Now generally available

Connect your AI assistant to TIN Comply. One URL. No setup.

TIN Comply's MCP server lets Claude, ChatGPT, Cursor, and any other AI assistant run real-time IRS TIN matching, OFAC screening, EIN lookup, and address validation on your behalf, secured with OAuth, controlled from your TIN Comply account. Nothing to install, no keys to paste. Authorize and go.

Same backend, same credits, same audit trail as the portal and API.

Add custom connector Beta

Connect your assistant to your data and tools.

TIN Comply
https://www.tincomply.com/mcp
Authorization

OAuth 2.1 with PKCE. You sign in on a TIN Comply page. The AI provider never sees your password.

Next step

Approve the scopes shown on the consent screen. The assistant gets a short-lived, revocable token.

Every call logged to your request history Revocable
OAuth 2.1 with PKCE
Revoke anytime
Per-tool permissions
Included

Part of every TIN Comply plan from $20/mo, not a separate purchase. See pricing

Try asking

The kinds of things you'll actually ask once it's connected

Multi-step compliance work compressed into a single prompt. The assistant works out which tools to call and stitches the results together, and every call it makes lands in your audit trail.

Vendor onboarding · multi-tool
You
Here's a W-9 a new vendor sent over. Run a TIN match, screen them against sanctions, validate the address, and tell me if this looks good to onboard. W-9_NorthwindTrading.pdf
tin_matchtin=47-XXXXX18, name=Northwind Trading Co
screen_sanctionsname=Northwind Trading Co
validate_address14 Industrial Way, Newark, NJ 07105
Assistant

I ran three checks on this W-9. Here's what came back:

  • TIN match: Code 7: matches IRS EIN records. The TIN and legal name line up.
  • Sanctions: No matches against OFAC SDN, US Trade CSL, UN, or EU lists.
  • Address: Validated and standardized. USPS added the ZIP+4 (07105-3284).

Bottom line: good to onboard. The only suggested correction is the ZIP+4.

Bulk validation · AP cleanup
You
Here's our vendor list. Run TIN matching on every row, screen each name against sanctions, and highlight any rows with issues. Q4_Vendors.xlsx · 184 rows
validate_tin_format184 rows · 3 malformed, skipped before paid calls
tin_match181 records
screen_sanctions181 records
Assistant

Done. I pre-checked formats first so the malformed rows didn't consume credits.

  • 172 clean: matched IRS records, no sanctions hits.
  • 6 name mismatches: mostly DBAs used instead of legal names.
  • 3 malformed TINs: flagged before submission.
  • 1 sanctions review: 78% name match, needs a human look.

Want me to draft W-9 correction requests for the six mismatches?

Get connected

Three clicks. Nothing to install.

1

Paste the URL

In your assistant's connector settings, add a custom connector and paste https://www.tincomply.com/mcp. That's the entire configuration.

2

Sign in & authorize

You're sent to a TIN Comply hosted sign-in page. Review the capabilities listed on the consent screen and approve. The AI provider never sees your password.

3

You're connected

Ask in plain language. The assistant picks the right tools, calls them against your account, and explains what came back.

Security & control

Your account. Your credits. Your rules.

Granting an AI assistant access to compliance tools is a real security decision, and we'd rather treat it as one. You stay in control at every step, with the controls where you'd expect to find them.

OAuth 2.1 with PKCE

Industry-standard authorization. No API keys living on your machine, in chat logs, or in screenshots. Every session uses a short-lived, revocable token bound to your account and device.

See exactly what's allowed

Before you click Authorize, the consent screen lists every capability the assistant will and won't have. No hidden permissions, no over-broad scopes.

One-click revoke

Every active connection is listed under Admin → AI Connections in your account, with a last-active timestamp. Revoke any of them instantly. The connection dies the moment you click.

Per-tool permissions

Inside the assistant, each TIN Comply tool can be set independently, so you can leave address validation on auto-approve and require an explicit click for anything touching PII.

Always allow Needs approval Blocked

Secure by default. All requests travel over encrypted HTTPS and are authenticated to your account. You control what data you submit, results are scoped to your queries, and we never repurpose your payee data, TINs, or screening results for anything beyond fulfilling your request.

The tool surface

Every compliance capability. One connection.

Every TIN Comply capability becomes a tool the assistant can use. What each one does, what its results mean, and which ones use credits are all built in, so it knows what to run and how to explain what comes back.

IRS TIN matching

Verify TIN and legal name against IRS records. Returns the result code (2/3/6/7/8) with plain-English interpretation.

EIN lookup

Search for candidate EINs by company name. Returns confidence-scored, masked matches.

Reverse lookup

Recover the registered business name for an EIN, useful when verifying or correcting vendor records.

Sanctions screening

Match names against OFAC SDN, US Trade CSL, UN, EU and other watchlists with confidence scoring.

Address validation

USPS standardization with ZIP+4, county, congressional district, and coordinates.

FATCA & LEI

Validate GIINs against the FATCA registry and Legal Entity Identifiers against GLEIF.

Format pre-check

Free, instant TIN format validation. Use it before paid matches so malformed input doesn't burn credits.

Company details

Enrich a vendor record with full address, phone, website, and coordinates from business registries.

Audit replay

Pull any prior validation by ID for compliance reports or dispute defense, without spending credits.

Compatibility

Works with every MCP-compatible client

One server. One sign-in. All the tools your team already uses.

Claude.ai Claude Desktop Claude Code ChatGPT Cursor VS Code Custom agents
Frequently asked

Answers your CTO and your CFO will both want

What is MCP, and do I need to know anything special to use it?

The Model Context Protocol is an open standard for connecting AI assistants to external tools. As an end user you don't need to know anything beyond pasting our connector URL and signing into TIN Comply when prompted, the same way you'd connect any "sign in with" application.

Does this consume my regular validation credits?

Yes. Calls through the connector hit the same backend as the REST API and the portal, and draw from the same plan. Format validation and audit-replay tools are free, and there's no separate MCP subscription.

How is the connection authenticated? Where does my password go?

OAuth 2.1 with PKCE, the same standard banks and major SaaS platforms use. You sign in once on a TIN Comply hosted page, so the AI provider never sees your password, and the assistant receives a short-lived access token bound to your account.

That token can be revoked at any time from the AI Connections page.

How do I revoke access?

Sign in, go to Admin → AI Connections, find the connection and click Revoke. It terminates immediately and the assistant must re-authorize before calling again.

This is independent of disconnecting on the client side: either action ends the connection.

What if an AI assistant runs my account out of credits?

The server returns a structured "insufficient credits" response the assistant recognizes and surfaces in plain English. It won't retry repeatedly or burn additional credits trying to recover.

For tighter control, use per-tool permissions to require explicit approval before any credit-consuming tool runs.

Which AI assistants are supported?

Any client that speaks MCP: Claude (web and desktop), Claude Code, Cursor, ChatGPT via MCP-compatible plugins, VS Code with Copilot's MCP support, and custom agents built on provider APIs or open-source frameworks. The connection steps are identical across all of them.

Are AI-run validations recorded in the audit trail?

Yes. Validations run through the connector land in the same request history as portal and API activity, with timestamps and results, so a check an assistant performed is as auditable as one a person performed.

Bring TIN Comply into the conversation

Your AI assistant should already know how to validate a vendor. Now it does, through the compliance infrastructure you already trust, with the security controls you'd expect.

Same credits. Same audit trail. No separate subscription.