{"_id":"@codespar/mcp-itau","_rev":"5-ea57d786772e9290ca975f3aeb490de9","name":"@codespar/mcp-itau","dist-tags":{"latest":"0.2.0-alpha.3","alpha":"0.2.0-alpha.2"},"versions":{"0.1.0-alpha.1":{"name":"@codespar/mcp-itau","version":"0.1.0-alpha.1","keywords":["mcp","itau","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"license":"MIT","_id":"@codespar/mcp-itau@0.1.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-itau":"dist/index.js"},"dist":{"shasum":"4eda5f7505bb7fcc5a7a78a32a29ecfa2312a97e","tarball":"https://registry.npmjs.org/@codespar/mcp-itau/-/mcp-itau-0.1.0-alpha.1.tgz","fileCount":6,"integrity":"sha512-xB1+KfSyWTdulM6KR2YmJi7UsUBMbe/lGhHC9XhCAlYRae6k9MwBOF0RWvkPUwbrCoAA0pP2QhdrHF2g/+D8hA==","signatures":[{"sig":"MEUCIQDwUD615RToEUDvgu0JUptwPeHb8L/5OtMiP6elioa4dwIgU2wJLE+DJtX18ytDMxwC8US0OnQZrv4HtOkH0qwI5j4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":53408},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"b2ef93b78816f2643cd387941a09940b2d7619e9","mcpName":"io.github.codespar/mcp-itau","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Itaú Unibanco — Brazil's largest private bank. Pix, Cobrança (boleto), Arrecadação, and Extrato via Itaú's Developer Portal APIs (OAuth2 + mTLS).","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-itau_0.1.0-alpha.1_1776996452774_0.5659893544926435","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.1":{"name":"@codespar/mcp-itau","version":"0.2.0-alpha.1","keywords":["mcp","itau","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"license":"MIT","_id":"@codespar/mcp-itau@0.2.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-itau":"dist/index.js"},"dist":{"shasum":"f3f0e072320e12788ab1d9e9f538e3da7bcf3c84","tarball":"https://registry.npmjs.org/@codespar/mcp-itau/-/mcp-itau-0.2.0-alpha.1.tgz","fileCount":6,"integrity":"sha512-m2sVICJ3Cqg0TPu3jrcVuCPRghXP8r+lVSBr3wCinCI11JReVq7wOSK9nkwaiGxRohcr5GQLDb+nagnynIhk/g==","signatures":[{"sig":"MEUCIF+OC7IpPAEK8no+pqlObIYeZUboYUyQlFkJCM10S3RWAiEA7KZHCb0IX6qoTJooeDD55dqslEDjtb3OTc1kqCUP+sc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":87184},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"475d6a412c639d70728792f31d502e9268bb06bb","mcpName":"io.github.codespar/mcp-itau","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Itaú Unibanco — Brazil's largest private bank. Pix, Cobrança (boleto), Arrecadação, and Extrato via Itaú's Developer Portal APIs (OAuth2 + mTLS).","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-itau_0.2.0-alpha.1_1777043006126_0.3516907235241531","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.2":{"name":"@codespar/mcp-itau","version":"0.2.0-alpha.2","keywords":["mcp","itau","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"license":"MIT","_id":"@codespar/mcp-itau@0.2.0-alpha.2","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-itau":"dist/index.js"},"dist":{"shasum":"c5ba47cc63d827a4faf782027bc52d7a25b11884","tarball":"https://registry.npmjs.org/@codespar/mcp-itau/-/mcp-itau-0.2.0-alpha.2.tgz","fileCount":6,"integrity":"sha512-b8AAuirQKv11z1UX0oKsox6rWp28u0gpc3Pntxjrp4+fLP2hrK5qntVJ7rH4EaF4LzG+Tr6y6w1fLLC0tTcL2Q==","signatures":[{"sig":"MEYCIQDMFZW96k2aPYmez9aB322vHsHDnSQ1VR8/D+vwyqjvaQIhAImfzR6ePA0043WDOh2DNMoonP3Opwxys8ss3Gu4g0pf","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":88646},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"b8f7e5b70db9046319ed757225e0eae8f2dc4451","mcpName":"io.github.codespar/mcp-itau","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Itaú Unibanco — Brazil's largest private bank. Pix, Cobrança (boleto), Arrecadação, and Extrato via Itaú's Developer Portal APIs (OAuth2 + mTLS).","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-itau_0.2.0-alpha.2_1777122924861_0.9977954665568496","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.3":{"name":"@codespar/mcp-itau","version":"0.2.0-alpha.3","description":"MCP server for Itaú Unibanco — Brazil's largest private bank. Pix, Cobrança (boleto), Arrecadação, and Extrato via Itaú's Developer Portal APIs (OAuth2 + mTLS).","type":"module","main":"./dist/index.js","bin":{"mcp-itau":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"devDependencies":{"@types/node":"^25.5.0","typescript":"^5.8.0"},"license":"MIT","keywords":["mcp","itau","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"mcpName":"io.github.codespar/mcp-itau","_id":"@codespar/mcp-itau@0.2.0-alpha.3","gitHead":"8e115a5cb8aed75e812af698b03aa996ccd8d7c1","types":"./dist/index.d.ts","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-AawKAHCAREWjMqNga0kR1P235kVj5IbIPS/ZHm0o8CjZpjeVpU5i+GoF/PpvFKOhgP5+BEmqslLzIj6w7L5nyA==","shasum":"b902714c782b27cfca3b6def497ba240199851e5","tarball":"https://registry.npmjs.org/@codespar/mcp-itau/-/mcp-itau-0.2.0-alpha.3.tgz","fileCount":6,"unpackedSize":90057,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICqDZe+b3D9NluoRL/NZpJYkeKwO6HEpUSeah58DbqPnAiBuh0OoHkLoNhpYCS4xikgy1IvagSVxgdkSnTjwKtQfvA=="}]},"_npmUser":{"name":"codespar-npm","email":"fabiano@codespar.dev"},"directories":{},"maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-itau_0.2.0-alpha.3_1782158073669_0.45603036548345033"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-24T02:07:32.662Z","modified":"2026-06-22T19:54:33.967Z","0.1.0-alpha.1":"2026-04-24T02:07:32.899Z","0.2.0-alpha.1":"2026-04-24T15:03:26.297Z","0.2.0-alpha.2":"2026-04-25T13:15:25.020Z","0.2.0-alpha.3":"2026-06-22T19:54:33.811Z"},"license":"MIT","keywords":["mcp","itau","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"description":"MCP server for Itaú Unibanco — Brazil's largest private bank. Pix, Cobrança (boleto), Arrecadação, and Extrato via Itaú's Developer Portal APIs (OAuth2 + mTLS).","maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"readme":"# @codespar/mcp-itau\n\nMCP server for [Itaú Unibanco](https://devportal.itau.com.br) — Brazil's largest private bank.\n\nItaú operates the largest private-bank API surface in the country. Merchants running high-volume Pix, boleto, and cash-management workloads integrate directly instead of going through a PSP.\n\n## Status: alpha (`0.1.0-alpha.1`)\n\nItaú's Developer Portal is **contract-gated** — the full OpenAPI specs for Pix, Cobrança, Arrecadação, and Extrato are only visible to onboarded merchants. The endpoint paths in this server are best-guesses based on (a) BACEN Pix v2 standard paths, (b) Itaú's public marketing pages, and (c) conventions shared across Santander / Bradesco / BB. Every unverified path is flagged `TODO(verify)` in the source.\n\nPin to exact versions during `0.1.x`; paths will be corrected to match the portal spec once an onboarded merchant can validate.\n\n## Tools (22)\n\n| Tool | Purpose |\n|---|---|\n| `get_oauth_token` | Mint or return a cached OAuth2 client_credentials bearer token for the Itaú Developer Portal. |\n| `send_pix` | Initiate an outbound Pix payment from the merchant's Itaú account. |\n| `create_pix_qr` | Create a dynamic Pix charge with QR code (cob). |\n| `get_pix` | Retrieve a Pix transaction by its BCB endToEndId (E<ispb><yyyymmddhhmm><sequence>). |\n| `resolve_dict_key` | Resolve a DICT key (CPF, CNPJ, email, phone, EVP) to the owner's account data before sending a Pix. |\n| `refund_pix` | Refund (devolução) a previously received Pix. |\n| `create_boleto` | Issue a boleto via Itaú Cobrança. |\n| `get_boleto` | Retrieve a boleto by its Itaú identifier (id or nosso_numero). |\n| `cancel_boleto` | Cancel (baixa) an outstanding boleto before payment. |\n| `get_statement` | Retrieve account statement transactions for a given period. |\n| `arrecadacao_pay` | Pay a utility, tax, or concessionária bill via Itaú Arrecadação. |\n| `create_pix_cobv` | Create a Pix charge with due date (cobv) — used for boleto-like Pix where the payer can pay at or after a d... |\n| `list_pix_charges` | List immediate Pix charges (cob) registered by the merchant within a date range. |\n| `register_pix_key` | Register a DICT key (CPF, CNPJ, email, phone, or EVP) on an Itaú account owned by the merchant. |\n| `delete_pix_key` | Delete a DICT key owned by the merchant. |\n| `list_pix_keys` | List DICT keys currently registered to the merchant's Itaú accounts. |\n| `get_boleto_pdf` | Download the PDF of an issued boleto. |\n| `send_ted` | Send a TED transfer to an account at another bank. |\n| `transfer_between_accounts` | TAA — transfer between two Itaú accounts (owned by the merchant or a counterparty). |\n| `get_tariffs` | Query the tariff schedule applicable to the merchant's active contracts (Pix per-transaction, boleto regist... |\n| `list_dda_bills` | List bills registered for the merchant under the DDA (Débito Direto Autorizado) enrolment. |\n| `schedule_payment` | Schedule a future-dated payment (Pix, boleto, arrecadação, or TED). |\n\n## Install\n\n```bash\nnpm install @codespar/mcp-itau@0.1.0-alpha.1\n```\n\n## Environment\n\n```bash\nITAU_CLIENT_ID=\"...\"       # OAuth client_id from Itaú's Developer Portal\nITAU_CLIENT_SECRET=\"...\"   # OAuth client_secret\nITAU_CERT_PATH=\"/abs/path/to/client.crt\"   # mTLS client certificate\nITAU_KEY_PATH=\"/abs/path/to/client.key\"    # mTLS private key\nITAU_ENV=\"sandbox\"                          # or \"production\" (default: sandbox)\n```\n\n## Authentication\n\nTwo factors are **both** required on every call:\n\n1. **OAuth2 `client_credentials`** — the server calls the token endpoint, caches the bearer until ~60s before expiry, and attaches `Authorization: Bearer <token>` to downstream calls.\n2. **mTLS** — BACEN mandates mutual TLS for Pix v2, and Itaú enforces it across product families. The server loads the client certificate and private key from the paths you set, builds a Node `https.Agent`, and routes every request through it.\n\nYou obtain the cert + key bundle from the Itaú Developer Portal after your merchant contract is signed. They are distinct from the OAuth credentials.\n\n## Run\n\n```bash\n# stdio (default)\nnpx @codespar/mcp-itau\n\n# HTTP transport\nMCP_HTTP=true MCP_PORT=3000 npx @codespar/mcp-itau\n```\n\n## Caveats\n\n- **Paths are unverified.** See the `TODO(verify)` markers in `src/index.ts`. Onboarded merchants should validate against their portal-issued OpenAPI spec and open a PR.\n- **Sandbox host is a guess.** Itaú issues a sandbox subdomain per merchant; override by editing `BASE_URL` if your provisioned sandbox URL differs.\n- **Arrecadação barcode validation** is server-side in this alpha — no client-side mod-10 / mod-11 check yet.\n\n## Enterprise\n\nNeed governance, budget limits, and audit trails for agent payments? [CodeSpar Enterprise](https://codespar.dev/enterprise) adds policy engine, payment routing, and compliance templates on top of these MCP servers.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}