# list_invoices

List the caller's OWN Stripe invoices — status/amounts (minor units)/currency/hosted_invoice_url/period (from stripe_invoices, owner-scoped to the caller's OAuth sub), newest first. Optional limit (default 50, max 200). A billing:view operator may pass all_users:true for the fleet. Returns { count, invoices:[…] }.

Agent View of the PolicyLayer registry record for `list_invoices`. HTML page: https://policylayer.com/tools/dev-busymate-busymate-devtools/list-invoices

## Facts

- Tool: `list_invoices`
- Server: Busymate DevTools (`https://mcp.busymate.dev`) — https://policylayer.com/tools/dev-busymate-busymate-devtools.md
- Homepage: https://github.com/serebano/busymate-devtools
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 2
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `limit` | number | no | Max invoices to return (1–200, default 50). |
| `all_users` | boolean | no | billing:view/admin only — return EVERY account's invoices. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "list_invoices",
    "arguments": {}
  }
}
```

## Why list_invoices is rated Low

This tool retrieves financial billing data (invoices) without modifying, deleting, or moving money. It is read-only and scoped to the caller's own data or fleet data for authorized operators. While it exposes financial information, it does not perform financial transactions, create obligations, or execute payments.

From the tool's own definition: "List the caller's OWN Stripe invoices — status/amounts/currency/hosted_invoice_url/period (from stripe_invoices, owner-scoped to the caller's OAuth sub)"

## Use case

AI agents call list_invoices to retrieve information from Busymate DevTools without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Busymate DevTools:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "list_invoices": {}
  }
}
```

## Other tools on Busymate DevTools (43)

- `share_advisor_finding` — Execute — https://policylayer.com/tools/dev-busymate-busymate-devtools/share-advisor-finding.md
- `summarize_device_traffic` — Execute — https://policylayer.com/tools/dev-busymate-busymate-devtools/summarize-device-traffic.md
- `download_snapshot` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/download-snapshot.md
- `export_har` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/export-har.md
- `get_advisor_finding` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-advisor-finding.md
- `get_audit_event` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-audit-event.md
- `get_block_rules_device` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-block-rules-device.md
- `get_device` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device.md
- `get_device_egress_fail_posture` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-egress-fail-posture.md
- `get_device_egress_status` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-egress-status.md
- `get_device_health` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-health.md
- `get_device_settings` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-settings.md
- `get_device_status` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-device-status.md
- `get_entry` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-entry.md
- `get_entry_count` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-entry-count.md
- `get_my_account` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-my-account.md
- `get_push_response` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-push-response.md
- `get_service_group` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-service-group.md
- `get_stats` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-stats.md
- `get_status` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-status.md
- `get_subscription` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-subscription.md
- `get_todo` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-todo.md
- `get_usage` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-usage.md
- `get_workspace` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/get-workspace.md
- `inspect_requests` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/inspect-requests.md
- `list_advisor_findings` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-advisor-findings.md
- `list_audit_events` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-audit-events.md
- `list_breakpoint_events` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-breakpoint-events.md
- `list_device_audit_modes` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-device-audit-modes.md
- `list_device_events` — Read — https://policylayer.com/tools/dev-busymate-busymate-devtools/list-device-events.md
- …and 13 more: https://policylayer.com/tools/dev-busymate-busymate-devtools.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dev-busymate-busymate-devtools · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dev-busymate-busymate-devtools
