
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
@codespar/mcp-kushki
Advanced tools
MCP server for Kushki — omnichannel LATAM PSP: card charges, preauth/capture, PSE/SPEI transfer-in, cash, subscriptions
MCP server for Kushki — the omnichannel PSP spanning Mexico, Colombia, Chile, Peru and Ecuador: card tokenization + one-step/two-step charges, bank transfer-in (PSE / SPEI), cash networks and subscriptions, all on one REST API.
Add to ~/.config/claude/claude_desktop_config.json:
{
"mcpServers": {
"kushki": {
"command": "npx",
"args": ["-y", "@codespar/mcp-kushki"],
"env": {
"KUSHKI_PUBLIC_MERCHANT_ID": "your-public-merchant-id",
"KUSHKI_PRIVATE_MERCHANT_ID": "your-private-merchant-id",
"KUSHKI_ENV": "sandbox"
}
}
}
}
claude mcp add kushki --env KUSHKI_PUBLIC_MERCHANT_ID=... --env KUSHKI_PRIVATE_MERCHANT_ID=... -- npx -y @codespar/mcp-kushki
Add the same block to .cursor/mcp.json or .vscode/mcp.json.
| Tool | Endpoint | What it does |
|---|---|---|
tokenize_card | POST /card/v1/tokens | Raw card → single-use token (public id) |
create_charge | POST /card/v1/charges | One-step card charge |
create_preauthorization | POST /card/v1/preAuthorization | Hold funds (two-step, step 1) |
capture_preauthorization | POST /card/v1/capture | Capture a preauth (step 2, partial OK) |
void_charge | DELETE /card/v1/charges/{ticket} | Void (same-day) or refund (settled) |
create_transfer_token | POST /transfer/v1/tokens | Token for PSE (CO) / SPEI (MX) transfer-in |
create_transfer_charge | POST /transfer/v1/init | Start the bank transfer; returns redirect URL |
create_cash_charge | POST /cash/v1/charges | Cash voucher for OXXO-style networks |
create_subscription | POST /card/v1/subscriptions | Recurring card charge on a periodicity |
cancel_subscription | DELETE /card/v1/subscriptions/{id} | Stop future charges |
Two merchant ids with distinct powers:
| Variable | Required | Description |
|---|---|---|
KUSHKI_PUBLIC_MERCHANT_ID | yes | Tokenization only — safe for client-side use |
KUSHKI_PRIVATE_MERCHANT_ID | yes | Money movement — server-side only |
KUSHKI_ENV | no | sandbox (api-uat, default) or production |
Amounts use Kushki's per-country tax shape: { subtotalIva, subtotalIva0, iva, currency } — currencies MXN, COP, CLP, PEN, USD.
"Tokenize this test card and charge COP 85,000 with 19% IVA."
The agent calls tokenize_card, then create_charge with { subtotalIva: 85000, subtotalIva0: 0, iva: 16150, currency: "COP" }.
Need governance, budget limits, and audit trails for agent payments? CodeSpar Enterprise adds policy engine, payment routing, and compliance templates on top of these MCP servers.
This open-source server calls Kushki's API directly with your credentials. CodeSpar's managed tier routes one interface across every LATAM provider with automatic failover, governance, audit and a credential vault: codespar.dev/agents.
MIT
FAQs
MCP server for Kushki — omnichannel LATAM PSP: card charges, preauth/capture, PSE/SPEI transfer-in, cash, subscriptions
We found that @codespar/mcp-kushki demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.