Promotions

New products

  • MCP+ for Dolibarr

    MCP+ connects Claude, ChatGPT and other AI assistants straight to your Dolibarr. Just ask: Which tickets still need an answer?, Show me the unpaid invoices for Miller Ltd — and your assistant works on your real data instead of copy-paste. No extra server, no data handed to third parties: it runs in your own Dolibarr, with clear rights per connection and a full audit log.

    300.00 €
  • Doli-Secure (Check for vulnerabilities in Dolibarr)

    Automatically check that your installed Dolibarr version is not affected by any known vulnerability (CVE), using the public NVD (NIST) database. A home page indicator and an automatic email alert keep your administrators informed. Technical support: dolibarr@joliciel.fr Module offered for free to the Dolibarr community.

    FREE

MCP+ for Dolibarr

mp1207d20260821154723

New

MCP+ connects Claude, ChatGPT and other AI assistants straight to your Dolibarr. Just ask: Which tickets still need an answer?, Show me the unpaid invoices for Miller Ltd — and your assistant works on your real data instead of copy-paste. No extra server, no data handed to third parties: it runs in your own Dolibarr, with clear rights per connection and a full audit log.

300.00 €
Excl. tax

  • Author Guenter Lukas (Guenter Lukas Consulting)
  • Module version 1.4
  • Release date 08/21/2026
  • Access to download and updates 1 year
  • How to contact support support@gl.co.at
  • Compatibility Dolibarr V20 - V24   -   PHP8.0 - 8.5
  • Last update 09/06/2026 03:56 PM

More info...

MCP+ connects AI assistants like Claude and ChatGPT directly to your Dolibarr — secure, fully auditable and without a single additional server process.

The server speaks the Model Context Protocol (MCP), the open standard AI clients use to access business data. Whether Claude Desktop, Claude Code, claude.ai in the browser or ChatGPT: the assistant sees your tickets, customers, invoices and projects — with exactly the permissions you grant, and not one more.

Native Dolibarr module instead of a middle layer

MCP+ runs as a regular Dolibarr module inside your existing installation. There is no external Python or Node server, no bridge, no cloud middle layer — and therefore a whole class of failure points and attack surface less.

  • Installed in minutes: enable the module, create a token, done — no extra service to install, monitor and update
  • Access through the Dolibarr object classes themselves: business logic, triggers, extrafields and multicompany entity separation apply automatically — no fragile re-implementation on top of the REST API
  • No data sharing with third parties: the connection runs directly between your MCP client and your Dolibarr
  • Not a single core patch: upgrade-safe on every Dolibarr update

57 tools in 9 categories

Full coverage of the key business objects — reading and (switchable per token) writing:

  • Tickets: list, search, read including message history, find unanswered tickets, create, reply, change status
  • Customers / third parties: list, search, read, create, update, delete
  • Contacts: list, read, create, update, delete
  • Products: list, search by label or reference, resolve references, create, update, delete
  • Invoices: list, read, create drafts, add/update/delete lines, validate, assign project
  • Orders: list, read, create, update, delete
  • Projects: list, search, read, create, update, delete
  • Users: list, read, create, update, delete
  • System: status, connection test and (optional, double-gated) passthrough to the Dolibarr REST API

Security in layers

Every request passes a fixed chain of security checks before a single record is read:

  • Per-client tokens: every client gets its own token — the database stores only the SHA-256 hash, the plaintext is visible exactly once
  • Permissions on three levels: Dolibarr rights of the service user, tool categories (scopes) per token, and a read-only mode that hides and blocks all write tools
  • Two separate IP whitelists (IPv4/IPv6, CIDR): one for static tokens, a dedicated one for OAuth connections — allowing the Anthropic/OpenAI ranges never loosens the restrictive token whitelist
  • Correct client IP resolution behind reverse proxies (trusted proxy list, X-Forwarded-For not spoofable)
  • Rate limit per token per minute, body size limit, origin check against DNS rebinding
  • Token hardening: expiration date, per-token IP restriction, one-click revocation
  • Error hygiene: internals never reach the client — they go to the server log only

OAuth 2.1 for claude.ai and ChatGPT

Cloud clients cannot store static headers — so MCP+ ships a complete OAuth 2.1 authorization server:

  • Connect straight from the claude.ai connector dialog or from ChatGPT: enter the URL, approve in Dolibarr, done
  • Consent page inside Dolibarr: per connection you decide the service user, the scopes and whether it is read-only
  • Standards-compliant and secure: mandatory PKCE S256, dynamic client registration (RFC 7591), discovery per RFC 8414/9728, refresh token rotation per OAuth 2.1
  • Every OAuth connection shows up as a regular token in the admin — same overview, same revocation, same audit log

Complete traceability

You can always see what an AI client did in your system:

  • Audit log of every single request: time, token, client IP, method, tool, parameters, result, duration
  • Dedicated log tab with filters (token, IP, tool, status, date range), sorting and paging — rejected access attempts are visible too
  • Configurable retention with automatic and manual purge (GDPR-friendly)

Broad compatibility

One code base, many environments:

  • Dolibarr 20.0 to 24.0 with one and the same module — including care for every API difference between the versions
  • Works with any MCP client: Claude Desktop, Claude Code, claude.ai, ChatGPT and every standards-compliant client (Streamable HTTP, JSON-RPC 2.0)
  • Multicompany-ready: tokens are bound to an entity, access stays cleanly separated

Why MCP+ instead of other solutions?

Typical MCP integrations for Dolibarr are external server processes (usually Python/Node) accessing the REST API with a single API key. The difference at a glance:

  MCP+ External MCP servers / REST bridges
Installation & operation Enable the Dolibarr module — runs inside the existing web server Separate process with a Python/Node environment that must be installed, started, monitored and updated
Authentication Per-client tokens (hash-only storage) plus OAuth 2.1 with consent One Dolibarr API key in plaintext in a configuration file
Permissions & restrictions Service user rights, scopes per token, read-only mode, expiration, per-token IPs Full access of the API key user — all or nothing
claude.ai / ChatGPT (cloud) Yes — built-in OAuth 2.1 server with a separate IP whitelist Usually no — local stdio servers are unreachable from the cloud
Audit & control Full audit log with UI, rate limiting, instant revocation At best the log files of the intermediate process
Data fidelity Direct object access including business logic, triggers and entity filters REST detours with custom mapping — deviations and gaps depending on the implementation
Updates Updates together with the Dolibarr instance, one code base for V20-V24 Separate release cycle, compatibility with the Dolibarr version must be verified manually
Developed by Günter Lukas Consulting
MCP+ is developed and maintained by Günter Lukas Consulting — specialists for Dolibarr custom development, integrations and AI connectivity. Questions, feature requests or help with the rollout:
Günter Lukas Consulting — https://gl.co.at



If you think this module is a fork of another one (published after the first one) or violates some terms or conditions of use (for users or vendors), you can make a report at dolistore@dolibarr.org