paymcp-security
v0.1.0
Published
PayMCP — an MCP server that helps AI coding agents add, audit, test, and debug payment integrations (V0.1: Razorpay + Next.js). Step 1: MCP foundation + secure read-only workspace layer.
Maintainers
Readme
PayMCP
PayMCP is a local MCP server that statically audits Razorpay payment integrations in Next.js App Router projects written in TypeScript. It is verification-first: it reads a project within a confined workspace, identifies common payment-integration mistakes, returns redacted evidence, calculates a deterministic engineering score, and produces a Test Mode readiness checklist.
V0.1 scope
Supported: Razorpay, Next.js App Router, TypeScript, static read-only analysis, plus a deliberately constrained Test Mode runtime order check.
Not included: payment processing, storage of credentials, live Test Mode transactions, generated source files, dashboards, hosted credential management, or other providers. A static PASS is not a payment, compliance, or production certification.
Installation
Recommended — npm
Once published to npm:
npx paymcp-securityor:
npm install -g paymcp-security
paymcp-securityNote: These commands require the
paymcp-securitypackage to be published on npm.
Development / GitHub
For contributors or pre-publication use:
git clone https://github.com/SKSAMIMGOOD/PayMCP.git
cd PayMCP
npm install
npm run build
node dist/index.jsMCP client configuration
Register PayMCP as a stdio MCP server in your MCP client. Every filesystem tool requires an explicit projectRoot; PayMCP does not default to a broad directory.
Using npx (after npm publication)
{
"mcpServers": {
"paymcp": {
"command": "npx",
"args": ["-y", "paymcp-security"]
}
}
}Using global install
{
"mcpServers": {
"paymcp": {
"command": "paymcp-security"
}
}
}Using local build
{
"mcpServers": {
"paymcp": {
"command": "node",
"args": ["/absolute/path/to/PayMCP/dist/index.js"]
}
}
}The exact configuration syntax may vary between MCP clients. Consult your client's documentation for the precise format.
MCP tools
list_payment_providers— supported providers and stacks.get_payment_requirements— secure Razorpay + Next.js requirements.audit_payment_integration— static findings, score, evidence, and caveats.test_payment_integration— static architecture/readiness checklist; it does not contact Razorpay or an application.test_payment_transaction— controlled Test Mode runtime validation against an already-running app. It requires an explicit base URL and secure host-environment credentials, never accepts secrets as arguments, never starts project commands, and stops for manual checkout.generate_payment_integration— deterministic, self-audited dry-run file plan; it never writes or overwrites project files.debug_payment— deterministic static explanation of audit findings; it never modifies files or contacts Razorpay.suggest_payment_fix— read-only, evidence-based plan for an AI coding agent to apply manually.
Security model
Project file reads are constrained to the supplied root. Traversal and symlink escapes are rejected; .env files are not read; dependency/build folders and binaries are skipped; individual reads are capped at 1 MB. Evidence is redacted before it is emitted over MCP. Do not put secrets in source code even when using PayMCP.
Development
npm run typecheck
npm test
npm run buildThe P0 static rules cover client-visible secrets, hardcoded key literals, client-controlled amounts, missing payment/webhook verification, raw webhook-body misuse, webhook secret configuration, client or pre-verification fulfillment, idempotency, capture confirmation, environment mixing, and refund authorization. Findings include confidence levels because source inspection cannot prove runtime behavior.
For AI coding agents, follow the agent audit workflow. Audit output is structured JSON with deterministic finding order and a supplemental humanReadable report; it is static-only and never modifies the project or calls Razorpay.
The controlled generator is documented in generator.md.
Runtime validation is documented in runtime-testing.md. A static PASS and runtime result remain separate evidence.
