Authoryze MCP Server
Authoryze gives your AI agent a spending limit. It lets you hand an agent a payment method without handing it your card: you define what it can buy, from which merchants, and up to what amount, and every purchase request comes to you for approval before a single-use virtual card is issued. It is built on Visa Intelligent Commerce and Mastercard Agent Pay, and is currently available for US-issued cards. Authoryze is a remote MCP (Model Context Protocol) server that works with Claude, Claude Code, ChatGPT, Cursor, Windsurf, and any MCP-compatible client.
Installation
OAuth-capable clients such as Claude and ChatGPT need only the endpoint:
{
"mcpServers": {
"authoryze": {
"url": "https://authoryze.ai/api/mcp"
}
}
}
Clients that don't support OAuth, such as Claude Code, Codex, and custom frameworks, authenticate with a static agent API key as a bearer token:
{
"mcpServers": {
"authoryze": {
"url": "https://authoryze.ai/api/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}
Tools
- request_purchase - Ask to make a purchase from a specific merchant, for a specific amount, with a reason. The request either gets approved automatically, gets sent to the account owner for approval, gets denied with a reason, or fails in a way that's safe to retry.
- check_status - Look up what happened to a purchase request: approved, denied, still waiting on approval, or failed. Doesn't reveal any card details itself.
- get_spending_summary - See how much has been spent so far against the configured limits (daily, weekly, monthly, and total), including any account-wide limit that applies across all of an account's agents.
- retrieve_card - Once a purchase is approved, get the actual card number, expiry, and security code to complete the purchase. This can only be done once per approved purchase; the details are shown a single time and can't be retrieved again.
Requirements
Authoryze is available for US-issued cards only. International support is pending issuer coverage on the agentic token programs.
Authentication requires either OAuth 2.1 with PKCE (S256) and Dynamic Client Registration, or a static agent API key used as a bearer token.
Links
Homepage: https://authoryze.ai
Docs: https://authoryze.ai/docs
Smithery
Listed on Smithery: https://smithery.ai/servers/authoryze/authoryze