Agent Payments with the Reevit MCP Server
@reevit/mcp is an MCP server that gives AI
agents scoped access to your Reevit account. The agent gets exactly the
permissions of the API key you mint — nothing more.
Quick start
Create an API key in the dashboard (Developers → API keys) with only the
scopes the agent should have, then:
Keys start pfk_test_ or pfk_live_. A key with any other prefix is rejected at
startup, which also catches a truncated or mispasted one immediately.
For Claude Desktop, Cursor, VS Code, Windsurf, Cline, Zed, Codex CLI, and
Gemini CLI configs, see the
MCP server guide.
Tool names gained a reevit_ prefix in 0.2.0, and get_analytics_summary became
reevit_get_payment_analytics. Only prompts that name tools explicitly need updating.
Safety model
- Scopes are enforced by the Reevit backend on every call — a
payments:read key cannot refund regardless of what the model asks.
- Mode comes from the key, not the environment.
pfk_test_ is test, pfk_live_ is
live. REEVIT_MODE is optional and, if it contradicts the key, the server refuses to
start — it can only misdescribe a key, never downgrade one.
- Live-money gate: in live mode
reevit_create_refund will not proceed without human
approval of that specific refund. On clients supporting elicitation the server asks the
user directly and confirm: true does not skip the prompt; elsewhere it falls back to
requiring confirm: true.
- Credentials never enter the transcript: per-payment
client_secret values and raw
pfk_… keys are redacted from every result before it leaves the server.
- Idempotency: money-moving calls carry an
Idempotency-Key derived from the request
itself, so a retry of the same operation is deduplicated. A deliberate repeat inside the
24h window returns the original and says "replayed": true.
Upgrade to 0.2.0 or later. Earlier versions defaulted REEVIT_MODE to test, and the
live-refund gate keyed off it — so a live key with the variable unset skipped
confirmation while the backend executed the refund for real.
Remote use
Run the same server over streamable HTTP for agent platforms:
REEVIT_MCP_HTTP_TOKEN is required — the server refuses to start without it. It binds
loopback only, rejects non-loopback Host headers (DNS-rebinding guard), and caps bodies
at 1 MB.
Do not run 0.1.1 in HTTP mode: it bound 0.0.0.0 with no authentication, so anything
that could reach the port could issue refunds with your key.