An external client can find a permitted customer, preview exact invoice totals and prepare a draft in Pepper. A person then opens that draft to review and issue it. MCP and HTTP access gives a client a defined job without giving it the ability to send invoices or record payment.
No AI account is required. A script or internal business tool can use the same access. If you connect a model-based client, that client's data handling is a separate choice.
Grant access to the work it needs
Access starts off. The owner enables agent connections and creates an expiring grant for a staff member's permitted work. The selected capabilities limit what the client can do; the staff member's current permissions and record access also apply.
Connections expire after 1 to 30 days. The owner can revoke a connection or turn access off. Keep the credential in a server-side secret store. HTTP calls require HTTPS and do not accept browser JavaScript. MCP clients can also use browser OAuth sign-in.
Begin with read and preview access when evaluating a client. Add draft creation or updates when you have checked how it selects the customer, tax rate and currency.
Make the review useful
Give the client a concrete instruction, such as preparing a USD 250 draft for two units of an agreed service at USD 125 each, with the intended dates and tax treatment. Open the saved record and compare it with the agreement.
Check the customer as well as the total. A mathematically correct invoice for the wrong customer is still wrong. Review the descriptions, quantities, price, currency and dates before issuance.
Pepper calculates the monetary result on the server. The client sends exact values, not a model's estimated total. Writes use retry keys to avoid creating a second draft when the same request repeats. A stale update leaves the draft unchanged and needs review against the latest record.
Keep the released boundary clear
A separately granted issue request needs the delegated person's approval of one invoice in Pepper. Approval expires 10 minutes after preparation. The client must execute the approved request before expiry; approval alone does not issue the invoice. Clients cannot send, settle or export documents, or change bank and tax settings. Pepper has no built-in assistant.
Revoking access stops later calls. It cannot remove a copy the client already made. Decide which permitted information the client may send to a model or another service, and read that service's terms before connecting it to business records.
The developer guide describes the endpoints, limits and retry behavior. The connection manual and API reference explain MCP, browser sign-in and the separate approval workflow. Consult the changelog for release history.