The Ask Directo solution is built on an MCP (Model Context Protocol) server, which, simply put, is a small local technical helper program running on your computer. By installing the MCP on your computer, you allow an AI assistant (Claude, Gemini) to securely read data directly from your Directo system. All you need to do is ask your questions in plain language.
Read more about what Ask Directo can do: https://directo.ee/ask-directo.
This guide explains how to connect the Directo ERP system to an AI assistant (Claude or Gemini) through a local MCP (Model Context Protocol) server. The guide is intended for both Claude Desktop and Gemini CLI users - the shared steps only need to be done once, after which you pick the section for your AI client.
MCP (Model Context Protocol) is an open standard that lets AI assistants communicate directly with external systems — databases, APIs (Application Programming Interfaces), and applications.
Without MCP, working with an AI assistant looks like this:
With MCP, it looks like this:
| Situation | Without MCP | With MCP |
|---|---|---|
| Stock level check | Open Directo → search → copy → paste into AI | “Which items have fewer than 10 units in stock?” |
| Invoice analysis | Export CSV → upload to AI → ask | “Which customers haven't paid in the last 90 days?” |
| Sales report | Build manually → copy → analyze | “Compare this month's sales to last year” |
| Order tracking | Open several views → copy info | “Which orders are more than 5 days overdue?” |
You (natural language)
↕
AI client (Claude Desktop or Gemini CLI)
↕ MCP protocol (local)
MCP Server (on your computer, Node.js)
↕ HTTPS
Directo API (cloud)
The MCP server runs on your computer. The Directo API key never leaves your machine. The data retrieved from Directo does, however, travel onward to the AI provider's cloud so the model can read it and formulate a natural-language answer — the same as any other message content in the conversation.
Check every prerequisite before installing. A missing prerequisite is the most common cause of failure.
| Prerequisite | How to check | Fix |
|---|---|---|
| Windows 10 or 11 (64-bit) | Start → Settings → System → About | — |
| Node.js 22 or newer (LTS) | node –version | nodejs.org → LTS |
| npm | npm –version (only works after execution policy is set, see below) | Comes bundled with Node.js |
| PowerShell execution policy | Get-ExecutionPolicy → should return RemoteSigned | See below |
| CredentialManager module | Get-Module -ListAvailable CredentialManager | See below |
| Directo API key | Directo → Admin → Settings → API | Ask your Directo administrator |
| Prerequisite | How to check | Link |
|---|---|---|
| Claude Desktop installed | Claude appears in the Start menu | https://claude.ai/download |
| Anthropic account | Sign-in works | https://claude.ai |
Official documentation: https://docs.claude.ai
On June 18, 2026, the Gemini CLI will be replaced by Antigravity CLI for the unpaid tier and Google One users — this affects a specific authentication path, not free access as a whole. For higher volume or Pro models you need a Google AI Pro/Ultra subscription or a Gemini Code Assist license. Check your project's actual limits in AI Studio, as they change frequently and depend on region and account status.
| Prerequisite | How to check | Link |
|---|---|---|
| Google account | gmail.com access works | https://accounts.google.com |
| Google AI Studio API key | https://aistudio.google.com/apikey | Create an API key |
| Gemini CLI installed | gemini –version | npm install -g @google/gemini-cli |
Official documentation: https://geminicli.com/docs
| Step | Admin rights? | Reason |
|---|---|---|
| Installing Node.js | Yes — the installer requires it | System-level install (Program Files) |
| PowerShell execution policy | No | -Scope CurrentUser writes to the HKCU registry |
| CredentialManager module | No | -Scope CurrentUser installs under the user's profile |
| npm install (MCP server) | No | User-level install |
| Claude Desktop config | No | User folders |
| Gemini CLI config | No | User folders |
| Saving the API key | No | Credential Manager, user-level entry |
Risks and an important warning:
-Scope CurrentUser exists specifically to avoid needing admin rightsnpm install as administrator — this creates permission conflictsnpm install -g (e.g. Gemini CLI, Step 5.1) only needs admin rights if npm's global prefix points at the Program Files folder — Step 5.1 includes a fix that avoids this.msi file as administratorVerify the install (regular PowerShell, not admin):
node --version
Expected result:
v22.11.0 or newer
npm –version here yet — npm is a PowerShell script (npm.ps1) and will give a running scripts is disabled error before the execution policy is set (Path A script, or Step B1), even if Node.js and npm themselves are installed correctly. This is not a bug, it's expected behavior at this stage. npm –version will work after completing Path A/B.
| Path A — Scripts | Path B — Manual | |
|---|---|---|
| Time | ~5 minutes | ~20 minutes |
| Best for | Most users | You want to understand every step yourself, or Path A doesn't work in your environment |
| Covers steps | A1—A2 | B1—B7 |
If you choose Path A and it succeeds, skip Path B (B1—B7) entirely — those steps describe, manually, exactly what the scripts already did for you. Path B is troubleshooting reference material, not an additional required step.
Step A1 — Downloading the files
Download directo-mcp-files.zip and extract it:
.js and .ps1 file uploads by default (for security, see conf/mime.conf), but .zip is allowed by default. Don't rename the files to a different extension (e.g. .txt) as a “fix” — the wrong extension is exactly what causes MODULE_NOT_FOUND-type errors later.
Extract it (right-click the ZIP → Extract All, or in PowerShell):
Expand-Archive "$env:USERPROFILE\Downloads\directo-mcp-files.zip" -DestinationPath "$env:USERPROFILE\Downloads\directo-mcp-files" cd "$env:USERPROFILE\Downloads\directo-mcp-files"
Before running the scripts, two Windows default security restrictions must be cleared — both are required, not optional:
1) Allow running scripts in PowerShell at all:
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
running scripts is disabled on this system / UnauthorizedAccess. -Scope CurrentUser does not require admin rights.
2) Remove Windows' “downloaded from the internet” (Mark of the Web) flag:
Get-ChildItem "$env:USERPROFILE\Downloads\directo-mcp-files" -Recurse | Unblock-File
RemoteSigned requires a digital signature for such files, which our scripts don't have. Without this step you'll see is not digitally signed / UnauthorizedAccess, which looks confusingly similar to the error from step 1, but has a different cause and fix.
The archive contains four files: directo-mcp.js (the MCP server itself), set-directo-apikey.ps1, install-claude-mcp.ps1, install-gemini-mcp.ps1.
Step A2 — Running the scripts
In the same PowerShell window (not as administrator), in the folder you just extracted:
# API key (shared by both clients, do this first) .\set-directo-apikey.ps1 # Pick your AI client (or both): .\install-claude-mcp.ps1 .\install-gemini-mcp.ps1
Each script prints a summary at the end — what's done (✅) and what still needs manual action (❗).
Check the current setting:
Get-ExecutionPolicy
If the answer isn't RemoteSigned, fix it in a regular PowerShell window (not as administrator):
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
-Scope CurrentUser writes the setting only to the HKEY_CURRENT_USER registry hive, not a machine-wide location — that's why it doesn't need admin rights. Admin rights would only be needed for -Scope LocalMachine, which this guide does not use.
It will ask for confirmation → press Y → Enter.
Open a regular PowerShell window (not as administrator) — under exactly the same user account the MCP server will later run under:
Install-Module -Name CredentialManager -Force -Scope CurrentUser
-Scope CurrentUser exists specifically to avoid needing admin rights — the module installs under your own profile (Documents\WindowsPowerShell\Modules). If the command asks to confirm the NuGet provider or an “untrusted repository,” answer Y — these steps don't need admin rights either.
Verify the install succeeded (in the same regular PowerShell window):
Get-Module -ListAvailable CredentialManager
Should show the module's name and version.
node directo-mcp.js will later run under. A PowerShell window opened with elevation may actually run under a different account's identity, which would leave the module or API key under the wrong profile, and the later step will fail invisibly.
Open a regular PowerShell window (not admin) and run:
New-Item -ItemType Directory -Force -Path "$env:USERPROFILE\directo-mcp"
$env:USERPROFILE variable, rather than manually typing C:\Users\YOURNAME. On domain-joined computers (corporate/AD environments) your actual profile folder may differ from your sign-in name — for example it may include a domain suffix (YOURNAME.DOMAIN). $env:USERPROFILE always gives the real, correct path, regardless.
Download the directo-mcp.js file — it's included in the directo-mcp-files.zip archive linked under Path A (extract it, see Step A1) — and place it in this folder:
$env:USERPROFILE\directo-mcp\directo-mcp.js
The simplest way: if the file is already in the extracted Downloads subfolder, copy it in PowerShell:
Copy-Item "$env:USERPROFILE\Downloads\directo-mcp-files\directo-mcp.js" "$env:USERPROFILE\directo-mcp\directo-mcp.js"
directo-mcp.js — not directo-mcp.js.txt. Check:Test-Path "$env:USERPROFILE\directo-mcp\directo-mcp.js"
Should return True. If False, check the exact file name:
Get-ChildItem "$env:USERPROFILE\directo-mcp"
Open a new Notepad window and paste:
{
"name": "directo-mcp",
"version": "1.0.0",
"type": "module",
"description": "Directo ERP MCP Server",
"main": "directo-mcp.js",
"scripts": {
"start": "node directo-mcp.js"
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.0.0",
"zod": "^3.22.0"
}
}
Save it in the same folder, named package.json (file type: All Files).
Regular PowerShell (not admin):
cd "$env:USERPROFILE\directo-mcp" npm install
A successful install creates a node_modules folder and a package-lock.json file in this folder.
directo-mcp folder's own node_modules), not global — it never needs admin rights or any special npm-prefix configuration, regardless of how Node.js was originally installed.
The Directo API key is saved to Windows Credential Manager — encrypted, under your user account only. No one else on the computer can see this key.
New-StoredCredential -Target DIRECTO_API_KEY -UserName directo -Password YOUR_REAL_KEY_HERE -Persist LocalMachine
Verify the save succeeded:
(Get-StoredCredential -Target DIRECTO_API_KEY).GetNetworkCredential().Password
Should display your API key.
Rotating the API key in the future:
Remove-StoredCredential -Target DIRECTO_API_KEY New-StoredCredential -Target DIRECTO_API_KEY -UserName directo -Password NEW_KEY -Persist LocalMachine
node directo-mcp.js will later run under. See the warning under Step B2 about the separate-admin-account risk.
set-directo-apikey.ps1) does the same thing more securely (asks for the key without echoing it to the screen) and also works for rotation — use it if you can.
install-claude-mcp.ps1 script under Path A (Chapter 3), Steps 4.1—4.2 are already done — the script detects, patches, and backs up the configuration file automatically. Go straight to Step 4.3.
Claude Desktop has two possible configuration locations on Windows, depending on how it was installed:
| Install type | Location |
|---|---|
Direct .exe installer (typical) | %APPDATA%\Claude\ |
| Microsoft Store / MSIX | %LOCALAPPDATA%\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude\ |
%APPDATA%\Claude\ location transparently to a different path. If you edit the wrong (standard) file, the change never reaches the app, and the MCP server silently fails to load, with no explanatory error.
Check which one applies on your machine — open File Explorer and try both in the address bar:
%APPDATA%\Claude
If a claude_desktop_config.json file already exists there (or Claude Desktop has already created something there), use this path. If not, try:
%LOCALAPPDATA%\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude
Create a file named claude_desktop_config.json in the (correct, as identified in Step 4.1) folder.
claude_desktop_config.json
File contents:
{
"mcpServers": {
"directo": {
"command": "node",
"args": [
"C:\\Users\\YOURNAME\\directo-mcp\\directo-mcp.js"
]
}
}
}
YOURNAME with your actual profile folder name — not your assumed username. On domain-joined (AD) computers, the actual profile folder may differ from your sign-in name (e.g. include a domain suffix). Check the exact value:$env:USERPROFILE
Use exactly what the command returns in the JSON (with double backslashes). Example for illustration — if $env:USERPROFILE returns C:\Users\john.user.COMPANY, the path in the JSON should be C:\\Users\\john.user.COMPANY\\directo-mcp\\directo-mcp.js. Whether or not a domain suffix (.COMPANY) is present depends on your own computer's setup — always use your own command's actual output, not this example.
preferences block) — do not overwrite it. mcpServers must be at the root level of the file, at the same level as preferences, not inside it. If you're unsure about correct brace placement, use the Path A script instead, which edits the file as a structure (ConvertFrom-Json/ConvertTo-Json), not as raw text — this completely eliminates brace-placement errors.
In a Claude Desktop conversation, type:
Show me all stock levels
Claude should automatically use the get_stocklevels tool and return data from Directo.
Checking the logs if something doesn't work:
The log location follows the same two possibilities as Step 4.1:
# Direct .exe installer: Get-Content "$env:APPDATA\Claude\logs\mcp-server-directo.log" -Tail 30 # Microsoft Store / MSIX: Get-Content "$env:LOCALAPPDATA\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude\logs\mcp-server-directo.log" -Tail 30
Official Claude Desktop MCP documentation: modelcontextprotocol.io — Connect to local MCP servers
install-gemini-mcp.ps1 script under Path A (Chapter 3), Steps 5.1 and 5.3—5.4 are already done. Only go through Step 5.2 (Google API key — the script doesn't do this, since it's separate Google, not Directo, authentication) and Steps 5.5—5.6.
mkdir "$env:APPDATA\npm-global" -Force npm config set prefix "$env:APPDATA\npm-global" [Environment]::SetEnvironmentVariable("Path", $env:Path + ";$env:APPDATA\npm-global", "User")
Close PowerShell completely and open a new window (PATH only refreshes in a new session), then install Gemini CLI:
npm install -g @google/gemini-cli
Verify:
gemini --version
C:\Program Files\…. Check the current setting with npm config get prefix — after the step above it should show %APPDATA%\npm-global, not a Program Files folder.
Go to https://aistudio.google.com/apikey and create an API key.
Save the key as a persistent environment variable:
[System.Environment]::SetEnvironmentVariable("GEMINI_API_KEY", "YOUR_GOOGLE_API_KEY", "User")
Close PowerShell and reopen it. Verify:
$env:GEMINI_API_KEY
The Gemini CLI configuration is located on Windows at:
$env:USERPROFILE\.gemini\settings.json
Check whether the folder exists:
Test-Path "$env:USERPROFILE\.gemini"
If the answer is False, create the folder:
New-Item -ItemType Directory -Force -Path "$env:USERPROFILE\.gemini"
Create or edit the file $env:USERPROFILE\.gemini\settings.json:
{
"mcpServers": {
"directo": {
"command": "node",
"args": [
"C:\\Users\\YOURNAME\\directo-mcp\\directo-mcp.js"
],
"env": {
"DIRECTO_API_KEY": "$DIRECTO_API_KEY"
}
}
}
}
YOURNAME with your actual profile folder name — check the exact value with $env:USERPROFILE (see the warning under Step 4.2 on this same topic).
directo-mcp.js reads the key from Credential Manager first (Path A script, or Step B7) — this works exactly the same way for Gemini as for Claude Desktop, since both run the same server file. The env block here is a fallback, not the only path — if Credential Manager is already set up, this block isn't strictly necessary, though it doesn't hurt either. If you do want to use it, save the value as an environment variable:[System.Environment]::SetEnvironmentVariable("DIRECTO_API_KEY", "YOUR_DIRECTO_API_KEY", "User")
Gemini CLI supports environment-variable expansion in env values using $VAR_NAME syntax — that's why the JSON contains “$DIRECTO_API_KEY”, not the actual key.
Gemini CLI has a security feature called Trusted Folders, which by default doesn't allow connecting MCP servers from an untrusted folder. If this feature is enabled, the folder needs to be trusted.
The simplest way — trust the server directly in settings.json, by adding “trust”: true to the directo block:
{
"mcpServers": {
"directo": {
"command": "node",
"args": [
"C:\\Users\\YOURNAME\\directo-mcp\\directo-mcp.js"
],
"env": {
"DIRECTO_API_KEY": "$DIRECTO_API_KEY"
},
"trust": true
}
}
}
“trust”: true skips the tool-call confirmation dialogs. Only use this for servers you fully manage yourself — this Directo server is such a case.
Alternative — if Trusted Folders is enabled, Gemini CLI shows a trust dialog the first time it opens this folder. Choose Trust folder there. The choice is saved to ~/.gemini/trustedFolders.json and is only asked once per folder. Use the /permissions command inside the CLI to change the trust level later.
Start Gemini CLI:
gemini
Check the MCP connection:
/mcp list
Should show:
🟢 directo - Ready (32 tools)
Test query:
Show me all stock levels
Official Gemini CLI MCP documentation: geminicli.com/docs/tools/mcp-server
| Error message | Cause | Fix |
|---|---|---|
DIRECTO_API_KEY puudub *(literal log text, still Estonian — see note below)* | Credential Manager save failed | Redo Step B7 (or Path A: .\set-directo-apikey.ps1) |
Cannot find module | npm install failed, OR directo-mcp.js is in the wrong folder/has the wrong name | Redo Step B6; check Test-Path “$env:USERPROFILE\directo-mcp\directo-mcp.js” |
SyntaxError | directo-mcp.js file is corrupted or incomplete | Download the file again, see Step B4 (or Path A: A1) |
Incorrect filter id | Invalid API filter name | Known limitation — use without that filter |
401 / 403 | Directo API key is invalid or expired | Check the key in Directo admin |
running scripts is disabled | PowerShell execution policy | Set-ExecutionPolicy RemoteSigned -Scope CurrentUser (Step A1 or B1) |
is not digitally signed / UnauthorizedAccess | Windows Mark-of-the-Web (file downloaded via a browser) | Get-ChildItem <folder> -Recurse \| Unblock-File (see Step A1) |
npm not recognized | Node.js is not on PATH | Close and reopen PowerShell |
directo-mcp.js, which is still written in Estonian pending an English version of that file. If you see this text in your logs, it means “DIRECTO_API_KEY is missing,” and the fix column above still applies.
| Problem | Fix |
|---|---|
| No hammer icon visible | Check the log file (see below) |
| MCP server doesn't start | Check that the config file's name doesn't have a .txt extension |
| Config folder is missing | Run Claude Desktop once — the folders are created automatically |
| Config edited, but nothing changes | Make sure you're editing the RIGHT file — see Step 4.1 (two possible locations, MSIX vs. direct install) |
Log file (try both, see Step 4.1):
Get-Content "$env:APPDATA\Claude\logs\mcp-server-directo.log" -Tail 30 Get-Content "$env:LOCALAPPDATA\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude\logs\mcp-server-directo.log" -Tail 30
| Problem | Fix |
|---|---|
/mcp list shows Disconnected | Add “trust”: true to the server config (Step 5.4), or trust the folder via the dialog / the /permissions command |
GEMINI_API_KEY error | Redo Step 5.2, open a new PowerShell window |
| Rate limit / 429 error | Free-tier request limit exceeded — wait for the limit to reset, or consider a paid subscription (see Step 2.3) |
Gemini CLI diagnostics:
/mcp list
Both clients (Claude Desktop and Gemini CLI) use the same tools:
| Group | Tools |
|---|---|
| Sales | get_invoices, get_orders, get_sales_quotations, get_sales_contracts, get_receipts |
| Customers | get_customers, get_suppliers, get_contacts |
| Products / stock | get_items, get_itemclasses, get_stocklevels, get_stocklevels_sn, get_allocations, get_priceformulas |
| Purchasing | get_purchase_orders, get_purchase_invoices, get_purchase_payments, get_stock_receipts |
| Accounting | get_transactions, get_accounts, get_financial_budgets, get_nettings |
| Logistics | get_deliveries, get_movements |
| Other | get_projects, get_objects, get_resources, get_events, get_users, get_recipes, get_replacementlogs |
| Sync | get_deleted |
| Measure | Explanation |
|---|---|
| Credential Manager (both clients) | API key is encrypted, visible only to your Windows account — Claude and Gemini read the same entry |
| Environment variable (Gemini fallback) | If Credential Manager is set up, the env block isn't strictly necessary — see the note under Step 5.4 |
| Local server | The MCP server only runs on your computer, it is not publicly reachable |
| Minimal permissions | Restrict the Directo API key's permissions to only the resources you need |
| OneDrive/Dropbox | Exclude the directo-mcp folder from cloud sync |
| Admin rights | Only for installing Node.js (Step 3.1) — a shared prerequisite for both paths — everything else, including the CredentialManager module, runs under -Scope CurrentUser without admin rights (see 2.4) |
Claude Desktop:
Gemini CLI:
Directo:
General:
Quick-install scripts (see Path A, Chapter 3):
directo-mcp.js — MCP server (32 tools, schema-verified)set-directo-apikey.ps1 — API key management (initial setup + rotation)install-claude-mcp.ps1 — automatic Claude Desktop installinstall-gemini-mcp.ps1 — automatic Gemini CLI install