{"_id":"@codespar/mcp-konduto","_rev":"5-5592a3989c5df93a43ceaa447e63a0f4","name":"@codespar/mcp-konduto","dist-tags":{"latest":"0.2.0-alpha.3","alpha":"0.2.0-alpha.2"},"versions":{"0.1.0-alpha.1":{"name":"@codespar/mcp-konduto","version":"0.1.0-alpha.1","keywords":["mcp","konduto","fraud","fraud-prevention","risk-scoring","device-intelligence","behavioral-fingerprint","blocklist","antifraud","brazil","ecommerce"],"license":"MIT","_id":"@codespar/mcp-konduto@0.1.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-konduto":"dist/index.js"},"dist":{"shasum":"c0421ab850752f29be7bd3b0f7e8cdbb804c2d4b","tarball":"https://registry.npmjs.org/@codespar/mcp-konduto/-/mcp-konduto-0.1.0-alpha.1.tgz","fileCount":7,"integrity":"sha512-X+VCh7GbisrRwBfhoNM6VIXrehKDvITygq14IkGrkZ5rQT4LwDup06A1mwNZxxQpe5RA1F34sD8olWr7Fachuw==","signatures":[{"sig":"MEUCIAk/TE3ghKXX29uJtBr7foID4JQeHxeqXEhJJX5Gu/bPAiEA/z+qAjNmASuflm/+GHUhKZkM+jQGf9zFoWBYG388qDU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45014},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"26b185ffb621230aec45ba62ad8f5d59b30cd44a","mcpName":"io.github.codespar/mcp-konduto","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Konduto — Brazilian fraud prevention, API-first order risk scoring, behavioral device intelligence, and blocklist/allowlist/reviewlist management","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-konduto_0.1.0-alpha.1_1776995750324_0.11527209992580723","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.1":{"name":"@codespar/mcp-konduto","version":"0.2.0-alpha.1","keywords":["mcp","konduto","fraud","fraud-prevention","risk-scoring","device-intelligence","behavioral-fingerprint","blocklist","antifraud","brazil","ecommerce"],"license":"MIT","_id":"@codespar/mcp-konduto@0.2.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-konduto":"dist/index.js"},"dist":{"shasum":"0609cf7cee9362907fc10455a9bb2aab03f155c9","tarball":"https://registry.npmjs.org/@codespar/mcp-konduto/-/mcp-konduto-0.2.0-alpha.1.tgz","fileCount":7,"integrity":"sha512-suA0bRwd7nthmwRYEGuhyOnlVXzGDVFOZ4H/3n0Rcjc2Kd/a5yBWF3lRQioRXnXYcthkndKK7dVdMZbadYm26g==","signatures":[{"sig":"MEQCIAlAHuv7DFOW8j9mcV7anOrsUbeo+TOitDW6dtZh9brdAiAW9a6w7zUM9Ahy1o8fzmzYJfqB6l09YywNZm5eQHTrrw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70638},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"a9ff36701206eb6feb7fffffc4cbb2a325757082","mcpName":"io.github.codespar/mcp-konduto","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Konduto — Brazilian fraud prevention, API-first order risk scoring, behavioral device intelligence, and blocklist/allowlist/reviewlist management","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-konduto_0.2.0-alpha.1_1777115938530_0.5768677656895895","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.2":{"name":"@codespar/mcp-konduto","version":"0.2.0-alpha.2","keywords":["mcp","konduto","fraud","fraud-prevention","risk-scoring","device-intelligence","behavioral-fingerprint","blocklist","antifraud","brazil","ecommerce"],"license":"MIT","_id":"@codespar/mcp-konduto@0.2.0-alpha.2","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-konduto":"dist/index.js"},"dist":{"shasum":"d31c5cf85db41b5dc929759af68f5dbb9f4cec05","tarball":"https://registry.npmjs.org/@codespar/mcp-konduto/-/mcp-konduto-0.2.0-alpha.2.tgz","fileCount":7,"integrity":"sha512-sC4pxvVVy8Kqwp0O9lNpAllkE0DGaAOfyVcI2zEZbwuQiOj+ZGCQFr/6/KthozlO+ufcklJUbHeDwakhAlLj4Q==","signatures":[{"sig":"MEUCIAPcVPu4Ata70JIctG9vF8c4ofsrQWvCo06Kk//3gZP2AiEAm4jaCIEO4trcHFl9IlgS2wed4y7X6QxliAXa8XIhkPY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71582},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"0ab801a863239f0cb986bbda65abbaee3c621b44","mcpName":"io.github.codespar/mcp-konduto","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Konduto — Brazilian fraud prevention, API-first order risk scoring, behavioral device intelligence, and blocklist/allowlist/reviewlist management","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-konduto_0.2.0-alpha.2_1777123097696_0.4160715541864439","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.3":{"name":"@codespar/mcp-konduto","version":"0.2.0-alpha.3","description":"MCP server for Konduto — Brazilian fraud prevention, API-first order risk scoring, behavioral device intelligence, and blocklist/allowlist/reviewlist management","type":"module","main":"./dist/index.js","bin":{"mcp-konduto":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"devDependencies":{"@types/node":"^25.5.0","typescript":"^5.8.0"},"license":"MIT","keywords":["mcp","konduto","fraud","fraud-prevention","risk-scoring","device-intelligence","behavioral-fingerprint","blocklist","antifraud","brazil","ecommerce"],"mcpName":"io.github.codespar/mcp-konduto","_id":"@codespar/mcp-konduto@0.2.0-alpha.3","gitHead":"e8f2ad023876683538fe7b66a2fc88ab8d8ef92f","types":"./dist/index.d.ts","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-8zQeTB3OlmuCkMfVwmS1qB6s0/ewmKRNxecATjD4vFMxQm0EH+ACkhd4Imxm84cwl26efU9Tns+M5fmc5NfQbg==","shasum":"47d1348a94ee25c8f922455006ea906e23018836","tarball":"https://registry.npmjs.org/@codespar/mcp-konduto/-/mcp-konduto-0.2.0-alpha.3.tgz","fileCount":7,"unpackedSize":73010,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDfobx6XDTPGS+8k1VISY84i4Qnwx7lH5ElP3KqNWUq3wIgc7xAkwbbXS5QMvqZh0h4vASQsAqSpmpLCs1nSPcEkk8="}]},"_npmUser":{"name":"codespar-npm","email":"fabiano@codespar.dev"},"directories":{},"maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-konduto_0.2.0-alpha.3_1782153664816_0.9762259689886437"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-24T01:55:50.076Z","modified":"2026-06-22T18:41:05.107Z","0.1.0-alpha.1":"2026-04-24T01:55:50.482Z","0.2.0-alpha.1":"2026-04-25T11:18:58.673Z","0.2.0-alpha.2":"2026-04-25T13:18:17.837Z","0.2.0-alpha.3":"2026-06-22T18:41:04.985Z"},"license":"MIT","keywords":["mcp","konduto","fraud","fraud-prevention","risk-scoring","device-intelligence","behavioral-fingerprint","blocklist","antifraud","brazil","ecommerce"],"description":"MCP server for Konduto — Brazilian fraud prevention, API-first order risk scoring, behavioral device intelligence, and blocklist/allowlist/reviewlist management","maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"readme":"# @codespar/mcp-konduto\n\nMCP server for [Konduto](https://konduto.com) — Brazilian fraud prevention, API-first.\n\nSecond entry in the CodeSpar `fraud` category after [`@codespar/mcp-clearsale`](../clearsale). Konduto sits alongside ClearSale as one of the two default antifraud layers BR merchants evaluate, and the two are often deployed in parallel for score comparison or failover.\n\n## Positioning vs. ClearSale\n\n|                          | ClearSale                           | Konduto                                  |\n|--------------------------|-------------------------------------|------------------------------------------|\n| Founded                  | 2001 (São Paulo)                    | 2014 (São Paulo)                         |\n| Strength                 | Larger chargeback history database  | Behavioral device intelligence           |\n| Shape                    | ML scoring + manual review services | API-first, tighter surface, dev-oriented |\n| Typical pairing          | Default for large BR retail         | Default for digital-native BR ecommerce  |\n\nMerchants commonly run both in parallel: Konduto for the fast behavioral signal, ClearSale for the long-tail chargeback history. When one flags `review` and the other flags `approved`, the merchant routes the order to manual inspection.\n\n## Tools (18)\n\n| Tool | Purpose |\n|---|---|\n| `send_order_for_analysis` | Submit an order to Konduto for fraud analysis. |\n| `get_order` | Retrieve the current analysis state of an order. |\n| `update_order_status` | Notify Konduto of the merchant's final status for an order. |\n| `report_chargeback` | Report a confirmed chargeback for an order. |\n| `report_order_approved` | Report that an order was ultimately approved by the merchant. |\n| `report_order_declined` | Report that an order was ultimately declined by the merchant. |\n| `add_to_blocklist` | Add a value to the Konduto blocklist. |\n| `query_blocklist` | Check whether a value is currently on the Konduto blocklist. |\n| `update_blocklist_entry` | Update an existing blocklist entry — typically used to extend or shorten the expiration window (expires_at)... |\n| `remove_from_blocklist` | Remove a value from the Konduto blocklist. |\n| `add_to_allowlist` | Add a value to the Konduto allowlist (trusted). |\n| `query_allowlist` | Check whether a value is currently on the Konduto allowlist. |\n| `update_allowlist_entry` | Update an existing allowlist entry — typically to extend or shorten the expiration window. |\n| `remove_from_allowlist` | Remove a value from the Konduto allowlist. |\n| `add_to_reviewlist` | Add a value to the Konduto reviewlist. |\n| `query_reviewlist` | Check whether a value is currently on the Konduto reviewlist. |\n| `update_reviewlist_entry` | Update an existing reviewlist entry — typically to extend or shorten the expiration window without removing... |\n| `remove_from_reviewlist` | Remove a value from the Konduto reviewlist. |\n\n## Install\n\n```bash\nnpm install @codespar/mcp-konduto@alpha\n```\n\n## Environment\n\n```bash\nKONDUTO_API_KEY=\"T00000...\"          # private key; required\nKONDUTO_BASE_URL=\"...\"               # optional; defaults to https://api.konduto.com/v1\n```\n\n## Authentication\n\nHTTP Basic. The API key is the username; password is empty:\n\n```\nAuthorization: Basic base64(KONDUTO_API_KEY + \":\")\n```\n\nThe server handles the base64 encoding — pass the raw key in `KONDUTO_API_KEY`.\n\n## Typical flow\n\n1. Embed Konduto's browser JS SDK on the merchant checkout page. It captures a `visitor` id (behavioral + device signals).\n2. At order submit, call `send_order_for_analysis` with the full order payload and the `visitor` id.\n3. Act on the response: `approved` ships it, `declined` blocks it, `review` holds for manual inspection or a second signal from ClearSale.\n4. Once the order lifecycle completes, call `update_order_status` with `approved` / `canceled` / `fraud` — this feeds Konduto's model.\n5. When a chargeback is confirmed, call `update_order_status` with status `fraud`. This is Konduto's primary ML feedback channel (there is no separate `/chargebacks` endpoint in the public docs).\n6. Use `add_to_blocklist` to permanently block specific emails / IPs / card BIN+last4 pairs observed in confirmed fraud.\n\n## Alpha note\n\nThis package is shipped as `0.1.0-alpha.1`. Scope vs. the original brief:\n\n- **Verified against docs.konduto.com:**\n  - `POST /orders` (send_order_for_analysis)\n  - `POST/GET/DELETE /blacklist/{type}` (blocklist family)\n  - `/whitelist/{type}` (allowlist) and `/greylist/{type}` (reviewlist), indexed under \"APIs de Blocklist, Allowlist e Reviewlist\"\n\n- **Standard REST pattern, not separately indexed in the public reference** (used by Konduto's official client libraries):\n  - `GET /orders/{id}` (get_order)\n  - `PUT /orders/{id}` (update_order_status)\n\n- **Dropped — not documented publicly:**\n  - `POST /disputes` — no dispute submission endpoint on docs.konduto.com\n  - `POST /cards/analyze` — no card-only pre-check endpoint documented\n  - `GET /visitors/{visitor_id}` — visitor ids are referenced on the order (`visitor` field) but no public retrieval endpoint exists\n\nChargeback feedback is folded into `update_order_status` with `status: fraud`, which is Konduto's documented feedback channel.\n\nPromote to `0.2.0` once the dropped endpoints are confirmed (via private docs or direct API response), or once Konduto publishes a broader public reference.\n\n## Run\n\n```bash\n# stdio (default — for Claude Desktop, Cursor, etc)\nnpx @codespar/mcp-konduto\n\n# HTTP (for server-to-server testing)\nMCP_HTTP=true MCP_PORT=3000 npx @codespar/mcp-konduto\n```\n\n## Category\n\n`fraud` — second server in this CodeSpar category after ClearSale. Fraud servers share a common shape (analyze → decide → feedback) distinct from payments, which makes cross-provider swaps (ClearSale ↔ Konduto ↔ Legiti) more straightforward than cross-acquirer swaps.\n\n## Enterprise\n\nNeed governance, budget limits, and audit trails for agent payments? [CodeSpar Enterprise](https://codespar.dev/enterprise) adds policy engine, payment routing, and compliance templates on top of these MCP servers.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}