Integrations · MCP

Use Nefin in Gemini

Add Nefin as a custom app in the Gemini app, or as a custom MCP server in Gemini Enterprise, and ask about your books in a chat. Gemini works as you and can do only what you can do.

Server URL
https://api-books.nefin.app/mcp
Paste this into Gemini when you add the app.

Before you start

  • The Gemini app or Gemini Enterprise. Google offers custom apps in the Gemini app in some places and accounts only. See Google’s custom apps help. In Gemini Enterprise a team admin adds the server.
  • A Nefin account with two-step verification. If you haven’t set it up, Nefin walks you through it the first time you connect.
  • AI switched on for at least one company. An owner turns it on in Settings → Company. Gemini can only reach companies where AI is on.
  • The Professional or Business plan in Nefin. Starter companies show up as locked, with an upgrade link.

The Gemini app

1

Add a custom app

On gemini.google.com open Settings, then Connected Apps. Under Custom apps choose Add a custom app. Google lists what you need for this in its help page.

2

Enter Nefin's server URL

Paste the server URL:

https://api-books.nefin.app/mcp

Leave the credentials empty. Nefin supports dynamic client registration, so Gemini registers itself. Click Next.

3

Connect and allow access

Follow the prompts. Nefin opens in a browser window. Sign in as usual, including your two-step code. Nefin shows which companies Gemini will reach and what it can do. The connection is read-only unless you turn on Allow changes. Click Allow access and you go back to Gemini.

If the screen asks for a client ID and secret, see the Advanced section.

Gemini Enterprise

An admin adds Nefin once. Each member then signs in with their own Nefin login, so everyone keeps their own permissions and the audit log shows who did what.

1

Add the MCP server

In Gemini Enterprise, Business edition, open Settings & help, choose your team, then Manage team, Connected apps and Add MCP Server. Google describes this in its help page. In the Google Cloud console the same setup is a custom MCP server data store, described in Google’s documentation.

2

Fill in the server and sign-in details

Use these values. Gemini Enterprise asks for them one by one:

Server URL
https://api-books.nefin.app/mcp
Authorization URL
https://api-books.nefin.app/oauth/authorize
Token URL
https://api-books.nefin.app/oauth/token
Scopes
nefin:read nefin:write

Choose OAuth 2.0 for authentication and switch on PKCE support if the form has that option. Nefin requires PKCE. Use nefin:read alone as the scope if the AI should never be able to change anything.

The form also asks for a client ID and client secret. Get them from the next section.

3

Enable it

Google adds the server disabled. An admin has to enable it before the team can use it. Each member then connects with their own Nefin account.

Advanced: register a client ID and secret

Gemini Enterprise, and some Gemini app setups, cannot register themselves and ask for a client ID and secret instead. Nefin gives you both from one call. You need the redirect URI the console shows. For Gemini Enterprise it is:

https://vertexaisearch.cloud.google.com/oauth-redirect

Run this in a terminal. Put the console’s redirect URI in the command:

Terminal
curl -X POST https://api-books.nefin.app/oauth/register \
  -H "Content-Type: application/json" \
  -d '{
    "client_name": "Gemini Enterprise",
    "redirect_uris": ["https://vertexaisearch.cloud.google.com/oauth-redirect"],
    "token_endpoint_auth_method": "client_secret_post"
  }'

Nefin answers with JSON. Paste client_id and client_secret into the console’s client ID and client secret fields. The secret is shown once, so copy it right away.

Keep the secret private. Anyone who has the client ID and secret can start a Nefin sign-in as that app, but still needs a real Nefin login and the person’s approval on Nefin’s consent screen. Don’t put the secret in a shared document. The client name may not contain the word Nefin.

Use it in a chat

Make sure Nefin is switched on for the chat. In the Gemini app you can type @ to choose which connected app Gemini should use. Then just ask:

  • “List my Nefin companies.”
  • “Which invoices in Acme Ltd are overdue, and who owes the most?”
  • “In Acme Ltd, run the profit and loss for last quarter and compare it with the quarter before.”
  • “In Acme Ltd, draft an invoice for Bardhi SHPK: 10 hours of consulting at 45.00, standard VAT.”
  • “In Acme Ltd, show me every bill from Bardhi SHPK this year and the total we paid.”
  • “Get Nefin's guide for bank statements, then reconcile this statement for Acme Ltd.”
  • “Get Nefin's guide for payroll, then show me last month's payroll run in Acme Ltd.”
Name the company in your request

Start with the company, such as “in Acme Ltd, …”. If you have only one company, Gemini picks it for you. If you have several and don’t say which, Gemini asks you before it does anything.

Every answer says which company it used and links to the record in Nefin, so you can check it in one click.

Ask for the workflow first

Bigger jobs take several steps in a fixed order. Nefin keeps those steps in short guides that Gemini reads on demand with the get_guide tool. Nefin tells Gemini to fetch one before bank statement, payroll or tax payment work, and you can ask for one yourself. Gemini then follows the guide instead of guessing the order. The guides are:

  • bank_statements: importing a bank statement and reconciling it
  • payroll: running payroll
  • tax_payments: paying income tax, pension, VAT or a tax debt
  • errors: what to do when Nefin refuses something

For example: “Get Nefin’s guide for bank statements, then reconcile this statement for Acme Ltd.”

Amounts come back as exact decimals, so nothing gets rounded along the way.

What Gemini can do

Nefin gives Gemini 26 tools. Each one works in one company at a time, so name the company in your request. With one company Gemini uses it automatically. With several, Gemini asks which one you mean.

Read

Never changes anything.
list_companiesSee the companies you can work in and your role in each
get_guideRead the step-by-step guide for a bigger job, such as a bank statement or payrolltopic: bank_statements · payroll · tax_payments · errors
run_reportRun a financial report, such as profit and loss, balance sheet or agingtype: trial-balance · profit-loss · balance-sheet · aging-receivable · aging-payable · general-ledger · tax-summary · cash-flow · budget-vs-actuals · cash-projection · sales-book · purchase-book
search_recordsFind a contact, document, item or account by name or number
list_contactsList customers and vendors with what they owe or are owed, or open onetype: customer · vendor
list_documentsList invoices and bills, or open one with its lines and paymentsdocType: invoice · bill
list_setupList your accounts, items, VAT rates and stock levelskind: account · item · vat_rate · stock_level
list_journalsList journal entries, optionally for a date range or status
list_paymentsList payments received and paid, including drafts waiting to be connected
list_bank_accountsList your bank accounts with their balances and open statement lines
list_bank_transactionsList imported bank statement lines and whether each one is matched
get_bank_reconciliationCheck a bank account against its statement and see what explains the difference
get_payrollRead salaries, adjustments, payroll runs and payslips, or calculate a salary

Create and update drafts

Records and drafts. Nothing reaches the ledger yet.
save_contactAdd a customer or vendor, or update an existing onetype: customer · vendor · both
create_setupAdd a ledger account, an item or a VAT ratekind: account · item · vat_rate
create_documentCreate a draft invoice or billdocType: invoice · bill
import_bank_statementImport bank statement lines for matching; nothing is posted yet
set_salarySet or change how an employee is paid

Post, correct or delete

Flagged as destructive, so the AI app should confirm with you first.
update_documentChange an invoice or bill; new lines on an activated one reverse and re-post its entrydocType: invoice · bill
delete_documentDelete a draft or void invoice or billdocType: invoice · bill
activate_documentFinalize a draft invoice or bill and post it to the booksdocType: invoice · bill
record_paymentRecord a payment received or paid and apply it to invoices or bills
manage_journalCreate a manual journal entry as a draft, or post a draft to the books
reconcile_bank_linesBook imported statement lines as payments, transfers, fees or journal entries
mark_bank_period_reconciledMark a bank account as reconciled up to a statement date and lock that period
run_payrollCreate, approve and pay a payroll run, and manage recurring payroll adjustments
Tools that were renamed

Old names keep working for now, so saved prompts and scripts don’t break. Permissions and allowlist entries belong to a tool’s name, so set them again on the new tool.

  • get_contact → list_contacts
  • get_document → list_documents
  • list_accounts → list_setup
  • list_items → list_setup
  • list_vat_rates → list_setup
  • list_stock_levels → list_setup
  • list_draft_payments → list_payments
  • create_contact → save_contact
  • update_contact → save_contact
  • create_account → create_setup
  • create_item → create_setup
  • create_vat_rate → create_setup
  • create_invoice → create_document
  • create_bill → create_document
  • update_invoice → update_document
  • update_bill → update_document
  • delete_invoice → delete_document
  • delete_bill → delete_document
  • send_invoice → activate_document
  • receive_bill → activate_document
  • create_journal → manage_journal
  • post_journal → manage_journal
  • connect_draft_payment → record_payment

Staying in control

  • Read-only by default. The consent screen has an Allow changes switch that starts off. Leave it off and Gemini can look things up and run reports but cannot create or change anything.
  • Your permissions, nothing more. Gemini works as you in each company. If your role can’t post journals, neither can Gemini.
  • Everything is on the record. Changes appear in the audit log under your name.
  • Check before you approve. Read what Gemini proposes before you let it change your books, especially the tools that post, correct or delete: update_document, delete_document, activate_document, record_payment, manage_journal, reconcile_bank_lines, mark_bank_period_reconciled and run_payroll.

To cut off access, go to Account → AI connectors in Nefin and click Disconnect next to Gemini. It takes effect immediately. To remove Nefin from Gemini as well, delete the custom app in Gemini’s settings.

Limits in each AI app

Every AI app has its own limits. This table shows what each one means for Nefin and what to do about it. The app on this page is first.

AI appTool namesLong instructionsSigning inApproving actionsAfter a change
GeminiGemini Enterprise recommends at most 100 enabled actions per server, well above what Nefin has.No cut-off is documented. For a long job, ask Gemini to get Nefin's guide first.Nefin registers the app for you where the console supports it. Where it asks for a client ID and secret, register one with the command in the guide.The connection is read-only unless you turn on Allow changes when you connect. Check what Gemini proposes before you approve a change.Disconnect and reconnect Nefin in the app's settings after anything changes.
Claude appsNothing to set. Tool names are capped at 64 characters and every Nefin tool name fits.Nothing to work around. For a long job, ask Claude to get Nefin's guide first.Choose Register automatically when you add the connector. Do not pick Use Claude's published identity, which Nefin does not support yet.Set each Nefin tool to Always allow, Needs approval or Blocked in Customize, Connectors.Start a new chat after anything changes. Each conversation keeps the tool list it started with.
Claude CodeNo limit to manage for Nefin's tools.Server instructions and each tool description are cut at 2 KB, so Nefin keeps long workflows behind get_guide. Ask Claude to get the guide before a big job.Run /mcp, choose nefin and pick Authenticate. Where no browser can open, send a personal token in the Authorization header instead.Claude Code asks before each tool you have not allowed. Allow the ones you trust in .claude/settings.json.Run /mcp and reconnect nefin after anything changes. A running session keeps the tool list it started with.
ChatGPTNothing to set for Nefin's tools.Nefin keeps its most important rules in the first 512 characters of its instructions and puts long workflows behind get_guide. Ask ChatGPT to get the guide before a big job.Choose OAuth and leave the client ID and secret empty, so ChatGPT registers itself with Nefin.ChatGPT asks you to confirm actions that change data. Nefin marks its read tools as read-only, so lookups run without a prompt.Refresh the app in ChatGPT's connector settings after anything changes, then start a new chat.
Cursor, VS Code, Gemini CLICursor loads about 40 tools across all connected servers and drops the rest. Turn off Nefin tools you don't use, or other servers. VS Code and Gemini CLI have no such cap for Nefin.Nothing to work around. For a long job, ask the agent to get Nefin's guide first.Add the server URL and sign in when the app opens Nefin in your browser. A personal token in the headers works in all three.Each app asks before it runs a tool unless you told it to trust or auto-run that tool. Leave that off for the tools that post.Toggle the server off and on in Cursor or VS Code, or restart Gemini CLI, after anything changes.

Troubleshooting

I can't find the custom app option in the Gemini app
Google offers custom apps in the Gemini app only in some places and accounts. It needs a personal Google account, an adult user in the United States, and Keep Activity switched on. Work and school accounts don't have it. Gemini Enterprise has its own setup, described above.
The console asks for a client ID and secret
Some Gemini setups can't register themselves with a server. Register a client with the command in the Advanced section, then paste the client_id and client_secret it returns.
Registration says the redirect URI is not valid
Nefin accepts https redirect URIs only, and the register call must include the exact redirect URI the console shows. Copy it from the console again. The client name may not contain the word Nefin.
Sign-in fails after I approve
The client secret or redirect URI doesn't match what you registered, or the console isn't sending the sign-in code with PKCE. In Gemini Enterprise switch on PKCE support and paste the exact values from the registration answer.
The Nefin sign-in page says AI features are not enabled
None of your companies has AI switched on. Ask an owner to turn it on in Settings, Company, then connect again.
Gemini can't find a company
Gemini only sees companies where AI is on and where you are an active member. Ask it to list your Nefin companies to see exactly what it can reach.
Gemini asked which company to use
You belong to more than one company, so Gemini asks before it does anything. Name one, for example "in Acme Ltd, ...". With only one company Gemini picks it for you.
Gemini doesn't see a tool or uses an old tool name
Disconnect and reconnect Nefin in the app's settings so Gemini reads the tool list again, then start a new chat.
A change was refused
The connection is read-only unless you turned on Allow changes when you connected. To change that, disconnect Nefin under Account, AI connectors, and connect again with Allow changes on. Your role in the company must also allow the action.

Using a different AI app?

The same server works elsewhere. Nefin has a setup guide for Claude apps, Claude Code, ChatGPT and Cursor, VS Code, Gemini CLI. See all of them on the integrations page.