Basis Theory MCP by usefulapi
Read token metadata, applications, audit logs, proxies and usage in the PCI vault.
- 1.11.1
- Version
- remote
- Transport
- 17
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 17 tools scanned
- metadata: scanned
No findings.
Tools (17)
basis_theory_list_tokens
List vault tokens as METADATA — id, type, container, fingerprint, metadata and timestamps. Does not return the underlying card number or PII. Basis Theory: GET /v2/tokens.
basis_theory_search_tokens
Search tokens with Basis Theory's query syntax over metadata, e.g. metadata.customer_id:"cus_1". Returns metadata only. Read-only despite being a POST — the query goes in the body. Basis Theory: POST /v2/tokens/search.
basis_theory_get_token
Fetch a single token by id. Returns metadata, container, fingerprint and timestamps. WARNING: if the configured API key carries a reveal permission, the response also contains the token's plaintext data — issue this server a read-only management key instead. Basis Theory: GET /tokens/{id}.
basis_theory_list_applications
List the applications (API-key holders) in the tenant, with their types and permissions. Basis Theory: GET /applications.
basis_theory_get_application
Fetch a single application with its type and permission list. Basis Theory: GET /applications/{id}.
basis_theory_whoami
Return the application the configured BT-API-KEY belongs to — the fastest way to check which permissions this server actually has. Basis Theory: GET /applications/key.
basis_theory_list_logs
List audit-log entries — who did what to which entity and when. The tool for answering 'who touched this token?'. Basis Theory: GET /logs.
basis_theory_list_log_entity_types
List the entity types the audit log records — the valid values for entity_type. Basis Theory: GET /logs/entity-types.
basis_theory_list_proxies
List the proxies that forward requests to third parties, detokenizing in flight. Basis Theory: GET /proxies.
basis_theory_get_proxy
Fetch a single proxy with its destination URL and transform configuration. Basis Theory: GET /proxies/{id}.
basis_theory_list_reactors
List reactors — the serverless functions that run against detokenized data inside the vault. Basis Theory: GET /reactors.
basis_theory_get_reactor
Fetch a single reactor with its configuration. Basis Theory: GET /reactors/{id}.
basis_theory_list_permissions
List the permissions that can be granted to an application, optionally for one application type. Basis Theory: GET /permissions.
basis_theory_list_roles
List the roles available for tenant members. Basis Theory: GET /roles.
basis_theory_get_tenant
Fetch the current tenant — name, id and settings. Basis Theory: GET /tenants/self.
basis_theory_get_tenant_usage
Fetch the tenant's usage report — token counts by type and container, and monthly API call volume. Basis Theory: GET /tenants/self/reports/usage.
basis_theory_list_tenant_members
List the people with access to the tenant, and their roles. Basis Theory: GET /tenants/self/members.