Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

AP Control Labs Finance Controls

REMOTE · API-PRODUCTION-9502.UP.RAILWAY.APP · SCANNED OCT 4

Read-only finance and operations controls for AI agents with evidence and safe next actions.

0 this week 23 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema not yet verified: we couldn't read the endpoint's schema, or could read only part of its tool list.Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.Unverified
Tool Safety0
  • Tool safety not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.Unverified
Capabilities0
  • Capabilities not yet verified: we couldn't read the endpoint's capabilities.Unverified

Unverified: 5 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

Install

How do I install the AP Control Labs Finance Controls MCP server?

AP Control Labs Finance Controls is a hosted endpoint at https://api-production-9502.up.railway.app/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · api-production-9502.up.railway.app

# add to Claude Code
claude mcp add --transport http juodoc-ap-control 'https://api-production-9502.up.railway.app/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "juodoc-ap-control": {
      "url": "https://api-production-9502.up.railway.app/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "juodoc-ap-control": {
      "type": "http",
      "url": "https://api-production-9502.up.railway.app/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.juodoc-ap-control]
url = "https://api-production-9502.up.railway.app/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "juodoc-ap-control": {
      "type": "remote",
      "url": "https://api-production-9502.up.railway.app/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add juodoc-ap-control --url 'https://api-production-9502.up.railway.app/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  juodoc-ap-control:
    url: "https://api-production-9502.up.railway.app/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "juodoc-ap-control": {
      "Transport": "http",
      "Url": "https://api-production-9502.up.railway.app/mcp"
    }
  }
}
# add to Vellum
assistant mcp add juodoc-ap-control -t streamable-http -u 'https://api-production-9502.up.railway.app/mcp'
// mcp.json
{
  "mcpServers": {
    "juodoc-ap-control": {
      "type": "http",
      "url": "https://api-production-9502.up.railway.app/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Aug 26 0
    • Endpoint reachability: reachable → not serving MCP ▼ security
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 10 Aug 26 0

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Oct 2026 · Probed https://api-production-9502.up.railway.app/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=*.up.railway.app CN=YE2,O=Let's Encrypt,C=US 27 Sept 2026 26 Dec 2026 ECDSA 256 ECDSA-SHA384 618edc56941aa1165ddb080bf9f799eb7c1
SANs: *.up.railway.app, up.railway.app
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of api-production-9502.up.railway.app. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
app. present 23684 8 Verified
railway.app. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Inconclusive

We could not reach the endpoint well enough to judge its authorisation posture.

Result Inconclusive
HTTP status 404

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api-production-9502.up.railway.app/mcp HTTP error 404
http (plaintext) http://api-production-9502.up.railway.app/mcp HTTPS enforced 301 https://api-production-9502.up.railway.app/mcp
MCP tools · 32 exposed · ~2,254 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
analyze_invoice ~56

Submit one normalized invoice for asynchronous duplicate analysis. Use the returned ID to poll; do not resubmit the same work with a new idempotency key.

NameTypeReqDescription
idempotency_keystringyes–
invoiceobjectyes–
NameTypeReqDescription
decision–––
exceptionsarrayyes–
idstringyes–
status–yes–

No examples provided.

check_certificate_expiry ~61

Check expiry windows and customer verification flags for supplied certificate metadata. It does not validate certificate authenticity.

NameTypeReqDescription
as_of_datestring––
certificatesarrayyes–
vendor_referencestringyes–
warning_daysinteger––
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

check_procurement_agent_action ~150

Evaluate a proposed procurement agent action against supplied budget, authority, category, vendor, contract, and approval policy. It never authorizes a payment or vendor-record change.

NameTypeReqDescription
action–yes–
agent_idstringyes–
amountstring|numberyes–
approval_presentboolean––
approval_required_abovestring|number––
budget_availablebooleanyes–
categorystringyes–
contract_referencestring––
currencystring––
requester_authorizedbooleanyes–
restricted_categoriesarray––
vendor_approvedboolean––
vendor_referencestring––
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

check_remittance_change ~67

Compare submitted fingerprinted remittance details with a customer-controlled vendor baseline. A change requires human out-of-band verification; this is not bank-account ownership verification.

NameTypeReqDescription
account_fingerprintstringyes–
remittance_referencestringyes–
vendor_referencestringyes–
NameTypeReqDescription
decision–yes–
exceptionsarrayyes–
next_actionstringyes–

No examples provided.

check_tax_form ~106

Check W-9 or W-8 form completeness using only a legal name, final four identifier digits, customer signature policy, and supplied dates. It is not tax advice or tax-ID verification.

NameTypeReqDescription
entity_countrystring––
expires_onstring––
form_type–yes–
legal_namestring––
signature_required_by_customerboolean––
signed_onstring––
tax_identifier_last4string––
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

check_vendor_domain_risk ~66

Compare a sender email domain with customer-provided approved and prior-domain baselines. Verify changes out of band.

NameTypeReqDescription
approved_domainsarray––
prior_sender_domainsarray––
sender_emailstringyes–
vendor_referencestringyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

check_vendor_onboarding ~71

Check customer-defined supplier onboarding packet completeness. It does not approve or create a vendor.

NameTypeReqDescription
approved_by_customerboolean––
remittance_fingerprint_presentboolean––
required_itemsarrayyes–
supplied_itemsarray––
vendor_referencestringyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

compare_quotes ~41

Compare customer-provided vendor quote lines and totals. It never selects or sends a quote.

NameTypeReqDescription
expected_currencystring––
quotesarrayyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

create_purchase_order ~67

Register one customer-provided purchase order as the baseline for AP Match. This stores only the caller's data and never writes to an ERP.

NameTypeReqDescription
currencystring––
linesarrayyes–
po_numberstringyes–
vendor_namestringyes–
NameTypeReqDescription
idstringyes–
linesarrayyes–
po_numberstringyes–
statusstringyes–

No examples provided.

diff_purchase_order_amendment ~53

Private preview. Compare two saved caller-owned PO revisions and return explicit header, term, and line changes.

NameTypeReqDescription
after_purchase_order_idstringyes–
before_purchase_order_idstringyes–
NameTypeReqDescription
decision–yes–
exceptionsarrayyes–
next_actionstringyes–

No examples provided.

extract_contract_obligations ~69

Find candidate ISO dates and obligation indicators in supplied contract text. Review results against the source; this is not legal advice.

NameTypeReqDescription
as_of_datestring––
contract_referencestringyes–
contract_textstringyes–
lookahead_daysinteger––
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

extract_purchase_order ~50

Private preview. Queue one uploaded customer-owned purchase-order document for structured extraction. Poll with get_purchase_order_extraction.

NameTypeReqDescription
idempotency_keystringyes–
upload_idstringyes–
NameTypeReqDescription
fieldsobject|null––
idstringyes–
next_actionstringyes–
status–yes–

No examples provided.

get_invoice_exceptions ~30

Retrieve the agent-readable exception packet for one caller-owned invoice.

NameTypeReqDescription
invoice_idstringyes–
NameTypeReqDescription
exceptionsarrayyes–

No examples provided.

get_invoice_extraction ~37

Retrieve canonical fields, OCR confidence, source evidence, and a next action for a submitted invoice.

NameTypeReqDescription
invoice_idstringyes–
NameTypeReqDescription
confidencenumber|null––
evidenceobject––
fields–––
invoice_idstringyes–
next_actionstringyes–
status–yes–

No examples provided.

get_invoice_risk_score ~44

Private preview. Return the deterministic 0-100 control score, priority band, and named evidence signals for a completed invoice.

NameTypeReqDescription
invoice_idstringyes–
NameTypeReqDescription
band–yes–
invoice_idstringyes–
next_actionstringyes–
scoreintegeryes–
signalsarrayyes–

No examples provided.

get_invoice_status ~36

Retrieve one analysis owned by the caller's organization. Poll until status is COMPLETED or FAILED.

NameTypeReqDescription
invoice_idstringyes–
NameTypeReqDescription
decision–––
exceptionsarrayyes–
idstringyes–
status–yes–

No examples provided.

get_purchase_order_extraction ~40

Private preview. Get the caller-owned PO extraction status, canonical fields, OCR evidence, and next action.

NameTypeReqDescription
extraction_idstringyes–
NameTypeReqDescription
fieldsobject|null––
idstringyes–
next_actionstringyes–
status–yes–

No examples provided.

match_invoice ~62

Run a read-only two- or three-way match against one registered purchase order. Supply exactly one purchase-order identifier.

NameTypeReqDescription
invoice_idstringyes–
mode–––
purchase_order_idstring––
purchase_order_numberstring––
NameTypeReqDescription
decision–yes–
exceptionsarrayyes–
invoice_idstringyes–
line_resultsarrayyes–
mode–yes–
purchase_order_idstringyes–

No examples provided.

match_reconciliation ~53

Produce deterministic candidate matches between two caller-provided record sets. It never posts a reconciliation.

NameTypeReqDescription
date_tolerance_daysinteger––
source_recordsarrayyes–
target_recordsarrayyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

match_remittance_advice ~92

Match a customer-supplied remittance amount and invoice references to the caller's supplied open-invoice baseline. It never posts a payment.

NameTypeReqDescription
currencystring––
invoice_referencesarray––
open_invoicesarrayyes–
remittance_referencestringyes–
remitted_amountstring|numberyes–
vendor_referencestring––
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

normalize_bank_statement ~45

Normalize customer-provided bank transaction records for reconciliation. It never connects to a bank or stores account numbers.

NameTypeReqDescription
account_referencestringyes–
transactionsarrayyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

normalize_invoice_lines ~44

Private preview. Deterministically normalize customer-supplied invoice descriptions, SKUs, and units. It does not invent missing values.

NameTypeReqDescription
line_itemsarrayyes–
NameTypeReqDescription
issuesarrayyes–
line_itemsarrayyes–
next_actionstringyes–
status–yes–

No examples provided.

preflight_erp_bill ~125

Check a proposed NetSuite or QuickBooks vendor bill using customer-supplied record references. This tool never connects to or writes to an ERP.

NameTypeReqDescription
approval_presentboolean––
approval_required_abovestring|number––
erp–yes–
existing_bill_referencestring––
expected_currencystring––
expected_vendor_referencestring––
invoiceobjectyes–
purchase_order_referencestring––
source_record_idstringyes–
vendor_referencestringyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

preflight_franchise_invoice ~92

Find exact same-vendor, same-invoice, same-amount duplicates across customer-supplied multi-location history. It never searches another organization’s records.

NameTypeReqDescription
approved_vendor_referencesarray––
historical_invoicesarray––
invoiceobjectyes–
location_openboolean––
location_referencestringyes–
vendor_referencestringyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

preflight_freight_invoice ~157

Check a freight invoice against supplied shipment, linehaul, fuel, and accessorial policy data. It does not connect to a TMS or carrier system.

NameTypeReqDescription
allowed_accessorialsarray––
carrier_scacstringyes–
duplicate_shipment_invoiceboolean––
invoiceobjectyes–
invoiced_accessorialsarray––
invoiced_fuel_surchargestring|number––
invoiced_linehaulstring|numberyes–
quoted_fuel_surchargestring|number––
quoted_linehaulstring|numberyes–
shipment_deliveredbooleanyes–
shipment_referencestringyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

preflight_subcontractor_invoice ~173

Check a subcontractor invoice against supplied commitment, retainage, schedule-of-values, work, lien-waiver, and insurance evidence. It does not determine legal validity of documents.

NameTypeReqDescription
approved_change_order_amountstring|number––
approved_contract_amountstring|numberyes–
billed_to_datestring|number––
current_application_amountstring|numberyes–
insurance_status–––
invoiceobjectyes–
lien_waiver_status–––
project_referencestringyes–
retainage_ratestring|number––
retainage_withheldstring|number––
schedule_of_values_matchedbooleanyes–
subcontract_referencestringyes–
work_completed_verifiedbooleanyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

record_receipt ~73

Record a customer-provided goods receipt for a registered purchase order. Use it before a THREE_WAY AP Match; it never updates a warehouse or ERP.

NameTypeReqDescription
linesarrayyes–
purchase_order_idstringyes–
receipt_numberstringyes–
received_atstring|null––
NameTypeReqDescription
idstringyes–
linesarrayyes–
purchase_order_idstringyes–
receipt_numberstringyes–

No examples provided.

resolve_vendor_entity ~89

Resolve customer-supplied vendor names, aliases, addresses, and domains against customer-provided expectations. It is not official verification.

NameTypeReqDescription
addressstring––
aliasesarray––
approved_domainsarray––
email_domainstring––
expected_addressstring––
expected_namestring––
vendor_namestringyes–
NameTypeReqDescription
decision–yes–
evidenceobjectyes–
exceptionsarrayyes–
next_actionstringyes–
productstringyes–
status–yes–

No examples provided.

save_extracted_purchase_order ~46

Private preview. Save a completed extraction as a named PO revision before matching or amendment diffing.

NameTypeReqDescription
extraction_idstringyes–
revision_labelstringyes–
NameTypeReqDescription
idstringyes–
po_numberstringyes–
revision_labelstringyes–

No examples provided.

search_invoice_history ~47

Find exact and near matches in the caller's own completed invoice history. Scores are explainable, not a fraud probability.

NameTypeReqDescription
invoiceobjectyes–
limitinteger––
NameTypeReqDescription
matchesarrayyes–
next_actionstringyes–

No examples provided.

upsert_vendor_baseline ~73

Create or replace a customer-controlled remittance baseline. Provide a fingerprint, not a raw account number. This is not bank-account ownership verification.

NameTypeReqDescription
account_fingerprintstringyes–
remittance_referencestringyes–
vendor_namestringyes–
vendor_referencestringyes–
NameTypeReqDescription
account_fingerprintstringyes–
idstringyes–
referencestringyes–
remittance_referencestringyes–
vendor_namestringyes–

No examples provided.

validate_invoice ~39

Run deterministic required-field, date, and line-total checks before AP routing. This does not create or alter accounting records.

NameTypeReqDescription
invoiceobjectyes–
NameTypeReqDescription
decision–yes–
exceptionsarrayyes–
next_actionstringyes–

No examples provided.

Common questions

What is the AP Control Labs Finance Controls MCP server?

AP Control Labs Finance Controls is an MCP server listed in the public MCP registry as io.github.juodoc/ap-control. Read-only finance and operations controls for AI agents with evidence and safe next actions. This page covers its hosted endpoint (https://api-production-9502.up.railway.app/mcp).

Is the AP Control Labs Finance Controls MCP server safe to use?

AP Control Labs Finance Controls scores 23 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the AP Control Labs Finance Controls MCP server expose?

AP Control Labs Finance Controls exposes 32 tools: analyze_invoice, get_invoice_status, get_invoice_exceptions, create_purchase_order, record_receipt, and 27 more. Their descriptions and schemas cost roughly 2,254 tokens of context every time the server is loaded.

Does the AP Control Labs Finance Controls MCP server require authentication?

Its publisher declares that AP Control Labs Finance Controls requires credentials, so you will need to authorise it in your MCP client. We have not been able to confirm that against the live endpoint.

Is the AP Control Labs Finance Controls MCP server still maintained?

AP Control Labs Finance Controls is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.