Skip to main content
P

Pomelo

@codespar/mcp-pomelo Β· v0.1.1

🌎 Latin AmericaPaymentsAuth · OAuth2beta9 tools6 env vars

Pan-LATAM card issuing as a service (Visa/Mastercard). Issue virtual or physical cards, freeze, set limits, and authorize each swipe against a CodeSpar mandate.

Get started Β· freeView docs

MIT Β· runs locally or through the CodeSpar runtime

Limitations

  • The npm package ships no server.json manifest.
Package
@codespar/mcp-pomelo
Version
0.1.1
npm dist-tag
latest
Category
Payments
Auth
OAuth2
Country
🌎 Latin America
License
MIT
Transport
stdio

Quickstart

Install, set the credentials, make the first call.

Pick your client. The server runs locally over stdio, or through the hosted runtime.

Add the server to your clientOne config entry. No build step, no SDK required.
Set the environment variables6 variables read by this server's code, listed below.
Restart and make the first callThe agent can call any of the 9 tools. Try create_user first.
terminal
# Claude Code claude mcp add pomelo -e POMELO_AUDIENCE=… -e POMELO_AUTH_URL=… -e POMELO_BASE_URL=… -e POMELO_CLIENT_ID=… -e POMELO_CLIENT_SECRET=… -e POMELO_ENV=… -- npx -y @codespar/mcp-pomelo@0.1.1 # then: /mcp to confirm the server is connected
Environment variables6 variables
POMELO_AUDIENCEOAuth2 audience override. Defaults per environment.optional
POMELO_AUTH_URLAuth base URL override. Defaults per environment.optional
POMELO_BASE_URLAPI base URL override. Defaults per environment.optional
POMELO_CLIENT_IDOAuth2 client idrequiredsecret
POMELO_CLIENT_SECRETOAuth2 client secretrequiredsecret
POMELO_ENVEnvironment: 'sandbox' or 'production'. Defaults to 'sandbox'.optional

Names read from the package code (@codespar/mcp-pomelo@0.1.1). Descriptions and flags come from its manifest. Self-hosted, you hold the credentials. On the CodeSpar runtime the credential you connect is stored encrypted (AES-256-GCM, key derived per organization), and the runtime adds it to the provider call itself; the agent never receives it.

First call democreate_user

"Create a card-holder identity"

tools/callcreate_userresult returned

Tools

What your agent can call.

9 tools, as the package's tools/list returns them.

create_user

Create a card-holder identity (POST /users/v1). The user is the person or business the card is issued to. Pass the Pomelo user shape for the target country (name, surname, identification_type/value, birthdate, address, email, phone).

get_user

Fetch a user by id (GET /users/v1/{id}).

update_user

Patch a user (PATCH /users/v1/{id}). Pass only the fields to change (e.g. status ACTIVE | BLOCKED, email, phone, address).

create_card

Issue a card for a user (POST /cards/v1). card_type VIRTUAL is usable immediately; PHYSICAL enters embossing/shipping and must be activated on receipt. affinity_group_id selects the card program (BIN, art, limits) configured with Pomelo.

get_card

Fetch a card by id (GET /cards/v1/{id}). Returns masked PAN, status, type and program data β€” never full card credentials.

list_cards

List cards (GET /cards/v1), filterable by user and status. Paginated.

update_card_status

Change a card's lifecycle status (PATCH /cards/v1/{id}): ACTIVE to unblock/activate, BLOCKED to freeze, DISABLED to cancel permanently. status_reason is required by Pomelo for blocks (e.g. CLIENT_INTERNAL_REASON, LOST, STOLEN).

list_transactions

Search the card-transactions feed (GET /transactions/v1), filterable by card, user and time window. Paginated.

get_transaction

Fetch a single card transaction by id (GET /transactions/v1/{id}).

Names and descriptions come from the package's tools/list (@codespar/mcp-pomelo@0.1.1). A kind (read, write, delete) is shown only when the package annotates its tools or each tool was verified one by one; neither exists for this server yet.

Compatibility

MCP is a protocol. Any client that speaks it can mount this server.

Through the CodeSpar runtime, codespar_discover finds this server's tools, and a tools/call runs with the credential connected in your project, a test key included.

hostedhttps://connect.codespar.dev/mcp15 meta-tools

Protocol

Any MCP client

stdio

Questions

Before you install.

How do I install the Pomelo MCP server?

Run npx -y @codespar/mcp-pomelo@0.1.1 and add the config block above to your MCP client: Claude Code, Cursor, Claude Desktop, VS Code, or any MCP-compatible client. No build step, no SDK required. Prefer hosted? Add the CodeSpar endpoint with a test key and connect Pomelo in your project; codespar_discover finds its tools.

What can my agent do with Pomelo?

Pomelo exposes 9 tools for payments. Your agent calls them directly; the full list is above.

How does Pomelo authenticate, and how are credentials stored?

Pomelo uses OAuth2. Self-hosted, you hold the credentials: the server reads them from its environment variables. On the CodeSpar runtime the credential you connect is stored encrypted for your organization, the runtime renews the OAuth2 access token, and it adds the token to each provider call, so the agent never handles it.

How does Pomelo handle upstream API changes?

Every server is versioned independently on npm. The command on this page pins 0.1.1, the version whose tools are listed here; your agent keeps running it until you change the version.

Is Pomelo open source? How do I report a bug?

Yes. Pomelo is MIT-licensed and published on npm as @codespar/mcp-pomelo, source on GitHub (link in the Details panel). Report issues on the package repository; security issues go to security@codespar.dev, and we respond within 24 hours.

Start in seconds.

On the CodeSpar runtime, the credential you connect stays encrypted for your organization and the runtime renews the OAuth2 access token. You just call the tool.

Start in seconds demo
Create an account and copy a test key.
Add the hosted endpoint to your client with the config above.
Connect Pomelo in your project and ask your agent for the first call.
Pomelo β€” MCP server Β· 9 tools | CodeSpar