For Claude, ChatGPT and Gemini CLI

Check a funding package from your chat window.

Ask your assistant to look at a funding request and its invoices. Plumbline runs the same twelve checks every time, quotes the numbers it verified, and names what it could not. Setup takes about a minute once your organization subscribes.

A person makes every funding decision

Copy this link first. Every setup below asks for it.

https://mcp-dev.plumbline.cloud/mcp

The first connection signs you in with Google, Microsoft or an emailed code. There is no key to paste. Plumbline creates your organization from your email domain, and one plan covers every user in it. Plumbline's login provider is Clerk, so the Google screen will say it is continuing to Clerk.

Set it up

Pick the assistant you already use. Each setup ends with the same first question, so you know the connection works before you send anything of yours.

Claude

Subscribe first at https://dev.plumbline.cloud/pricing.

Works on any plan. A free account can hold one of these at a time.

  1. Open Customize, then Connectors.
  2. Press Add in the top-right corner.
  3. Paste the link into the box and name it Plumbline.
  4. The second screen already has the right sign-in settings, each marked Detected. Keep them and press Add.
  5. On the Plumbline page, press Connect. The sign-in page opens in the same tab; press Continue with Google and use your work account.
  6. Press Allow to let Claude use Plumbline.

You are done when Claude shows Connected to Plumbline and lists seven tools. The first time Claude uses a tool it asks first; press Allow once or Always allow. Start a new chat and ask:
“What can you verify, and what do you need from me?”

On a Team or Enterprise plan an owner adds it once for everybody, and you press Connect on the row they created.

ChatGPT

Subscribe first at https://dev.plumbline.cloud/pricing.

Needs a paid plan (Plus, Pro, Business, Enterprise or Edu) and a web browser. The phone app cannot do this yet.

  1. Open Settings, then Security and login, and switch on Developer mode.
  2. Go to Plugins and press the plus button.
  3. Name it Plumbline and paste the link into the connection box.
  4. Choose OAuth, create it, and sign in with Google when the window opens.
  5. ChatGPT lists seven tools it found. Switch them on.

You are done when those seven tools are switched on. Your new app sits under Drafts until someone publishes it. Start a new chat, pick Plumbline, and ask:
“What can you verify, and what do you need from me?”

To give it to a whole team, an admin opens Workspace Settings, then Apps, and publishes it from Drafts.

Gemini CLI

Subscribe first at https://dev.plumbline.cloud/pricing.

Needs the Gemini CLI. The Gemini website and phone app have no place to add a server yet, and Gemini Enterprise is set up by an administrator.

  1. Open a terminal in a folder you have told Gemini to trust, then run:
    gemini mcp add --transport http --scope user plumbline https://mcp-dev.plumbline.cloud/mcp
  2. Start gemini and type /mcp. Sign in with Google in the browser tab that opens.

You are done when /mcp lists plumbline as connected with seven tools. Then ask:
“What can you verify, and what do you need from me?”

Gemini CLI refuses to start a server from a folder it does not trust; trust the folder first, at user level.

Claude on the web was connected to this server and checked on 2026-09-16. Claude Code and the MCP Inspector were checked on 2026-09-15. The ChatGPT setup follows the vendor's current published instructions and has not yet been captured against this server. The Gemini CLI command was confirmed to write the server on 2026-09-15; the connection itself is still to be captured.

Ask it plainly

Plain questions work. You never have to name a tool.

“Check this funding request against the invoices and tell me what doesn't add up.”

“Which checks couldn't you finish, and what document is missing?”

“Write up what you found for the person who has to approve this.”

Nothing of yours is needed to try it. Ask for the sample package with a missing document, and watch eleven of the twelve checks report that they never ran.

Where it stops

It will

  • Run the same twelve checks, in the same order, every time
  • Name every check it could not run, and say why
  • Quote the amounts and names it verified
  • Write up what it found, for a person who has to decide

It won't

  • Approve or decline funding
  • Move, release or schedule any money
  • Sign off an exception or a waiver
  • Change banking instructions
  • Overrule a finding, even if you ask it to

None of that is a setting somebody could turn on. Those tools do not exist on this server, and a test fails if anyone adds one.

Kept

  • Tool name, timing, and outcome per call
  • Every document you send that the server read, as you sent it, for 30 days. A call the server refused before reading its documents (too many, too large, an unsupported type) keeps the refusal and the names and sizes of its files, not the files
  • The arguments of each call and the answer it got back, for the same 30 days, including calls the engine or the extraction refused, up to a daily ceiling per account; past it a call keeps its envelope and file summary only, and the row says so
  • A SHA-256 of submitted evidence
  • The sample package id and run id a call referred to
  • The engine's result for six hours, then deleted.
  • For an extraction: each field's path, confidence, and source
  • Client name and version, user agent, country, and a daily salted IP hash
  • When you sign in: your Clerk account id, the OAuth client you connected through, the scopes it was granted, and that the call was authenticated
  • When a platform calls for you: the workspace id and member id it names, so a workspace can total its own usage
  • For a subscribed organization: its organization id, a count of supplier screens and documents per calendar month, and whether each call went past the included allowance
  • Model token counts

Never kept

  • Raw IP addresses
  • Your name or your email — the record holds an opaque account id, never the address behind it
  • Your sign-in token
  • A whole bank account number sent as a field — an account number or an IBAN you type into the banking check is cut to the last four digits and a salted hash before the record is written. A number written inside a document or inside pasted text is part of that document, and documents are kept as sent, above

One caution, new on 15 September 2026. The operator keeps what you submit: the documents, the call, the answer. Counts outlive the 30 days; the documents do not. Signing in with Google ties each call to an opaque account id. The record holds no name or email, but the operator can look that id up in Clerk, so treat what you send as attributable to your account. Send the sample packages and your own documents. A customer's documents are a decision for whoever owns them.

Your connection

Sign-in is a Google grant to Plumbline's sign-in service, Clerk. Removing the connector in your assistant ends its access. Removing the Google grant stops any new sign-in; an assistant that is already signed in keeps working until its token expires or you remove the connector there.

Disconnecting does not delete what you already sent. Where it stops lists what is kept and for how long.

For developers

Command line

Claude Code

verified 2026-09-15
claude mcp add --transport http plumbline https://mcp-dev.plumbline.cloud/mcp

MCP Inspector

verified 2026-09-15
npx @modelcontextprotocol/inspector --cli https://mcp-dev.plumbline.cloud/mcp --transport http --method tools/list

Gemini CLI

gemini mcp add --transport http --scope user plumbline https://mcp-dev.plumbline.cloud/mcp

Gemini CLI refuses to start any MCP server from an untrusted folder, so trust the folder first.

Tools
  • check_banking_format Check banking identifiers for well-formedness
  • explain_verification_run Explain a run in plain language
  • get_evidence_requirements Get evidence requirements
  • get_review_artifact Get the review artifact for a run
  • get_verification_capabilities Get verification capabilities
  • get_verification_run Get the control trace for a run
  • verify_funding_package Verify a funding package

Transport is Streamable HTTP with no session. Sign-in is OAuth through Clerk with a Google account; every request carries a bearer token the server verifies before any tool runs. Evidence read from a document by a language model comes back labelled untrusted, carrying a confidence and a source for every field.

Limits
  • max_documents 10
  • max_total_bytes 26214400
  • max_pages 100
  • media_types application/pdf, image/png, image/jpeg, text/plain
  • max_lines 100
  • max_supporting_invoices 75

Per client: 60 calls per ten minutes. Over a limit, the server answers with a retry delay.