Back to Browse

Dev Latam MCP Server

by User
Developer ToolsUse Caution4.2Local
Free

MCP server for Access Worldpay — enterprise processor: authorize, capture, refund, tokenize

About

MCP server for Access Worldpay — enterprise processor: authorize, capture, refund, tokenize

Security Report

4.2
Use Caution4.2High Risk

This is a monorepo of 109 MCP servers spanning Latin American commerce integrations. The codebase shows good security practices overall: authentication is required across all servers (API keys, OAuth2), environment variables are used for credentials, and permissions align with each server's purpose (network_http for API calls, env_vars for secrets). However, the audit uncovered several concerns: hardcoded API credentials in example/test files, missing input validation in the Sift server, and broad error handling that could leak sensitive data. Additionally, the alpha tier (roughly one-third of servers) ships with unverified endpoint paths due to contract-gated provider portals, creating maintenance risk. These issues are recoverable with fixes to test files and input validation, but prevent a higher score. Supply chain analysis found 2 known vulnerabilities in dependencies (1 critical, 0 high severity). Package verification found 1 issue (1 critical, 0 high severity).

4 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

What You'll Need

Set these up before or after installing:

Access Worldpay API username (Basic Auth)Optional

Environment variable: WORLDPAY_USERNAME

Access Worldpay API password (Basic Auth)Required

Environment variable: WORLDPAY_PASSWORD

Merchant entity identifier assigned during onboarding. Injected as merchant.entity into every request body.Optional

Environment variable: WORLDPAY_ENTITY

sandbox | production. Defaults to sandbox. sandbox -> https://try.access.worldpay.com, production -> https://access.worldpay.com.Optional

Environment variable: WORLDPAY_ENV

Payments API version for the Content-Type/Accept media-type header. Defaults to v7.Optional

Environment variable: WORLDPAY_API_VERSION

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-codespar-mcp-worldpay": {
      "env": {
        "WORLDPAY_ENV": "your-worldpay-env-here",
        "WORLDPAY_ENTITY": "your-worldpay-entity-here",
        "WORLDPAY_PASSWORD": "your-worldpay-password-here",
        "WORLDPAY_USERNAME": "your-worldpay-username-here",
        "WORLDPAY_API_VERSION": "your-worldpay-api-version-here"
      },
      "args": [
        "-y",
        "mcp-dev-latam"
      ],
      "command": "npx"
    }
  }
}

Reviews

No reviews yet

Be the first to review this server!