Your payment workspace, driven by your AI assistant.
Connect an assistant you already use. It reads your workspace and drafts payments for review. Every release is approved by a named person, or released under a standing rule a named person approved.
Live surface · read + draft · release stays with the licensed partner
Before you start
MCP connects to your workspace, so an account comes first. Five minutes, once.
- Create your Next Payment account
MCP authorizes against your own account. There is no shared key and no service account.
- Complete onboarding and add a payment method
A workspace is a real operating account. Onboarding and a payment method on file are required before payments can be prepared.
- Choose a plan that includes MCP
Read tools are available on paid plans; draft tools are available on operations plans.
- Install an MCP-capable client
Claude Code, Cursor, Claude Desktop, ChatGPT, or any client with Streamable HTTP and OAuth 2.1.
- Sign in once from that client
You authorize the connection yourself, and you can revoke it at any time from Settings → MCP.
How it works
Your assistant never touches funds. It prepares the decision record; the approval and the settlement stay on our side of the boundary.
What your assistant can do
- Read balances, transactions and recipients
- Follow a payment through its review stages
- Draft a payout and prepare reconciliation
- Report a payment’s current review stage
What it can never do
- Release funds or settle a payment
- Approve its own work
- Change policy or limits
- Sign on behalf of your wallet
Connect a client
Add the server once, then authorize with your Next Payment account. About a minute.
Your endpoint is shown in Settings → MCP inside your workspace. It reads and drafts in the same session your workspace uses; a release still needs the named approver, and settlement stays with the licensed partner.
- Add the server in your terminal.
claude mcp add next-paymentos --scope user --transport http https://next-paymentos.vercel.app/api/mcp
- Start a new session and open the MCP menu.
claude /mcp
- Choose Authenticate and sign in with your Next Payment account.
- Ask your assistant: “Show my balances and draft a payout for review.”
- In Cursor, open Settings → Tools & MCPs and add a new HTTP MCP server.
- Paste this configuration.
{ "mcpServers": { "Next Payment": { "type": "http", "url": "https://next-paymentos.vercel.app/api/mcp" } } } - Click Connect and sign in with your Next Payment account.
- In Claude Desktop, open Settings → Connectors.
- Choose Add custom connector and paste your endpoint from Settings → MCP.
- Authorize with your Next Payment account.
- In ChatGPT, open Settings → Connectors and add a custom connector.
- Paste your endpoint from Settings → MCP as the MCP server URL.
- Authorize with your Next Payment account.
- Any client that supports Streamable HTTP and OAuth 2.1 will work.
- Add your endpoint from Settings → MCP, then complete the sign-in prompt.
Example workflows
Three things teams do in the first week. Each one stops at review — nothing moves money.
Morning position check
“What are our balances across currencies, and what is still in review?”
Draft a payout for review
“Draft a payout of SGD 4,200 to Northwind Supplies and send it to LA for approval.”
Weekly reconciliation
“Match last week’s settled payouts against our statement and list anything unmatched.”
Tools
Every capability is a typed tool with its own scope. The catalogue grows, but it always stops before settlement.
| Tool | What it does | Scope | |
|---|---|---|---|
get_accounts | List your workspace accounts | read | Live |
get_balances | Current balances per currency | read | Live |
get_transactions | Activity with its review stage | read | Live |
get_beneficiaries | Screened payout recipients | read | Live |
get_payout_status | Follow a payment’s lifecycle | read | Live |
get_fx_reference | Reference rate — not executable | read | Live |
get_compliance_status | Your compliance state | read | Live |
draft_payout | Draft a single or batch payout | draft | Live |
prepare_reconciliation | Match statements and queue exceptions | draft | Live |
Submit-for-review is next; today it happens in the console, not on this surface. Asking for anything outside these scopes returns an explicit, logged refusal — never a silent gap.
Safety & access
Built so that an assistant can be useful without ever becoming a way to move money.
OAuth, not API keys
You authorize with your own account. There is no key to copy into a config file or leak in a screenshot.
Scoped by design
Read and draft are the two scopes. Neither includes release or approval.
A named human, or a named rule
Every release is approved by a named person, or released under a standing rule a named person approved — with a timestamp and an audit record.
Revoke in one click
Open Settings → MCP, pick the client and revoke access. It takes effect immediately.
Availability
Every capability carries one of five labels. The label is part of the claim, so a capability never appears without one.
| Label | What it means |
|---|---|
| Available for approved customers | Live, for a customer whose account and profile are approved for it. |
| Available after partner onboarding | Built and tested; switched on when the partner onboarding completes. |
| Live | Live on this deployment. |
| Under verification | Being checked for integration, entitlement and customer availability. |
| Planned | Not built. Described so you can plan against it. |
Four levels sit behind any claim we make: the upstream network's own capability, our integration with it, our commercial entitlement to use it, and your customer availability for that market, method, recipient type and amount. We publish the narrowest level that is true, and we do not turn the first level into the fourth. Where a local scheme is not yet evidenced end to end, the method stays generic on purpose.
Quote, approval and status
One corridor has a customer price today. This is the lifecycle every payment follows, and where each step is owned.
- Draft
Recipient, amount, purpose and funding source. A draft creates no payable order.
- Customer quote
Source amount, target currency, the customer rate, all customer charges, the estimated recipient amount and, if it expires, the validity. Draft reference rates are never executable and never lock a price.
- Named approval
A named person confirms the locked payment version with a fingerprint on a FIDO security key. The approval binds the recipient, amount, currency, customer rate and charges; change any of them and the payment returns for a fresh review.
- Submission
We submit the approved payment to the applicable licensed partner. Execution and settlement are the partner's, under its licence. Processing time depends on the route, cutoffs, partner checks and the recipient bank; we do not promise a settlement time.
- Partner status
We map the partner's statuses onto our own stages and deliver signed webhooks. Stages after release belong to the partner and are reported, not invented.
- Reconciliation
The same payment identifier carries the approval, the partner status and the reconciliation, and anything unmatched lands in an exception queue rather than being written off.
The quote contract, the status mapping and the webhook payloads are versioned. Ask our team for the current contract for the corridor you intend to use.
Chat hand-off
Chat can answer product questions and take a brief. It cannot move money, and it never takes documents or secrets.
What the assistant may do
- Answer product and documentation questions
- Explain the availability labels and how to read them
- Collect a short use-case brief: company, use case, market, recipient type, volume range and contact
- Hand the brief to a named human through the approved channel
What it must never do
- Release, amend, cancel or approve a payment
- Change a beneficiary or an amount
- Accept identity documents, API keys or other secrets
- Quote a price, a fee or a settlement time
A hand-off reaches a named human through an approved WhatsApp or Telegram workflow, and the escalation owner is on the brief. Support hours are shown only when the line is staffed and the hours are confirmed — we do not publish a promise we cannot keep.
FAQ
Do I need an API key?
No. The connection uses OAuth with your own account, and can be revoked at any time from Settings → MCP.
Can the assistant move money?
No. It can read and draft. Review and approval happen in the console, never on the MCP surface.
What do I need before connecting?
A Next Payment account, completed onboarding with a payment method on file, and a plan that includes MCP.
What happens if a request is out of scope?
It is refused explicitly and recorded. You get a clear error rather than a silent gap.
What does it cost?
MCP is part of your plan; read tools are available on paid plans and draft tools on operations plans. Fees and settlement times are indicative and depend on the corridor.
Ready to try it
Create your account, connect a client, and let your assistant prepare the next decision record.