Shatale MCP Server
OfficialThe Shatale MCP Server enables AI agents to explore and integrate with AI-native payment infrastructure. It operates in two modes:
Guest mode (no API key required):
Simulate the full purchase lifecycle offline (policy check → approval → virtual card → timeline).
Generate and validate spending policy templates with risk assessments and recommended controls.
Browse merchant category codes (MCCs) and search the merchant catalog by keyword, category, country, or capability.
Retrieve detailed merchant information.
Discover capabilities and get started via
explain_shatale.
Sandbox mode (requires sk_sandbox_* API key):
Unlock the complete payment lifecycle: initiate, track, and cancel purchases; simulate policy-based authorizations.
Pre-register users and check onboarding/verification status.
Request and manage temporary virtual card credentials (PAN, CVV, expiry).
Test integrations against real APIs without real money.
Key features across modes:
Built-in documentation (quickstart guides, policy references, use case examples).
Integration with AI IDEs (Claude Code, Cursor, Windsurf, etc.).
Security: blocks production keys, encrypts credentials, runs locally via stdio, no telemetry in guest mode.
Enables making purchases from Amazon via Shatale's payment flow, with policy checks, approval decisions, and virtual card credentials.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Shatale MCP Serversimulate a purchase flow for a $25 subscription with $100 budget"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Shatale MCP Server
MCP server for Shatale — AI-native payment infrastructure. Give your AI agents the ability to make purchases, issue virtual cards, and manage spending within delegated budgets and policy controls.
60-second demo, no API key required
See the whole agent payment lifecycle before you sign up. Guest mode makes no real API call and no payment.
1. Run it:
npx shatale-mcp-server2. Point your IDE at it (Claude Code shown — see Configure your IDE for Desktop/Cursor/Windsurf):
claude mcp add shatale -- npx shatale-mcp-server3. Ask your assistant:
Use Shatale to simulate an AI agent buying a $25 developer tool subscription with a $100 monthly budget. Show the policy check, approval decision, virtual card step, and final timeline.
You'll see the policy evaluation, the approve / decline / requires-approval decision, the (simulated) virtual card step, and a trace — all in guest mode, with no key.
Tip: call
explain_shatalefirst. It reports the current mode, the tools available to you, and the recommended first prompt.
Related MCP server: ClawPay
Run the same flow in sandbox
No code changes required. Add a sandbox key and re-run the same prompt. The guest simulation becomes a real sandbox integration — onboarding, purchase requests, approval, credential issuance, status and audit — against Shatale Sandbox APIs, with no real money.
SHATALE_API_KEY=sk_sandbox_xxx npx shatale-mcp-server…or just add the key to the env block of your IDE's MCP config (see below) — same prompt, no other changes.
Free sandbox key, no card required → admin.shatale.com/register?ref=mcp
Guest = explore (3 simulation tools + catalog). Sandbox = build (full 18-tool lifecycle). Production keys (
sk_live_*) are blocked in this MCP server by design — a local IDE/agent is not a trust boundary for live payment credentials; integrate via your backend.
Configure Your IDE
Omit the
SHATALE_API_KEYenv entirely to run in guest mode (60-second demo). Add ask_sandbox_*key to unlock the full sandbox.
Claude Desktop
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"shatale": {
"command": "npx",
"args": ["shatale-mcp-server"],
"env": {
"SHATALE_API_KEY": "sk_sandbox_your_key_here"
}
}
}
}Claude Code
claude mcp add shatale -- npx shatale-mcp-serverCursor / Windsurf
Add to .cursor/mcp.json or ~/.windsurf/mcp.json:
{
"mcpServers": {
"shatale": {
"command": "npx",
"args": ["shatale-mcp-server"],
"env": {
"SHATALE_API_KEY": "sk_sandbox_your_key_here"
}
}
}
}Tools
Discovery & Setup (no API key required)
Tool | Description |
| Start here. Reports the current mode (guest/sandbox/blocked production), the tools available to you, and the recommended first prompt |
| Simulates the Shatale agent payment lifecycle in guest mode — policy check, approve/decline/requires-approval decision, virtual card step, timeline. No real API call or payment is made |
| Generates and validates a spending policy for your use case — returns risk level, warnings, and recommended controls (never a silently unsafe policy) |
| Browse merchant category codes for policy design |
| See all available tools and capabilities |
Purchase Flow
Tool | Description |
| Request a purchase on behalf of a user — starts the full flow |
| Check the status of an existing purchase request |
| Cancel a pending purchase |
Merchant Catalog
Tool | Description |
| Search for merchants by name, category, or country |
| Get detailed info about a specific merchant (MCC, country, limits) |
User Onboarding (Cold Start)
Tool | Description |
| Pre-register a user with email, name, country — before any purchase |
| Check if a user has completed verification and onboarding |
Card Credentials
Tool | Description |
| Get temporary virtual card credentials (PAN, CVV, exp) for a purchase |
| Check the status of issued credentials |
Sandbox Testing
Tool | Description |
| Run the policy engine on a simulated authorization — side-effect-free (no ledger, no money). Returns approve/decline + explanation. Test cards: |
| Instantly complete user onboarding (skip verification) |
| Approve a sandbox purchase that is pending approval |
Note (v0.4.0, SHAT-1488): the sandbox surface now maps 1:1 to the routes the backend actually deploys.
request_purchaseis disabled when a sandbox key is set (it is not sandbox-gated on the backend and would create real ledger state) — usesandbox_simulate_authorizationinstead. The previoussandbox_create_test_user,sandbox_decline_request,sandbox_resetandsandbox_approve_requesttools have been removed/renamed.
Example Prompts
Try these with your AI assistant:
"Search for electronics merchants in Germany"
"Request a purchase of $49.99 at Amazon for user john@example.com"
"Check the status of my last purchase"
"Register a new user with email alice@startup.io and country US"
"Run a sandbox authorization for a $49.99 charge at MCC 5732 and explain the policy decision"
"What merchants are available in the travel category?"
"Generate a spending policy for a procurement bot with $5000 monthly limit"
How It Works
AI Agent → MCP Server → Shatale Sandbox API → issuing partner → virtual cardAgent requests purchase via
request_purchasewith merchant and amountShatale evaluates policy — checks delegation scope, amount limits, MCC rules
User verifies (if new) — opens personalized onboarding URL, confirms identity
Virtual card issued — the issuing partner provisions a card locked to the merchant and amount
Agent receives credentials — PAN, CVV, expiry via
request_temporary_credentialsAgent completes purchase — uses card at the merchant
In guest mode none of this hits the network — simulate_purchase_flow walks the same steps deterministically so you can see them before registering for a sandbox key.
Resources
Built-in documentation available as MCP resources:
shatale://guides/quickstart— 5-minute quickstart guideshatale://guides/policies— Policy engine and skills referenceshatale://guides/verticals— Use case examples (shopping, travel, procurement, expense)
Security
Only sandbox keys (
sk_sandbox_*) are accepted — production keys (sk_live_*) are rejectedCard credentials are encrypted (JWE) and delivered only to authorized agents
Local stdio transport — no network server exposed
See SECURITY.md for vulnerability reporting
Privacy & telemetry
This server has no telemetry: no analytics endpoint, no beacons, no install ID, no fingerprinting.
Guest mode (no API key) sends no attribution headers and no telemetry. The simulation tools (
simulate_purchase_flow,generate_policy_template) run fully offline and make no network calls. Guest activity is intentionally not measured remotely.Sandbox mode (
sk_sandbox_*) already authenticates to the Shatale Sandbox API. Those requests carry three static attribution headers so we can understand aggregate adoption of the official client:User-Agent: shatale-mcp-server/<version>X-Shatale-Client: shatale-mcp-serverX-Shatale-Client-Version: <version>
These add no new transport, endpoint, or payload — they only label calls you are already making. Analytics are derived server-side from your authenticated activity.
Never collected: API key values, prompts, policy contents, merchant/customer/card data, PAN, and no machine identifiers (OS, hostname, username, file path, or persistent install ID).
Links
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityFmaintenanceEnables AI agents to perform financial transactions such as direct payments, escrows, and bounty management using natural language with zero code integration. It provides a comprehensive suite of tools for fund streaming, subscriptions, and reputation tracking to facilitate secure agent-to-agent commerce.Last updated11MIT
- AlicenseBqualityFmaintenanceConnects AI agents to payment processors (Lithic, Stripe, PayPal) for automated shopping with single-use virtual cards and transaction management.Last updated98Apache 2.0
- Alicense-qualityCmaintenanceBanking infrastructure for AI agents: open accounts, issue cards, send SEPA/SWIFT payments, run mass payouts, and pay invoices via natural language.Last updated2MIT
- Alicense-qualityFmaintenanceEnables AI agents to make payments by securely storing encrypted card details and enforcing user-defined policies, allowing agents to fill checkout forms on any site.Last updated14MIT
Related MCP Connectors
Agent payments, API key vaulting, and governed mandates. Agents spend within user-defined limits.
Stripe-native marketplace where AI agents discover and pay per call for API services.
Commission infrastructure for AI commerce — program discovery, attribution, and settlement.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Shatale-SASU/shatale-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server