Controls agent purchases with approvals, spending limits, and single-use virtual card details.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
๐ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Authoryze.
request_purchaseAsk to make a purchase from a specific merchant, for a specific amount, with a reason. The request either gets approved automatically, gets sent to the account owner for approval, gets denied with a reason, or fails in a way that's safe to retry.
check_statusLook up what happened to a purchase request: approved, denied, still waiting on approval, or failed. Doesn't reveal any card details itself.
get_spending_summarySee how much has been spent so far against the configured limits (daily, weekly, monthly, and total), including any account-wide limit that applies across all of an account's agents.
retrieve_cardOnce a purchase is approved, get the actual card number, expiry, and security code to complete the purchase. This can only be done once per approved purchase; the details are shown a single time and can't be retrieved again.
The Authoryze MCP server gives an AI agent a controlled way to request purchases without directly providing the agent with an existing payment card. A purchase request identifies the merchant, amount, and reason. Depending on the configured controls, the request may be approved automatically, sent to the account owner, denied with an explanation, or return a retry-safe failure.
The service is built around single-use virtual cards. After an approved request, the agent can retrieve the card number, expiration date, and security code needed to complete that purchase. Card details are displayed only once and cannot be retrieved again through the service.
Authoryze also reports spending against daily, weekly, monthly, and total limits. The summary can include an account-wide limit shared across the account's agents, rather than only the limits associated with one agent.
Authoryze is a remote MCP server available at https://authoryze.ai/api/mcp. An MCP-compatible client connects to that endpoint and invokes the purchase and reporting tools. OAuth-capable clients can authenticate through the configured OAuth flow. Clients without OAuth support can send a static agent API key as a bearer token.
A typical purchase flow starts with request_purchase. The agent can then call check_status to determine whether the request was approved, denied, remains pending, or failed. The agent should call retrieve_card only after approval. That operation returns the payment details for the approved purchase and is intentionally one-time. get_spending_summary provides current usage against the relevant limits.
OAuth-capable clients can be configured with the MCP endpoint alone. Clients that do not support OAuth use the same endpoint with an Authorization header containing the agent API key as a bearer token. The README specifically describes OAuth 2.1 with PKCE using S256 and Dynamic Client Registration, or static agent API-key authentication.
The service currently supports US-issued cards. International availability depends on issuer coverage for the relevant agentic payment programs, so deployments requiring non-US cards should verify coverage before relying on the service.
request_purchase: submits a merchant-specific purchase request with an amount and reason, then reports approval, owner-review, denial, or a retry-safe failure.check_status: checks the outcome of a purchase request without exposing card information.get_spending_summary: reports spending against daily, weekly, monthly, total, and applicable account-wide limits.retrieve_card: returns the number, expiration date, and security code for an approved purchase once; the details cannot be fetched again.The Authoryze MCP server is therefore suited to agents that need to buy something under explicit controls, but it does not remove the need to handle approval states and one-time secret retrieval carefully.
Factual signals from GitHub, npm, and our automated checks โ not a rating.
No reviews yet โ be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/authoryze)<a href="https://allmcps.com/mcp/authoryze"><img src="https://allmcps.com/api/badge/authoryze?style=directory" alt="Authoryze on AllMCPs" /></a>