Skip to content

Guides

What is MCP and how is it used so an AI agent can pay?

MCP (Model Context Protocol) is an open-source standard for connecting AI applications to external systems, and for payments it lets an agent call tools such as requesting a payment or reading transactions, while spending rules are enforced on the server and not in the prompt.

Last updated:

What MCP is, in plain terms

MCP stands for Model Context Protocol and is an open-source standard for connecting AI applications to external systems. With it, an application such as Claude or ChatGPT can connect to data sources (local files, databases), tools (search engines, calculators) and workflows (specialized prompts). The official documentation compares it to a USB-C port for AI applications (modelcontextprotocol.io).

The analogy helps: just as one port connects screens, drives and chargers without a different cable for each, MCP aims to let an agent use many tools through one well-known route. It is supported by assistants such as Claude and ChatGPT and by development tools such as Visual Studio Code and Cursor, among others.

Applied to payments, the practical question is this: if the agent can call a tool that moves money, who decides how much, to whom and when? The right answer is not the agent. It is a server with rules the agent cannot change.

What a payments MCP server does

A payments MCP server exposes a small set of tools the agent can call. Inside each one, the server evaluates the spending rules before anything moves.

Example tool
Example toolWhat it doesWhat should happen if it is rejected
`get_policy`Shows the agent the current rules: caps, allowed destinations, approval threshold and whether it is pausedNot applicable: it only reads. If the key lacks read permission, it responds with a clear reason
`request_spend`Requests a payment with an amount, a destination and a reasonResponds with status declined and a readable reason, for example per_spend_limit; nothing is paid and it is not an opaque error
`list_transactions`Reads the agent recent transactionsResponds with an empty list or a reason if permission is missing; it never shows another agent transactions
`get_approval_status`Checks whether a pending payment was approved, declined or expiredIf it expired or was declined, it reports declined; a pending payment is never approved on its own
The tool names in the table are examples and may change. They do not describe an official MCP schema or that of any service.

One important detail: a rejection by rule is a valid result, not a technical failure. The agent reads it, understands the reason and decides whether to ask for less, pick another destination or wait for a person.

MCP or API: when to use each

Situation
SituationBetter fitWhy
Your own code or an automated flow decides when to payAPIYou control the calls, the retries and the error handling in your code
An AI agent must use payment tools without you writing a custom integrationMCPThe agent discovers and calls the tools through a standard route
You need a dashboard, reports or administration tasksAPIAdministration should use a key and a route separate from the agent ones
You want both to coexistBothThey should rely on the same rules engine, so a rule applies the same way through either route

Choosing MCP does not change the rules: it changes how the agent reaches them. If MCP and the API applied different rules, the agent could use the looser route. That is why the rule must live in one place.

What a payment tool over MCP must meet to be safe

  • Rules on the server, not in the prompt. Asking the agent not to overspend is a suggestion. The limit must be evaluated before the money moves. The limit types are explained in the spending limits guide.
  • Separate keys to pay and to administer. If the agent key can edit its own policy, the limit does not exist.
  • Idempotency. Each request carries a unique key, so a retry does not charge twice.
  • Rejection as a readable result. A clear status and a reason, not an opaque error the agent interprets in its own way.
  • Human approval over a threshold. Large payments or payments to new destinations wait for a person, and silence means rejection.
  • A record of transactions. Every request, approved or declined, is logged with its reason and the version of the rule that evaluated it.
  • Defense against hidden instructions. An agent that reads emails, pages and tool responses can receive malicious text that leads it to request a payment. This is prompt injection, risk LLM01 on the OWASP list. An allowed-destinations list and human approval reduce the damage.
  • The ability to pause. There must be an immediate way to stop all of the agent spending.

To see how money moves between agents and services, also read the guide what is x402 and the one on giving an AI agent a budget. Another useful reference is the x402 introduction.

Short glossary

  • MCP. Model Context Protocol, an open-source standard for connecting AI applications to external systems.
  • MCP server. The program that offers tools and data to an AI application over MCP.
  • Tool. A concrete action the agent can call, such as requesting a payment.
  • AI agent that pays. A program that uses a language model to decide and carry out purchases or other payments within the rules it was given.
  • USDC. A digital dollar that aims to hold a value of 1 dollar; there is no promise it always will.
  • Spending rules. Caps per payment and per period, allowed destinations, approval threshold and pause.
  • WhatsApp approval. A message that asks a person to confirm or decline a payment before it runs.

What Nouron Pass does with this

Nouron Pass is designed as an API and an MCP server on the same rules engine. The idea: you deposit in your local currency, the balance is converted to USDC and your AI agent pays and collects under your rules, with WhatsApp approval when a payment goes over your threshold.

Nouron Pass is under construction and we open access in batches. Today we do not process real payments yet, and what is described here is the design of the MCP server and the API. If you want your agent to be among the first, reserve your spot.

Frequently asked questions

What is MCP in one sentence?

It is an open-source standard for connecting AI applications to data sources, tools and workflows, which its documentation compares to a USB-C port for AI applications.

Is MCP the same as an API?

No. An API is a way for your code to talk to a service. MCP is a standard way for an AI application to discover and use tools. A service can offer both on the same rules engine.

Can an agent pay over MCP without my approval?

It depends on the rules you set. Small payments within the limits can run on their own; those over the threshold must wait for a person, and if nobody responds in time, they are declined.

Is it safe to connect a payments MCP server to my agent?

It depends on how it is built. Check that rules are enforced on the server, that the pay and admin keys are different, that there is a record and that you can pause spending. No design fully removes prompt injection.

What happens if the tool rejects a payment?

The agent receives a rejection status with a readable reason and nothing is paid. With that information it can ask for a smaller amount, change destination or wait for a person.

Put your agent to work with rules

Reserve your spot and we will write to you when your access opens.