{"_id":"@apier-no/mcp","_rev":"6-6ecb93372cade06108c4110e52f3e31b","name":"@apier-no/mcp","dist-tags":{"latest":"1.2.1"},"versions":{"0.1.0":{"name":"@apier-no/mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","apier","norway","norwegian-compliance","altinn","skatteetaten","claude","cursor"],"author":{"name":"PowerLaunch AS"},"license":"MIT","_id":"@apier-no/mcp@0.1.0","maintainers":[{"name":"diviscodude","email":"antonycelcius@gmail.com"}],"homepage":"https://www.apier.no","bugs":{"url":"https://github.com/PowerLaunch/apier-mcp/issues"},"bin":{"apier-mcp":"dist/cli.js"},"dist":{"shasum":"e8d91d4815a2a6dd263ba3dc2f06bbe34f900fdd","tarball":"https://registry.npmjs.org/@apier-no/mcp/-/mcp-0.1.0.tgz","fileCount":7,"integrity":"sha512-Sj4DH7oyVyLMqbgLqPS7wPN5R+qB0+mvFHuDIlcMbtgoArjEy/c0qpI7+izSOoA+027QHg0niothn8QHzJs0aA==","signatures":[{"sig":"MEUCIDGPW6mZo1j0S8pW6GJecRoYLFkrY42aoIOJp9ZWTEDlAiEAja7MYE5BEzzvlCH34cJrjuyHYY/Bwh2X1YsqyyridnI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@apier-no%2fmcp@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":18806},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"gitHead":"be6266b75dfe4fbd3bc219e76bd6d7d45f55f722","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"diviscodude","email":"antonycelcius@gmail.com"},"repository":{"url":"git+https://github.com/PowerLaunch/apier-mcp.git","type":"git"},"_npmVersion":"10.9.7","description":"Thin npm proxy: connect local MCP clients (Claude Desktop, Cursor) to Apier's hosted Norwegian compliance MCP server.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.1.6","typescript":"^6.0.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.0_1778664800813_0.5383352075392553","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@apier-no/mcp","version":"0.1.1","keywords":["mcp","model-context-protocol","apier","norway","norwegian-compliance","altinn","skatteetaten","claude","cursor"],"author":{"name":"PowerLaunch AS"},"license":"MIT","_id":"@apier-no/mcp@0.1.1","maintainers":[{"name":"diviscodude","email":"antonycelcius@gmail.com"}],"homepage":"https://www.apier.no","bugs":{"url":"https://github.com/PowerLaunch/apier-mcp/issues"},"bin":{"apier-mcp":"dist/cli.js"},"dist":{"shasum":"cbee568d9ab6797d0159c4a3f99502a3202a8ddf","tarball":"https://registry.npmjs.org/@apier-no/mcp/-/mcp-0.1.1.tgz","fileCount":7,"integrity":"sha512-V5JhDFhxKRD/P9D/tTW3l6/bBQ6YCmJZPM5XrvWD+AKg5bD/aP6fnT9WwqbaUKssqrFbpypmoJQ2zG1oi8lg/g==","signatures":[{"sig":"MEQCIC7PA239ZDlOgTvHR/nyGWsPI6JNDdQz525gN1mXhmJLAiBGG7iFXCD4nFFECXqiYtWyg6VBvlQ/KL0Zyd7xOH4hag==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@apier-no%2fmcp@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":18806},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22"},"gitHead":"77042a3059c804f367cb50b5a0567ff867bdc8f1","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"diviscodude","email":"antonycelcius@gmail.com"},"repository":{"url":"git+https://github.com/PowerLaunch/apier-mcp.git","type":"git"},"_npmVersion":"10.9.7","description":"Thin npm proxy: connect local MCP clients (Claude Desktop, Cursor) to Apier's hosted Norwegian compliance MCP server.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.1.6","typescript":"^6.0.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.1_1779266735066_0.9988629611488535","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@apier-no/mcp","version":"1.0.0","keywords":["mcp","model-context-protocol","apier","norway","norwegian-compliance","altinn","skatteetaten","claude","cursor"],"author":{"url":"org.nr. 833 397 982","name":"Grov Digital"},"license":"MIT","_id":"@apier-no/mcp@1.0.0","maintainers":[{"name":"diviscodude","email":"antonycelcius@gmail.com"}],"homepage":"https://www.apier.no","bugs":{"url":"https://github.com/PowerLaunch/apier-mcp/issues"},"bin":{"apier-mcp":"dist/cli.js"},"dist":{"shasum":"d4690f2d18556a27eedbe3f28080494f4e5a5c5f","tarball":"https://registry.npmjs.org/@apier-no/mcp/-/mcp-1.0.0.tgz","fileCount":10,"integrity":"sha512-+WtQh02PosioJ4PWEcbPmmwHDyJLCX9kWXpa31F9ynr8+6AlanYONndSIdcsQ+ZHIr8jVZa8lPFxA0rtOhI+6w==","signatures":[{"sig":"MEUCIQC+YZyCU8LvmDQKtv60fJftEAupscy5bCy1leLH9TjelQIgMURGTeJiR7i+xtth5F4urcd7hB43KcsDlngv+adj19c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@apier-no%2fmcp@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":23083},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"2cc1231c0e753a613caa77fb22b5f459ac2b2454","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ab1f3748-6ea9-49d8-9caa-4f51c6bcccd7"}},"repository":{"url":"git+https://github.com/PowerLaunch/apier-mcp.git","type":"git"},"_npmVersion":"11.16.0","description":"Hardened thin proxy: connect local MCP clients (Claude Desktop, Cursor, Zed, Codex) to Apier's hosted Norwegian compliance MCP server at https://www.apier.no/api/mcp. Reads APIER_API_KEY from the environment and scrubs it from the spawned child process be","directories":{},"_nodeVersion":"22.22.3","dependencies":{"mcp-remote":"0.1.38"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.0.0_1779951506186_0.7018980768588794","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@apier-no/mcp","version":"1.1.0","keywords":["mcp","model-context-protocol","apier","norway","norwegian-compliance","altinn","skatteetaten","claude","cursor"],"author":{"url":"org.nr. 833 397 982","name":"Grov Digital"},"license":"MIT","_id":"@apier-no/mcp@1.1.0","maintainers":[{"name":"diviscodude","email":"antonycelcius@gmail.com"}],"homepage":"https://www.apier.no","bugs":{"url":"https://github.com/PowerLaunch/apier-mcp/issues"},"bin":{"apier-mcp":"dist/cli.js"},"dist":{"shasum":"66ac5495c4dc19cb754e648b67af30f4c7467262","tarball":"https://registry.npmjs.org/@apier-no/mcp/-/mcp-1.1.0.tgz","fileCount":10,"integrity":"sha512-B5dfNISruYeRip+CRfT4KHq3C1qsbbALouB0Yx5GBh9k2/LhgP2MMAcWR1ZZKFK0BpMW1Y0HZXzjX9NIAskBEQ==","signatures":[{"sig":"MEYCIQDuZTa0AqNTvwCMZxuOieRaizodS2QwSUNQy3nkaH2DFQIhAPzlL/df6dJjTtzx9Yd6D1CcjJhePVzCUkfNHz4QxBpC","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@apier-no%2fmcp@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":32453},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"6b5f874d5575f086d07c13e78773dc092ae8bbaa","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ab1f3748-6ea9-49d8-9caa-4f51c6bcccd7"}},"repository":{"url":"git+https://github.com/PowerLaunch/apier-mcp.git","type":"git"},"_npmVersion":"11.16.0","description":"Hardened thin proxy: connect local MCP clients (Claude Desktop, Cursor, Zed, Codex) to Apier's hosted Norwegian compliance MCP server at https://www.apier.no/api/mcp. Reads APIER_API_KEY from the environment and scrubs it from the spawned child process be","directories":{},"_nodeVersion":"22.22.3","dependencies":{"mcp-remote":"0.1.38"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.1.0_1779963853479_0.49744649920619755","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@apier-no/mcp","version":"1.2.0","keywords":["mcp","mcp-server","model-context-protocol","norway","norwegian","brreg","bronnoysund","altinn","compliance","company-data","kyc","regtech"],"author":{"url":"org.nr. 833 397 982","name":"Grov Digital"},"license":"MIT","_id":"@apier-no/mcp@1.2.0","maintainers":[{"name":"diviscodude","email":"antonycelcius@gmail.com"}],"homepage":"https://apier.no","bugs":{"url":"https://github.com/PowerLaunch/apier-mcp/issues"},"bin":{"apier-mcp":"dist/cli.js"},"dist":{"shasum":"7bc700f4ca2bf8a09479b7a3cbd1441d9d9e862b","tarball":"https://registry.npmjs.org/@apier-no/mcp/-/mcp-1.2.0.tgz","fileCount":10,"integrity":"sha512-8dPQz8kx7SYhIzqI22o2wzayBADBVOsM2DU1Ps/nhUHhuN7qa2XAuOrtUoljvWcyonm5Yu20pNAlJyBlYPJp8w==","signatures":[{"sig":"MEUCIQCe21Irju0hK1mWgwIXNn1rAgF8sVSqUOD1DNpnu5ea0wIgGH4BSlaozRowDGI41NaZQL4ZQ9ezEPhOhMNYVCp0HeY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@apier-no%2fmcp@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":47162},"main":"dist/index.js","type":"module","_from":"file:apier-no-mcp-1.2.0.tgz","types":"dist/index.d.ts","engines":{"node":">=20"},"scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ab1f3748-6ea9-49d8-9caa-4f51c6bcccd7"}},"_resolved":"/home/runner/work/apier-mcp/apier-mcp/apier-no-mcp-1.2.0.tgz","_integrity":"sha512-8dPQz8kx7SYhIzqI22o2wzayBADBVOsM2DU1Ps/nhUHhuN7qa2XAuOrtUoljvWcyonm5Yu20pNAlJyBlYPJp8w==","repository":{"url":"git+https://github.com/PowerLaunch/apier-mcp.git","type":"git"},"_npmVersion":"11.19.0","description":"Apier MCP Server — Norwegian company data and compliance for AI agents. Hardened thin proxy connecting local MCP clients (Claude Desktop, Cursor, VS Code, Zed) to Apier's hosted MCP server at https://www.apier.no/api/mcp: Brønnøysund company data, Altinn ","directories":{},"_nodeVersion":"22.23.1","dependencies":{"mcp-remote":"0.1.38"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^5.5.0","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_1.2.0_1786438250050_0.322946166486477","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@apier-no/mcp","version":"1.2.1","description":"Apier MCP Server — Norwegian company data and compliance for AI agents. Hardened thin proxy connecting local MCP clients (Claude Desktop, Cursor, VS Code, Zed) to Apier's hosted MCP server at https://www.apier.no/api/mcp: Brønnøysund company data, Altinn ","type":"module","bin":{"apier-mcp":"dist/cli.js"},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"scripts":{"build":"tsc","lint":"tsc --noEmit","test":"vitest run","prepublishOnly":"npm run build && npm test"},"publishConfig":{"access":"public","provenance":true},"repository":{"type":"git","url":"git+https://github.com/PowerLaunch/apier-mcp.git"},"homepage":"https://apier.no","bugs":{"url":"https://github.com/PowerLaunch/apier-mcp/issues"},"keywords":["mcp","mcp-server","model-context-protocol","norway","norwegian","brreg","bronnoysund","altinn","compliance","company-data","kyc","regtech"],"author":{"name":"Grov Digital","url":"org.nr. 833 397 982"},"license":"MIT","dependencies":{"mcp-remote":"0.1.38"},"devDependencies":{"@types/node":"^20.14.0","typescript":"^5.5.0","vitest":"^4.1.10"},"_id":"@apier-no/mcp@1.2.1","_integrity":"sha512-QmZl1P/1v21TZnE+Ak4AERQMLzhGzop0gFCd5MOE2X9fcvzr3TIKvaq/XSm/Lg0sIZXbuOP8LbqX5cn3B/7iuA==","_resolved":"/home/runner/work/apier-mcp/apier-mcp/apier-no-mcp-1.2.1.tgz","_from":"file:apier-no-mcp-1.2.1.tgz","_nodeVersion":"22.23.1","_npmVersion":"11.19.0","dist":{"integrity":"sha512-QmZl1P/1v21TZnE+Ak4AERQMLzhGzop0gFCd5MOE2X9fcvzr3TIKvaq/XSm/Lg0sIZXbuOP8LbqX5cn3B/7iuA==","shasum":"2c167e7304aed4d424a6f7338c0dd698e502a879","tarball":"https://registry.npmjs.org/@apier-no/mcp/-/mcp-1.2.1.tgz","fileCount":10,"unpackedSize":49834,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@apier-no%2fmcp@1.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIApbh5TOeEXOlu5/jZjOoD8JjnltNlDU2PknQggzpKN3AiBgAy4tq02jZydCUwmUSBHjJw1V2svVTHq+luXYYghscQ=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ab1f3748-6ea9-49d8-9caa-4f51c6bcccd7"}},"directories":{},"maintainers":[{"name":"diviscodude","email":"antonycelcius@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_1.2.1_1786537499173_0.23107902009823156"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-13T09:33:20.684Z","modified":"2026-08-12T12:24:59.692Z","0.1.0":"2026-05-13T09:33:21.033Z","0.1.1":"2026-05-20T08:45:35.208Z","1.0.0":"2026-05-28T06:58:26.310Z","1.1.0":"2026-05-28T10:24:13.620Z","1.2.0":"2026-08-11T08:50:50.197Z","1.2.1":"2026-08-12T12:24:59.330Z"},"bugs":{"url":"https://github.com/PowerLaunch/apier-mcp/issues"},"author":{"name":"Grov Digital","url":"org.nr. 833 397 982"},"license":"MIT","homepage":"https://apier.no","keywords":["mcp","mcp-server","model-context-protocol","norway","norwegian","brreg","bronnoysund","altinn","compliance","company-data","kyc","regtech"],"repository":{"type":"git","url":"git+https://github.com/PowerLaunch/apier-mcp.git"},"description":"Apier MCP Server — Norwegian company data and compliance for AI agents. Hardened thin proxy connecting local MCP clients (Claude Desktop, Cursor, VS Code, Zed) to Apier's hosted MCP server at https://www.apier.no/api/mcp: Brønnøysund company data, Altinn ","maintainers":[{"name":"diviscodude","email":"antonycelcius@gmail.com"}],"readme":"# Apier MCP Server — Norwegian company data and compliance for AI agents\n\n[Apier](https://apier.no) is a hosted [MCP](https://modelcontextprotocol.io) (Model Context Protocol) server that gives AI agents structured access to Norwegian company data and regulatory compliance. It resolves any 9-digit **organisasjonsnummer** (organisation number) against **Brønnøysundregistrene** (the Brønnøysund Register Centre / Enhetsregisteret), answers who holds **signing authority** for a company (**signaturrett** and **prokura**), reads **annual accounts** (årsregnskap) from Regnskapsregisteret, computes **filing deadlines** for MVA, A-melding and Årsregnskap, and brokers **fullmakt** — scoped, revocable company→agent authority delegated through an **Altinn 3** systembruker, authenticated upstream via **Maskinporten** against **Skatteetaten** and other agencies. This repository is the thin, hardened npm proxy (`@apier-no/mcp`) that connects local stdio MCP clients to the hosted server.\n\n## What you can ask\n\nWith this server connected, an AI agent can answer questions like:\n\n- \"What's the organisasjonsnummer for Equinor?\" *(search_companies)*\n- \"Who can legally sign on behalf of org number 923 609 016 — and is it signaturrett or prokura?\" *(get_company_authority)*\n- \"Is this company VAT-registered, and what regulatory obligations does it have?\" *(get_company_summary)*\n- \"What filing deadlines is this company facing in the next six months?\" *(get_company_deadlines)*\n- \"Show me the latest annual accounts (årsregnskap) for this company.\" *(get_company_accounts)*\n- \"What is the Altinn 3 equivalent of this old Altinn 2 role code?\" *(get_altinn_migration_guidance)*\n- \"What's the current Norges Bank exchange rate for EUR to NOK?\" *(get_exchange_rate)*\n- \"Request a fullmakt so I can act on behalf of this company, then verify it before filing.\" *(request_fullmakt, check_fullmakt)*\n\n## Tools\n\nAll 25 tools exposed by the hosted server at `https://www.apier.no/api/mcp` (discovered live via `tools/list`):\n\n| Tool | Description |\n|---|---|\n| `get_company_summary` | Retrieve a one-shot compliance summary for a Norwegian organisation by its 9-digit organisasjonsnummer (organisation number, the public ID issued by the Brønnøysund Register Centre / Enhetsregisteret — Central Register of Legal Entities). |\n| `get_public_obligations` | Retrieve the universal obligation set for a Norwegian entity type. |\n| `get_exchange_rate` | Fetch the most recent Norges Bank (Norway's central bank, Norges Bank in Norwegian — the official issuer of the krone) exchange-rate reference for a currency against NOK. |\n| `list_acting_capacity` | Resolve every Norwegian regulatory action a person is currently authorised to perform on behalf of a specific organisation. |\n| `get_company_profile` | Resolve a Norwegian organisasjonsnummer (9-digit org number) into a structured company profile sourced from Brønnøysund Enhetsregisteret (data.brreg.no). |\n| `check_authorization` | Return the authorisation snapshot for the calling consumer's delegation on a Norwegian organisation. |\n| `get_company_context` | Retrieve the structured Brønnøysund identity slice for a Norwegian organisation by its 9-digit organisasjonsnummer (organisation number, the public ID issued by the Brønnøysund Register Centre / Enhetsregisteret — Central Register of Legal Entities). |\n| `get_company_deadlines` | Compute the upcoming Norwegian regulatory filing calendar for a specific organisation, looking horizon_months into the future. |\n| `get_company_obligations` | Evaluate the Apier Rulebook for a Norwegian organisation and return every applicable regulatory obligation with its current state and the legal reference it derives from. |\n| `get_public_deadlines` | Compute the universal Norwegian regulatory filing calendar — the set of deadlines that apply to every Norwegian business of the covered categories (MVA, A-melding, Årsregnskap), independent of any specific organisation. |\n| `validate_action` | Run the Apier dry-run validator against a proposed regulatory action without producing ANY upstream side effect — no Maskinporten call, no Altinn / Skatteetaten / NAV submission. |\n| `explain_compliance_error` | Resolve a structured Apier compliance error code into a Norwegian-bokmål Explanation envelope sourced from the Apier Compliance Explainer (PR-049). |\n| `search_companies` | Resolve a Norwegian company NAME to its 9-digit organisasjonsnummer (organisation number). |\n| `get_company_verification` | Get the deterministic verification verdict for a Norwegian organisation by its 9-digit organisasjonsnummer (organisation number, the public ID issued by the Brønnøysund Register Centre / Enhetsregisteret). |\n| `get_company_authority` | Use this to answer \"who can legally sign for this Norwegian company, and how?\" before acting on its behalf. |\n| `get_company_accounts` | Use this for a current-snapshot read of a Norwegian company's annual accounts (årsregnskap) from the OPEN Regnskapsregisteret tier. |\n| `get_company_filing_history` | Use this to reconcile a Norwegian company's Altinn 3 filing history against the filings YOUR consumer submitted through Apier — the accountant/auditor reconciliation wedge. |\n| `list_changes` | Use this to read Apier's cross-source change archive — detected created / updated / deleted events across the upstreams Apier polls: Brønnøysund ingestion plus the multi-source pollers for Altinn schemas, DigDir policies, and Norges Bank rates. |\n| `get_altinn_migration_guidance` | Use this to discover the Altinn 3 equivalent of an Altinn 2 service or role code. |\n| `request_fullmakt` | Broker a fullmakt — a legally-grounded, scoped, revocable company→agent authority delegated through an Altinn systembruker (system user). |\n| `check_fullmakt` | Check your fullmakt state for a Norwegian company BEFORE acting on its behalf — the read leg of AGT-02 Fullmakt Rails and the natural follow-up to request_fullmakt. |\n| `revoke_fullmakt` | Revoke a fullmakt — withdraw an agent's delegated authority for a Norwegian company and retire the agent principal. |\n| `get_pricing` | Call this BEFORE metered work to check per-call cost and whether billing enforcement is live. |\n| `get_credit_balance` | Call this BEFORE a batch of metered calls to confirm the calling key's prepaid credit balance covers it, and AFTER a 402 INSUFFICIENT_CREDITS + human top-up to verify the funds landed before retrying. |\n| `redeem_issuance_token` | Call this to convert an owner-issued key-issuance token into your own API key — the headless onboarding step for an agent that holds no credential yet. |\n\n## Try without a key\n\nEvery Category B company endpoint has a zero-auth sandbox mirror under `/api/v1/sandbox/` on apier.no — no signup: where a bearer is expected, you invent your own on the spot. These are direct HTTP calls to the Apier API; starting this npm proxy itself still requires `APIER_API_KEY` (see [Quickstart](#quickstart)).\n\nList the canonical sandbox test data (no auth at all):\n\n```bash\ncurl -sL https://apier.no/api/v1/sandbox/fixtures\n```\n\nTrimmed response — `…` marks omitted fields:\n\n```text\n{\"success\":true,\"data\":{\"schema_version\":\"1.0.0\",\n  \"reserved_test_orgs\":[{\"org_number\":\"999000001\",\"name\":\"Sandbox AS\",\"entity_type\":\"AS\",\"data_tier\":\"tier_1\", …}],\n  \"realistic_orgs\":[{\"org_number\":\"818000006\",\"name\":\"Fjellberg Regnskap AS\",\"entity_type\":\"AS\",\"data_tier\":\"tier_1_2\"}, …],\n  \"magic_scenarios\":[{\"org_number\":\"999660010\",\"state\":\"konkurs\",\"label\":\"Bankrupt (konkurs)\"}, …], …}}\n```\n\nVerify the bankrupt fixture company with a self-invented bearer — any suffix of 1–64 chars from `A-Za-z0-9_-` after `apier_sandbox_test_` works; here bash's `$RANDOM` supplies one. (This call goes to the `www` host directly: the apex→www 308 redirect makes curl drop the `Authorization` header.)\n\n<!--\n  CI COUPLING — keep $RANDOM in the command below; do not substitute a literal\n  suffix. README.md ships inside the npm tarball, and the tarball-audit job in\n  .github/workflows/ci.yml greps the packed files for secret-shaped strings.\n  One of its patterns is the word Bearer, then whitespace, then 20 or more\n  characters from [A-Za-z0-9._+/=-]. The sandbox token prefix on the next line\n  is exactly 19 of those characters, and `$` falls outside the class, so the\n  run stops at 19 and the pattern does not match. Any literal suffix pushes it\n  to 20 or more and fails CI.\n-->\n\n```bash\ncurl -s -H \"Authorization: Bearer apier_sandbox_test_$RANDOM\" https://www.apier.no/api/v1/sandbox/company/999660010/verify\n```\n\nTrimmed response — `…` marks omitted fields:\n\n```text\n{\"success\":true,\"data\":{\"org_number\":\"999660010\",\"name\":\"Sandbox Konkurs AS\",\n  \"verification_status\":\"fail\",\n  \"signals\":{\"is_active\":false,\"not_bankrupt\":false, …},\n  \"summary\":\"Selskapet er ikke aktivt registrert i Enhetsregisteret.\", …}}\n```\n\nDon't confuse the two test prefixes: `apier_test_` is a production test-mode key that requires signup, while `apier_sandbox_test_` is self-generated and keyless. `GET /api/v1/sandbox/fixtures` is the canonical machine-readable table of sandbox test data.\n\n## Quickstart\n\n### Hosted endpoint (streamable HTTP)\n\nThe fastest path — no install. Point any streamable-HTTP-capable MCP client at:\n\n```text\nhttps://www.apier.no/api/mcp\n```\n\nDiscovery is **keyless**: `initialize`, `tools/list`, resources and prompts all work without credentials, so an agent can explore the full catalogue before authenticating. An API key (`Authorization: Bearer apier_live_…`) is needed only for protected tool calls. See https://www.apier.no/docs/authentication for how to get a key, then create one in the dashboard at https://www.apier.no/dashboard.\n\n### npx stdio proxy (`@apier-no/mcp`)\n\nFor stdio-only clients, this package wraps [`mcp-remote`](https://github.com/geelen/mcp-remote), reads `APIER_API_KEY` from your environment, removes it from the spawned child's environment, redacts it from stderr, and hands the bearer value over out-of-band so it never appears on the child's command line — see [SECURITY.md](./SECURITY.md).\n\n**Published as `@apier-no/mcp`.** The `@apier` scope was unavailable, so this package ships under the `@apier-no` scope.\n\n**Claude Desktop / Cursor** (`claude_desktop_config.json` / `~/.cursor/mcp.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"apier\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@apier-no/mcp\"],\n      \"env\": { \"APIER_API_KEY\": \"apier_live_<your_key_here>\" }\n    }\n  }\n}\n```\n\n**VS Code** (`.vscode/mcp.json`):\n\n```json\n{\n  \"servers\": {\n    \"apier\": {\n      \"type\": \"stdio\",\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@apier-no/mcp\"],\n      \"env\": { \"APIER_API_KEY\": \"apier_live_<your_key_here>\" }\n    }\n  }\n}\n```\n\n**Zed** (`settings.json`):\n\n```json\n{\n  \"context_servers\": {\n    \"apier\": {\n      \"source\": \"custom\",\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@apier-no/mcp\"],\n      \"env\": { \"APIER_API_KEY\": \"apier_live_<your_key_here>\" }\n    }\n  }\n}\n```\n\nReady-to-paste config files for each client live in [`examples/`](./examples).\n\n## Configuration\n\n| Variable | Required | Default |\n|---|---|---|\n| `APIER_API_KEY` | yes | — |\n| `--endpoint <url>` | no | `https://www.apier.no/api/mcp` |\n| `MCP_REMOTE_CONFIG_DIR` | no | `~/.mcp-auth` |\n\n## Security\n\n- `APIER_API_KEY` is read by the parent process and **scrubbed from the spawned child's environment**, and stderr is passed through a redactor that strips `Bearer …`, `apier_(live|test)_…`, `ghp_…`, and `Authorization:` substrings.\n- **The key never appears in the child's command line.** The `--header` argument carries only the placeholder `Authorization:${APIER_MCP_AUTH_HEADER}`; the bearer value is passed out-of-band in that variable and expanded by `mcp-remote` at request time. Command lines are world-readable on Linux (`/proc/<pid>/cmdline`), process environments are not — so this is no longer readable by other local users ([#33](https://github.com/PowerLaunch/apier-mcp/issues/33), fixed in 1.2.0). An attacker already running as you can still read the environment — see [SECURITY.md](./SECURITY.md).\n- Non-https endpoints are rejected before spawn; `mcp-remote` is exact-pinned and releases are published with npm provenance via GitHub Actions Trusted Publishing (OIDC).\n- Treat client config files (`claude_desktop_config.json`, `.cursor/mcp.json`, …) like `.env` files — never commit them with a real key.\n\nFull threat model and disclosure policy: [SECURITY.md](./SECURITY.md).\n\n## Documentation\n\n- MCP server docs: https://www.apier.no/docs/mcp\n- Apier platform docs: https://apier.no/docs\n\n## License\n\nMIT\n","readmeFilename":"README.md"}