{"_id":"@codespar/mcp-worldpay","_rev":"5-7a4eecb015cb84e1b58ace1a46d1b9e3","name":"@codespar/mcp-worldpay","dist-tags":{"latest":"0.2.0-alpha.3","alpha":"0.2.0-alpha.2"},"versions":{"0.1.0-alpha.1":{"name":"@codespar/mcp-worldpay","version":"0.1.0-alpha.1","keywords":["mcp","worldpay","access-worldpay","payments","global-payments","card-payments","fraudsight","disputes","enterprise"],"license":"MIT","_id":"@codespar/mcp-worldpay@0.1.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-worldpay":"dist/index.js"},"dist":{"shasum":"444836e639fd32a73f93369acb9ce1d667c5f2d5","tarball":"https://registry.npmjs.org/@codespar/mcp-worldpay/-/mcp-worldpay-0.1.0-alpha.1.tgz","fileCount":6,"integrity":"sha512-HR4SIOuaqC2cyI6IVXvg7uz3FTEBWm01d/YgAHSFUUr6Q1DONBfJY6b4RsH0/whFXt6Qpm6wY2nXBJ3iyPedIQ==","signatures":[{"sig":"MEQCIBSs4Ek7vyMM8Wto0gr97gHPPdDpa0SDkYKoJ3tC9DjjAiB17U6LcYg/PpNYaYTm80JDGprNc9KFuO5GfNACb0YKjw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":54716},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"472f257c5702fe7b9c9f5f24230875c585c1dfc6","mcpName":"io.github.codespar/mcp-worldpay","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Access Worldpay — global enterprise payment processor (authorize, capture, refund, reverse, verify, tokenize, fraud screen, disputes)","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-worldpay_0.1.0-alpha.1_1776994123988_0.8397658942207646","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.1":{"name":"@codespar/mcp-worldpay","version":"0.2.0-alpha.1","keywords":["mcp","worldpay","access-worldpay","payments","global-payments","card-payments","fraudsight","disputes","enterprise"],"license":"MIT","_id":"@codespar/mcp-worldpay@0.2.0-alpha.1","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-worldpay":"dist/index.js"},"dist":{"shasum":"c9c2275bf9cb2a19ba934e1a0b96272c4af810eb","tarball":"https://registry.npmjs.org/@codespar/mcp-worldpay/-/mcp-worldpay-0.2.0-alpha.1.tgz","fileCount":6,"integrity":"sha512-o+5hOGzBBuMWH7rx4OQ7QSiCxg0Ov4mX7tTzbMQiOqk+7ZSE7QltkA34GecjbEW8IKiwlKb8dgyjqYPwStYxCA==","signatures":[{"sig":"MEUCIQDYsUQ9ZweZbkNZm/jFE5KD18nXhw7LLDJXPZe8ug2ERAIgNimnSLacXkA5AvnMNA7Hty066GrUYBX0CRvKXOTntUg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":77375},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"aa155cfd90298f7233644389f945286db9d20fe4","mcpName":"io.github.codespar/mcp-worldpay","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Access Worldpay — global enterprise payment processor (authorize, capture, refund, reverse, verify, tokenize, fraud screen, disputes)","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-worldpay_0.2.0-alpha.1_1777065409235_0.8796604571225599","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.2":{"name":"@codespar/mcp-worldpay","version":"0.2.0-alpha.2","keywords":["mcp","worldpay","access-worldpay","payments","global-payments","card-payments","fraudsight","disputes","enterprise"],"license":"MIT","_id":"@codespar/mcp-worldpay@0.2.0-alpha.2","maintainers":[{"name":"codespar-npm","email":"contact@codespar.dev"}],"bin":{"mcp-worldpay":"dist/index.js"},"dist":{"shasum":"1ee8bb045506102afcc7f5c427995b3ac8fe6a64","tarball":"https://registry.npmjs.org/@codespar/mcp-worldpay/-/mcp-worldpay-0.2.0-alpha.2.tgz","fileCount":6,"integrity":"sha512-kepjB1GijRip+lDNpYlturRdo7BILAyyvyawMpGIlrxEvnwuVCBt9jxC7ef8s4Yt1b8HYaE6Pip6O+4ftDVVhg==","signatures":[{"sig":"MEUCIEDEd4piZxXipRTZymiJl/zr/B+9v+/eZ2dvzDBUcxkHAiEA1YHSTEHSU+gsYyrSiiEMiRSpCc+hjXA71GopqL2Q/AU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":78599},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"0ab801a863239f0cb986bbda65abbaee3c621b44","mcpName":"io.github.codespar/mcp-worldpay","scripts":{"build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"codespar-npm","email":"contact@codespar.dev"},"_npmVersion":"11.8.0","description":"MCP server for Access Worldpay — global enterprise payment processor (authorize, capture, refund, reverse, verify, tokenize, fraud screen, disputes)","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"typescript":"^5.8.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-worldpay_0.2.0-alpha.2_1777123291849_0.991164946543339","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.3":{"name":"@codespar/mcp-worldpay","version":"0.2.0-alpha.3","description":"MCP server for Access Worldpay — global enterprise payment processor (authorize, capture, refund, reverse, verify, tokenize, fraud screen, disputes)","type":"module","main":"./dist/index.js","bin":{"mcp-worldpay":"dist/index.js"},"scripts":{"build":"tsc","start":"node dist/index.js"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"devDependencies":{"@types/node":"^25.5.0","typescript":"^5.8.0"},"license":"MIT","keywords":["mcp","worldpay","access-worldpay","payments","global-payments","card-payments","fraudsight","disputes","enterprise"],"mcpName":"io.github.codespar/mcp-worldpay","_id":"@codespar/mcp-worldpay@0.2.0-alpha.3","gitHead":"e8f2ad023876683538fe7b66a2fc88ab8d8ef92f","types":"./dist/index.d.ts","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-LdrAl0X2V4glYpbzmWRyxKMNTZlNPrzJhkspMsyaYgaw6fYbWHlksv50HZLfmA2KQeA5UMrt0OaPVEuTHViKrg==","shasum":"87fc4c12d476edd57601a260e8add239b6273c1e","tarball":"https://registry.npmjs.org/@codespar/mcp-worldpay/-/mcp-worldpay-0.2.0-alpha.3.tgz","fileCount":6,"unpackedSize":80047,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCuuYyn6klOON4axg7wzI4yU5WpbCJFYuzMpsfCGjdkwAIgfPSH90I/zuzM467YwvsHdyL3K2+924E9ZH0nNUtCFCs="}]},"_npmUser":{"name":"codespar-npm","email":"fabiano@codespar.dev"},"directories":{},"maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-worldpay_0.2.0-alpha.3_1782154012984_0.42100901190123374"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-24T01:28:43.877Z","modified":"2026-06-22T18:46:53.292Z","0.1.0-alpha.1":"2026-04-24T01:28:44.132Z","0.2.0-alpha.1":"2026-04-24T21:16:49.394Z","0.2.0-alpha.2":"2026-04-25T13:21:31.980Z","0.2.0-alpha.3":"2026-06-22T18:46:53.144Z"},"license":"MIT","keywords":["mcp","worldpay","access-worldpay","payments","global-payments","card-payments","fraudsight","disputes","enterprise"],"description":"MCP server for Access Worldpay — global enterprise payment processor (authorize, capture, refund, reverse, verify, tokenize, fraud screen, disputes)","maintainers":[{"name":"codespar-npm","email":"fabiano@codespar.dev"},{"name":"dangazineu","email":"daniel.gazineu@gmail.com"}],"readme":"# @codespar/mcp-worldpay\n\nMCP server for [Access Worldpay](https://docs.worldpay.com/access) — global enterprise payment processor.\n\nWorldpay is one of the largest card acquirers in the world and a default rail for EU/UK/US enterprise merchants. This server targets the modern **Access Worldpay** REST surface, not the legacy FIS/WPG XML gateway.\n\n> **Status: 0.1.0-alpha.1** — Access Worldpay uses HATEOAS action links (`linkData`) for lifecycle operations. Exact endpoint paths and media-type versions have been validated against the public docs (v7 payments, v4 verifications, v3 tokens, v1 fraudsight/disputes) but are moving targets. See [Stability](#stability) below.\n\n## Tools (22)\n\n| Tool | Purpose |\n|---|---|\n| `verify_account` | Run an AVS/CVC account verification on a card without charging it. |\n| `authorize_payment` | Authorize a card payment. |\n| `capture_payment` | Capture (settle) an authorized payment. |\n| `cancel_payment` | Void an authorization that has not yet been captured. |\n| `refund_payment` | Refund a captured payment. |\n| `reverse_payment` | Reverse a payment atomically — voids if not yet captured, refunds if already captured. |\n| `get_payment` | Retrieve the detail of a payment event by its Worldpay eventId. |\n| `create_token` | Tokenize a card for reuse (card-on-file). |\n| `get_token` | Retrieve a stored card token's metadata (bin, scheme, last4, cardHolderName, expiryDate, etc.). |\n| `update_token` | Update metadata on a stored card token (e.g. |\n| `delete_token` | Delete a stored card token. |\n| `query_payment` | Look up a payment by the merchant-side transactionReference you assigned on authorize_payment. |\n| `list_payment_events` | List recent payment events for the configured merchant entity. |\n| `lookup_3ds` | Step 1 of 3DS2 — submit device-data-collection (DDC) output to Worldpay to determine whether a challenge is... |\n| `authenticate_3ds` | Step 2 of 3DS2 — authenticate the cardholder. |\n| `challenge_3ds` | Step 3 of 3DS2 — post the CReq back after the issuer challenge window closes, to retrieve the final authent... |\n| `get_dispute` | Retrieve a dispute's current state, evidence requirements, deadlines, and HATEOAS action links. |\n| `defend_dispute` | Open a defence on a dispute — signals intent to defend before submit_dispute_evidence. |\n| `get_reconciliation_batch` | Retrieve a reconciliation batch (daily settlement file equivalent) — lists all settled transactions, fees,... |\n| `accept_dispute` | Accept a dispute (forfeit the chargeback). |\n| `submit_dispute_evidence` | Submit evidence to defend a dispute. |\n| `fraud_screen` | Run a standalone FraudSight assessment on a payment method (no authorization). |\n\n## Install\n\n```bash\nnpm install @codespar/mcp-worldpay@alpha\n```\n\n## Environment\n\n```bash\nWORLDPAY_USERNAME=\"...\"    # API username (Basic Auth)\nWORLDPAY_PASSWORD=\"...\"    # API password (Basic Auth)\nWORLDPAY_ENTITY=\"...\"      # Merchant entity id; injected as merchant.entity\nWORLDPAY_ENV=\"sandbox\"     # sandbox | production; default sandbox\nWORLDPAY_API_VERSION=\"v7\"  # Payments API version; default v7\n```\n\n## Authentication\n\nHTTP Basic auth with your Worldpay-issued credentials:\n\n```\nAuthorization: Basic base64(username:password)\n```\n\nEach API family uses its own versioned media type. The server sets the correct `Content-Type` / `Accept` headers per call:\n\n| Family | Media type |\n|--------|-----------|\n| payments | `application/vnd.worldpay.payments-v7+json` |\n| verifications | `application/vnd.worldpay.verifications.accounts-v4+json` |\n| tokens | `application/vnd.worldpay.tokens-v3.hal+json` |\n| fraudsight | `application/vnd.worldpay.fraudsight-v1.hal+json` |\n| disputes | `application/vnd.worldpay.disputes-v1.hal+json` |\n\n## HATEOAS and `linkData`\n\nAccess Worldpay is HATEOAS-driven. After `authorize_payment`, the response contains `_links` such as `payments:settle`, `payments:partialSettle`, `payments:cancel`, `payments:refund`, `payments:partialRefund`, and `payments:reverse`. Each `href` ends in an opaque segment we call **`linkData`**, e.g.:\n\n```\n/payments/settlements/eyJrIjoiazNhYjYzMiJ9\n                       ^^^^^^^^^^^^^^^^^^^ linkData\n```\n\nExtract that segment and pass it as `linkData` to `capture_payment` / `cancel_payment` / `refund_payment` / `reverse_payment`. When omitted, the server POSTs to the bare resource path; this only works for onboardings configured for `transactionReference`-addressable settlements.\n\n## Run\n\n```bash\n# stdio (default — for Claude Desktop, Cursor, etc.)\nnpx @codespar/mcp-worldpay\n\n# HTTP (for server-to-server testing)\nMCP_HTTP=true MCP_PORT=3000 npx @codespar/mcp-worldpay\n```\n\n## Stability\n\n- Published as `0.1.0-alpha.1` until we validate end-to-end against a real sandbox account.\n- **Global Payments acquired Worldpay in January 2026.** Base URLs (`try.access.worldpay.com` / `access.worldpay.com`) remain valid as of this writing, but Global Payments has publicly signalled platform consolidation. Expect URL and media-type rebranding over the next 12–18 months. Pin the `WORLDPAY_API_VERSION` env var and watch the [release notes](https://developer.worldpay.com/products/releases).\n- This server does **not** cover: Worldpay Total (US CNP-API legacy), the WPG/FIS XML gateway, Disputes Direct (separate from Access Disputes), or Worldpay for Platforms. Those are separate surfaces and would be separate packages.\n\n## Enterprise\n\nNeed governance, budget limits, and audit trails for agent payments? [CodeSpar Enterprise](https://codespar.dev/enterprise) adds policy engine, payment routing, and compliance templates on top of these MCP servers.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}