Connect your AI assistant to TIN Comply. One URL. No setup.
TIN Comply's MCP server lets Claude, ChatGPT, Cursor, and any other AI assistant run real-time IRS TIN matching, OFAC screening, EIN lookup, and address validation on your behalf, secured with OAuth, controlled from your TIN Comply account. Nothing to install, no keys to paste. Authorize and go.
Same backend, same credits, same audit trail as the portal and API.
Connect your assistant to your data and tools.
OAuth 2.1 with PKCE. You sign in on a TIN Comply page. The AI provider never sees your password.
Approve the scopes shown on the consent screen. The assistant gets a short-lived, revocable token.
Part of every TIN Comply plan from $20/mo, not a separate purchase. See pricing
The kinds of things you'll actually ask once it's connected
Multi-step compliance work compressed into a single prompt. The assistant works out which tools to call and stitches the results together, and every call it makes lands in your audit trail.
I ran three checks on this W-9. Here's what came back:
- TIN match: Code 7: matches IRS EIN records. The TIN and legal name line up.
- Sanctions: No matches against OFAC SDN, US Trade CSL, UN, or EU lists.
- Address: Validated and standardized. USPS added the ZIP+4 (07105-3284).
Bottom line: good to onboard. The only suggested correction is the ZIP+4.
Done. I pre-checked formats first so the malformed rows didn't consume credits.
- 172 clean: matched IRS records, no sanctions hits.
- 6 name mismatches: mostly DBAs used instead of legal names.
- 3 malformed TINs: flagged before submission.
- 1 sanctions review: 78% name match, needs a human look.
Want me to draft W-9 correction requests for the six mismatches?
Three clicks. Nothing to install.
Paste the URL
In your assistant's connector settings, add a custom connector and paste
https://www.tincomply.com/mcp. That's the entire configuration.
Sign in & authorize
You're sent to a TIN Comply hosted sign-in page. Review the capabilities listed on the consent screen and approve. The AI provider never sees your password.
You're connected
Ask in plain language. The assistant picks the right tools, calls them against your account, and explains what came back.
Your account. Your credits. Your rules.
Granting an AI assistant access to compliance tools is a real security decision, and we'd rather treat it as one. You stay in control at every step, with the controls where you'd expect to find them.
OAuth 2.1 with PKCE
Industry-standard authorization. No API keys living on your machine, in chat logs, or in screenshots. Every session uses a short-lived, revocable token bound to your account and device.
See exactly what's allowed
Before you click Authorize, the consent screen lists every capability the assistant will and won't have. No hidden permissions, no over-broad scopes.
One-click revoke
Every active connection is listed under Admin → AI Connections in your account, with a last-active timestamp. Revoke any of them instantly. The connection dies the moment you click.
Per-tool permissions
Inside the assistant, each TIN Comply tool can be set independently, so you can leave address validation on auto-approve and require an explicit click for anything touching PII.
Secure by default. All requests travel over encrypted HTTPS and are authenticated to your account. You control what data you submit, results are scoped to your queries, and we never repurpose your payee data, TINs, or screening results for anything beyond fulfilling your request.
Every compliance capability. One connection.
Every TIN Comply capability becomes a tool the assistant can use. What each one does, what its results mean, and which ones use credits are all built in, so it knows what to run and how to explain what comes back.
IRS TIN matching
Verify TIN and legal name against IRS records. Returns the result code (2/3/6/7/8) with plain-English interpretation.
EIN lookup
Search for candidate EINs by company name. Returns confidence-scored, masked matches.
Reverse lookup
Recover the registered business name for an EIN, useful when verifying or correcting vendor records.
Sanctions screening
Match names against OFAC SDN, US Trade CSL, UN, EU and other watchlists with confidence scoring.
Address validation
USPS standardization with ZIP+4, county, congressional district, and coordinates.
Format pre-check
Free, instant TIN format validation. Use it before paid matches so malformed input doesn't burn credits.
Company details
Enrich a vendor record with full address, phone, website, and coordinates from business registries.
Audit replay
Pull any prior validation by ID for compliance reports or dispute defense, without spending credits.
Works with every MCP-compatible client
One server. One sign-in. All the tools your team already uses.
Answers your CTO and your CFO will both want
What is MCP, and do I need to know anything special to use it?
The Model Context Protocol is an open standard for connecting AI assistants to external tools. As an end user you don't need to know anything beyond pasting our connector URL and signing into TIN Comply when prompted, the same way you'd connect any "sign in with" application.
Does this consume my regular validation credits?
Yes. Calls through the connector hit the same backend as the REST API and the portal, and draw from the same plan. Format validation and audit-replay tools are free, and there's no separate MCP subscription.
How is the connection authenticated? Where does my password go?
OAuth 2.1 with PKCE, the same standard banks and major SaaS platforms use. You sign in once on a TIN Comply hosted page, so the AI provider never sees your password, and the assistant receives a short-lived access token bound to your account.
That token can be revoked at any time from the AI Connections page.
How do I revoke access?
Sign in, go to Admin → AI Connections, find the connection and click Revoke. It terminates immediately and the assistant must re-authorize before calling again.
This is independent of disconnecting on the client side: either action ends the connection.
What if an AI assistant runs my account out of credits?
The server returns a structured "insufficient credits" response the assistant recognizes and surfaces in plain English. It won't retry repeatedly or burn additional credits trying to recover.
For tighter control, use per-tool permissions to require explicit approval before any credit-consuming tool runs.
Which AI assistants are supported?
Any client that speaks MCP: Claude (web and desktop), Claude Code, Cursor, ChatGPT via MCP-compatible plugins, VS Code with Copilot's MCP support, and custom agents built on provider APIs or open-source frameworks. The connection steps are identical across all of them.
Are AI-run validations recorded in the audit trail?
Yes. Validations run through the connector land in the same request history as portal and API activity, with timestamps and results, so a check an assistant performed is as auditable as one a person performed.
What the assistant can reach
Bring TIN Comply into the conversation
Your AI assistant should already know how to validate a vendor. Now it does, through the compliance infrastructure you already trust, with the security controls you'd expect.
Same credits. Same audit trail. No separate subscription.