an identity on the signup page if you do not have one.
Create an access token with the permission scopes you need. Match them to the toolsets you plan to enable.
Copy the token straight away. It is shown once, at creation, and never again.
Freelancer account tokens are self served. Client team and organization tokens, which the scim toolset needs, come through your Malt representative.
There is no OAuth 2.0 here. Malt publishes no authorization server and no token endpoint, so the API token above is the only way in. docs/authentication.md explains this in more detail, including the header detail that trips most people up.
Install
Published three ways from one release: the npm package on npmjs and on GitHub Packages, and the container image on GHCR. npx is the usual choice for an MCP client; Docker suits a locked-down or shared setup.
To install from GitHub Packages instead of npmjs, point the scope at it: @ialejandro:registry=https://npm.pkg.github.com in your .npmrc.
npx
// Claude Desktop: claude_desktop_config.json
// Cursor: .cursor/mcp.json
{
"mcpServers": {
"malt": {
"command": "npx",
"args": ["-y", "@ialejandro/mcp-malt"],
"env": {
"MALT_API_TOKEN": "your-token-here",
"MALT_TOOLSETS": "invoices,payments,fee-invoices"
}
}
}
}Claude Code
claude mcp add malt \
--env MALT_API_TOKEN=your-token-here \
--env MALT_TOOLSETS=invoices,payments,fee-invoices \
-- npx -y @ialejandro/mcp-maltDocker
The server speaks JSON-RPC over stdin and stdout, so -i is required and -t must be left off.
docker run -i --rm \
-e MALT_API_TOKEN=your-token-here \
-e MALT_TOOLSETS=invoices \
ghcr.io/ialejandro/mcp-malt// Claude Desktop: claude_desktop_config.json
// Cursor: .cursor/mcp.json
{
"mcpServers": {
"malt": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MALT_API_TOKEN",
"-e", "MALT_TOOLSETS",
"ghcr.io/ialejandro/mcp-malt"
],
"env": {
"MALT_API_TOKEN": "your-token-here",
"MALT_TOOLSETS": "invoices,payments,fee-invoices"
}
}
}
}From source
git clone https://github.com/ialejandro/mcp-malt
cd mcp-malt
npm ci && npm run build{
"mcpServers": {
"malt": {
"command": "node",
"args": ["/absolute/path/to/mcp-malt/dist/index.js"],
"env": {
"MALT_API_TOKEN": "your-token-here",
"MALT_TOOLSETS": "invoices,payments,fee-invoices"
}
}
}
}{
"mcpServers": {
"malt": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MALT_API_TOKEN",
"-e", "MALT_TOOLSETS",
"ghcr.io/ialejandro/mcp-malt"
],
"env": {
"MALT_API_TOKEN": "your-token-here",
"MALT_TOOLSETS": "invoices,payments,fee-invoices"
}
}
}
}Configuration
Variable | Default | What it does |
| required | Your token from My Account, API Keys |
| empty | Comma list of |
|
| Exposes the four SCIM write tools. |
|
| Caps list results, since Malt does not paginate the billing endpoints |
|
| Outbound pacing. Our number, not Malt's, which publishes none |
|
| Per request timeout |
|
| Override, mostly for testing |
|
|
|
|
|
|
With no MALT_TOOLSETS the server starts and offers nothing. That is deliberate, not a failure: you decide what a model gets to see. Add toolsets one at a time.
An unknown toolset name stops the server with an error rather than being ignored, because a typo that silently costs you three tools is miserable to debug.
Common tasks
Reconcile a quarter. Enable invoices,payments,fee-invoices and run the malt_reconcile_revenue prompt. It pulls all three lists, matches payments to the invoices they settle, and reports gross billed, tax, Malt's commission, and cash received.
Reconcile my Malt revenue for Q1 2026.
Get an invoice PDF. Malt returns PDFs base64-encoded inside a JSON body. The tools decode them and hand back a real PDF attachment.
Download the PDF for invoice INV-123456.
Offboard someone. Enable scim with MALT_ALLOW_WRITES=true and use malt_user_lifecycle. It deactivates rather than deletes, which is the path Malt actually supports.
Offboard jane.doe@acme.com from our Malt organization.
Documentation
Development
npm ci
npm run typecheck
npm test
npm run build
npm run check-spec # diff the live Malt spec against spec/malt-openapi.jsonTests mock fetch and never call the live API.
spec/malt-openapi.json is a committed snapshot of Malt's published document. A daily workflow diffs the live spec against it and opens a PR when anything moves. Malt has kept info.version at 0.0.1 throughout, so the check compares operations rather than trusting the version number.
Contributing
See CONTRIBUTING.md. Adding an endpoint or a toolset is described in docs/extending.md.
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityNot gradedmaintenanceEnables programmatic access to Meta Ads data and management features, including campaign insights, ad account details, performance metrics, and change history through the Meta Ads API.

fintaro-mcpofficial
AlicenseAqualityCmaintenanceEnables MCP-capable agents to read Fintaro invoices and transactions, and upload receipts, via a scoped API key with PII-safe projections.6Apache 2.0- FlicenseNot gradedqualityCmaintenanceProvides full access to the Make.com API, enabling creation, modification, deletion, and execution of scenarios, as well as management of connections, webhooks, data stores, and organizations.
- AlicenseAqualityCmaintenanceEnables management of endpoint inventory, patching, and vulnerabilities through the Action1 REST API, with read-only access by default and optional write support for update approvals.15Apache 2.0
Related MCP Connectors
Issue, rotate and revoke scoped API-key passes for 25+ providers — the agent never sees a real key
Agent payments, API key vaulting, and governed mandates. Agents spend within user-defined limits.
Apideck Unified API MCP — 330 tools across 200+ SaaS connectors (accounting, CRM, HRIS, ATS).
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ialejandro/mcp-malt'
If you have feedback or need assistance with the MCP directory API, please join our Discord server