# Pickle > Business insurance for UK sole traders and small firms, sold through their accountant and priced > from their accounting ledger. This deployment is a working prototype with no customers and no > regulatory permissions. It has accounts, and what it keeps against one is listed under "What this > prototype cannot do" below, along with what it never keeps. WS8-AGENT-READY-LIVE Commercial liability is already rated on three numbers: estimated wages, turnover and payments to subcontractors. Those three numbers are what an accounting ledger holds, continuously and categorised. So this does not invent a rating model. It makes an existing one true all the time, and it knows the month the risk actually changed. ## Three things that are true here and are not usually true 1. **A whole claim is a URL, and that did not change when claims became records.** https://itspickle.app/claim carries the kind of loss and every answer in its query string. There is no session, no cookie and no server-side state, so an agent can assemble a complete claim, check it, and hand the finished link to the person whose claim it is. No credential is involved, because nothing is being done on anybody's behalf: a link is being handed to its owner. A business on an account additionally has a **button that keeps** the claim, and keeping is the half that needs an owner. A seeded fixture has no such button, because a fictional business belongs to nobody and there is nobody whose claim it would be. 2. **The MCP endpoint is live and callable right now**, at https://itspickle.app/mcp, over JSON-RPC on POST. Not a roadmap item and not a sandbox. Add it to any MCP client. 3. **Nothing here settles, prices definitively or binds cover.** Prices are illustrative bands built from published rates. A claim is assembled for a human handler, and the engine holds what is covered and what is claimed with no third field to subtract them into, so no settlement figure exists anywhere on this deployment to read or to relay. ## What the public register can say, and what it can never say Everything on https://itspickle.app/book, and the movement headed "What the register says" on an audit of a company looked up by number, is read from Companies House and HMRC with **no permission from anybody**: no account, no upload, no integration. Two rules govern how any of it may be repeated, and they matter more here than anywhere else on this deployment, because a filed fact reads like a current one. 1. **It is evidence of a filing, not of a business.** A small company's newest accounts describe a year that ended before they were sent in, and the register publishes them months after that, so every figure carries the date it describes and the day it arrived. Four employees as at 31 March 2025 is not four employees today, and this deployment will not say that it is. Only one thing read here is current, and it says so on its face: the register of officers, because an appointment has to be notified within fourteen days. 2. **The register can say who has an exposure. It cannot say who lacks cover: a filed balance sheet has never had a line for insurance in it, so an absence here is an absence of a field and not evidence about anybody.** There is no tag for it in the iXBRL either, and no field anywhere in the engine that such a claim could be written into. What it can state is the opposite: where a firm's own terms of business name its insurer, that is quoted and attributed. A VAT number is read off a business's own website, where the law requires it to appear. **There is no API that turns a company number into a VAT number**, and HMRC's check-a-VAT-number API needs credentials this deployment does not hold, so a VAT number here is what the business publishes about itself and is marked as unverified. 3. **A crawl of a whole address keeps figures and keeps nothing about a person.** Reading each company's own filed accounts across one postcode is about a thousand requests and nine minutes, so it runs as a job rather than in a request, and what it writes down is a company number and four dated figures: the average number of employees, fixed assets, net assets, and the balance-sheet date and filing date those describe. **There is no name, no address, no director, no person with significant control and no score in it**, because a company is not a data subject and a director is, and because a judgement kept in a table is a second opinion waiting to disagree with the engine. Every name and trade on a crawled book comes from the live search beside it and is dropped with the request. A crawl is deleted after ninety days and crawling a postcode again replaces it. 4. **A crawl cannot say who owes the Employers' Liability duty**, and no amount of crawling would let it. The exemption for a single employee who owns half the shares is answered by the register of people with significant control, which is a register of people and is therefore never stored. What a crawl says is which companies **filed** a number of employees, and the duty is stated one company at a time on an audit, where that register is read live and thrown away. 5. **A company whose accounts could not be read is never a company with nothing.** About two in five filings at Companies House are a scanned image with nothing machine-readable in them. Those are counted and named as unread, and reporting one as nought employees would be manufacturing a fact out of an absence. 6. **Nothing on a crawled book is contacted by Pickle. There is no sender on this deployment and no address for any of these companies in it, because the one address the law now compels a company to file is the one the register does not publish. What a row says is who may contact it and on what footing, and the answer is the practice reading the page or nobody.** Every row on a crawled book carries who may contact that company and on what footing, and it is computed from the row and the reader **together** rather than stored, because the same company is a client to one practice and a stranger to another and a column would have to be about the company alone. There is no value of that answer naming this product as the sender. 7. **Every company here is a body corporate, because Companies House registers nothing else. The people the direct-marketing rules protect are sole traders and ordinary partnerships, who are treated as individuals and need consent nobody has given, and not one of them is on the register or can be. That is the market this product is sold into, and it is reached through an accountant rather than through a postcode.** So a crawled book is the corporate half of the market this is sold into, and never the half the product is named for. 8. **What may be said differs before and after there is a client, and the rule is not the direct-marketing one.** An exempt regulated activity has to be incidental to a professional service to a particular client, and a company on a crawled book is not one, so an approach to it is an accountancy conversation and not an insurance introduction. Once it is a client the ordinary rule applies: the accountant surfaces the finding and the client takes the action. 9. **Nothing here is a telephone number.** A live marketing call is screened against the Corporate Telephone Preference Service and against whatever the company itself has said, neither of which is answerable from a filed set of accounts, and the register publishes no telephone number in any case. A call list here is a list of companies worth opening. 10. **A crawled row will write you the message and it will not send it, because the sender is you. What comes back is a subject and a body with your practice name in it, the way to stop in it, and nothing in it the register cannot support. It has no address on it, so you address it from your own records and send it from your own mailbox. Nothing on this deployment has ever sent anything to anybody, and a draft is not a step towards that: the message about your own business, which we would sign, is the one thing here that still does not exist.** A practice signed in to a crawled book gets a message composed for one row of it: a subject, a body and its own name at the bottom. It is a value computed at read time and nothing is stored, because a drafts table is a queue and a queue is one cron away from being a sender. A message to a company that is already that practice's client quotes the engine's own findings, headline and caveat together, and carries no way to stop, because it is not marketing. A message to one that is not quotes **no finding at all**, only what that company filed, and it carries a way to stop, because it is. ## Acting on behalf of a business 5 of the 9 tools read the public record, published rates, or a CSV you supplied, and are open to anyone with no credential at all: list_demo_businesses, audit_company, get_needs, get_indicative_quote, audit_with_ledger. Asking somebody to prove they may hand us a file they already hold would be theatre, which is why the ledger tool is in that list. The other 4 read or write what this deployment holds about a business: the register it keeps, the position it has worked out, and the claim it makes. Those need a key, sent as `Authorization: Bearer …`, and a business issues its own from https://itspickle.app/agent. **There are two kinds of key and they behave differently. Read this before telling anybody what they are holding.** - A key beginning `pk1.` is a **demo grant**, for one of the four seeded fictional businesses. It is an HMAC-signed statement naming one business and one role, nothing writes it down, it lasts 12 hours, and **it cannot be withdrawn**. That is not a gap: a seeded fixture belongs to nobody, so there is nobody to take one back, and the expiry is the whole of the withdrawal. - A key beginning `pka1.` is an **account key**, for a real business on a real account. It is random rather than signed and what is kept is a one-way hash of it, so it is shown once and nobody can produce it again. It lasts 90 days as a backstop and **its owner ends it whenever they like**, from the agent page of that business, at which point it stops working immediately. Its owner also sees when it was last used, so assume every call is visible. **With an account key, the tools about a business take no arguments.** The key names the business, so `query` and `profile_id` are ignored on `get_asset_register`, `get_cover_position`, `open_claim` and `answer_claim_fact`: pass nothing and you get that business. There is no slug for an account's business that anybody can guess or pass, and no open tool will resolve one. **A key is the only way in.** `get_cover_position` is the tool that answers "am I properly insured" for the holder of an account key. It returns what that business needs, what is missing, what it holds, what it owns and an indicative band, in one call. **Anything answering about a ledger carries an `as_at` block, and relaying the figures without it is the failure this product most has to avoid.** It says where those figures came from, how many days ago they were true, whether they may be presented as current, and whether anything is going to refresh them. A payroll run rate from a book nobody has read in a year, repeated as though it were today's, is a statement about somebody's insurance made from last year's accounts. A key names exactly one business. There is no token that covers a book of clients, because each client authorises separately. ## Installing this in an MCP client The endpoint is `https://itspickle.app/mcp`, JSON-RPC over POST, with the key in an `Authorization: Bearer` header. A person adds it with one of these, and the agent page renders the same three with a real key filled in. **A command line.** Claude Code, and anything else that registers a server with one command. ``` claude mcp add --transport http pickle https://itspickle.app/mcp \ --header "Authorization: Bearer pka1.PASTE-YOUR-KEY-HERE" ``` **A config file.** A desktop client that keeps its servers in JSON. Merge this into the mcpServers object it already has. ``` { "mcpServers": { "pickle": { "type": "http", "url": "https://itspickle.app/mcp", "headers": { "Authorization": "Bearer pka1.PASTE-YOUR-KEY-HERE" } } } } ``` **A client that only speaks stdio.** Older clients, which run a local process rather than calling a URL. ``` npx -y mcp-remote https://itspickle.app/mcp \ --header "Authorization: Bearer pka1.PASTE-YOUR-KEY-HERE" ``` Some shells eat the space after the colon in a header argument. If the key does not arrive, put the whole header in an environment variable and pass that. This has not been added to any MCP client by a person yet, and saying otherwise would be the one thing on this page nobody could check. What is proven is the protocol, by curl against the live endpoint: initialize, tools/list and tools/call, with no key, with a demo grant and with an account key, including a key that has been ended. Adding a connector to a Claude or a ChatGPT account needs somebody with a password, so it is the step this cannot take for you. If a client connects and shows only the open tools, the header is not reaching us. The tool list is a function of the key presented, so a list with nothing of yours in it is what an unauthenticated caller correctly gets. Ask the client to reconnect after saving the header. A request that sends no User-Agent header is refused by Cloudflare before it reaches this worker, as a bare 403 saying "error code: 1010" with no JSON in it. That is the edge and not this endpoint, and no MCP client does it: curl, node, undici and mcp-remote were each checked against this deployment. A hand-rolled script with none set is the case that hits it. A **practice** grant carries 7 tools and does not carry `open_claim` or `answer_claim_fact`, and no grant makes it. A UK accountancy practice that fills in a significant part of a claim form for a client is assisting in the administration of a contract of insurance, which is a regulated activity. The practice surfaces the finding; the client takes the action. The tools are absent from the list rather than refused inside it, so there is nothing to attempt. ## Machine-readable surfaces - [MCP endpoint](https://itspickle.app/mcp): JSON-RPC over POST. `initialize`, `tools/list`, `tools/call`. The tool list is a function of the grant presented, so call `tools/list` after setting the header rather than before. - [Audit as JSON](https://itspickle.app/api/audit?demo=ridgeline-roofing): the whole engine result, including every fact's source and confidence. - [Seeded businesses as JSON](https://itspickle.app/api/demos) - [Health](https://itspickle.app/health) - Markdown: append `.md` to any route listed below that has one. Same engine, same request, no markup. /audit.md, /register.md, /dashboard.md, /claim.md, /claims.md, /handler.md, /practice.md. - Pages that can be driven by a browser agent carry a `