Skip to main content
ArcenPay exposes Model Context Protocol (MCP) servers so assistants and agents can work with your account. There are two surfaces, deliberately separated: The hosted server is intentionally read-only: it never moves funds and never changes billing state. Payment execution stays on the local agent, which holds the key. See the Agent SDK MCP tools for the local server.

Enable the hosted server

The endpoint is off by default — existing deployments are unchanged until you enable it. The server mounts at POST /mcp (Streamable HTTP, stateless). The MCP surface is exempt from the edge bot/shield protection (it is consumed by machine clients such as OpenAI’s verifier and the ChatGPT/Codex connectors).

Authentication

Two credential types are accepted:
  • OAuth 2.1 access token — used by ChatGPT connectors, which cannot send a static API key. Authorization-code + PKCE (S256), public clients via Client ID Metadata Documents (CIMD).
  • API key (Authorization: Bearer sk_/rk_…) — for Claude/Cursor/Codex and server-to-server clients.
Publishable (pk_) keys are rejected. Every tool is scoped to the caller’s team and environment; a team id is never taken from the request. Requests without a valid credential receive 401 with a WWW-Authenticate challenge pointing at the protected-resource metadata.

OAuth flow

  1. The client opens GET /oauth/authorize with the standard OAuth parameters.
  2. If the user has no session, the backend hands off to the dashboard’s consent screen (app.arcenpay.com/oauth/authorize). The user signs in once if needed, then clicks Authorize — no repeated login.
  3. The backend issues an authorization code; the client exchanges it at POST /oauth/token for an access token (+ refresh token), which is then sent as Authorization: Bearer … on every MCP request.

Tools (read-only)

All tools carry readOnlyHint: true.

Connect a client

  • MCP Inspector: npx @modelcontextprotocol/inspector → Streamable HTTP → https://api.arcenpay.com/mcp, add the Authorization header.
  • ChatGPT: add the MCP server URL and choose OAuth; you’ll get the one-click consent screen.
  • Claude / Cursor / Codex: add a remote MCP server with the /mcp URL and an API-key Authorization header.

ChatGPT plugin

A packaged plugin (plugin.json + mcp.json + skills/) points ChatGPT at https://api.arcenpay.com/mcp. Only the read-only account tools are submitted for listing — payment and lifecycle operations are never part of the public plugin, per the host’s commerce rules.
State-changing operations (creating payment links, changing plans, issuing mandates) are not part of this read-only surface. They are available to MCP clients that operate against your own infrastructure, and their public-listing eligibility is constrained by the host’s commerce rules.
Last modified on October 6, 2026