SezzleOps MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SEZZLE_ENV | No | Environment: sandbox or production. | sandbox |
| MCP_HTTP_HOST | No | Host for HTTP transport. | 127.0.0.1 |
| MCP_HTTP_PORT | No | Port for HTTP transport. | 3000 |
| MCP_TRANSPORT | No | Transport: stdio or http. | stdio |
| SEZZLE_API_KEY | No | Your Sezzle API public key. Required for production. | |
| SEZZLE_READ_ONLY | No | If true, mutation tools are not registered. | true |
| SEZZLE_API_SECRET | No | Your Sezzle API private key. Required for production. | |
| MCP_HTTP_AUTH_TOKEN | No | Bearer token for non-loopback HTTP bind. Required if binding to non-loopback address. | |
| SEZZLE_API_BASE_URL | No | Base URL for Sezzle API. Default for sandbox: https://sandbox.gateway.sezzle.com, for production: https://gateway.sezzle.com. | |
| SEZZLE_MERCHANT_UUID | No | Your Sezzle merchant UUID. Required for production. | |
| SEZZLE_WEBHOOK_SECRET | No | Your Sezzle webhook signing secret for HMAC-SHA256 verification. | |
| MCP_HTTP_ALLOWED_HOSTS | No | Allowed hosts for non-loopback HTTP bind. Required if binding to non-loopback address. | |
| MCP_HTTP_ALLOWED_ORIGINS | No | Allowed origins for non-loopback HTTP bind. Required if binding to non-loopback address. | |
| SEZZLE_PERMISSION_PROFILE | No | Permission profile: read, finance, webhooks, support, or admin. | read |
| SEZZLE_REQUIRE_CONFIRMATION | No | If true, mutations require explicit confirmation with preview_id. | true |
Capabilities
Features and capabilities supported by this server
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| prompts | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| sezzle_authenticate_merchantA | Acquire or refresh a merchant bearer token from configured environment credentials. Secrets are never returned. |
| sezzle_get_merchant_contextA | Return non-secret environment, merchant, safety, and permission context for this server process. |
| sezzle_get_payment_sessionA | Read a documented Sezzle v2 payment session by UUID. |
| sezzle_get_orderA | Read a documented Sezzle v2 order and return a minimized financial projection without customer PII. |
| sezzle_list_settlement_summariesB | List documented settlement payout summaries with lossless minor-unit amounts. |
| sezzle_get_settlement_detailsA | Get and parse a documented settlement detail CSV by payout UUID. |
| sezzle_get_order_reportA | Get the allowlisted Sezzle order report for a maximum seven-day range, excluding customer PII. |
| sezzle_get_interest_balanceA | Get interest-account balance losslessly at four-decimal scale. Enrollment is required by Sezzle. |
| sezzle_get_interest_activityA | Get and parse interest-account activity at four-decimal scale. Enrollment is required by Sezzle. |
| sezzle_diagnose_integrationB | Run deterministic Integration Doctor checks over supplied configuration, order, webhook, and reconciliation evidence. |
| sezzle_validate_session_payloadA | Validate a proposed Sezzle session payload deterministically without sending customer or order data to Sezzle. |
| sezzle_validate_redirect_urlsA | Validate cancel and complete redirects against HTTPS and supplied merchant hosts. |
| sezzle_audit_auth_capture_flowC | Audit supplied authorization, capture, refund, reference, and currency state for deterministic flow defects. |
| sezzle_detect_stuck_authorizationsB | Find approved uncaptured authorizations that have not progressed within a threshold. |
| sezzle_detect_uncaptured_ordersA | Find approved orders whose captured amount remains below authorization. |
| sezzle_detect_duplicate_refundsA | Detect duplicate refund IDs or repeated amount/time fingerprints in supplied order evidence. |
| sezzle_test_webhook_configurationB | Evaluate webhook subscriptions, invalid signatures, missing events, and out-of-order evidence without sending a test event. |
| sezzle_generate_go_live_checklistA | Generate a deterministic production-readiness checklist and blocking findings from supplied evidence. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| sezzle_daily_operations_review | Sezzle Daily Operations Review using evidence-first, non-executing SezzleOps workflows. |
| sezzle_integration_go_live_review | Sezzle Integration Go-Live Review using evidence-first, non-executing SezzleOps workflows. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| sezzle-config | Secret-free runtime safety configuration. |
| sezzle-permissions | |
| sezzle-capabilities | |
| sezzle-diagnostic-codes |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/onatozmenn/sezzle-merchant-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server