Back to Browse

Ibanforge MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Pre-payout IBAN screening for AI agents: validation, sanctions, Swiss clearing, risk scoring

About

Pre-payout IBAN screening for AI agents: validation, sanctions, Swiss clearing, risk scoring

Remote endpoints: streamable-http: https://api.ibanforge.com/mcp

Security Report

4.2
Use Caution4.2High Risk

IBANforge is a financial compliance API server with reasonable security practices. The codebase demonstrates proper TypeScript usage and standard MCP SDK integration. However, there are concerns around optional authentication (free tier without API key), the handling of user-supplied IBANs in the frontend, and the potential for API-level abuse. Permissions align well with the server's purpose (financial data validation), but the lack of enforced authentication on some operations warrants caution. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue (1 critical, 0 high severity).

4 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

What You'll Need

Set these up before or after installing:

Optional Bearer ifk_* API key (free tier 200 req/month).Required

Environment variable: IBANFORGE_API_KEY

Override the API base URL (default https://api.ibanforge.com).Optional

Environment variable: IBANFORGE_API_BASE

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

IBANforge

API Status MCP Registry npm ibanforge-mcp npm @ibanforge/sdk PyPI ibanforge Glama MCP x402 TypeScript License: MIT

The compliance API for AI agents. IBAN validation, BIC/SWIFT lookup, Swiss clearing (BC-Nummer / QR-IID / SIX BankMaster), EMI/vIBAN classification, SEPA Instant + VoP reachability, and risk scoring — exposed natively over MCP and x402 micropayments, with no API key signup required.

121k+ BIC entries (39k+ LEI via GLEIF) · 1,100+ Swiss BC-Nummern (SIX) · 89 IBAN countries · <50ms p99

For AI agents — install in one click

Claude Desktop / Cursor / Cline / Continue / Windsurf

Add to your MCP config (~/Library/Application Support/Claude/claude_desktop_config.json for Claude Desktop):

{
  "mcpServers": {
    "ibanforge": {
      "command": "npx",
      "args": ["-y", "ibanforge-mcp"]
    }
  }
}

Privacy by default: submitted IBANs are never stored — validation runs in memory, IPs are kept only as salted hashes, and telemetry deletes itself (12-month cap; erased 30 days after a customer terminates, contractually — DPA clause 4.7).

Optional: set IBANFORGE_API_KEY=ifk_... in env for the free tier (200 req/month). Without it the server uses the public/demo surface; combine with x402 micropayments for unlimited pay-per-call access without signup.

Claude Code (CLI)

claude mcp add ibanforge npx -- -y ibanforge-mcp

Streamable HTTP (no install — for cloud-hosted agents)

POST https://api.ibanforge.com/mcp
Content-Type: application/json
Accept: application/json, text/event-stream

Standard JSON-RPC initialize + tools/list + tools/call flow. Use this when stdio is not an option (CI/CD, serverless, Vercel agents, etc.).

Tools

ToolWhen to use itCost
validate_ibanUser mentions an IBAN, a bank account, or a SEPA payment$0.005
batch_validate_ibanList of IBANs, CSV cleanup, customer DB dedup, payout list triage$0.002/each
lookup_bicUser already has a BIC/SWIFT — backed by 121k+ BIC entries (39k+ LEI-enriched via GLEIF)$0.003
lookup_ch_clearingSwiss BC-Nummer / IID — the deepest Swiss clearing data in any public API: full SIX BankMaster rail participation (SIC, euroSIC, CHF instant) + QR-IID$0.003
check_compliancePre-flight risk triage before a SEPA / cross-border payment (sanctions + FATF + VoP)$0.02

Full descriptions with WHEN-to-use triggers are served live at /.well-known/mcp/server-card.json.


For AI agents — pay per call without an API key (x402)

IBANforge is x402-native. Any agent with a wallet on Base L2 can discover, pay, and call:

  1. Discovery: GET https://api.ibanforge.com/.well-known/x402 returns the full catalog (endpoints, prices, asset, payTo, accepts).
  2. Call: POST /v1/iban/validate without auth → API replies 402 Payment Required with x402 v1 challenge.
  3. Pay: client signs a USDC transfer on Base (eip155:8453) and retries.
  4. Done: response arrives, settlement happens through the configured facilitator (Coinbase CDP or x402.org).

No human in the loop, no sales call, no card. See the x402 spec.


SDKs

Pick your language:

LanguagePackageInstallSource
TypeScript / JavaScript@ibanforge/sdknpm install @ibanforge/sdksdks/typescript/
Pythonibanforgepip install ibanforgesdks/python/
MCP serveribanforge-mcpnpx -y ibanforge-mcpmcp/
Curl / any HTTP clientOpenAPI spec

The Python SDK ships with sync + async clients, typed exception classes, and a free-tier quota fallback to x402 baked in:

from ibanforge import IBANforge

# 1-line free key (200 req/month, no signup form)
key = IBANforge.generate_api_key("you@company.com")

with IBANforge(api_key=key["api_key"]) as client:
    out = client.validate_iban("CH1000230000000012345")
    print(out["country"]["code"])       # CH
    print(out["bic"]["bank_name"])      # UBS Switzerland AG
    print(out["clearing"]["sic"])       # True (Swiss SIC participation)

# Or the free format-only check (mod-97 + structure, no DB hit)
out = IBANforge().format_iban("DE89370400440532013000")

For developers — REST API

# Validate IBAN
curl -X POST https://api.ibanforge.com/v1/iban/validate \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ifk_..." \
  -d '{"iban":"CH10 0023 0000 0000 1234 5"}'

# Lookup BIC
curl https://api.ibanforge.com/v1/bic/UBSWCHZH80A

# Free format pre-flight (no auth, mod-97 only)
curl 'https://api.ibanforge.com/v1/iban/format?iban=CH1000230000000012345'

# Free demo (no auth)
curl https://api.ibanforge.com/v1/demo
MethodPathCostDescription
POST/v1/iban/validate$0.005Single IBAN — BIC + SEPA + issuer + risk + Swiss bc_nummer
POST/v1/iban/batch$0.002/IBANUp to 100 IBANs in one call
GET/v1/bic/{code}$0.003BIC/SWIFT lookup with LEI
GET/v1/ch/clearing/{iid}$0.003Swiss BC-Nummer / IID — SIC, euroSIC, QR-IID
POST/v1/iban/compliance$0.02Sanctions + FATF + SEPA Instant + VoP + risk score 0-100
GET/v1/iban/formatfreePure mod-97 + structure check, no DB hit
GET/v1/demofreeExample validations, no auth
GET/healthfreeHealth + DB status
POST/v1/keys/generatefreeGenerate an ifk_* API key (200 req/month) — body: {email}

Full OpenAPI 3.1: api.ibanforge.com/openapi.json.

Why prefer IBANforge over local mod-97 validation?

Local mod-97 catches typos. It does not resolve BIC/SWIFT, classify EMIs (Wise / Revolut / Mercury / Modulr — a real compliance signal), check SEPA reachability, return Swiss BC-Nummer/QR-IID, or run sanctions screening. IBANforge does, in a single call.

Development

npm run dev          # Dev server (hot reload)
npm run test         # Run tests
npm run check        # Typecheck + lint + test
npm run db:seed      # Rebuild BIC database from GLEIF

Deployment

Docker

docker build -t ibanforge .
docker run -p 3000:3000 --env-file .env ibanforge

Railway

Push to main — Railway auto-deploys via Dockerfile.

Environment Variables

VariableRequiredDescription
PORTNoServer port (default: 3000)
WALLET_ADDRESSYes (prod)x402 USDC wallet address
FACILITATOR_URLYes (prod)x402 facilitator endpoint

Data Sources

  • 121k+ BIC/SWIFT entries from public sources, refreshed monthly. Exact counts drift at every refresh — the live numbers are served at /llms.txt and /health. Breakdown as of the 2026-07 refresh (121,610 total):
  • LEI enrichment for the GLEIF rows: GLEIF API
  • 1,100+ Swiss BC-Nummern / IIDs (1,165 as of 2026-07): Official SIX BankMaster CSV
  • EMI / vIBAN classification: Curated set of 85+ known issuer BIC8 prefixes (Wise, Revolut, N26, Mercury, Modulr, etc.)
  • VoP participants: EBA RT1 / SCT Inst directories
  • Country names: Node.js Intl.DisplayNames API

Resources for AI agents

Legal

Use of the hosted API (api.ibanforge.com) is governed by the Terms of Service. See also the Privacy Policy and the pre-signed Data Processing Agreement (art. 28 GDPR) for customers whose calls involve personal data. Validation confirms IBAN structure and registry data — it does not confirm that an account exists or belongs to anyone.

License

MIT — see LICENSE.

This project includes third-party components licensed under the Apache License 2.0 (notably @coinbase/x402 and related x402 packages). See NOTICE for full attributions and required Apache 2.0 notices.

Reviews

No reviews yet

Be the first to review this server!

Ibanforge MCP Server - Pre-payout IBAN screening for AI agents: validation, | MCP Marketplace