npm myfatoorah-mcpstdioMITupdated 12d ago
An LLM-friendly Model Context Protocol server for the MyFatoorah API. It lets Claude, VS Code, Cursor, and other MCP hosts discover payment methods, create payment links, verify payments, inspect invoices, and manage refunds through focused tools.
O que dá para fazer com MyFatoorah MCP?
MyFatoorah MCP
An LLM-friendly Model Context Protocol server for the MyFatoorah API. It lets Claude, VS Code, Cursor, and other MCP hosts discover payment methods, create payment links, verify payments, inspect invoices, and manage refunds through focused tools.
This is an independent community project, not an official MyFatoorah product. Test in the sandbox before using a live account.
For step-by-step host setup, Inspector testing, agent prompts, payment verification, refunds, and troubleshooting, see the usage guide.
Requirements
- Node.js 20 or newer
- A MyFatoorah API token with only the permissions required by the tools you use
Setup
npm install
cp .env.example .env
npm run build
Set MYFATOORAH_API_TOKEN in the MCP host's environment. The server does not automatically load .env; the VS Code debug configuration does.
Environment variables
| Variable | Required | Default | Description |
|---|---|---|---|
MYFATOORAH_API_TOKEN |
Yes, when calling the API | — | Bearer token. Never expose it to an agent prompt. |
MYFATOORAH_ENVIRONMENT |
No | test |
test, kuwait, uae, saudi_arabia, qatar, or egypt |
MYFATOORAH_BASE_URL |
No | Environment URL | HTTPS override for a supported MyFatoorah deployment or test proxy |
MYFATOORAH_TIMEOUT_MS |
No | 30000 |
Request timeout from 1 to 300000 ms |
Kuwait also covers the shared Bahrain, Jordan, and Oman API origin. Multi-country accounts use a separate token for each country.
Connect an MCP host
Use an absolute path in host configurations. Replace /absolute/path/to/myfatoorah-mcp and the token placeholder locally.
Claude Desktop
Add this server to Claude Desktop's MCP configuration:
{
"mcpServers": {
"myfatoorah": {
"command": "node",
"args": ["/absolute/path/to/myfatoorah-mcp/dist/index.js"],
"env": {
"MYFATOORAH_API_TOKEN": "YOUR_TOKEN",
"MYFATOORAH_ENVIRONMENT": "test"
}
}
}
}
Restart Claude Desktop after saving the configuration.
Claude Code
Project-scoped configuration can use .mcp.json (keep it uncommitted if it contains a token):
{
"mcpServers": {
"myfatoorah": {
"type": "stdio",
"command": "node",
"args": ["/absolute/path/to/myfatoorah-mcp/dist/index.js"],
"env": {
"MYFATOORAH_API_TOKEN": "YOUR_TOKEN",
"MYFATOORAH_ENVIRONMENT": "test"
}
}
}
}
VS Code / GitHub Copilot
The included .vscode/mcp.json launches the built server and securely prompts for a token. Build once, open the MCP servers view, then start myfatoorah. The token is not stored in the repository.
Cursor and generic stdio hosts
Use the same command, args, and env values as the Claude Desktop example. MCP protocol messages use stdin/stdout; server diagnostics must use stderr.
After publishing to npm, hosts can instead launch it with npx -y myfatoorah-mcp.
Tools
| Tool | Effect | Purpose |
|---|---|---|
myfatoorah_get_payment_methods |
Read-only | Lists enabled methods and their ApiName values |
myfatoorah_create_payment |
Creates data | Creates a hosted checkout or invoice link with POST /v3/payments |
myfatoorah_get_payment |
Read-only | Gets authoritative payment details by PaymentId |
myfatoorah_get_invoice |
Read-only | Gets an invoice by InvoiceId or external identifier |
myfatoorah_create_refund |
Destructive | Creates a full or partial refund; requires confirm: true |
myfatoorah_get_refund |
Read-only | Gets refund details by RefundId |
myfatoorah_api_request |
Varies | Restricted escape hatch for relative /v2/ or /v3/ paths; mutations require confirmation |
The server also exposes:
- Resource
myfatoorah://configuration: environment, base URL, timeout, and whether a token is configured—never the token itself. - Prompt
create-payment-safely: a reusable guided payment-link workflow.
Successful tools return a concise text summary plus machine-readable structuredContent containing the MyFatoorah response.
Safe payment workflow
- Read
myfatoorah://configurationand confirm test versus live. - If selecting a gateway, call
myfatoorah_get_payment_methodsand use itsApiName. - Confirm amount, currency, customer, notification method, and callback URL.
- Call
myfatoorah_create_paymentand give the customer itsPaymentURL. - After callback, call
myfatoorah_get_paymentwith the returned PaymentId. A redirect is not proof of payment; require invoice statusPAIDand transaction statusSUCCESS.
Refunds move money in live mode. Obtain explicit user approval for the exact PaymentId and amount before passing confirm: true.
Development
npm run format
npm run lint
npm run typecheck
npm test
npm run build
npm run inspect
npm run inspect starts the official MCP Inspector against the compiled stdio server. VS Code also includes build/test tasks and a debug configuration.
Tests mock every MyFatoorah request; they do not make network calls or require a token.
Security
- Use a least-privilege MyFatoorah API key and rotate it regularly.
- Put credentials in the host environment or a secret manager, never source control or model context.
- The generic request tool rejects absolute URLs, protocol-relative URLs, traversal, and paths outside
/v2/and/v3/to prevent credential exfiltration. - API errors and Bearer values are redacted before reaching the model.
- Prefer idempotency keys for supported mutations and stable order identifiers.
- Do not expose this stdio process as an unauthenticated network service.
- Direct card handling is intentionally not modeled as a focused tool; it requires PCI compliance.
API scope and references
The focused tools use MyFatoorah's documented v3 routes as of August 2026:
GET /v3/payment-methodsPOST /v3/paymentsGET /v3/payments/{paymentId}GET /v3/invoices/{invoiceId}GET /v3/invoices/externalIdentifier/{externalIdentifier}POST /v3/refundsGET /v3/refunds/{refundId}
References:
License
MIT
Instalação
Adicione MyFatoorah MCP ao seu cliente. Escolha o que você usa.
claude mcp add myfatoorah-mcp -- npx -y myfatoorah-mcpcodex mcp add myfatoorah-mcp -- npx -y myfatoorah-mcpamp mcp add myfatoorah-mcp -- npx -y myfatoorah-mcp{
"mcpServers": {
"myfatoorah-mcp": {
"command": "npx",
"args": [
"-y",
"myfatoorah-mcp"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"myfatoorah-mcp": {
"command": "npx",
"args": [
"-y",
"myfatoorah-mcp"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"myfatoorah-mcp","command":"npx","args":["-y","myfatoorah-mcp"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"myfatoorah-mcp": {
"command": "npx",
"args": [
"-y",
"myfatoorah-mcp"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"myfatoorah-mcp": {
"command": "npx",
"args": [
"-y",
"myfatoorah-mcp"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"myfatoorah-mcp": {
"command": "npx",
"args": [
"-y",
"myfatoorah-mcp"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"myfatoorah-mcp": {
"type": "local",
"command": "npx",
"args": [
"-y",
"myfatoorah-mcp"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"myfatoorah-mcp": {
"command": {
"path": "npx",
"args": [
"-y",
"myfatoorah-mcp"
]
}
}
}
}Add to your Zed `settings.json`.
npx -y myfatoorah-mcpRun `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
7 ferramentas
MyFatoorah MCP expõe 7 ferramentas a um agente conectado.
- myfatoorah_get_payment_methods
- Read-only
- myfatoorah_create_payment
- Creates data
- myfatoorah_get_payment
- Read-only
- myfatoorah_get_invoice
- Read-only
- myfatoorah_create_refund
- Destructive
- myfatoorah_get_refund
- Read-only
- myfatoorah_api_request
- Varies
Pontuação
78 / 100
Boa
- Documentação25/25
- Manutenção19/25
- Confiança16/20
- Capacidade6/15
- Instalação12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 5 days ago
- Has a release history
- Repository is not archived
- Licensed MIT
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 7 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Histórico de versões
| Versões | Publicada |
|---|---|
| 0.1.0Mais recente | 27 de ago. de 2026 |