MCP server registry
Business operationsPublic source

MCP Payments

Governed Payment Operations MCP — payment intents, approval gates, evidence, reconciliation, and audit for AI agents

What it gives an agent

A purpose-built capability behind one MCP connection.

The server owns its domain logic and publishes a tool contract an MCP client can discover. ADK-Rust can load that contract into an agent, normalize each schema for the chosen model provider, and keep the connection lifecycle outside the agent’s business logic.

01

Intent-based — agents create payment intents, never execute payments directly

02

No direct execution — every financial action passes through policy evaluation and approval gates

03

i64 money — all amounts in minor units (cents/pence), no floating point, no rounding errors

04

No secrets — credentials stay in vault references, never in tool parameters or responses

05

Idempotency — every write tool requires an idempotency_key to prevent duplicate operations

06

Audit trail — every action records actor, reason, and timestamp for compliance

Architecture

How MCP Payments fits into an agent system.

The model never needs the implementation details or credentials of the system behind the server. It sees reviewed tool definitions. The MCP client handles discovery and calls, while the server keeps ownership of validation, policy, and communication with its domain system.

01

ADK-Rust agent

Chooses a capability from the reviewed tool catalog.

02

MCP client

Discovers schemas, sends calls, and receives typed content.

03

MCP Payments

Validates the request and owns 10 documented tool contracts.

04

Domain system

Keeps the API, data, credentials, and business rules behind the server.

Connection: stdio · Server framework: ADK MCP SDK + rmcp

From the project documentation

The server’s published architecture

Open the source diagram ↗
MCP Payments architecture diagram from its official repository

Tool catalog

What can an agent ask MCP Payments to do?

Each tool has a stable name, a human-readable purpose, and a JSON input contract discovered during MCP initialization. Risk classes come from the project’s registry manifest when one is available.

10 named tools

lookup_payment

Look up a payment intent by ID

read only
list_customer_payments

List all payments for a customer

read only
get_payment_status

Get the current status of a payment intent

read only
create_checkout_intent

Create a checkout payment intent (Draft). Amounts > 10000 minor units require approval.

internal write
create_refund_intent

Create a refund intent for an existing payment. Direction=Outbound.

financial action
create_payout_intent

Create a payout intent. Direction=Outbound. Always requires approval.

financial action
request_payment_approval

Request approval for a Draft payment intent. Moves Draft → PendingApproval.

internal write
execute_approved_intent

Execute an approved payment intent. ONLY works if status=Approved.

financial action
reconcile_payment

Reconcile a payment against an order/invoice reference.

internal write
attach_payment_evidence

Attach evidence artifact to a payment intent for audit trail.

internal write

Governance

Understand the effect of every tool.

A server connection inherits the authority of its credentials and deployment environment. The declarations below come from this project’s README and MCP registry manifest; your application still decides which tools an agent receives and where approval is required.

4 internal write3 read only3 financial action
  • Actor identification — every write requires actor field identifying who/what initiated
  • Reason logging — every write requires reason explaining business justification
  • Idempotency — every write requires idempotency_key preventing duplicate execution
  • Amount thresholds — checkout intents 10,000 minor units automatically require approval
  • Refund approval — all refunds require finance_manager approval
  • Payout approval — all payouts require finance_manager + compliance_officer approval

MCP surface

What the current documentation declares.

MCP can carry tools, resources, prompts, structured results, progress, cancellation, and long-running work. This record highlights the modern protocol features explicitly mentioned by this repository.

Subscriptions
ADK MCP SDKrmcpRegistry manifest

Install and connect

Follow the project’s documented starting point.

Install the server in the environment that owns its credentials and domain access. Add it to your MCP host, verify the discovered tools, and narrow the toolset before giving it to a production agent.

Install
cargo install mcp-payments
MCP client configuration
{
  "mcpServers": {
    "payments": {
      "command": "mcp-payments",
      "args": [],
      "env": {}
    }
  }
}

Commands and configuration are extracted from the public README. Confirm prerequisites, environment variables, and release-specific options in the official documentation before deployment.

Official documentation

Continue with the project maintainers’ source of truth.

This page provides an approachable map of the server. The repository remains authoritative for exact schemas, prerequisites, configuration, examples, tests, releases, and security updates.

Source record

Release and repository metadata for this catalog entry.

View public repository ↗
Version
2.0.0
License
Apache-2.0
Tools
10
Revision
ddff90892cf2
Updated
May 24, 2026
Transportsstdio