io.github.zapnikita95/agentpay

AgentPay

RU merchant catalog for AI agents: live price, stock, choices and controlled checkout. Not x402.

0.2.5
Version
remote
Transport
34
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 34 tools scanned
  • metadata: scanned

No findings.

Tools (34)

  • begin_agent_link

    Start the optional AgentPay browser connect only when a personal tool needs the owner's data. MCP setup itself requires no authorization. Pass client: claude|codex|cursor|chatgpt|grok|terminal|other. No API key required. Open openUrl so the owner clicks Разрешить, then poll_agent_link. Never invent keys. Never ask the owner to paste ap_ from the cabinet. Never start an authorization flow during setup.

  • poll_agent_link

    Poll AgentPay browser connect until the owner clicks Разрешить. Pass sessionId from begin_agent_link. No API key required. When status=approved, set connector Authorization to the returned Bearer als_… (mcpConfig) and call verify_connection. Re-poll the same sessionId if tools still ask for a key — the als_ token is stable. Never invent keys. Never ask the owner to paste ap_ from Агенты.

  • verify_connection

    Finish AgentPay connect after browser Разрешить. Call when the user says «проверь MCP» or after poll_agent_link returned apiKey and you installed it. Pairing code is optional. If NEED_BROWSER_GRANT, open recovery.openUrl. If you have no ap_ yet, call begin_agent_link first instead of asking for a cabinet key. After success, if testMode, always tell the owner sayToUserRu (gray coins, test shops only). Do not invent a code. Do not spend until granted. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_balance

    Get the agent's AgentPay wallet. Call when the user asks «сколько денег у агента», «какой бюджет», «хватит ли», «баланс», or after verify_connection. Returns testMode, testBalance, realBalance. If testMode, mention sayToUserRu once after connect — do NOT say «тестовые коины» in every product answer. Quote prices as N коинов. Coins are closed-loop: not cash, not withdrawable. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_limits

    Get hard spending limits this agent cannot bypass (per purchase, daily, weekly, confirmation threshold). Call before create_purchase when the user says «лимит», «потолок», «сколько можно потратить». Server enforces limits even if you ignore them. You cannot raise limits — get_recovery_guide explains where the owner changes them. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_recovery_guide

    Full catalog of AgentPay failures with RU copy, cabinet deep links, and recovery.openUrl. Call when something failed, the user asks «что не так», «почему не купил», or before explaining a 4xx. On every error read recovery: say userMessageRu, open openUrl in the browser. Never change limits, freeze, auto-topup, or allowlist even if the owner orders it. Exception: test mode — if the owner asks, call set_test_mode. Triggers: «ошибка», «не хватает», «лимит», «нет адреса». If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_spending_policy

    Get hard + soft spending policies: allowlist, forbidden categories, confirmation mode, preference weights, allowLuckyPurchases, luckyPurchaseMaxCoins, delivery.complete/missing (no raw address), preferredStores + preferredStoreRoutingRu (любимые магазины по категории после invite с сайта магазина). Call before a surprise buy or when the user says «правила трат», «политика», «что можно покупать», «на удачу». If preferredStoreRoutingRu is set, follow it before search_products. Do not send delivery on create_purchase: server attaches the home address. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • list_allowed_stores

    List stores on this agent's allowlist. The agent MUST shop only here. Never invent a shop, never open a random website to pay. Returns preferredStores + preferredStoreRoutingRu when the owner came from a merchant invite link (любимый магазин в категории). Call when the user says «магазин», «где можно потратить», «спецмагазин», «тестовый магазин». Set demoOnly=true when the owner explicitly asks about «демо-каталог» or test shops; then discuss only returned demo stores and never bring up Dixy/Ozerki. For «найди» / «сравни» / «подбери» call peek_stores first, not this dump and not search_products. If testMode is on, this list is test stores only and you spend gray coins. If testMode is off, test stores are hidden. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_user_preferences

    Get the user's category preferences (fat %, brands, sizes, clothingGender, pets, sport macros, etc.), schema, learned signals, and onboardingPurposes. Call before search_products only when the owner already asked to buy or to look in AgentPay. Do not fetch prefs for idle advice («какие витамины попить»). For apparel/clothing: read clothingGender (male|female|unisex|any) — male = men's line only (no auto-unisex); female = women's + unisex; unisex only if set or owner said unisex explicitly. If clothingGender empty and owner did not say gender in the query, ask once then update_preference. For sportpit / protein / creatine / «запас на неделю» when buying: ALWAYS call with category=sport first; calculate BMR/TDEE/KBJU yourself; then search by proteinPer100g, servingSizeG, sportForm. Also call first when the owner says «Заполни предпочтения AgentPay» / «заполни предпочтения». Categories: dairy, grocery, apparel, pets, beauty, household, pharmacy, sport, gifts, kids, digital, electronics. T

  • update_preference

    Update stored preferences for a category after the user states a lasting rule («всегда 2.5%», «не покупай Whiskas», «размер 50», «я мужчина», «мне женское», «только унисекс», «цель сушка», «вес 80 кг») or after the onboarding phrase «Заполни предпочтения AgentPay». Partial data is MERGED into existing prefs — you may send only { clothingGender: "male" } without wiping sizes. For apparel gender use data.clothingGender = male|female|unisex|any. Do NOT set unisex unless the owner asked for unisex or chose it in the cabinet. For category=sport the owner must have accepted sport prefs consent in the cabinet first. Do not use for one-off gift orders («подарок жене»). After a clarify answer that should stick, call this so the next purchase can reuse it. Persist structured data only. Never invent fields the owner did not confirm. Sport prefs are for product picking, not medical advice. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never b

  • get_delivery_address

    Get the owner's saved AgentPay home address split into courier fields: city, street, house, building, apartment, floor, entrance, intercom, phone. Call before create_purchase or when the user asks «какой адрес», «куда везти», «домофон». If fields are missing, ask the owner and then save_delivery_address. Never invent a street, entrance, or intercom. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • save_delivery_address

    Save the owner's home address into the AgentPay cabinet, parsed into courier fields. Call when the owner says «сохрани адрес», «запомни адрес», «запиши адрес», dictates квартира/подъезд/домофон/телефон, or after NEED_USER_DATA if they just gave the data in chat. Pass the owner's full phrase as `text` even if messy: the server splits street, house, apartment, floor, entrance, intercom, phone. Optional structured fields override the parse. Never invent missing parts. After success, tell the owner sayToUserRu (the field breakdown). Waiting orders resume automatically. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • peek_stores

    Quiet first hop. Call ONCE when shopping-adjacent: «найди», «подбери», «сравни», «поищи», «что есть», «посмотри в AgentPay», «актуальная цена», «есть в наличии», «сколько стоит сейчас». Pass need (витамины, техника, протеин). Returns matched stores + sayToUserRu. Speak that one sentence. Do NOT list SKUs, prices, or a catalog. Do NOT call search_products until the owner agrees to look. Never call for advice or rumination («какие витамины попить», «стоит ли креатин», hypotheticals). Those stay chat-only, no AgentPay tools. If unmatched, say so once and stop pushing. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • search_products

    Search products in allowlisted AgentPay stores. If the owner explicitly asks «что вообще есть», «покажи ассортимент», «ассортимент по ремонту» or asks what the catalog is for, set catalogOverview=true and SHOW the returned catalogOverviewRu in chat; this is an explicit browse request, so the normal two-name quiet limit does not apply. For «демо-каталог» or test shops also set demoOnly=true; discuss only returned demo stores and never mention Dixy/Ozerki unless the owner asks. If this is the Ozerki MCP profile, ALWAYS call this tool for «подбери», «найди», «что есть/какой ассортимент в Озерках», price, stock, medicine, pharmacy or vitamin requests; use ordinary web search only after an explicit MCP/API failure. Ozerki geography is progressive: no city or region from the owner means the global.xml feed (omit location and regionId); a named city/region means pass location and the server resolves the matching regional feed; a metro/street/district means use the candidates only to choose go

  • get_product

    Get one ProductCard by product_id + store_id from an allowlisted store. Public/demo catalog needs no authorization. For live stock and price on the owner's allowlist, connect only if the owner asks for personal/live data: begin_agent_link → poll_agent_link, then call again. Returns merchant-synced price, inStock, imageUrls, sku, description, catalogSyncedAt, priceSource (feed|live). Always includes an attributed url, AgentPay trackedUrl, and pick (whyRu + steps + settings). Whenever you give the owner a merchant product link, use trackedUrl, never reconstruct or replace it with url. Pass q as the owner's search phrase so pick explains this sku against that query. Call to confirm price and stock before create_purchase. Never quote price from memory. Triggers: «актуальная цена», «есть в наличии», «сколько стоит сейчас», «не выдумывай цену». If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the own

  • present_choices

    Create a comparison page (choice board, 2–4 options with pros/cons). MANDATORY when search_products returns 2+ similar hits or clarifyHint.action is present_choices — call immediately, do not wait for «сравни». For apparel: pass gendered wants (or rely on saved clothingGender); server filters men's/women's so the board must not mix opposite lines. For a basket/recipe: pass kind=bundles and wants[{q}] for EVERY ingredient in one call (server searches each want in category-matched stores only — PC parts → ТехноДвор, phones → ТехноСалон; no Auchan/Fix Price junk). Returns choiceSetId + pageUrl + catalogSearchScopeRu. Share pageUrl in chat ALWAYS. Do NOT hand-pick SKUs from other stores when scope says ТехноДвор only. NEVER substitute a markdown table for this page (especially ChatGPT/Grok: pass canRenderImages=false, tell owner to open pageUrl). Do NOT create_purchase until get_choice_status shows chosen or the owner picks in chat (then pass clarification.confirmed). If AGENTPAY_API_KEY r

  • get_choice_status

    Poll a choice set from present_choices. Returns status draft|chosen and chosenOptionId. Call after present_choices when waiting for the owner, or before create_purchase to attach choiceSetId. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • list_purchases

    List the owner's recent AgentPay purchases (bought statuses only) with line items. Call when the user says «как обычно», «то же самое», «повтори заказ», «что я заказывал», «прошлый раз», or wants to reorder. Returns last plus purchases[]. Use last.items, then search_products or get_product for current price and stock, then create_purchase. If testMode, repeat spend uses gray test coins in test stores. Do not invent a past basket. Do not search the idiom as a product name. If usePastPurchases is false, history is empty. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_partner_purchase_context

    Get the owner's on-demand purchase history from a linked enterprise partner account. Call when the owner asks to use past orders/history/loyalty from a specific partner, or before a repeat/personalized order in an enterprise store. Requires an explicit partner customer link with orders:read; if missing, ask the owner to connect the partner account in AgentPay. Returns only normalized order IDs, dates, item names/SKUs/categories/brands and compact frequency signals; no delivery address, phone, or email. Use this context for product choice, then verify current price/stock with search_products or get_product before create_purchase. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • preview_purchase

    Preview an AgentPay purchase before create_purchase. Call after search_products/get_product and present_choices/clarification, before asking the owner to approve checkout. Returns amount, storeName, itemSummary, needsConfirmation, and reviewOnly. This does not debit coins and does not place an order. Show this preview to the owner and wait for explicit approval via MCP elicitation/cabinet/Telegram before create_purchase. For Dixy this is only AgentPay-side preview; real Dixy checkout still requires Dixy-specific live-cart/checkout integration. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • check_dixy_live_cart

    Dixy-only live basket resolver. Pass item queries plus optional preferred external catalog ids. The server searches the selected shop's official JSON catalog, checks stock and resolves internal basket ids before adding. Never brute-force ids with cart mutations; bskState del/limit describes UI buttons, not availability. Preserve resolvedItems and quantities. Troubleshoot unresolved items using close alternatives inside MCP; ask before material substitutions, not before routine checks. Respect demoScope when returned: only that shop and approved demo address are supported. Never ask the owner to shop manually or send a phone/SMS in chat. Recover dixySessionId through start_dixy_call_auth, and share openUrl only if returned. Reuse linked sessions without SMS upgrades. This does not create an order or pay. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or rec

  • start_dixy_call_auth

    Create or recover the secure Dixy sign-in. Call when current prices, a money budget, live availability, cart or checkout is needed. If this MCP already has a completed Dixy link, the tool returns linked=true and reuses it without another call. Set forceNew=true only after the server explicitly returned DIXY_REAUTH_REQUIRED or DIXY_WEB_SESSION_REQUIRED for that recovered session. It takes no phone number. When openUrl is returned, share it immediately: the owner enters the phone and confirms the Dixy call on that page, so the phone never enters chat or model context. Never ask the owner to type or approve a phone number in chat. Then poll_dixy_call_auth with linkSessionId. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • poll_dixy_call_auth

    Poll the secure Dixy sign-in link after the owner completes it in the browser. Prefer linkSessionId from start_dixy_call_auth; attemptId and sessionId are accepted aliases for MCP hosts that rename opaque IDs. If linked, pass partner_session_id as dixySessionId to live-cart/checkout tools. Repeating this poll is safe and must not trigger another phone call. Never ask for a phone number in chat and never request a separate platform authorization. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • prepare_dixy_checkout

    Dixy-only checkout preparation. Call only after check_dixy_live_cart and after the owner has provided/approved delivery address details. Uses the owner's connected Dixy web session to set delivery store/address, add/update cart lines, and return a real Dixy basket preview with totals, delivery fee, kg/pcs quantities, minimum-order signals, and canSubmitOrder. Dixy delivery usually requires a 1000 RUB minimum order; if preview is below the minimum or blockOrder/isDisallow is true, tell the owner how much is missing and offer to add promos, favorites, frequent goods, or analogs. If the response errors with DIXY_CART_NOT_EMPTY, ask the owner whether to clear the existing Dixy basket; retry with clearExistingCart:true only after explicit approval. If order creation later returns action=showAuth / DIXY_REAUTH_REQUIRED, use the fresh openUrl and linkSessionId included in that same error; call start_dixy_call_auth(forceNew:true) only if the recovery link is absent. Never ask for a phone numbe

  • get_ozerki_pickup_options

    Ozerki pickup-point resolver for multi-brand Ozerki-network pharmacies. MUST be called before handoff when the owner asks for pickup near a place or has no exact delivery address. An exact address is NOT required for pickup: pass the intended goodsId basket (include each product name so missingItems are human-readable) and near with at least city + metro/street/district (for example 'метро Белорусская, Москва'), or lat/lon. A city name alone only selects a region and MUST NOT be treated as the user's location; the tool returns NEED_PICKUP_LANDMARK instead of pharmacies measured from an arbitrary city center. If neither landmark nor coordinates are known, ask one short question for city and metro/street/district; do not build a basket yet. Returns distanceBasis, complete-basket options, nearbyIncompleteOptions with missing items, exact inStock counts, lowStockItems, distanceAssessment, and—when complete pickup is far—deliveryPreview. Always quote inStock for the relevant items. If stock

  • prepare_ozerki_handoff

    Ozerki-only availability preflight and tracked basket handoff. Call only after fulfillment is agreed with the owner. For pickup, first call get_ozerki_pickup_options with the intended basket and the owner's landmark, present nearby complete-basket pharmacies, obtain an explicit choice, and pass that storeId; storeId is mandatory for pickup. Never leave pharmacy selection for the owner after handoff. This tool selects the agreed pharmacy, checks exact goodsId + quantity and payment compatibility there, then returns handoffUrl: normally a tracked extCart link that imports directly into the ordinary Ozerki basket. Warn that extCart merges with any existing basket and the owner must check the final contents. If direct import fails, use fallbackUrl, a tracked shared-cart link. Neither link persists store selection, so name the already-checked address and say Ozerki may ask to confirm it again. This does NOT create the final Ozerki order and does NOT pay. If a line status is available_darkst

  • create_purchase

    Requires the owner's connection: if there is no session, call begin_agent_link and poll_agent_link first. Without it refuse and start browser connect — do not pretend the order went through. Propose or place an order in an allowlisted store using AgentPay coins. Cursor/Claude Code with MCP elicitation: server shows a button «Оформить · N коинов» — do NOT ask «да/нет» in chat; the button is the owner's payment approval for orders above confirmAbove. Without elicitation the server falls back to awaiting_confirmation + cabinet/Telegram HITL. If testMode, spend only gray test coins in test stores. If the owner asks for a surprise («сюрприз», «на удачу», «порадуй», «покупка на удачу») and get_spending_policy.allowLuckyPurchases is true, pass lucky:true, pick the SKU yourself in the allowlist, skip present_choices, stay within luckyPurchaseMaxCoins. If clarifyHint required present_choices/ask_one and lucky is not set, you MUST pass choiceSetId (chosen) or clarification:{confirmed:true,answer

  • get_purchase_status

    Get purchase status by id. Returns paid (boolean) and payment.status (succeeded/pending/failed). Call after create_purchase or when the user asks «где заказ», «статус покупки», «прошла ли оплата». If you do not have purchase_id, call list_purchases first. If pending, wait. If failed, do not retry payment. Chat «ок» is not proof of payment. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_payment_status

    Check whether the last top-up/payment succeeded. Call after create_topup_intent, after a failed purchase, or when the user asks «оплата прошла», «списали карту». Returns paid, payment.status, latest topups, autoTopup.usedToday/remainingToday (max 3 auto-topups per day). If status is pending or succeeded, do not create another payment. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • create_topup_intent

    Ask the owner to top up coins (opens YooKassa or cabinet). Call on INSUFFICIENT_FUNDS when auto-topup did not cover the purchase. Never take a card in chat. Never enable auto-topup yourself. Reuses today's pending payment for the same amount — do not hammer retries. If get_payment_status shows pending, wait instead of calling again. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • set_test_mode

    Turn AgentPay test mode on or off. Call when the owner says «выключи тестовый режим», «включи тестовый режим», «хочу в настоящие магазины», or after a real top-up when they agree to leave the sandbox. This is the only *policy* setting the agent may change. Owner-provided home address is saved via save_delivery_address. After a real wallet top-up, suggest turning test mode off. While enabled: spend only gray test coins in test stores. While disabled: hide test stores and spend real coins. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_agent_skills

    Fetch AgentPay skills index (skills.json) and install hints for Cursor, Claude Code, ChatGPT. Call at session start when the user shops in Russia, after verify_connection, or when they ask «как подключить skill», «скачай skill», «используй skill AgentPay». Returns skillUrl links — Cursor/Claude agents MUST fetch and follow the public shopping-ru SKILL.md (or store-specific skill from preferredStoreSkills). After browser Разрешить, fetch personal skill-bundle via GET /agent-link/{sessionId}/skill-bundle. Never improvise catalog rules when a skill URL is returned. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • get_faq

    Look up AgentPay operational FAQ before guessing. Call when the owner asks why a SKU looks wrong, why a photo is missing, why search is empty, why coins stuck, returns, delivery data, MCP connect, or «FAQ», «почему фото», «не работает картинка», «почему такой товар». Returns sayToUserRu, side (agentpay vs merchant), and the contact to give the owner. Do not invent a reason. Do not hide whose side it is. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.

  • request_user_confirmation

    Ask the human to confirm in AgentPay web or Telegram. Call when the user must approve a spend, freeze, or missing delivery data. Triggers: «спроси меня», «подтверди», HITL. Do not treat chat 'ok' as payment approval — cabinet/Telegram is source of truth. If AGENTPAY_API_KEY required and you already have sessionId from this chat: pass sessionId and retry. Never begin_agent_link again. Never ask the owner to edit connector settings or reconnect. Never web-search.