Skip to content
Tally Engine
Read and write Tally over HTTPS

Your Tally books,answering in milliseconds.

Tally Engine puts a real API in front of TallyPrime — eighteen report pulls, ten write operations, and an MCP server your AI assistant can talk to. Reads degrade when the desktop is off. Writes defer and land exactly once.

No inbound port. No per-site DNS. The connector dials out.

GET /v1/reports/balance-sheet?company=ACME%20LTD
200 OKfreshness "live"as_of 2026-09-11T19:42Z
Balance sheetas at 31-Mar-2026
Liabilities
Capital Account
2,93,97,006.62
Loans (Liability)
18,40,112.00
Current Liabilities
26,22,203.40
Suspense A/c
0.00
Total3,38,59,322.02
Assets
Fixed Assets
1,04,21,880.00
Current Assets
2,34,37,442.02
Profit & Loss A/c
—
 
Total3,38,59,322.02
Matches the TallyPrime desktop to the paisa — Tally drew this report, not us.
18
Tally reports, pulled and cached
10
Write operations, exactly once
<10 ms
Warm read, served from cache
0
Inbound ports opened on your LAN

From a desktop nobody can reach to an API anyone can call.

Tally holds the ledger, and Tally is a program on one computer in one office. Tally Engine sits beside it — on the LAN, dialling out — so the same books answer a report request from a server, a spreadsheet, a dashboard or an AI agent, without anybody opening a port or copying a company file.

Before Tally Engine

Somebody has to be at the machine with Tally open.

Exports go out as XLSX over email, stale the moment they are sent.

A report request means a phone call and a wait.

Integrations post twice when a retry is unlucky.

“Is this number current?” has no answer but “probably”.

After Tally Engine

The books answer over HTTPS whether or not anyone is at the desk.

One key, one URL, JSON with an `as_of` on every row.

A report comes back in milliseconds from a verified-fresh cache.

Writes carry an idempotency key Tally itself collapses on.

Freshness is proven against Tally's own AlterID, not guessed.

Your network
TallyPrime
port 9000
Connector
dials out
Tally Engine
cache · outbox
REST /v1
your code
MCP server
your AI agent
Dashboard
your team

How it works

Three steps, and the third one is the only one you repeat.

Fifteen minutes on the day you set it up. Nothing to maintain afterwards — the connector updates itself.

Step one, in full

& ([scriptblock]::Create((irm https://tally-engine.up.railway.app/install.ps1))) -Token <your-token>

The dashboard fills in the token for you, so there is nothing to type and nothing to configure. macOS and Linux get the same line through install.sh.

  1. One command, any modern Windows box

    Install the connector

    Paste a single line into PowerShell on any Windows machine on the same network as Tally — it does not have to be the Tally machine itself. It registers as a background task, starts on logon and restarts if it stops. macOS and Linux builds exist for the same one-liner.

  2. It finds the machine for you

    Point it at your Tally

    The connector scans its own network and shows you the company names it found — not IP addresses. Pick the books you mean. Nothing is stored on our side but the address you chose.

  3. Or hand your AI agent the key

    Call the API

    A tenant-scoped key, a URL and a company name is the whole contract. The same endpoints back the dashboard, your own integration and the MCP server that Claude, ChatGPT or any MCP client connects to.

Features

Everything a finance team asks of Tally, over an API.

Built for integrators. Usable by the person who actually keeps the books.

Provable freshness

Every cached row stores the AlterID it was computed at. A read is served from cache only when that counter still matches Tally's — provably unchanged, not probably. The response says which it was.

Writes land exactly once

Ten write operations carry an idempotency key that TallyPrime itself collapses duplicates on — verified across a full restart. A write attempted while Tally is off is queued, not failed.

Offline cover

A background warmer keeps the reports a company actually asks for current, so the books still answer questions when the Tally desktop is closed for the night.

MCP, not a chatbot

An MCP server exposes every report and every write as a tool. Point Claude at your books and ask in words; the answer is Tally's own figure, not a model's arithmetic.

Many sites, one workspace

Branches, clients, group companies — each Tally machine is a site under one workspace, addressed by id. Resellers provision customers and run them from the dashboard they already use.

It updates itself

The connector checks in, verifies a new build by hash, drains its in-flight work and swaps. Your customer's machine is never a version behind because nobody drove out to it.

Reports

Tally's own reports, not our impression of them.

A balance sheet asks TallyPrime to draw its balance sheet. We never recompute a figure — no reimplemented opening-balance carry-forward, no guessed group rollups. The numbers match the desktop to the paisa.

Pull18 reports, cached and served with a freshness verdict
balance-sheetprofit-losstrial-balancecash-flowratio-analysisday-bookledger-accountledger-balancegroup-detailsbills-outstandingsales-registerpurchase-registercost-centre-summarystock-summarystock-item-accountstock-item-balancechart-of-accountslist-master
Push10 write operations, each idempotent and queued when Tally is off
create-vouchercreate-ledgeralter-ledgerdelete-ledgercreate-groupalter-groupdelete-groupcreate-stock-itemalter-stock-itemdelete-stock-item
We cache Tally’s output. We never recompute it.
No reimplemented opening-balance carry-forward, no guessed group rollups, no stock valuation of our own. Every figure on every report is the one TallyPrime produced.

Security

The books stay where they are.

A finance system is a target. The architecture answers that before the feature list does.

Outbound only — nothing on your network is addressable from ours

Nothing dials in

The connector opens an outbound WebSocket to us. There is no inbound port to forward, no per-site DNS record, no certificate to renew and nothing on your network reachable from the internet. Revoking a site closes the socket.

One credential, one machine

Each connector holds a machine credential bound to one installation, minted at enrolment and hashed at a pinned cost. It is never an admin's login token, so it cannot be widened and does not expire out from under you.

Keys are scoped and shown, not lost

An API key belongs to one workspace and can be confined to a single Tally site. It is sealed with AES-256-GCM so your dashboard can show it again, while the only thing authentication ever consults is the hash.

Refusals say nothing

A wrong tenant, an unknown site and a revoked key return one identical response. There is no probe that tells an outsider which workspaces or machines exist.

FAQ

Questions we get asked a lot.

Does the connector have to run on the Tally machine?

No — and often it should not. Install it on any modern Windows computer on the same network and point it at the Tally server's address. That matters because Tally still runs happily on machines far older than our connector supports.

What happens when TallyPrime is closed?

Reads degrade and writes defer. A report request is served from cache with an `as_of` timestamp and a freshness flag that says plainly it was not read live. A write is queued and posted the moment the connector reconnects — it is never silently dropped and never posted twice.

Can it write to my books?

Only if you use the write endpoints. There are ten of them, each validated before submission — a voucher whose entries do not balance is refused by us before Tally ever sees it. Referential checks are left to Tally so it stays the authority.

How do I know a number is current?

Every response carries `as_of`, `freshness` and `verified_at`. `live` means Tally was read during your request. `sampled` means a background probe proved the books unchanged as of a stated instant. `stale` means the desktop was unreachable and you are reading cache. We never present one as another.

Do you copy my company data to your servers?

We cache the reports you ask for, so they can still be answered when Tally is off — that is the whole point of the product. We do not mirror the company file, and nothing is ever recomputed from it. Self-hosting the server is available for firms whose policy requires it.

Does it work with several companies?

Yes. Companies are addressed by the exact name Tally reports, suffix included, and cache is keyed by the company's GUID as well as its name — so two branches whose books are both called “ACME LTD” never see each other's figures.

What does an AI agent actually get?

An MCP server with every report and write as a typed tool, plus a SQL layer for asking questions across a report it has already pulled. The model reads Tally's figures; it does not produce them.

Which TallyPrime versions are supported?

TallyPrime with its HTTP gateway enabled — F1 → Connectivity, off by default. Note the Tally Gateway Server on port 9999 is a licence server and serves no company data; the port that matters is 9000.

Point it at your books tonight.

One command on one Windows machine, and the whole ledger answers over HTTPS. Nothing to migrate, nothing to change in how your team uses Tally.

Works with the TallyPrime you already run. Nothing to migrate.