Back to Browse

Dev Latam MCP Server

by User
Developer ToolsUse Caution4.2Local
Free

MCP server for Kushki — LATAM PSP: card charges, preauth, PSE/SPEI transfer, cash, subscriptions

About

MCP server for Kushki — LATAM PSP: card charges, preauth, PSE/SPEI transfer, cash, subscriptions

Security Report

4.2
Use Caution4.2High Risk

MCP Dev LATAM is a large, well-structured monorepo of 110+ MCP servers for Latin American commerce and payment APIs. The codebase demonstrates reasonable security practices overall: authentication is required for most tools (API keys, OAuth), permissions align with the Developer Tools category baseline (network_http and env_vars are standard), and the code quality is good. However, two findings warrant attention: (1) the Sift server ships in alpha status with unverified endpoint paths due to gated documentation, creating moderate risk of incorrect API calls, and (2) environment variable handling in several servers lacks explicit validation that required secrets are present before startup, which could lead to silent failures or unexpected behavior. No malicious patterns, data exfiltration, or dangerous code execution vulnerabilities were detected. Supply chain analysis found 2 known vulnerabilities in dependencies (1 critical, 0 high severity). Package verification found 1 issue (1 critical, 0 high severity).

4 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

What You'll Need

Set these up before or after installing:

Kushki public merchant id (card/transfer tokenization)Required

Environment variable: KUSHKI_PUBLIC_MERCHANT_ID

Kushki private merchant id (charges, captures, voids, subscriptions)Required

Environment variable: KUSHKI_PRIVATE_MERCHANT_ID

Environment: 'sandbox' (api-uat) or 'production'. Defaults to 'sandbox'.Optional

Environment variable: KUSHKI_ENV

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-codespar-mcp-kushki": {
      "env": {
        "KUSHKI_ENV": "your-kushki-env-here",
        "KUSHKI_PUBLIC_MERCHANT_ID": "your-kushki-public-merchant-id-here",
        "KUSHKI_PRIVATE_MERCHANT_ID": "your-kushki-private-merchant-id-here"
      },
      "args": [
        "-y",
        "mcp-dev-latam"
      ],
      "command": "npx"
    }
  }
}

Reviews

No reviews yet

Be the first to review this server!

Dev Latam MCP Server - MCP server for Kushki — LATAM PSP: card charges, preauth, | MCP Marketplace