InvoiceShelf
Open source invoicing solution for individuals and businesses
Alternative to: freshbooks, invoice ninja, zoho invoice
3.0.0-alpha.5
2026-09-23Fifth public alpha of InvoiceShelf 3.0. AI assistants can now work in InvoiceShelf: Claude, ChatGPT, Claude Code and Cursor connect over the Model Context Protocol and read, draft and send documents with the permissions of the user who connected them. The release also brings a headless install for servers that are configured rather than clicked through, the demo mode behind demo.invoiceshelf.com, and images on GHCR.
⚠️ Pre-release, not for production. Back up your database before upgrading and use this release for evaluation and testing only.
Security
- The setup wizard’s token worked as a super-administrator sign-in. Sent without the wizard’s header it opened the whole API, and nothing revoked it once the install finished. It now opens the installer alone, only while the install is unfinished, and finishing the install revokes it. (#847)
Highlights
- Connect an AI assistant. An MCP server at
/mcp, off until a super administrator switches it on under Administration > Settings > AI connections (orphp artisan mcp:enable). Assistants sign in with OAuth, and each connection is bound to one user, one company and read or read-and-write access, chosen on a consent screen. Every user sees their connected apps under Account settings, with how to connect each client, and can make one read-only or disconnect it. (#805, #806, #845) - 39 tools. Search and read customers, items, invoices, estimates, payments and expenses, company figures and rankings; create and update customers, items, invoices and estimates, record payments and expenses, preview a document before saving it; send documents and delete records, which need the user’s confirmation. The server does the document arithmetic exactly as the invoice form does, validates with the app’s own rules, and logs every change and email. (#841 to #844)
- Headless install.
php artisan invoiceshelf:installmigrates, creates the super administrator and the first company from options orINSTALL_*variables, and closes the installer. It never creates the defaultadmin@invoiceshelf.comaccount, and does nothing on an installed app, so it can run on every start. (#847) - Demo mode. With
APP_ENV=demothe app rebuilds itself on a schedule with sample data and a customer portal sign-in, refuses the changes that would lock out the next visitor, and tells visitors they are in the demo. This is what runs demo.invoiceshelf.com. (#848)
Improvements and fixes
- A signed-out visitor to the customer portal’s login page was sent to the staff login. (#848)
- Release images are published on GHCR as well as Docker Hub. (#849)
Upgrade notes
- The MCP server stays off until you switch it on. Switching it on creates the OAuth signing keys in
storage/if there are none; the Docker image creates them on start. To keep them outside the volume, setPASSPORT_PRIVATE_KEYandPASSPORT_PUBLIC_KEY. Replacing the keys signs every connected app out. - Hosted assistants such as Claude and ChatGPT connect only over HTTPS, to the address in
APP_URL. - An unfinished install’s wizard token no longer works outside the installer. Finish the install in the browser, or run
php artisan invoiceshelf:install. - The client manifest gains a
demoblock for the apps. - The module runtime still advertises module API 1.3.0, so modules need no change.
Docker: invoiceshelf/invoiceshelf:3.0.0-alpha.5 or ghcr.io/invoiceshelf/invoiceshelf:3.0.0-alpha.5 (also :next).