
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@krystiangw/zen-mcp
Advanced tools
Unofficial MCP server for the ZEN.com Payment Gateway (payment links, transactions, refunds, payouts, reporting).
An MCP server that lets AI assistants work with the ZEN.com Payment Gateway: hosted payment links, transaction lookup, refunds, payouts, and reporting.
Unofficial. This project is not affiliated with, endorsed by, or maintained by ZEN.com.
Read-only tools:
Write tools:
This integration was built from public ZEN documentation without access to a live merchant account. Endpoint versions, request fields, response fields, signing details, and webhook behavior must be checked against ZEN's current OpenAPI or Postman collection before production use. Mock mode is included for evaluation without an account.
Add the published package to Claude Code:
claude mcp add zen --env ZEN_API_KEY=your_terminal_api_key -- npx -y @krystiangw/zen-mcp
For Claude Desktop, add this entry to its MCP configuration:
{
"mcpServers": {
"zen": {
"command": "npx",
"args": ["-y", "@krystiangw/zen-mcp"],
"env": {
"ZEN_API_KEY": "your_terminal_api_key",
"ZEN_PAYWALL_SECRET": "your_paywall_secret",
"ZEN_IPN_SECRET": "your_ipn_secret",
"ZEN_ENV": "sandbox"
}
}
}
}
| Variable | Required | Description |
|---|---|---|
ZEN_API_KEY | Outside mock mode | Terminal API Key sent in Authorization without a Bearer prefix |
ZEN_PAYWALL_SECRET | Write operations | Checkout/paywall secret used to sign request bodies |
ZEN_IPN_SECRET | Webhook verification | IPN secret used only by verify_webhook_signature |
ZEN_ENV | No | sandbox (default) or production |
ZEN_BASE_URL | No | API base URL override; takes priority over ZEN_ENV |
ZEN_MOCK | No | 1 or true enables deterministic offline responses |
ZEN_HASH_ALG | No | sha224, sha256 (default), sha384, or sha512 |
In the ZEN merchant panel, go to my.zen.com → Shop settings → Terminal to find the Terminal API Key. Use sandbox first; the default API host is api.zen-test.com, although sandbox availability and onboarding requirements should be confirmed with ZEN.
No merchant account yet? You can open a ZEN business account. That is a referral link: it credits the author of this project if you sign up through it, and costs you nothing. Every other link in this README is a plain one.
| Name | Type | Description |
|---|---|---|
list_payment_methods | Read | List payment methods for the terminal |
get_transaction | Read | Get a transaction by ZEN or merchant ID |
list_payment_links | Read | List hosted payment links |
get_payment_link | Read | Get one hosted payment link |
get_payout | Read | Get a payout by ZEN ID |
download_report | Read | Request a report download |
list_supported_currencies | Read | List documented supported currencies |
verify_webhook_signature | Read | Verify a ZEN IPN signature locally |
create_payment_link | Write | Create a hosted checkout link and QR code |
refund_transaction | Write, destructive | Issue a full or partial refund |
capture_transaction | Write, destructive | Capture an authorized transaction |
cancel_transaction | Write, destructive | Cancel a transaction |
create_payout | Write, destructive | Send an outbound payout |
create_customer | Write | Create a customer record |
ZEN_IPN_SECRET before trusting its contents.Run the server with deterministic canned API responses:
ZEN_MOCK=1 ZEN_IPN_SECRET=demo npx -y @krystiangw/zen-mcp
verify_webhook_signature does real cryptography instead of calling the API, so it needs a secret even in mock mode. Any value works for a demo.
From a development checkout:
npm install
npm run build
ZEN_MOCK=1 ZEN_IPN_SECRET=demo npm run inspect
Requires Node.js 18 or newer.
npm install
npm run typecheck
npm run build
npm test
ZEN_MOCK=1 ZEN_IPN_SECRET=demo npm run inspect
FAQs
Unofficial MCP server for the ZEN.com Payment Gateway (payment links, transactions, refunds, payouts, reporting).
The npm package @krystiangw/zen-mcp receives a total of 19 weekly downloads. As such, @krystiangw/zen-mcp popularity was classified as not popular.
We found that @krystiangw/zen-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.