{"_id":"@codespar/mcp-santander","_rev":"5-d8180086c3888ae688acfa3ef0e64506","name":"@codespar/mcp-santander","dist-tags":{"latest":"0.2.0-alpha.3","alpha":"0.2.0-alpha.2"},"versions":{"0.1.0-alpha.1":{"name":"@codespar/mcp-santander","version":"0.1.0-alpha.1","keywords":["mcp","santander","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"license":"MIT","_id":"@codespar/mcp-santander@0.1.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-santander":"dist/index.js"},"dist":{"shasum":"61a1094207cab5f4ca2fd516e85d6c026d34275c","tarball":"https://registry.npmjs.org/@codespar/mcp-santander/-/mcp-santander-0.1.0-alpha.1.tgz","fileCount":6,"integrity":"sha512-9CnSoNzXup3yPILVTkmqrHZK92QtwPq0hvoXB0MwbbryhytfZXWgshmkqmyzMqLGNG8z3+iHVwLIvm9rNR9C7g==","signatures":[{"sig":"MEYCIQDeZ6h9F0gtLcXeXvPmGJxB0D4y2odmeq/yziPWkh28LAIhAJ4jvhVPIEbmsdgEOL/H/NqUp0sUPBf0Gs/fTfEHxJfO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":59443},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"9529bebc044ae16a46a6722419594f660d719c2e","mcpName":"io.github.codespar/mcp-santander","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Santander Brasil — 3rd largest private bank in Brazil. Pix, Cobrança (boleto), Arrecadação, and Extrato via Santander's trust-open Developer Portal APIs (OAuth2 + mTLS).","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-santander_0.1.0-alpha.1_1777031875830_0.8310127902044404","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.1":{"name":"@codespar/mcp-santander","version":"0.2.0-alpha.1","keywords":["mcp","santander","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"license":"MIT","_id":"@codespar/mcp-santander@0.2.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-santander":"dist/index.js"},"dist":{"shasum":"ba1e9fa61fe570da8cb6b13de0d9450e801e0681","tarball":"https://registry.npmjs.org/@codespar/mcp-santander/-/mcp-santander-0.2.0-alpha.1.tgz","fileCount":6,"integrity":"sha512-xiI40Iybsht2vppUA2EVNYDbbcq55vxJ25gpq+N0r0M1NSAmg56GtFAo4DnTnLAUKMEvKMtWR9KmovyY8Gf57A==","signatures":[{"sig":"MEYCIQDY3ffriFlhiUURqwhKigs4z9F4wBHua71QHRFQZWBGWAIhAOpK4jMmfLGd8dvq/pYNTwNGZO8a3fg1+19dR/tITJwM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":94819},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"aa155cfd90298f7233644389f945286db9d20fe4","mcpName":"io.github.codespar/mcp-santander","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Santander Brasil — 3rd largest private bank in Brazil. Pix, Cobrança (boleto), Arrecadação, and Extrato via Santander's trust-open Developer Portal APIs (OAuth2 + mTLS).","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-santander_0.2.0-alpha.1_1777065416842_0.508018718681871","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.2":{"name":"@codespar/mcp-santander","version":"0.2.0-alpha.2","keywords":["mcp","santander","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"license":"MIT","_id":"@codespar/mcp-santander@0.2.0-alpha.2","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-santander":"dist/index.js"},"dist":{"shasum":"0daafe58f57b54d4745ddbf596cce5a50255c7af","tarball":"https://registry.npmjs.org/@codespar/mcp-santander/-/mcp-santander-0.2.0-alpha.2.tgz","fileCount":6,"integrity":"sha512-rycO7SfpaYprmM9rGFYUAwbN55HaghP4/8kcKqJAzyWD3UfBtDM06GuVjMLgXJ7iM+kiXtPukrAYuLDw6DTZ5A==","signatures":[{"sig":"MEUCIQDSau3Tt1Wml419ateMc4fgnAotlvBoyBHVMgXvici78gIgLHJ/vMJEqkY40GbcOpA3Pv4u9+kDqvEd+2uW5P7XEpE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":96353},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"b8f7e5b70db9046319ed757225e0eae8f2dc4451","mcpName":"io.github.codespar/mcp-santander","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Santander Brasil — 3rd largest private bank in Brazil. Pix, Cobrança (boleto), Arrecadação, and Extrato via Santander's trust-open Developer Portal APIs (OAuth2 + mTLS).","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-santander_0.2.0-alpha.2_1777122937445_0.4194303049672248","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.3":{"name":"@codespar/mcp-santander","version":"0.2.0-alpha.3","description":"MCP server for Santander Brasil — 3rd largest private bank in Brazil. Pix, Cobrança (boleto), Arrecadação, and Extrato via Santander's trust-open Developer Portal APIs (OAuth2 + mTLS).","type":"module","main":"./dist/index.js","bin":{"mcp-santander":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"devDependencies":{"@types/node":"^25.5.0","typescript":"^5.8.0"},"license":"MIT","keywords":["mcp","santander","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"mcpName":"io.github.codespar/mcp-santander","_id":"@codespar/mcp-santander@0.2.0-alpha.3","gitHead":"8e115a5cb8aed75e812af698b03aa996ccd8d7c1","types":"./dist/index.d.ts","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-Bb8updlUZPqjxZSTfPLm06MmdRoUU/NzVfKFoNAzNQhtq29sTSHVjJClnJZSkXEmqEpyPEI6o2kjioTKvnsVeA==","shasum":"b0d22180ee9e5e1279fe8d60890280016c6bccbc","tarball":"https://registry.npmjs.org/@codespar/mcp-santander/-/mcp-santander-0.2.0-alpha.3.tgz","fileCount":6,"unpackedSize":97772,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDtl6o1t8C5Pvr67FNJLHgBLaCmCkOfyEp/9vx1L9wP2wIhAIkQeOepfPjlaKzaQJJ9tzivzPeFV9ApnGvDRYb6qacp"}]},"_npmUser":{"name":"codespar-npm","email":"fabiano@codespar.dev"},"directories":{},"maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-santander_0.2.0-alpha.3_1782158089429_0.5151931499233768"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-24T11:57:55.766Z","modified":"2026-06-22T19:54:49.732Z","0.1.0-alpha.1":"2026-04-24T11:57:55.970Z","0.2.0-alpha.1":"2026-04-24T21:16:56.999Z","0.2.0-alpha.2":"2026-04-25T13:15:37.615Z","0.2.0-alpha.3":"2026-06-22T19:54:49.572Z"},"license":"MIT","keywords":["mcp","santander","banking","pix","boleto","cobranca","arrecadacao","extrato","brazil"],"description":"MCP server for Santander Brasil — 3rd largest private bank in Brazil. Pix, Cobrança (boleto), Arrecadação, and Extrato via Santander's trust-open Developer Portal APIs (OAuth2 + mTLS).","maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"readme":"# @codespar/mcp-santander\n\nMCP server for [Santander Brasil](https://developer.santander.com.br) — 3rd largest private bank in Brazil.\n\nCompletes the top-3 BR private-bank trio: **Itaú + Bradesco + Santander**. Same OAuth2 + mTLS shape as its peers; different merchant contract.\n\nMerchants with meaningful Pix, boleto, and cash-management volume integrate directly with Santander instead of going through a PSP.\n\n## Status: alpha (`0.1.0-alpha.1`)\n\nSantander's Developer Portal is **contract-gated** — the full OpenAPI specs for Pix, Cobrança, Arrecadação, and Extrato are only visible to onboarded merchants. The following pieces are **verified** against Santander's public integration guides:\n\n- Production host: `https://trust-open.api.santander.com.br`\n- Sandbox host: `https://trust-sandbox.api.santander.com.br`\n- OAuth2 token: `/auth/oauth/v2/token`\n- Cobrança v2 base: `/collection_bill_management/v2/workspaces/{workspace_id}/bank_slips`\n\nRemaining paths (Pix, Arrecadação, Extrato) are best-guesses based on (a) BACEN Pix v2 standard paths, (b) Santander public marketing, and (c) conventions shared across Itaú / Bradesco / BB. Every unverified path is flagged `TODO(verify)` in the source.\n\nPin to exact versions during `0.1.x`; paths will be corrected to match the portal spec once an onboarded merchant can validate.\n\n## Tools (23)\n\n| Tool | Purpose |\n|---|---|\n| `get_oauth_token` | Mint or return a cached OAuth2 client_credentials bearer token for the Santander Developer Portal. |\n| `send_pix` | Initiate an outbound Pix payment from the merchant's Santander account. |\n| `create_pix_qr` | Create a dynamic Pix charge with QR code (cob). |\n| `get_pix` | Retrieve a Pix transaction by its BCB endToEndId (E<ispb><yyyymmddhhmm><sequence>). |\n| `resolve_dict_key` | Resolve a DICT key (CPF, CNPJ, email, phone, EVP) to the owner's account data before sending a Pix. |\n| `refund_pix` | Refund (devolução) a previously received Pix. |\n| `create_boleto` | Issue a boleto via Santander Cobrança (collection_bill_management v2). |\n| `get_boleto` | Retrieve a boleto by its Santander bill_id (SONDA query via collection_bill_management v2). |\n| `cancel_boleto` | Cancel (baixa) an outstanding boleto before payment. |\n| `get_statement` | Retrieve account statement transactions for a given period. |\n| `create_pix_cobv` | Create a Pix charge with due date (cobv — cobrança com vencimento). |\n| `get_pix_cob` | Retrieve a Pix immediate charge (cob) by its txid. |\n| `list_pix_cob` | List Pix immediate charges (cob) created in a given period. |\n| `update_pix_cob` | Update (PATCH) an existing Pix immediate charge. |\n| `list_pix_received` | List received Pix (Pix recebidos) in a given period. |\n| `register_dict_key` | Register a new DICT key for one of the merchant's Santander accounts. |\n| `delete_dict_key` | Remove (unregister) a DICT key previously registered for the merchant. |\n| `download_boleto_pdf` | Fetch the PDF (second copy / segunda via) of a registered boleto. |\n| `get_account_balance` | Get current available and blocked balance for a Santander merchant account. |\n| `send_ted` | Initiate a TED transfer from a Santander merchant account to an account at another bank. |\n| `transfer_internal` | Transfer between two Santander accounts (TEF / mesma instituição). |\n| `create_openfinance_consent` | Create an Open Finance consent (BACEN-regulated) for data access or payment initiation against a third-part... |\n| `arrecadacao_pay` | Pay a utility, tax, or concessionária bill via Santander Arrecadação / Pagamento de Contas. |\n\n## Install\n\n```bash\nnpm install @codespar/mcp-santander@0.1.0-alpha.1\n```\n\n## Environment\n\n```bash\nSANTANDER_CLIENT_ID=\"...\"       # OAuth client_id from Santander's Developer Portal\nSANTANDER_CLIENT_SECRET=\"...\"   # OAuth client_secret\nSANTANDER_CERT_PATH=\"/abs/path/to/client.crt\"   # mTLS client certificate\nSANTANDER_KEY_PATH=\"/abs/path/to/client.key\"    # mTLS private key\nSANTANDER_ENV=\"sandbox\"                         # or \"production\" (default: sandbox)\n```\n\n## Authentication\n\nTwo factors are **both** required on every call:\n\n1. **OAuth2 `client_credentials`** — the server POSTs to `/auth/oauth/v2/token` on the `trust-open` (or `trust-sandbox`) gateway, caches the bearer until ~60s before expiry, and attaches `Authorization: Bearer <token>` to downstream calls.\n2. **mTLS** — BACEN mandates mutual TLS for Pix v2, and Santander's `trust-open` gateway enforces it across product families. The server loads the client certificate and private key from the paths you set, builds a Node `https.Agent`, and routes every request through it.\n\nYou obtain the cert + key bundle from the Santander Developer Portal after your merchant contract is signed. They are distinct from the OAuth credentials.\n\n## Cobrança: workspace model\n\nSantander's Cobrança v2 is **workspace-scoped**. Before registering boletos you provision one or more `workspace_id`s via the Developer Portal — each binds a convênio, boleto/Pix billing mode, and webhook URL. The `create_boleto`, `get_boleto`, and `cancel_boleto` tools all take a `workspace_id` argument.\n\n## Run\n\n```bash\n# stdio (default)\nnpx @codespar/mcp-santander\n\n# HTTP transport\nMCP_HTTP=true MCP_PORT=3000 npx @codespar/mcp-santander\n```\n\n## Caveats\n\n- **Pix / Arrecadação / Extrato paths are unverified.** See the `TODO(verify)` markers in `src/index.ts`. Onboarded merchants should validate against their portal-issued OpenAPI spec and open a PR.\n- **Cobrança cancel** is modelled as a `PATCH` with `status: \"BAIXADO\"`; the covenant-specific cancellation semantics may differ.\n- **Arrecadação barcode validation** is server-side in this alpha — no client-side mod-10 / mod-11 check yet.\n\n## Enterprise\n\nNeed governance, budget limits, and audit trails for agent payments? [CodeSpar Enterprise](https://codespar.dev/enterprise) adds policy engine, payment routing, and compliance templates on top of these MCP servers.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}