# Authoryze [Health: Active]

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/kevinfee3/authoryze-mcp  
**GitHub Stars:** 0  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/authoryze

## Description
Give your AI agent a spending limit: approval controls and single-use virtual cards.

## Tools
Capabilities this server exposes over MCP:

- **request_purchase** — Ask to make a purchase from a specific merchant, for a specific amount, with a reason. The request either gets approved automatically, gets sent to the account owner for approval, gets denied with a reason, or fails in a way that's safe to retry.
- **check_status** — Look up what happened to a purchase request: approved, denied, still waiting on approval, or failed. Doesn't reveal any card details itself.
- **get_spending_summary** — See how much has been spent so far against the configured limits (daily, weekly, monthly, and total), including any account-wide limit that applies across all of an account's agents.
- **retrieve_card** — Once a purchase is approved, get the actual card number, expiry, and security code to complete the purchase. This can only be done once per approved purchase; the details are shown a single time and can't be retrieved again.

## Claude Desktop Quick Installation
Remote MCP endpoint (confidence: high). Install path detected from listing signals. Add as a URL/SSE server in your client:

```json
"mcpServers": {
  "authoryze": {
    "url": "https://authoryze.ai/api/mcp"
  }
}
```

## Documentation

## What the Authoryze MCP server does

The Authoryze MCP server gives an AI agent a controlled way to request purchases without directly providing the agent with an existing payment card. A purchase request identifies the merchant, amount, and reason. Depending on the configured controls, the request may be approved automatically, sent to the account owner, denied with an explanation, or return a retry-safe failure.

The service is built around single-use virtual cards. After an approved request, the agent can retrieve the card number, expiration date, and security code needed to complete that purchase. Card details are displayed only once and cannot be retrieved again through the service.

Authoryze also reports spending against daily, weekly, monthly, and total limits. The summary can include an account-wide limit shared across the account's agents, rather than only the limits associated with one agent.

## How it works

Authoryze is a remote MCP server available at `https://authoryze.ai/api/mcp`. An MCP-compatible client connects to that endpoint and invokes the purchase and reporting tools. OAuth-capable clients can authenticate through the configured OAuth flow. Clients without OAuth support can send a static agent API key as a bearer token.

A typical purchase flow starts with `request_purchase`. The agent can then call `check_status` to determine whether the request was approved, denied, remains pending, or failed. The agent should call `retrieve_card` only after approval. That operation returns the payment details for the approved purchase and is intentionally one-time. `get_spending_summary` provides current usage against the relevant limits.

## Setup and configuration

OAuth-capable clients can be configured with the MCP endpoint alone. Clients that do not support OAuth use the same endpoint with an `Authorization` header containing the agent API key as a bearer token. The README specifically describes OAuth 2.1 with PKCE using S256 and Dynamic Client Registration, or static agent API-key authentication.

The service currently supports US-issued cards. International availability depends on issuer coverage for the relevant agentic payment programs, so deployments requiring non-US cards should verify coverage before relying on the service.

## Tools and capabilities

- `request_purchase`: submits a merchant-specific purchase request with an amount and reason, then reports approval, owner-review, denial, or a retry-safe failure.
- `check_status`: checks the outcome of a purchase request without exposing card information.
- `get_spending_summary`: reports spending against daily, weekly, monthly, total, and applicable account-wide limits.
- `retrieve_card`: returns the number, expiration date, and security code for an approved purchase once; the details cannot be fetched again.

The Authoryze MCP server is therefore suited to agents that need to buy something under explicit controls, but it does not remove the need to handle approval states and one-time secret retrieval carefully.

_Full upstream README: https://allmcps.com/mcp/authoryze/readme_

