adyen-mcp

mcp
Guvenlik Denetimi
Gecti
Health Gecti
  • License — License: MIT
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Community trust — 20 GitHub stars
Code Gecti
  • Code scan — Scanned 12 files during light audit, no dangerous patterns found
Permissions Gecti
  • Permissions — No dangerous permissions requested
Purpose
This is an official TypeScript-based MCP server that allows Large Language Models (LLMs) to interact directly with Adyen's payment and management APIs. It enables developers to automate payment operations, retrieve transaction statuses, and manage terminal accounts via function calling.

Security Assessment
Overall Risk: Medium. The tool itself does not execute arbitrary shell commands, contained no hardcoded secrets, and did not exhibit any dangerous code patterns during the file scan. However, the core function of this server is to make authenticated network requests to Adyen's highly sensitive financial APIs. It is capable of creating payment sessions, processing refunds, canceling authorized payments, and managing company accounts. Because an LLM will have the ability to initiate financial transactions or access payment data, the blast radius for a misconfiguration or a prompt injection attack is very high. Strict access controls and careful API permission scoping are mandatory.

Quality Assessment
Overall Quality: High. The repository is actively maintained, with very recent updates, and is backed by a reputable financial technology company (Adyen). It is licensed under the standard MIT license and has accumulated a solid baseline of community engagement. The light code audit scanned 12 files without finding any red flags or requesting dangerous local system permissions.

Verdict
Use with caution. The code itself is safe and well-maintained, but developers must implement strict guardrails to prevent unauthorized financial transactions or unintended access to sensitive payment data.
SUMMARY

Typescript library for integrating Adyen APIs via an MCP server

README.md

Adyen MCP Server - Alpha

The Adyen Model Context Protocol (MCP) server allows you to integrate with Adyen APIs through LLMs function calling utilizing various clients. It currently supports the following tools. Read more on our Blog - Part 1.

  1. CheckoutAPI - Sessions
  2. CheckoutAPI - Payment Links
  3. Checkout API - Modifications
  4. Management API - Accounts
    • Gets a list of merchant accounts for your company account - GET /merchants
  5. Management API - Terminals
  6. Management API - Webhooks

Usage

  • Run the MCP server via npx with the following command:
npx -y @adyen/mcp --adyenApiKey=YOUR_ADYEN_API_KEY --env=TEST

If you are using the LIVE environment then you must also provide your live URL prefix, for example:

npx -y @adyen/mcp --adyenApiKey=YOUR_ADYEN_API_KEY --env=LIVE --livePrefix=YOUR_PREFIX_URL

We advise to only run a subset of tools required for your particular use case:

npx -y @adyen/mcp --adyenApiKey=YOUR_ADYEN_API_KEY --env=TEST --tools=list_all_company_webhooks,list_all_merchant_webhooks

Example usage in .vscode:

{
  "servers": {
    "adyen-mcp-server": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@adyen/mcp", "--adyenApiKey=YOUR_ADYEN_API_KEY", "--env=TEST"],
      "env": {
        "ADYEN_API_KEY": "${ADYEN_API_KEY}"
      }
    }
  }
}

Note: To run certain functionality (tools) in the mcp-server, you need a webservice user with the following roles:

  • Management API - Accounts Read
  • Management API - Payment methods Read
  • Checkout Webservice Role
  • Merchant PAL Webservice Role
  • Management API - Terminals read
  • Management API — Assign Terminal
  • Management API — Terminal actions read
  • Management API — Terminal actions read and write
  • Management API — Android files read
  • Management API — Terminal settings read
  • Management API — Terminal settings read and write
  • Management API — Webhooks read

Adyen recommends creating a new webservice user and generating a new API key for the purpose of this application.
Only use the new user’s API key for the MCP application and limit the roles to match the tools you'll be using.

License

MIT license. For more information, see the LICENSE file.

Contributing

We strongly encourage you to contribute to our repository. Find out more in our contribution guidelines. If you'd like to run this in Codespaces, follow this guide.

Support

If you have a feature request, or spotted a bug or a technical problem, create a GitHub issue. For other questions, contact: [email protected]

Yorumlar (0)

Sonuc bulunamadi