Give AI agents access to your SlickPay account so they can read data, quote fees and create payments — in plain language, without writing API calls.
The Model Context Protocol is an open standard for connecting AI assistants to external systems. This server exposes 37 tools covering every endpoint of the SlickPay API, to any MCP client — Claude, Cursor, VS Code and others.
Ask for the outcome. The agent picks the endpoints, handles pagination, and reports back.
Create an invoice from a sentence and get a SATIM payment link to send.
Ask what a payment will cost in commission before anything is created.
Find unpaid invoices across thousands of records and total them.
Divide one payment across several sellers and issue a single link.
Add and update contacts and bank accounts without opening the dashboard.
Search the SlickPay documentation from inside your editor.
Your client talks to the MCP server; the server talks to the SlickPay API on your behalf, using your credential.
Invoices, transfers and split payments all work the same way: creating one returns a SATIM payment link and leaves the record pending. Funds move only when that link is paid, and an unpaid record can be deleted. Card details never reach this server or the SlickPay API.
| Environment | Endpoint | Talks to | Money |
|---|---|---|---|
| Sandbox | https://mcp.sandbox.unshortlink.com/mcp | devapi.slick-pay.com | Not real |
| Live | https://mcp.unshortlink.com/mcp | prodapi.slick-pay.com | Real |
Keys are issued per environment and are not interchangeable — a sandbox key returns 401 against the live endpoint, and vice versa. Every result states which environment produced it.
Two minutes of setup. Start in sandbox — nothing there is real money.
Sign up at slick-pay.com if you do not already have one.
From your dashboard, switch to sandbox and copy the PUBLIC_KEY. It looks like 54|BZ7F….
Any MCP client works. If you plan to run the server locally instead of using the hosted one, you will also need Node 20.18 or newer.
Examples use the sandbox endpoint. Swap in the live URL when you are ready.
claude mcp add --transport http slickpay https://mcp.sandbox.unshortlink.com/mcp
Desktop's Connectors screen requires OAuth, which this server does not yet offer. Use the local proxy instead — note there is no space after Authorization:, the token lives in env.
{
"mcpServers": {
"slickpay": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://mcp.sandbox.unshortlink.com/mcp",
"--header",
"Authorization:${AUTH_HEADER}"
],
"env": {
"AUTH_HEADER": "Bearer your-key"
}
}
}
}
{
"mcpServers": {
"slickpay": {
"url": "https://mcp.sandbox.unshortlink.com/mcp"
}
}
}
{
"servers": {
"slickpay": {
"type": "http",
"url": "https://mcp.sandbox.unshortlink.com/mcp"
}
}
}
{
"mcpServers": {
"slickpay": {
"command": "npx",
"args": [
"-y",
"@slick-pay/mcp"
],
"env": {
"SLICKPAY_API_KEY": "your-key",
"SLICKPAY_ENVIRONMENT": "sandbox",
"SLICKPAY_TOOLS": "read"
}
}
}
}
MCP is an open protocol. Point your client at the endpoint over Streamable HTTP and pass your key as a bearer token.
curl -X POST https://mcp.sandbox.unshortlink.com/mcp \
-H "Authorization: Bearer your-key" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
Two ways to authenticate. Use a scoped token for anything you would not want written in a config file.
Pass it as a bearer token. Simple, but it grants everything your account can do and cannot be revoked without rotating the key itself.
Mint a token carrying only the scopes you choose. Your key is sealed inside it and never reaches the client, and the token can be revoked by id.
curl -X POST https://mcp.sandbox.unshortlink.com/tokens \
-H "Authorization: Bearer your-slickpay-key" \
-H "Content-Type: application/json" \
-d '{"tools":"read"}'
Returns an spmcp_… token. Use it as your bearer token instead of your key — it carries its own scopes, so no ?tools= parameter is needed. List tokens with GET /tokens and revoke one with DELETE /tokens/{id}. The token is shown once and cannot be retrieved again.
The server starts read-only. Anything that changes state is opt-in, and money movement is a separate opt-in again.
| Selector | Tools | Grants |
|---|---|---|
(none) | 19 | Reading, fee quotes, documentation search |
?tools=read,write | 29 | … plus creating and updating invoices, contacts, accounts and split payments |
?tools=all | 37 | … plus transfers and deletion |
?tools=invoices.write | varies | A single resource, for a narrowly scoped agent |
Transfers and deletion require ?tools=all and are never implied by read,write. The selector can only ever narrow what a credential already permits — it cannot widen it.
What to say, which tools it uses, and what comes back.
?tools=read,write.?tools=read,write.?tools=read,write.37 tools covering every SlickPay endpoint. All names are prefixed slickpay_; the prefix is omitted below for readability.
| Tool | Description | Tier | Scope |
|---|---|---|---|
calculate_aggregation_commission |
Quote how a split payment divides across contacts, with the commission for each share, without creating anything. | read | aggregations:read |
calculate_invoice_commission |
Quote the SlickPay commission for an invoice of a given amount, without creating anything. | read | invoices:read |
calculate_transfer_commission |
Quote the SlickPay commission for a transfer of a given amount, without moving any money. | read | transfers:read |
get_account |
Retrieve a single account by its uuid. | read | accounts:read |
get_aggregation |
Retrieve a single aggregation by its id. | read | aggregations:read |
get_contact |
Retrieve a single contact by its uuid. | read | contacts:read |
get_invoice |
Retrieve a single invoice by its id. | read | invoices:read |
get_merchant_invoice |
Retrieve a single merchant invoice by its id. | read | merchant_invoices:read |
get_payment_status |
Check whether an invoice, transfer, or aggregation has been paid. | read | invoices:read, transfers:read, aggregations:read |
get_profile |
Return the authenticated SlickPay merchant. | read | — |
get_transfer |
Retrieve a single transfer by its id. | read | transfers:read |
list_accounts |
List the merchant's own bank accounts, which receive collected funds. | read | accounts:read |
list_aggregations |
List split payments, where one total is divided across several contacts. | read | aggregations:read |
list_contacts |
List payees — the counterparties for transfers and the parties billed on invoices. | read | contacts:read |
list_invoices |
List invoices, each of which carries a SATIM payment link. | read | invoices:read |
list_merchant_invoices |
List invoices issued on the merchant endpoint rather than the user endpoint. | read | merchant_invoices:read |
list_transfers |
List outgoing transfers to payees. | read | transfers:read |
report_feedback |
Report a missing capability, a bug, or general feedback about these tools to SlickPay. | read | — |
search_docs |
Search the bundled SlickPay API documentation. | read | — |
create_account |
Register one of the merchant's own bank accounts to receive collected funds. | write | accounts:write |
create_aggregation |
Create a split payment dividing one total across several contacts, returning a SATIM payment link. | write | aggregations:write |
create_contact |
Create a payee — the counterparty for transfers and the party billed on invoices. | write | contacts:write |
create_invoice |
Create an invoice and get back a SATIM payment link to give the customer. | write | invoices:write |
create_merchant_invoice |
Create an invoice on the merchant endpoint rather than the user endpoint. | write | merchant_invoices:write |
update_account |
Update one of the merchant's own bank accounts. | write | accounts:write |
update_aggregation |
Update an unpaid split payment's type or total. | write | aggregations:write |
update_contact |
Update an existing payee. | write | contacts:write |
update_invoice |
Update an unpaid invoice. | write | invoices:write |
update_merchant_invoice |
Update an unpaid merchant invoice. | write | merchant_invoices:write |
create_transfer |
Create an outgoing transfer to a payee and get back a SATIM payment link. | money | transfers:execute |
delete_account |
Permanently delete a account. | money | accounts:delete |
delete_aggregation |
Permanently delete a aggregation. | money | aggregations:delete |
delete_contact |
Permanently delete a contact. | money | contacts:delete |
delete_invoice |
Permanently delete a invoice. | money | invoices:delete |
delete_merchant_invoice |
Permanently delete a merchant invoice. | money | merchant_invoices:delete |
delete_transfer |
Permanently delete a transfer. | money | transfers:delete |
update_transfer |
Change a pending transfer's amount, destination account, or return URL. | money | transfers:execute |
An AI agent will occasionally get things wrong. These limits hold regardless of what the client does.
Above a configured amount a call is refused outright, before it reaches SlickPay. Raising the limit is a server change only a human can make.
An identical create inside a short window returns the original result, so a retrying agent cannot bill a customer twice.
Every change is recorded with the tool, arguments and resulting record. RIBs are masked to the last four digits everywhere.
Per-credential limits sit below the API's own budget, so a runaway agent cannot exhaust your quota.
Payments settle through SATIM. Card numbers never reach this server or the SlickPay API.
Scoped tokens can be revoked by id without rotating your SlickPay key or disturbing other integrations.
amount: 1000 means 1,000 DZD — the opposite of the minor-unit convention most payment APIs use. Never multiply by 100. Commission is added on top of the amount, so a 100 DZD invoice bills the customer more than 100.
Prove the flow with fake money before pointing anything at production.
Leave connections read-only unless the task requires more, and use a scoped token rather than your key.
The commission tools cost nothing and let the agent show you the fee first.
Enable your client's tool-confirmation prompts, and take care when combining this server with others — tool results are untrusted input.
The problems people actually hit, and what they mean.
Keys are issued per environment and are not interchangeable. A sandbox key returns 401 against the live host and vice versa. Check which endpoint you configured — slickpay_get_profile names the environment it is talking to.
You are on the default read-only tier. Add ?tools=read,write to the endpoint URL for creates and updates, or ?tools=all to include transfers and deletes. Restart the client fully afterwards — tool lists are cached at launch.
Connectors requires OAuth, which this server does not yet offer. Use the mcp-remote proxy shown above, or Claude Code, both of which accept a bearer token.
Amounts are DZD major units. amount: 1000 means 1,000 DZD, not 10.00. This is the opposite of the minor-unit convention used by most payment APIs.
It exceeded the configured ceiling. The limit cannot be raised from the client — it is a server configuration change. Splitting the amount across smaller calls is also refused by design.
It has not. An identical create inside a 60-second window returns the original result with deduplicated: true rather than creating a second record.
Endpoint reference, parameters and response shapes.
The open standard this server implements.
Ask your agent to use slickpay_report_feedback to tell us what is missing.