A ChatGPT Plugin: Connecting MyÚčto and Invoicing
"Prepare an invoice for my client's consultation, due in seven days, and show it to me before you issue it."
That's exactly how I picture invoicing in 2026. I type one sentence, ChatGPT finds the client, reaches for the right tools and prepares the document. All I do is check it.
Sounds simple. But when ChatGPT and I built a private plugin for MyÚčto together, it turned out that the road from "that could work" to "we can actually use this" runs through connections, permissions and a pile of small details you don't think about at the start.

1. Start With What We Actually Do
Before writing a single line, we listed what we normally do with invoices: look up clients, check their history, prepare drafts, issue invoices, keep an eye on receivables and orders.
What helped most was writing down the real sentences we'd type into the chat:
- "How much do my clients owe me right now?"
- "Show me overdue invoices."
- "Prepare a draft for the interior design proposal."
- "Change the price of the second item."
Every such sentence has to be backed by a tool. If the system can't do something, no instruction will add it to the plugin. Worth realising right at the beginning; it saves a lot of disappointment.
2. The MCP Server Already Existed
MyÚčto already had a remote MCP server, so we didn't have to build another server or a middleman. An advantage that's hard to overstate.
MCP gives the assistant tools: it uses them to read live data and perform permitted operations. The plugin adds instructions for specific workflows; OpenAI calls them skills. They define the order of steps, what to do when something is missing, and what the result should look like.
For invoicing, that means in practice: find the client, verify the request, prepare a draft, check the result.
3. Instructions Are Not a Connection
The first lesson was fairly banal: loaded instructions don't mean the plugin can actually do anything.
The plugin described beautifully how to look up a client, but without the MCP tools available it had nowhere to get the data from. We had to properly wire together the app, the MCP server and the OAuth sign-in.
The user signs in to their MyÚčto account and chooses the scope of access. Read-only is enough for overviews and searches; creating and editing records needs write access.
We first tested the connection with the simplest read operations: who am I and which companies can I see. Only once that worked did it make sense to move on.
4. Good Instructions Take the Most Work
The technical connection is only half of it. The plugin also has to know when to stop and ask.
"Make another invoice for 666 CZK" doesn't say what's being invoiced. The assistant must not fill in "consulting" just because it was on the last invoice.
Likewise, "add an item to the client's draft" doesn't necessarily identify a single invoice. If the client has several drafts, the plugin should show them and let me pick.
So we added a guided flow: pick the document, specify the change, fill in missing values, run the operation and verify the result. At the same time we made sure a precise request doesn't turn into a pointless questionnaire. If I've said everything, I don't want to answer five questions.
Here's what one real exchange looks like. The plugin found the client unambiguously, asked for the due date I hadn't given, and after my answer created only a draft:

5. A Draft Isn't Issuing, and Issuing Isn't Sending
Creating a draft isn't consent to issue it. Issuing isn't consent to send it to the client.
Before every significant action, the plugin shows a concrete summary and asks for confirmation. When sending, it also has to be clear who the e-mail goes to. After an error or timeout, it first checks the actual state of things, so that a retry doesn't create a duplicate invoice or send the e-mail twice.
And one thing from a security person's point of view: instructions steer the assistant's behaviour, but they are not a security boundary. Permissions and limits on operations must be enforced by the server itself.
6. The Plugin Grows With the Service
At first, MCP couldn't properly edit draft line items. We were the ones who asked for it: we proposed exactly what we wanted, and the next day it was done. Four tools were added: changing the header, adding an item, editing an item and removing it.
Updating the plugin therefore also meant cleaning up: dropping the old limitations from the instructions and verifying that ChatGPT had really loaded the new tools.
Further tweaks came from everyday use: a saved non-VAT-payer setting, a direct link to the document, and an offer to download the PDF right after issuing.
7. The Private Version Is for Testing
First it makes sense to run the plugin through real situations. Not only those that work on the first try, but also vague requests, several similar clients or missing permissions.
Only then does it make sense to think about a public version. Personal settings, such as a specific domain or not being a VAT payer, have to be replaced by per-user configuration.
In the end, the best measure is a practical one: I say what I need in plain words, I understand what's happening, and at the end I get a verified result. That's what the connection, the tools and the instructions all have to aim for.