
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
Unofficial read-only MCP server for the wFirma API v2 (api2.wfirma.pl): companies, invoices, contractors, expenses, payments.
Unofficial, read-only MCP server for the wFirma API v2
(api2.wfirma.pl). Gives MCP-compatible AI assistants typed, read-only access
to company data, invoices, contractors, expenses, and payments — with
credentials that never leave your machine and no commercial middleware between
you and wFirma.
Not affiliated with wFirma. "wFirma" is a trademark of its respective owner.
| Tool | Endpoint |
|---|---|
wfirma_list_companies | GET /user_companies/find |
wfirma_list_invoices | GET /invoices/find |
wfirma_get_invoice | GET /invoices/get/{id} |
wfirma_list_contractors | GET /contractors/find |
wfirma_get_contractor | GET /contractors/get/{id} |
wfirma_list_expenses | GET /expenses/find |
wfirma_get_expense | GET /expenses/get/{id} |
wfirma_list_payments | GET /payments/find |
wfirma_get_payment | GET /payments/get/{id} |
Every company-scoped tool requires the internal companyId returned by
wfirma_list_companies. A Polish NIP is not accepted as a company id.
The server intentionally contains no add, edit, delete, send, fiscalization,
KSeF, or payment-mutation operation. The full list of excluded categories,
reviewed against the official documentation at
doc.wfirma.pl, is recorded in
coverage-manifest.json. If you need writes, use
wFirma's own tooling — not this server.
wFirma API keys are created in your wFirma panel (Integrations → API). Required environment variables:
WFIRMA_ACCESS_KEYWFIRMA_SECRET_KEYWFIRMA_APP_KEYSee .env.example. Never commit real values.
pnpm install
pnpm build # → dist/index.js (self-contained esbuild bundle)
pnpm test # all HTTP traffic is mocked; no live account needed
{
"mcpServers": {
"wfirma": {
"command": "node",
"args": ["/absolute/path/to/wfirma-mcp/dist/index.js"],
"env": {
"WFIRMA_ACCESS_KEY": "your-access-key",
"WFIRMA_SECRET_KEY": "your-secret-key",
"WFIRMA_APP_KEY": "your-app-key"
}
}
}
}
claude mcp add wfirma -- node /absolute/path/to/wfirma-mcp/dist/index.js
https with a hard 20s timeout and a bounded response-size
guard.wfirma_* error code instead of a generic failure.coverage-manifest.json maps every tool to its
endpoint, risk class, and the test that proves it; a CI test enforces the
manifest stays in sync with the source.FAQs
Unofficial read-only MCP server for the wFirma API v2 (api2.wfirma.pl): companies, invoices, contractors, expenses, payments.
The npm package wfirma-mcp receives a total of 27 weekly downloads. As such, wfirma-mcp popularity was classified as not popular.
We found that wfirma-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.