Skip to main content
B

Bold

@codespar/mcp-bold-co Β· v0.1.0

πŸ‡¨πŸ‡΄ ColombiaPaymentsAuth Β· API Keybeta7 tools2 env vars

Colombian acquirer with a clean REST charge API: your agent creates a payment intent and takes cards or PSE bank debit in one call.

Get started Β· freeView docs

MIT Β· runs locally or through the CodeSpar runtime

Limitations

  • The npm package ships no server.json manifest.
Package
@codespar/mcp-bold-co
Version
0.1.0
npm dist-tag
latest
Category
Payments
Auth
API Key
Country
πŸ‡¨πŸ‡΄ Colombia
License
MIT
Transport
stdio Β· streamable-http

Quickstart

Install, set the credentials, make the first call.

Pick your client. The server runs locally over stdio, or through the hosted runtime.

Add the server to your clientOne config entry. No build step, no SDK required.
Set the environment variables2 variables read by this server's code, listed below.
Restart and make the first callThe agent can call any of the 7 tools. Try create_payment_link first.
terminal
# Claude Code claude mcp add bold-co -e BOLD_API_KEY=… -e BOLD_SECRET_KEY=… -- npx -y @codespar/mcp-bold-co@0.1.0 # then: /mcp to confirm the server is connected
Environment variables2 variables
BOLD_API_KEYBold identity API key (llave de identidad), sent as x-api-keyrequiredsecret
BOLD_SECRET_KEYBold secret key. Only needed for the local checkout-signature and webhook-validation tools.optionalsecret

Names read from the package code (@codespar/mcp-bold-co@0.1.0). Descriptions and flags come from its manifest. Self-hosted, you hold the credentials. On the CodeSpar runtime the credential you connect is stored encrypted (AES-256-GCM, key derived per organization), and the runtime adds it to the provider call itself; the agent never receives it.

First call democreate_payment_link

"Create a Bold payment link"

tools/callcreate_payment_linkresult returned

Tools

What your agent can call.

7 tools, as the package's tools/list returns them.

create_payment_link

Create a Bold payment link (POST /online/link/v1). Returns payload.payment_link (LNK_ id) and payload.url to hand to the payer. Supports cards, PSE, Nequi and BotΓ³n Bancolombia; restrict with payment_methods.

create_pse_payment_link

Convenience wrapper: create a Bold payment link restricted to PSE bank debit (payment_methods=["PSE"]).

create_card_payment_link

Convenience wrapper: create a Bold payment link restricted to cards (payment_methods=["CREDIT_CARD"]).

get_payment_link

Query a Bold payment link by id (GET /online/link/v1/{payment_link}). Returns status (ACTIVE, PROCESSING, PAID, REJECTED, EXPIRED), amount, and transaction data once paid.

list_payment_methods

List the payment methods enabled for this merchant (GET /online/link/v1/payment_methods).

generate_checkout_signature

Generate the SHA-256 integrity signature Bold's embedded checkout button requires: sha256(orderId + amount + currency + secretKey). Runs locally; requires BOLD_SECRET_KEY.

validate_webhook_signature

Verify the HMAC-SHA256 signature of a Bold webhook notification against BOLD_SECRET_KEY. Pass the raw request body string and the signature header value. Accepts hex or base64 encodings. Runs locally.

Names and descriptions come from the package's tools/list (@codespar/mcp-bold-co@0.1.0). A kind (read, write, delete) is shown only when the package annotates its tools or each tool was verified one by one; neither exists for this server yet.

Compatibility

MCP is a protocol. Any client that speaks it can mount this server.

Through the CodeSpar runtime, codespar_discover finds this server's tools, and a tools/call runs with the credential connected in your project, a test key included.

hostedhttps://connect.codespar.dev/mcp15 meta-tools

Protocol

Any MCP client

stdio Β· streamable-http

Questions

Before you install.

How do I install the Bold MCP server?

Run npx -y @codespar/mcp-bold-co@0.1.0 and add the config block above to your MCP client: Claude Code, Cursor, Claude Desktop, VS Code, or any MCP-compatible client. No build step, no SDK required. Prefer hosted? Add the CodeSpar endpoint with a test key and connect Bold in your project; codespar_discover finds its tools.

What can my agent do with Bold?

Bold exposes 7 tools for payments. Your agent calls them directly; the full list is above.

How does Bold authenticate, and how are credentials stored?

Bold uses API Key. Self-hosted, you hold the credentials: the server reads them from its environment variables. On the CodeSpar runtime the credential you connect is stored encrypted for your organization, and the runtime adds it to each provider call, so the agent never handles it.

How does Bold handle upstream API changes?

Every server is versioned independently on npm. The command on this page pins 0.1.0, the version whose tools are listed here; your agent keeps running it until you change the version.

Is Bold open source? How do I report a bug?

Yes. Bold is MIT-licensed and published on npm as @codespar/mcp-bold-co, source on GitHub (link in the Details panel). Report issues on the package repository; security issues go to security@codespar.dev, and we respond within 24 hours.

Start in seconds.

On the CodeSpar runtime, the credential you connect stays encrypted for your organization and the runtime adds it to each call. You just call the tool.

Start in seconds demo
Create an account and copy a test key.
Add the hosted endpoint to your client with the config above.
Connect Bold in your project and ask your agent for the first call.
Bold β€” MCP server Β· 7 tools | CodeSpar