MCP server for CloudPayments API — charge, auth, confirm, void, refund, find transaction. 6 tools.
SaferSkills independently audited cloudpayments-mcp (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for CloudPayments API -- one-step and two-step payments, refunds, subscriptions, orders (invoice links), transaction history. 12 tools.
Part of Russian API MCP series by @theYahia.
{
"mcpServers": {
"cloudpayments": {
"command": "npx",
"args": ["-y", "@theyahia/cloudpayments-mcp"],
"env": {
"CLOUDPAYMENTS_PUBLIC_ID": "your-public-id",
"CLOUDPAYMENTS_API_SECRET": "your-api-secret"
}
}
}
}claude mcp add cloudpayments -e CLOUDPAYMENTS_PUBLIC_ID=your-id -e CLOUDPAYMENTS_API_SECRET=your-secret -- npx -y @theyahia/cloudpayments-mcp{
"cloudpayments": {
"command": "npx",
"args": ["-y", "@theyahia/cloudpayments-mcp"],
"env": {
"CLOUDPAYMENTS_PUBLIC_ID": "your-public-id",
"CLOUDPAYMENTS_API_SECRET": "your-api-secret"
}
}
}HTTP_PORT=3000 npx @theyahia/cloudpayments-mcp
# or
npx @theyahia/cloudpayments-mcp --http 3000Endpoints: POST /mcp (JSON-RPC), GET /health (status).
| Variable | Required | Description |
|---|---|---|
CLOUDPAYMENTS_PUBLIC_ID | Yes | Public ID (HTTP Basic username) |
CLOUDPAYMENTS_API_SECRET | Yes | API secret (HTTP Basic password) |
For testing, use the CloudPayments test terminal.
| Tool | API Endpoint | Description |
|---|---|---|
charge_payment | POST /payments/charge | One-step payment (immediate charge) |
auth_payment | POST /payments/auth | Two-step payment (authorize/hold) |
confirm_payment | POST /payments/confirm | Confirm authorized payment (full or partial) |
void_payment | POST /payments/void | Void authorized payment (release hold) |
get_transaction | POST /payments/find | Find transaction by ID |
| Tool | API Endpoint | Description |
|---|---|---|
refund_payment | POST /payments/refund | Full or partial refund by transaction ID |
| Tool | API Endpoint | Description |
|---|---|---|
create_subscription | POST /subscriptions/create | Create recurring subscription with token |
update_subscription | POST /subscriptions/update | Update amount, interval, period |
cancel_subscription | POST /subscriptions/cancel | Cancel active subscription |
list_subscriptions | POST /subscriptions/find | List subscriptions for a user |
| Tool | API Endpoint | Description |
|---|---|---|
create_order | POST /orders/create | Create payment order (invoice link) |
| Tool | API Endpoint | Description |
|---|---|---|
list_transactions | POST /payments/list | List all transactions for a date |
Charge 5000 RUB from the card cryptogram, IP 192.168.1.1, description "Premium plan"Create a monthly subscription for 999 RUB using token from the last payment, starting May 1stShow me all transactions for yesterday and refund 2500 RUB on transaction 123456| MCP | Status | Description |
|---|---|---|
| @metarebalance/dadata-mcp | ready | Addresses, companies, banks, phones |
| @theyahia/cbr-mcp | ready | Currency rates, key rate |
| @theyahia/yookassa-mcp | ready | Payments, refunds, receipts, payouts, webhooks |
| @theyahia/cloudpayments-mcp | ready | Payments, subscriptions, orders |
| ... | +46 servers -- full list |
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.