{"_id":"@codespar/mcp-legiti","_rev":"5-4e4806cc82ae197f4f4e764c1c9251d6","name":"@codespar/mcp-legiti","dist-tags":{"latest":"0.2.0-alpha.3","alpha":"0.2.0-alpha.2"},"versions":{"0.1.0-alpha.1":{"name":"@codespar/mcp-legiti","version":"0.1.0-alpha.1","keywords":["mcp","legiti","inspetor","fraud","fraud-prevention","risk-scoring","chargeback","ticketing","antifraud","brazil","ecommerce"],"license":"MIT","_id":"@codespar/mcp-legiti@0.1.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-legiti":"dist/index.js"},"dist":{"shasum":"6efca5e238cdcd3915fbfeb7240a0d88240e15a5","tarball":"https://registry.npmjs.org/@codespar/mcp-legiti/-/mcp-legiti-0.1.0-alpha.1.tgz","fileCount":7,"integrity":"sha512-IFe93x8DLqy3OQEmdzU1I9xuHxxiCni5rv7eonJd557J0afmbwugVckdQBSQ/zf8I64bKaBbFWJhVJQLZ6TwXg==","signatures":[{"sig":"MEYCIQCGUIwG/e+gMEJQq6kdVF501Lt4jxFLihbXPweRwUy2hQIhAKoz4NuiPruq+lm5okscDmpxwJzuNDXEXeHYIRT+YidN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":53318},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"9529bebc044ae16a46a6722419594f660d719c2e","mcpName":"io.github.codespar/mcp-legiti","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Legiti — Brazilian fraud prevention (ticketing + ecommerce), real-time order evaluation, chargeback feedback, and account/event/sale collection","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-legiti_0.1.0-alpha.1_1777031879099_0.9958351805842669","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.1":{"name":"@codespar/mcp-legiti","version":"0.2.0-alpha.1","keywords":["mcp","legiti","inspetor","fraud","fraud-prevention","risk-scoring","chargeback","ticketing","antifraud","brazil","ecommerce"],"license":"MIT","_id":"@codespar/mcp-legiti@0.2.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-legiti":"dist/index.js"},"dist":{"shasum":"c28cc7692fdf052e70845d268d7f90b519191163","tarball":"https://registry.npmjs.org/@codespar/mcp-legiti/-/mcp-legiti-0.2.0-alpha.1.tgz","fileCount":7,"integrity":"sha512-70dinMgC1D65h5m40kwAb+9U6OG9Hz0FBVgUu08aSv683Y9OlL71//uPH87N/jzR6+Gcf9vxg960q2gzVPkHaA==","signatures":[{"sig":"MEQCIC3GnsymoFZDQ+bO9gfe1YGiN3hSo68aMVUjHK0iB3F+AiAySw56MmqN+Ca3Perb87pIsQUm8JKaWkZHM5TdhFF6MQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":81993},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"67945e20ee596c2c3f388bf366a80236dc032b40","mcpName":"io.github.codespar/mcp-legiti","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Legiti — Brazilian fraud prevention (ticketing + ecommerce), real-time order evaluation, chargeback feedback, and account/event/sale collection","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-legiti_0.2.0-alpha.1_1777118616787_0.6747906510402075","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.2":{"name":"@codespar/mcp-legiti","version":"0.2.0-alpha.2","keywords":["mcp","legiti","inspetor","fraud","fraud-prevention","risk-scoring","chargeback","ticketing","antifraud","brazil","ecommerce"],"license":"MIT","_id":"@codespar/mcp-legiti@0.2.0-alpha.2","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-legiti":"dist/index.js"},"dist":{"shasum":"85e5b09ff0b277776583bd5ac7a898d75842e161","tarball":"https://registry.npmjs.org/@codespar/mcp-legiti/-/mcp-legiti-0.2.0-alpha.2.tgz","fileCount":7,"integrity":"sha512-Firqw/ncS1yjNB225Xp/IHqOESdYZ7zeBw4fVpn262feD+x1+vWIBns+gCW0YDQrw807mZEtdmMWiG5d4nKTpQ==","signatures":[{"sig":"MEQCIBsFGBy03963lfVQr4skG/yjFrnXL6TAgkxnDze8y/dNAiA7+9q/ZuNtUoEoEezpwHfSuB7fX8Np1RVzeD9yaq73IQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":83041},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"0ab801a863239f0cb986bbda65abbaee3c621b44","mcpName":"io.github.codespar/mcp-legiti","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Legiti — Brazilian fraud prevention (ticketing + ecommerce), real-time order evaluation, chargeback feedback, and account/event/sale collection","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-legiti_0.2.0-alpha.2_1777123101132_0.6131134883849954","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.3":{"name":"@codespar/mcp-legiti","version":"0.2.0-alpha.3","description":"MCP server for Legiti — Brazilian fraud prevention (ticketing + ecommerce), real-time order evaluation, chargeback feedback, and account/event/sale collection","type":"module","main":"./dist/index.js","bin":{"mcp-legiti":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"devDependencies":{"@types/node":"^25.5.0","typescript":"^5.8.0"},"license":"MIT","keywords":["mcp","legiti","inspetor","fraud","fraud-prevention","risk-scoring","chargeback","ticketing","antifraud","brazil","ecommerce"],"mcpName":"io.github.codespar/mcp-legiti","_id":"@codespar/mcp-legiti@0.2.0-alpha.3","gitHead":"e8f2ad023876683538fe7b66a2fc88ab8d8ef92f","types":"./dist/index.d.ts","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-Ylp5MzACgS/lwoO+vutLbJfWp9cf+6kTlCoeHhuACiJmJ0Us3yiagIp5qKTTdbozzjV8rjteSj8HYCXiQPLQUA==","shasum":"ca7d8b85f8bd29dd6db55e6814e85a1110df8e1f","tarball":"https://registry.npmjs.org/@codespar/mcp-legiti/-/mcp-legiti-0.2.0-alpha.3.tgz","fileCount":7,"unpackedSize":84474,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGZy7Wxb0FQ5MLV72SGR9p80KSgB2IAUzqnzTo85Iqr7AiAMHPlgZ+Jr4qduoGr+dpRfLVZw0xIEDYUbfIhEjEYk+g=="}]},"_npmUser":{"name":"codespar-npm","email":"fabiano@codespar.dev"},"directories":{},"maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-legiti_0.2.0-alpha.3_1782153672642_0.10667038916155791"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-24T11:57:59.004Z","modified":"2026-06-22T18:41:12.950Z","0.1.0-alpha.1":"2026-04-24T11:57:59.232Z","0.2.0-alpha.1":"2026-04-25T12:03:36.954Z","0.2.0-alpha.2":"2026-04-25T13:18:21.295Z","0.2.0-alpha.3":"2026-06-22T18:41:12.776Z"},"license":"MIT","keywords":["mcp","legiti","inspetor","fraud","fraud-prevention","risk-scoring","chargeback","ticketing","antifraud","brazil","ecommerce"],"description":"MCP server for Legiti — Brazilian fraud prevention (ticketing + ecommerce), real-time order evaluation, chargeback feedback, and account/event/sale collection","maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"readme":"# @codespar/mcp-legiti\n\nMCP server for [Legiti](https://legiti.com) — Brazilian fraud prevention, ticketing-native with a simple synchronous evaluation API.\n\nFourth entry in the CodeSpar `fraud` category, after [`@codespar/mcp-clearsale`](../clearsale), [`@codespar/mcp-konduto`](../konduto), and [`@codespar/mcp-sift`](../sift). Legiti (formerly Inspetor, São Paulo) occupies the mid-size BR tier: smaller public footprint than ClearSale, more vertical depth than Konduto for ticketing / events, and a simpler API surface than Sift.\n\n## Positioning\n\n|                      | Strength                                    | Typical fit                               |\n|----------------------|---------------------------------------------|-------------------------------------------|\n| **ClearSale**        | BR pioneer (2001), large chargeback history | Default for large BR retail               |\n| **Konduto**          | BR, API-first, behavioral device intel      | Digital-native BR ecommerce               |\n| **Legiti** *(this)*  | BR, ticketing-native, sync evaluation       | BR ticketing marketplaces, mid-size retail|\n| **Sift**             | Global, multi-abuse-type ML, workflows      | International enterprise                  |\n\nBR merchants frequently bundle 2-3 of these for best-of-breed scoring — Legiti for its ticketing-specific signals, ClearSale or Konduto for the generalist fraud layer, Sift for cross-border flows.\n\n## Tools (18)\n\n| Tool | Purpose |\n|---|---|\n| `evaluate_order` | Submit an order to Legiti for real-time fraud evaluation via the v2 order endpoint. |\n| `update_order` | Notify Legiti of a status change on an existing order (e.g. |\n| `mark_order_fraudulent` | Report a confirmed chargeback / fraud outcome back to Legiti. |\n| `evaluate_sale` | Legacy single-shot sale evaluation via POST /evaluation. |\n| `track_account` | Notify Legiti of an account lifecycle event (created / updated / deleted). |\n| `track_event` | Notify Legiti of an Event (concert, show, match, session) lifecycle change. |\n| `track_sale` | Notify Legiti of a Sale state change (created / updated). |\n| `track_auth` | Notify Legiti of an authentication or password event (login attempt, logout, password recovery request, pas... |\n| `track_login` | Notify Legiti of a login attempt (successful or failed). |\n| `track_logout` | Notify Legiti of a logout event. |\n| `track_signup` | Notify Legiti of a new account creation. |\n| `track_account_update` | Notify Legiti of an account profile change (email, phone, CPF, address). |\n| `track_password_recovery` | Notify Legiti of a password recovery request (the 'forgot password' click). |\n| `track_event_view` | Notify Legiti that a user viewed an event/show page. |\n| `track_payment` | Notify Legiti of a payment-method-level event (authorization attempt, capture, refund, void). |\n| `get_decision` | Fetch the latest Legiti decision for an order. |\n| `update_decision_status` | Manually override Legiti's decision for an order — typically used to accept or decline a sale that landed i... |\n| `mark_dispute_resolution` | Report the outcome of a chargeback dispute back to Legiti — i.e. |\n\n## Install\n\n```bash\nnpm install @codespar/mcp-legiti@alpha\n```\n\n## Environment\n\n```bash\nLEGITI_API_KEY=\"eyJhbGciOi...\"   # JWT bearer token; required\nLEGITI_BASE_URL=\"...\"             # optional; defaults to https://collection-prod.inspcdn.net\n```\n\n## Authentication\n\nBearer token (JWT-format):\n\n```\nAuthorization: Bearer <LEGITI_API_KEY>\n```\n\nLegiti issues separate **sandbox** and **production** keys. The sandbox key tags every request as test data so it does NOT train the ML model. Always develop and run integration tests with the sandbox key — hitting production with test data pollutes the model.\n\n## Decision values\n\n`evaluate_order` and `evaluate_sale` return one of three decisions:\n\n- `approve` — ship it\n- `reject` — block the sale\n- `manual` — route to manual review\n\nEvaluation is synchronous; the response may take up to ~20 seconds.\n\n## Typical flow (ticketing)\n\n1. At signup / login, call `track_account` (create/update) and `track_auth` (login/logout, password_recovery, password_reset). Every auth attempt — successful or failed — is valuable signal for account-takeover detection.\n2. When a new event (concert, show, match) is published on the platform, call `track_event` (create). Update on price/capacity/date changes.\n3. At checkout, call `evaluate_order` with the sale, account, payment, CPF, and the primary `event_date_id`. Act on the returned decision: `approve` → ship, `reject` → block, `manual` → human review.\n4. As the order progresses (paid, shipped, delivered, cancelled, refunded), call `update_order`.\n5. When a chargeback is confirmed by the issuer, call `mark_order_fraudulent`. This is Legiti's primary ML feedback channel — unreported chargebacks degrade future decision quality for similar buyers.\n\n## Typical flow (non-ticketing ecommerce)\n\nSkip `track_event`. The `event_date_id` fields become optional in `evaluate_order` — Legiti will still evaluate on account + sale + payment signal, though ticketing-vertical features will be unused.\n\n## Alpha note\n\nShipped as `0.1.0-alpha.1`. Legiti's public documentation is tighter than ClearSale's or Konduto's:\n\n- **Documented in open-source `github.com/legiti/docs-backend`:** `POST /evaluation`, plus the Collection API (account, event, sale, transfer, auth, password) shape and the `Authorization: Bearer` scheme.\n- **Documented on `docs.legiti.com` integration guides:** the v2 order family (`POST /v2/order`, `PUT /v2/order`, `POST /v2/order/mark_fraudulent`).\n- **Dropped from the original category spec:** `create_rule` / `list_rules` / `update_rule` / `delete_rule` — no public custom-rules surface exists on Legiti. If a customer contract exposes one, promote to `0.2.0`.\n\nPromote to `0.1.0` once the v2 order payload schema is confirmed in production.\n\n## Run\n\n```bash\n# stdio (default — for Claude Desktop, Cursor, etc)\nnpx @codespar/mcp-legiti\n\n# HTTP (for server-to-server testing)\nMCP_HTTP=true MCP_PORT=3000 npx @codespar/mcp-legiti\n```\n\n## Category\n\n`fraud` — fourth server in this CodeSpar category alongside ClearSale, Konduto, and Sift. Fraud servers share a common shape (analyze → decide → feedback) distinct from payments, which makes cross-provider swaps (ClearSale ↔ Konduto ↔ Legiti) more straightforward than cross-acquirer swaps.\n\n## Enterprise\n\nNeed governance, budget limits, and audit trails for agent payments? [CodeSpar Enterprise](https://codespar.dev/enterprise) adds policy engine, payment routing, and compliance templates on top of these MCP servers.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}