MCP server for integrating with Autumn billing and entitlements API
AutumnMCP has basic tool definitions with schemas and descriptions, but falls short of production-grade quality. All four tools are explicitly registered with Zod schemas and descriptions, which is a good foundation. However, descriptions are minimal (10-50 characters), parameter descriptions lack depth and constraints, output schemas are not documented, and error handling is generic. The server follows verb_noun naming correctly (get_*, create_*) but lacks the contextual richness needed for reliable LLM tool selection. Notably, the create_customer tool has no output schema documentation, and none of the tools specify what they return beyond generic JSON responses. Error handling returns raw API errors without recovery guidance.
Create a new customer
Get a user by ID
Get the billing portal for a user
Get a specific entitlement set for a user
Output schemas completely undocumented. All four tools return JSON responses but nowhere do the tool definitions specify what fields are returned, their types, or structure. LLMs cannot know what to expect or plan downstream calls.
Descriptions too brief (10-50 chars) and lack actionable context. Current descriptions like 'Get a user by ID' and 'Get a specific entitlement set for a user' provide minimal guidance for LLM tool selection.
Parameter descriptions lack constraints and format guidance. All parameters ('id', 'name', 'email', 'feature_id') have basic descriptions but no format hints, valid ranges, or relationship explanations. E.g., 'email' should specify valid format; 'id' should clarify if it accepts usernames or only internal IDs.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 45 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 32 | - | v1 |
Error responses provide no recovery guidance. The returnError() function returns raw API errors (status, statusText) without actionable suggestions. Try search_users() with a partial name.' Current errors leave agents blocked.
No parameter type validation documented. While Zod schemas define types (z.string()), there is no validation on format (email regex), length, or enum constraints visible in descriptions. LLMs will not discover these constraints and will pass invalid values.
create_customer description does not explicitly state it modifies state. Current description 'Create a new customer' is passive and fails to highlight irreversible action.
API key passed as command-line argument. While not a parameter, this exposes the API key in process arguments visible in system logs and ps output. Per pattern:secret-injection, secrets should use environment variables or vault.
getBillingPortal endpoint has incorrect URL template. Code shows '/customers/:id/billing_portal' with params.id injection, but most APIs require explicit string interpolation. This may cause API calls to fail if :id is not properly substituted.