Pop Pay MCP Server
by 100xpercentio.github.100xPercent/pop-payv0.5.7
The runtime security layer for AI agent commerce. Drop-in CLI + MCP server — blocks hallucinated purchases and keeps card credentials out of agent context. It only takes 0.1% of hallucination to drain 100% of your wallet.
context tax
queued
security
queued
cold start
queued
freshness
Slowing3mo ago
Install Pop Pay MCP server
Install in Claude Code
claude mcp add pop-pay -- npx -y pop-payInstall in Cursor
{
"mcpServers": {
"pop-pay": {
"command": "npx",
"args": [
"-y",
"pop-pay"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"pop-pay": {
"command": "npx",
"args": [
"-y",
"pop-pay"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"pop-pay": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"pop-pay"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"pop-pay": {
"command": "npx",
"args": [
"-y",
"pop-pay"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| POP_CDP_URL | — | — | Chrome DevTools Protocol endpoint for credential injection (default: http://localhost:9222) |
| POP_ALLOWED_CATEGORIES | — | — | JSON array of allowed vendor categories (e.g. '["aws","cloudflare"]') |
| POP_MAX_PER_TX | — | — | Per-transaction spending limit in USD |
| POP_MAX_DAILY | — | — | Daily spending limit in USD |
| POP_GUARDRAIL_ENGINE | — | — | Guardrail engine: 'keyword' (offline, default) or 'llm' (requires API key) |
Freshness
Slowing — last maintenance signal 3mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-07-07 · 3mo ago · GitHub
Latest release
2026-04-13 · 6mo ago · GitHub · v0.5.7
Package published
no data · npm/PyPI
Registry entry updated
2026-04-13 · 6mo ago · official registry · v0.5.7
FAQ
›How do I install the Pop Pay MCP server in Claude Code?
Run: claude mcp add pop-pay -- npx -y pop-pay. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Pop Pay require an API key?
No required environment variables are declared in its published metadata.
›Can I use Pop Pay as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Pop Pay in the official MCP registry?
Yes, as io.github.100xPercent/pop-pay.
Alternatives to Pop Pay
Other security MCP servers.