Sovereign e-invoice tools for AI agents

A local, offline toolbox that lets Claude Desktop, Claude Code and any MCP client read, check, explain, create and convert German/EU e-invoices (XRechnung, ZUGFeRD/Factur-X, EN 16931) with the official KoSIT rulebooks. No cloud, no API keys, no network calls, no Java.

  • 89/89parity with the KoSIT validator
  • 0network calls, proven by test
  • 8MCP tools · 4 resources · 3 prompts
  • 357tests · Ubuntu, macOS, Windows
RECHNUNG
Nr. RE-2026-0417 · 26.08.2026
XRechnung 3.0 · UBL 2.1
VerkäuferMuster GmbH
Bremen
KäuferFreie Hansestadt Bremen
Senator für Finanzen
Käuferreferenz (BT-10)BR-DE-15— fehlt —
Fälligkeit25.09.2026
Pos.BeschreibungMengeNetto
1Beratung E-Rechnung8 h1.200,00
2Validator-Integration12.400,00
Gesamt inkl. 19 % USt.4.284,00
Zahlungsbedingungen (BT-20)BR-DE-18Zahlbar innerhalb 30 Tagen, 2 % Skonto bei 10 Tagen
UNGÜLTIG1 error · 1 warning · 84 ms · offline
BR-DE-15errorKäuferreferenz (Leitweg-ID) fehlt. Pflicht bei Rechnungen an öffentliche Auftraggeber.Fix: <cbc:BuyerReference>04011000-12345-67</cbc:BuyerReference>
BR-DE-18warningSkonto muss im Format #SKONTO#TAGE=10#PROZENT=2.00# in den Zahlungsbedingungen stehen.
What

Six things it does with an e-invoice

  • ReadDetects UBL, CII or a ZUGFeRD/Factur-X PDF (XML embedded in the PDF) and returns the EN 16931 model: parties, lines, totals, VAT.
  • CheckValidates against XSD plus the official KoSIT XRechnung and CEN EN 16931 Schematron rules, unmodified. Same verdict as the public-sector validator.
  • ExplainTurns [BR-DE-15] Buyer reference MUST be provided into German or English text with the affected business term and a fix hint.
  • CreateGenerates a valid XRechnung 3.0 UBL file or a ZUGFeRD 2.3 / Factur-X PDF/A-3 from structured data, validated before it is returned.
  • ConvertUBL ↔ CII, XML out of a ZUGFeRD PDF, HTML preview, with a loss report when a mapping cannot be exact.
  • AdviseWhich parts of the German e-invoicing mandate apply to a business, from when, with primary sources. Informational, not legal advice.
The key promise is sovereignty. No cloud, no API keys, no network calls, no Java at runtime. A test blocks every socket, DNS and HTTP path and asserts zero attempts; CI repeats it in a container with networking disabled.
Why

Why it exists

Germany's Wachstumschancengesetz makes e-invoicing mandatory for domestic B2B trade. An e-invoice is structured XML under EN 16931, not a PDF: more than 100 business rules decide whether it is valid, and a failed invoice can cost the input-VAT deduction. The validator's messages mean nothing to the people who receive them.

Invoices carry personal data, bank details and prices, so GDPR and procurement policy push for processing on-premises. Existing tooling for AI agents is either a cloud API wrapper or a partial, hand-rolled validator. Kontor MCP runs the official rule sets where the invoices live.

  • Suppliers to federal bodies must send XRechnung with a Leitweg-ID
  • Every German business must be able to receive e-invoices. In force.
  • Businesses with turnover above €800k must issue e-invoices
  • All businesses must issue them; paper and plain PDF no longer count
How

How it works

  1. ConnectOne entry in your MCP client. Claude Desktop starts npx -y @kontor-mcp/server as a child process over stdio; nothing listens on the network. For shared setups, run the container and use Streamable HTTP with a bearer token.
  2. Ask“Ist diese Rechnung gültig?” The assistant calls the right tool with a file path or XML and gets structured JSON plus a readable summary.
  3. ActFindings carry the official rule id, a DE/EN explanation and a fix. Built-in prompts cover auditing an incoming invoice, drafting a supplier rejection and creating an invoice by interview.
kontor-agent audit invoice.xml
› detect      UBL 2.1 · XRechnung 3.0                12 ms
› xsd         ok
› schematron  EN 16931 1.3.16 · XRechnung 2.5.0      61 ms
  ✗ BR-DE-15  BT-10 Buyer reference MUST be provided
    fix  <cbc:BuyerReference>04011000-12345-67</cbc:BuyerReference>
› verdict     UNGÜLTIG · recommend reject · 0 network calls · exit 2

Reference client kontor-agent (@kontor-mcp/client): tools lists the server's surface; audit <file> is a scriptable audit that needs no LLM and exits 0 / 1 / 2 for accept / review / reject (3 on error), so it drops straight into CI or a mail pipeline; chat runs an Anthropic agent loop over the server and prints every tool call (needs ANTHROPIC_API_KEY; the server itself never does).

MCP clientClaude Desktop · Claude Code · kontor-agent · any client
@kontor-mcp/server8 tools · 4 resources · 3 prompts · stdio + HTTP · Zod schemas
@kontor-mcp/coreSaxon-JS Schematron · xmllint-wasm · pdf-lib · UBL ↔ CII
@kontor-mcp/rulesKoSIT + EN 16931 rule sets · XSDs · code lists · rule KB
@kontor-mcp/clientkontor-agent: tools · audit (exit codes, no LLM) · chat (Anthropic agent loop)
Tools

Eight tools

validate_invoiceXSD + official rules + plausibility checks; KoSIT-equivalent verdict with findingsread-only
audit_invoiceOne call, one recommendation: accept / review / reject, with reasonsread-only
parse_invoiceDetect the format and return the EN 16931 semantic modelread-only
explain_ruleAny rule id → DE/EN explanation and fix hint; suggests near matches for typosread-only
check_obligationsGerman mandate: who must do what, from when, with sourcesread-only
list_capabilitiesFormats, bundled standard versions, sovereignty statementread-only
generate_invoiceStructured data → XRechnung 3.0 UBL or ZUGFeRD 2.3 / Factur-X PDF/A-3writes file
convert_invoicePDF → XML, UBL ↔ CII, HTML preview, with a loss reportwrites file

Resources kontor://samples/{name} kontor://reference/rules kontor://reference/codelists/{list} kontor://reference/cheatsheet · Prompts audit-incoming-invoice draft-supplier-rejection create-invoice-interview

Install

Install

Claude Desktop · Settings → Developer → Edit Config, then quit and reopen
{
  "mcpServers": {
    "kontor": { "command": "npx", "args": ["-y", "@kontor-mcp/server"] }
  }
}
kontor-agent, the reference client · scriptable audit, exit 0 / 1 / 2 = accept / review / reject
npx -y -p @kontor-mcp/client kontor-agent audit invoice.xml
Claude Code
claude mcp add kontor -- npx -y @kontor-mcp/server
Any MCP client · stdio
npx -y @kontor-mcp/server
Docker · Streamable HTTP on 127.0.0.1:3333/mcp, bearer token required
docker run -d -p 127.0.0.1:3333:3333 \
  -e KONTOR_AUTH_TOKEN="$(openssl rand -hex 24)" \
  ghcr.io/dashankanadeeshandesilva/kontor-mcp

Node ≥ 20. Rules, schemas, code lists and fonts ship inside the package; nothing is downloaded at runtime. Env: KONTOR_MAX_FILE_MB (20), KONTOR_LANG_DEFAULT (de/en).

Claude Desktop validating a broken invoice: UNGÜLTIG, BR-DE-15 explained
validate_invoice in Claude Desktop, network off
Claude Desktop parsing a ZUGFeRD PDF
parse_invoice on a ZUGFeRD PDF
Claude Desktop explaining rule BR-DE-18
explain_rule BR-DE-18 · 43-s video
Technical

Guarantees

  • No network at runtimeblocked and asserted by sovereignty.test.ts (sockets, DNS, TLS, http(s), fetch) and a --network none CI job
  • Nothing stored or loggedstateless; payload logging off unless KONTOR_LOG_PAYLOADS is set; no accounts, no telemetry
  • Hardened parsingDTDs and external entities disabled (XXE, billion-laughs), size and depth caps, path hygiene, PDF bytes untrusted
  • Exact money mathdecimal.js everywhere, never floating point
  • HTTP hardeningbearer token with constant-time compare, Origin allow-list, Host validation, loopback bind, session cap, idle expiry
  • Supply chaintag-triggered releases, npm trusted publishing with Sigstore provenance, multi-arch image from CI, artefacts pinned by SHA-256 in PROVENANCE.md

Standards and verification

XRechnung (KoSIT)3.0.2 · Schematron 2.5.0
CEN EN 16931 Schematron1.3.16
Code lists · plausibility rules13 · 22
Rule knowledge base, DE/EN1,642 + 50 curated
Parity with KoSIT validator 1.6.389 / 89
ZUGFeRD PDF/A-3b: veraPDF · Mustang6 / 6 · 6 / 6
Tests · CI357 · 3 OS × Node 20/22
StackTypeScript strict · pnpm · vitest

Conformance is a CI gate; any drift from the official validator fails the build. Full report.