Run your business from Claude — accounting included (Malaysia)
More and more Malaysian operators run the day from an AI agent rather than from a screen: the agent reads the inbox, the WhatsApp thread and the shared Drive, and does the work. That arrangement raises one hard question — which box do the numbers land in? This guide describes the stack in full, and what it takes for an accounting ledger to be a proper backend for an AI agent rather than a website the agent cannot reach.
The stack: your agent in the middle, your books underneath
Picture how an operator actually works now. Documents and messages arrive where they always did — email, WhatsApp, a shared Drive, a photo taken at the counter. In the middle sits an agent: Claude Code in a terminal, claude.ai in a browser, Claude Desktop, ChatGPT, Cursor. Underneath sit the systems of record that have to end up correct, and the ledger is the least forgiving of them. The agent reads a supplier bill out of the inbox and needs somewhere to put it; that somewhere is the accounting box. Taokeh is built to be that box. It is a Malaysian SME ledger — sales, purchases, bank, stock, payroll, SST and e-invoice on one set of books — with an official Model Context Protocol server at taokeh.my/mcp, 37 tools, live since 16 July 2026. The inputs are not ours: email, WhatsApp and Drive reach your agent through your agent’s own connectors, never through Taokeh.
That division matters when you are shopping. The layer you are choosing is only the bottom one. Your agent, your model and your input connectors are yours to pick and to change, and none of them is bought from us. What you are buying is a ledger that your agent can reach directly, in a country whose statutory rules it has to get right.
| Layer | What sits there | Who owns the connection |
|---|---|---|
| Inputs | Email, WhatsApp, a shared Drive, your files — the documents and messages a business runs on | Your agent’s own connectors, not Taokeh’s |
| The agent | Claude Code, claude.ai, Claude Desktop, ChatGPT, Cursor — the model that reads, decides and drafts | Your own AI subscription |
| Other systems of record | Whatever else you keep — a storefront, a marketplace, a spreadsheet, a CRM | Each system’s own connector, if it has one |
| The accounting box | Taokeh: one Malaysian ledger for sales, purchases, bank, stock, payroll, SST and e-invoice | The Taokeh MCP server at taokeh.my/mcp |
Taokeh owns the bottom row only. It does not read your email, your WhatsApp or your Drive, and it does not send anything to anyone on your behalf.
What does “an accounting backend for an AI” actually mean?
It means the ledger publishes a tool surface an agent can call directly, instead of a website a human clicks through or a nightly file export. Three properties make it real. First, the agent reads the live books — not a copy, not last night’s snapshot: it asks for the aging or the cash position and the answer comes out of the ledger as it stands. Second, the agent can hand work back: file an expense off a receipt, a bill off a supplier PDF, an invoice off an instruction. Third, and most important, the boundary between the two is enforced by the server rather than by how the agent was prompted. A chatbot built into an accounting app is a different animal — it knows one app, it lives in that app’s chat window, and you cannot point it at your inbox. A backend is something your own agent reaches, alongside everything else it already reaches.
What can the AI actually do against Taokeh — 28 reads and 9 writes?
The server exposes 37 tools: 28 that read and 9 that write. The reads cover the questions an operator asks a bookkeeper — the day’s and month’s trading, cash across every account, an eight-week cash forecast, profit and loss, balance sheet, SST position and e-invoice status, receivables and payables aging, sales by channel, stock on hand and the reorder list, document search, and the bank rows still waiting for review. The writes are narrower on purpose. Six of them file drafts — expense, bill, invoice, quote, customer receipt, and a contact read off a name card. One imports a bank statement into the review queue. One proposes categories for bank rows as suggestions the owner sees. One issues an upload link for a file too large to inline. That is the whole write surface, and none of it posts.
The safety contract behind those numbers is structural, not a setting. Reads answer immediately, because a read changes nothing. Writes land as pending drafts that a human approves before anything reaches the ledger. And there is no tool at all that posts to the ledger, amends or voids a posted document, deletes anything, confirms a bank row, or sends an email — the capability does not exist to be misused, whatever an agent is told to do.
One more property matters for anyone assembling a stack: on MCP paths the Taokeh server never calls a language model. Your agent reads the receipt, the statement or the name card and sends structured fields; our server validates them, re-computes every line and total itself, and files a draft. The reasoning runs on your subscription with your choice of model, and your documents are not fanned out to some third model we picked for you.
| Group | Tools | What the agent can ask for |
|---|---|---|
| Overview & cash | 5 | business_snapshot, daily_brief, cash_position, cash_forecast, profit_drivers |
| Statements & tax | 3 | income_statement, balance_sheet, tax_position |
| Who owes whom | 4 | ar_aging, ap_aging, open_invoices, payer_history |
| Sales, stock & channels | 5 | sales_summary, expenses_summary, channel_summary, stock_level, low_stock |
| Documents & search | 3 | search_documents, search_expenses, get_document_pdf |
| Banking review | 2 | bank_review_queue, bank_reconciliation_status |
| Lookups & shaping | 6 | resolve_customer, resolve_vendor, resolve_product, expense_accounts, intake_contract, find_in_taokeh |
Plus 9 write tools, every one of which files a draft, a review-queue row or a suggestion — never a posted entry. The current list is published in full on the Taokeh MCP server page.
How do I connect it to my agent?
Two routes, depending on where your agent lives. For claude.ai and ChatGPT, add https://taokeh.my/mcp as a custom connector: the client registers itself, you are bounced to Taokeh to sign in, and a consent screen names the workspace and the scope before anything is granted — no key to copy and no config file to edit. For Claude Code, Claude Desktop, Cursor and other command-line clients, generate a personal access token inside Taokeh (they look like tkm_…) and send it as an Authorization bearer header; tokens are stored only as a hash, are scoped to one workspace, and can be revoked at any time. Either route needs the connector add-on switched on for the workspace, and only admin and bookkeeper seats can connect or use it. The transport is Streamable HTTP; auth is OAuth 2.1 with dynamic client registration and PKCE, or the bearer token.
On the OAuth route you also choose the scope on the consent screen: read-only, or read plus drafts. You can reconnect later at a different scope, and disconnecting an assistant stops its access immediately. The step-by-step version of this, with screenshots of where each setting lives, is the sibling guide linked at the foot of this page; the endpoint reference lives on the MCP server page.
What stays human in this arrangement?
Three things, deliberately. Approvals: every draft the agent files waits for a person to check it against the original document and tap approve, either from the review strip inside Taokeh or from a one-tap approval link that still requires you to be signed in as an admin or bookkeeper. Money: nothing the agent does moves funds, settles an invoice or confirms a bank line — a payment is recorded when a human records it. Anything outward: the connector emails nobody and contacts nobody on your behalf. Ask for an invoice PDF and it hands you a short-lived signed link, not a sent message. Your agent may well draft the chase email from the figures it read, and that is useful, but pressing send is your move and it happens in your own mail client, not through us.
This is also why the read/write asymmetry is worth understanding rather than working around. An agent that can read everything and write nothing but drafts is safe to give a lot of latitude; an agent that could post would need to be watched constantly, which defeats the point of having it.
Why does jurisdiction depth matter more than the tool count?
Because the hard part of Malaysian books is not reading them — it is being right about Malaysian rules. A ledger built for another market can expose a perfectly good connector and still leave you doing the local work by hand: LHDN e-Invoice submission and consolidation through MyInvois, SST registration thresholds and the SST-02 return, payroll that has to compute PCB, EPF, SOCSO and EIS to the sen against the current schedules, EA forms at year end, and an interface your staff can actually use in Bahasa Malaysia. Those are the parts an agent cannot invent for you, because they are compliance, not reasoning. Taokeh carries them in the ledger itself, which is what makes the connector worth pointing at: the agent asks for your SST position or your e-invoice status and gets a real answer, rather than a number it would have had to assemble from a spreadsheet you maintain.
The practical test when you are comparing options: ask whether the statutory work happens inside the box or beside it. If the local filing, the payroll schedules and the e-invoice submission live outside the system your agent can reach, then your agent is only helping with the easy half.
What does this cost?
The connector is an add-on at RM29 a month as at August 2026, available on any Taokeh plan rather than reserved for a top tier, and it is included in the 14-day free trial — so you can connect an agent and see how a draft feels before paying for anything. It is a flat price with no per-question metering: you bring your own AI subscription, so the cost of the reasoning is whatever you already pay Anthropic or OpenAI, and there is no usage bill from us that grows with how much you ask. Two clarifications worth making. Taokeh’s in-app document scan is a separate, metered feature and is not the same thing as asking a question through the connector. And the add-on price sits on top of the base subscription, which is priced separately. Confirm the current figures on the pricing page before you rely on them.
Frequently asked questions
Can Claude reconcile my bank account for me?
Partly, and the split is deliberate. Your agent can import a bank statement (rows land in Banking → Review, and the server refuses a statement whose rows do not tie to the printed closing balance), read the review queue with Taokeh’s own suggested categories and confidence scores, read how you have categorised the same counterparty before, and propose categories for up to 50 rows as suggestions. It cannot confirm a row. The matching is assisted; the confirmation is yours.
Can it file my SST return or submit my e-invoices?
No. The connector can read your current SST period position and your e-invoice consolidation status and the filing due date, so your agent can tell you where you stand and what is due. Filing and submission are done by a human in Taokeh, and no connector tool submits anything to LHDN or Customs. What is due, and how your own registration is treated, is a question for the authority or your tax agent.
Does Taokeh read my email, WhatsApp or Drive?
No. Those reach your agent through your agent’s own connectors, and Taokeh never sees them. What arrives at our server is what your agent sends: structured fields for a draft, plus any document image you asked it to attach. In the other direction the connector sends nothing outward — it hands you a signed link to a document rather than emailing anybody.
Which clients has this been tested with?
claude.ai, ChatGPT custom connectors, Claude Desktop, Claude Code and Cursor. Anything else that speaks MCP over Streamable HTTP should work the same way, using OAuth where the client supports it or a personal access token where it does not.
Do I need a Taokeh AI subscription on top of my Claude or ChatGPT one?
No. The connector is a flat monthly add-on and the reasoning runs on your own AI subscription — the Taokeh server never calls a language model on MCP paths. There is no per-question metering on the connector itself.
What happens if I revoke access, or an agent goes wrong?
Disconnect the assistant, or revoke the personal access token, and its access stops immediately. Because no tool can post, amend, void or delete, the worst a misbehaving agent can leave behind is drafts and review-queue rows that nobody approved — your posted books are unchanged.
Updated August 2026
This guide is general information for Malaysian SMEs, not tax, legal or accounting advice. Always confirm current rules and figures with the relevant authority or your own adviser.
The Taokeh MCP server — endpoint, tools and the safety contract
Run the books for your Malaysian SME on one ledger — accounting, payroll and selling channels.
Related guides
- Connect Claude or ChatGPT to your accounting books (Malaysia, 2026)
- The Ask Taokeh connector — how it works for your business
- The Taokeh MCP server (developer documentation)