The runtime security layer for AI agent commerce. Drop-in CLI + MCP server — blocks hallucinated purchases and keeps card credentials out of agent
Connect Pop Pay to Claude, Cursor or any other MCP client and it stops being a tab you switch to. The runtime security layer for AI agent commerce. Drop-in CLI + MCP server — blocks hallucinated purchases and keeps card credentials out of agent context. It only takes 0.1% of hallucination to drain 100% of your wallet. The pop pay mcp server is what makes that connection.
The runtime security layer for AI agent commerce. Drop-in CLI + MCP server. Card credentials are injected directly into the browser DOM via CDP — they never enter the agent's context window. One hallucinated prompt can't drain a wallet it can't see.
The toolset is worth reading before you wire it up, because it tells you what the integration is really for:
request_virtual_card — Issue a virtual card and inject credentials into the checkout page via CDP. Automatically scans the page for hidden prompt injectionsrequest_purchaser_info — Auto-fill billing/contact info (name, address, email, phone). Automatically scans the page for hidden prompt injectionsrequest_x402_payment — Pay for API calls via the x402 HTTP payment protocolConfiguration is passed through the environment: POP_CDP_URL, POP_STRIPE_KEY. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
The server ships on npm as pop-pay, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.
Plenty of payments and commerce servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Pop Pay's toolset — request_virtual_card, request_purchaser_info, request_x402_payment — is a fair guide to whether it matches your workflow. It is maintained by 100xpercent; worth a glance at recent repository activity before you build anything load-bearing on it.
We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.
| Tool | What it does |
|---|---|
| request_virtual_card | Issue a virtual card and inject credentials into the checkout page via CDP. Automatically scans the page for hidden prompt injections. |
| request_purchaser_info | Auto-fill billing/contact info (name, address, email, phone). Automatically scans the page for hidden prompt injections. |
| request_x402_payment | Pay for API calls via the x402 HTTP payment protocol. |
{
"mcpServers": {
"pop-pay": {
"command": "npx",
"args": ["-y", "pop-pay"],
"env": {
"POP_CDP_URL": "your-value",
"POP_STRIPE_KEY": "your-value"
}
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
| Variable | Description | Required |
|---|---|---|
| POP_CDP_URL | Endpoint or connection string the server talks to. | Yes |
| POP_STRIPE_KEY | Credential the server authenticates with. | Yes |
Payments infrastructure meets AI — customers, invoices, subscriptions and current API docs from Stripe's server.
Build for Shopify with current APIs — the official Dev MCP server for schema-accurate storefront and admin code.
Give your AI assistant a supervised window into your Interactive Brokers account — balances, positions, live quotes and orders.
Invoices, payments and disputes through PayPal's official server — commerce operations by conversation.
Enables querying and listing Azure resources and costs directly from an MCP client.
Empowers LLMs with Bitcoin Lightning Network payment capabilities via the ZBD API.