
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Your AI agent, fluent in Australian tax. MCP server with cited answers from 34,500+ ATO documents, the income tax and GST Acts and 4,900+ rulings — plus deduction, depreciation, BAS and audit-risk tools that know your tax profile.
Your AI agent, fluent in Australian tax.
Cited answers from 34,500+ ATO documents, the income tax and GST Acts and 4,900+ public rulings — plus tax workflow tools that know your situation.
First, install the ATO MCP server with your client.
Standard config works with most tools that run stdio servers:
{
"mcpServers": {
"ato": {
"command": "npx",
"args": ["-y", "ato-mcp"]
}
}
}
npm install -g ato-mcp # optional — npx works without installing
For hosts that natively support remote MCP servers, connect your client directly:
claude mcp add --transport http ato https://api.ato-mcp.com.au/mcp
Then run /mcp inside Claude Code, select ato, and choose Authenticate —
your browser opens to sign in.
codex mcp add ato --url https://api.ato-mcp.com.au/mcp
codex mcp login ato
codex mcp login opens your browser to sign in.
gemini mcp add --transport http ato https://api.ato-mcp.com.au/mcp
Gemini CLI detects the auth challenge on first use and opens your browser automatically.
Or from the command line:
code --add-mcp '{"name":"ato","type":"http","url":"https://api.ato-mcp.com.au/mcp"}'
VS Code prompts to authenticate in your browser when the server first connects.
Or add to ~/.cursor/mcp.json:
{
"mcpServers": {
"ato": {
"url": "https://api.ato-mcp.com.au/mcp"
}
}
}
Cursor shows a "Needs login" prompt on the server — click it to sign in via your browser.
Add to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"ato": {
"type": "streamable-http",
"serverUrl": "https://api.ato-mcp.com.au/mcp"
}
}
}
If Windsurf doesn't open a sign-in window, use the standard npm config at the top of this section instead — it handles the browser sign-in itself.
https://api.ato-mcp.com.au/mcpAvailable on paid Claude plans. Claude Desktop can alternatively use the standard
npm config at the top of this section in claude_desktop_config.json.
https://api.ato-mcp.com.au/mcpRequires a plan with connector support.
Use the standard npm config at the top of this section — this package bridges any stdio host to the hosted server with the same browser sign-in.
Full instructions available here.
| Source | Contents |
|---|---|
| ato.gov.au | 23,000+ guidance pages, forms & instructions, occupation guides |
| Legislation | ITAA 1997, ITAA 1936 and the GST Act — 6,468 sections + 2,310 statutory definitions, point-in-time aware |
| Public rulings | 4,900+ rulings across 10 types (TR, TD, GSTR, GSTD, PR, CR, LCR, PCG, MT, FTR), withdrawn rulings flagged |
| Citation graph | 64,217 cross-references between rulings and legislation |
| Thresholds | Time-keyed scalars: IAWO, GST registration, CGT discount, super caps, … |
34,500+ documents (286,000+ searchable passages), hybrid-indexed (BM25 + vector), refreshed monthly.
Retrieval — search (hybrid keyword + semantic), get_doc, get_chunks,
get_doc_anchors (citation graph), get_definition (statutory, point-in-time),
get_threshold (time-keyed scalars), fetch, stats.
Personal context — get_user_facts: 25 facts captured once at onboarding
so the agent never re-asks.
Workflows — deterministic, cited, branched on your taxpayer structure:
| Tool | What it does |
|---|---|
deduction_discovery | Every deduction category that plausibly applies to your profile |
depreciation_helper | Prime-cost / diminishing-value / instant-write-off / pool schedules |
bas_prep_checklist | A tiered, cited BAS checklist for your reporting period |
audit_risk_check | Flags the patterns the ATO scrutinises in a draft return |
Full reference: docs/tools.md
This service is provided as information infrastructure, not tax advice. It does not consider your full financial circumstances and it is not a registered tax agent service. Confidence ratings and risk bands are heuristic indicators, not professional judgement. Verify material decisions with a registered tax agent.
ATO content remains subject to ATO publication terms. ITAA 1997 text is reproduced from the Federal Register of Legislation under its open licensing.
See the Terms of Service & Privacy Policy for more details.
License AGPL-3.0 © William Laverty
The hosted platform and corpus are proprietary. Commercial licensing available on request.
FAQs
Your AI agent, fluent in Australian tax. MCP server with cited answers from 34,500+ Australian Taxation Office documents
The npm package ato-mcp receives a total of 284 weekly downloads. As such, ato-mcp popularity was classified as not popular.
We found that ato-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.