Agent Payments with the Reevit MCP Server

@reevit/mcp is an MCP server that gives AI agents scoped access to your Reevit account. The agent gets exactly the permissions of the API key you mint — nothing more.

Quick start

Create an API key in the dashboard (Developers → API keys) with only the scopes the agent should have, then:
Keys start pfk_test_ or pfk_live_. A key with any other prefix is rejected at startup, which also catches a truncated or mispasted one immediately. For Claude Desktop, Cursor, VS Code, Windsurf, Cline, Zed, Codex CLI, and Gemini CLI configs, see the MCP server guide.

Tools

Tool names gained a reevit_ prefix in 0.2.0, and get_analytics_summary became reevit_get_payment_analytics. Only prompts that name tools explicitly need updating.

Safety model

  • Scopes are enforced by the Reevit backend on every call — a payments:read key cannot refund regardless of what the model asks.
  • Mode comes from the key, not the environment. pfk_test_ is test, pfk_live_ is live. REEVIT_MODE is optional and, if it contradicts the key, the server refuses to start — it can only misdescribe a key, never downgrade one.
  • Live-money gate: in live mode reevit_create_refund will not proceed without human approval of that specific refund. On clients supporting elicitation the server asks the user directly and confirm: true does not skip the prompt; elsewhere it falls back to requiring confirm: true.
  • Credentials never enter the transcript: per-payment client_secret values and raw pfk_… keys are redacted from every result before it leaves the server.
  • Idempotency: money-moving calls carry an Idempotency-Key derived from the request itself, so a retry of the same operation is deduplicated. A deliberate repeat inside the 24h window returns the original and says "replayed": true.
Upgrade to 0.2.0 or later. Earlier versions defaulted REEVIT_MODE to test, and the live-refund gate keyed off it — so a live key with the variable unset skipped confirmation while the backend executed the refund for real.

Remote use

Run the same server over streamable HTTP for agent platforms:
REEVIT_MCP_HTTP_TOKEN is required — the server refuses to start without it. It binds loopback only, rejects non-loopback Host headers (DNS-rebinding guard), and caps bodies at 1 MB.
Do not run 0.1.1 in HTTP mode: it bound 0.0.0.0 with no authentication, so anything that could reach the port could issue refunds with your key.