Servidor MCP

IMBA Agent Spend

com.imbawallet/agent
Comercio y retail Cripto y Web3 Pagos y fintech Público y accesible MCP 2025-11-25

Qué hace este MCP

Manages USDT TRC-20 deposits and enables purchases of prepaid cards, eSIMs, gift cards, and crypto address screening.

create_card
Buy a virtual card
Issue a Visa/MasterCard prepaid from this agent 2401 USDT so the agent can pay merchants that require a card (airlines, hotels, SaaS, datacenter/GPU clouds). POST /api/pin/create_card. ext_id required. imba_product_id is core.card_product.id. Never payment_source=stars. Never pass client_id. IMBA does not create the booking.
Destructivo Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['imba_product_id', 'ext_id'], 'properties': {'email': {'type': 'string', 'maxLength': 254, 'description': 'Cardholder KYC email, not the agent 3DS mailbox.'}, 'phone': {'type': 'string', 'maxLength': 32}, 'ext_id': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Idempotency key. Reuse the same id to retry the same order.'}, 'country': {'type': 'string', 'maxLength': 8}, 'last_name': {'type': 'string', 'maxLength': 64}, 'birth_date': {'type': 'string', 'maxLength': 32}, 'first_name': {'type': 'string', 'maxLength': 64}, 'imba_product_id': {'type': 'integer', 'maximum': 9007199254740991, 'exclusiveMinimum': 0}}}
get_balance
Ledger 2401 balance
GET /api/balance. USDT is the spendable catalog currency.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', 'properties': {}}
get_card_details
Card payment credentials
POST /api/pin/get_card_details for a card this agent owns. Needed to present PAN at merchant checkout (airline, datacenter, SaaS). PAN/CVV arrive as card_encrypted JWE when jwe_public_key is registered (PATCH webhook). Without that key the number is masked. Never logs raw PAN. cvv defaults true. Never pass client_id.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['card_id'], 'properties': {'cvv': {'type': 'boolean'}, 'card_id': {'type': 'string', 'maxLength': 256, 'minLength': 1}}}
get_deposit_address
USDT TRC-20 deposit address
POST /api/deposit_address blockchain=tron. Address is issued for the authenticated agent only. Always re-fetch before send. Do not cache. USDT TRC-20 only. 24h unfunded hold.
Esquema de entrada
{'type': 'object', 'properties': {}}
get_spend_policy
Spend policy
Forbidden rails and tier rules. Allowed catalog: Visa prepaid, travel eSIM, gift cards, paid KYT address screen. Read-only.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', 'properties': {}}
kyt_check
Paid KYT check
Screen a crypto address for dirt (sanctions / mixer exposure). Use BEFORE you accept a TRC-20 send, or AFTER a wallet is blocked and the reason is unclear. POST /api/kyt_check. Body: network (tron_usdt | eth | btc) + address. Debits ~0.99 USDT from 2401. Returns a report — does not gate deposit, does not ban or unblock. TON is not in this catalog. Never pass client_id. Space ~1s.
Destructivo
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['network', 'address'], 'properties': {'address': {'type': 'string', 'maxLength': 128, 'minLength': 8}, 'network': {'type': 'string', 'maxLength': 32, 'minLength': 2}, 'refresh': {'type': 'boolean'}}}
kyt_check_get
KYT check by id
POST /api/kyt_check_get. Poll until the report is ready. Own check only (404 otherwise). Use after kyt_check when a wallet was blocked and you need the dirt report. Never pass client_id.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['id'], 'properties': {'id': {'type': 'integer', 'maximum': 9007199254740991, 'exclusiveMinimum': 0}}}
kyt_checks
KYT history
POST /api/kyt_checks. Own KYT history plus quote fields. Use to find a past address check. Space ~1s. Never pass client_id.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 100, 'minimum': 1}, 'last_id': {'type': 'integer', 'maximum': 9007199254740991, 'exclusiveMinimum': 0}}}
kyt_quote
KYT price
POST /api/kyt_quote. Price for a paid crypto-address screen (Didit). Debit is on kyt_check (~0.99 USDT from 2401), not on quote. Off unless didit.enabled and didit.agent_api. Does not gate TRON deposit. Not /api/client/kyt_* and not partner. Space ~1s.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', 'properties': {}}
list_card_products
List card products
POST /api/card_products. Use id as imba_product_id for create_card (Visa prepaid). Space catalog calls ~1s apart.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', 'properties': {}}
list_cards
List cards
POST /api/cards for the authenticated agent. No client_id argument.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', 'properties': {}}
list_esim_plans
List eSIM plans
POST /api/esim/plans. Travel/data eSIM. esim_provider=yesim. Optional country ISO2. Use plan id with purchase_esim. Space catalog calls ~1s apart (agent catalog_gap).
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'country': {'type': 'string', 'maxLength': 8}, 'esim_provider': {'type': 'string', 'maxLength': 32}}}
list_gift_offers
List gift offers
POST /api/offers. Live gift catalog (~20k positions / ~2k unique: Apple, Google Play, Steam, games, travel, retail). Optional query string. Then purchase_gift with offer_id + ext_id. Space catalog calls ~1s apart. Do not assume a SKU.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'query': {'type': 'string', 'maxLength': 64}}}
list_notifications
Inbox and 3DS OTP
POST /api/notifications. Poll this when a Visa payment asks for 3-D Secure. Agents keep payload.code (never SMS, never Telegram). category=codes for 3-D Secure OTP. Also delivered on webhook field otp if callback_url is set, and optional email. Space catalog calls ~1s apart.
Solo lectura Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'limit': {'type': 'integer', 'maximum': 100, 'minimum': 1}, 'prev_id': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, 'prev_ts': {'type': 'number'}, 'category': {'enum': ['all', 'codes', 'support', 'tx'], 'type': 'string'}}}
purchase_esim
Buy an eSIM plan
POST /api/esim/new_plan5. Buy a travel/data eSIM plan from this agent 2401. Omit blank/null iccid so SQL takes the new-eSIM path. A set iccid must already belong to this agent. ext_id required. Never Stars.
Destructivo Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['plan_id', 'ext_id'], 'properties': {'iccid': {'type': 'string', 'maxLength': 32}, 'ext_id': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'plan_id': {'type': 'string', 'maxLength': 64, 'minLength': 1}, 'payment_source': {'type': 'string', 'maxLength': 32}}}
purchase_gift
Buy a gift card
POST /api/purchase. Buy a brand gift code (Apple, Steam, Google Play, … — live list). ext_id required. Never payment_source=stars.
Destructivo Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['offer_id', 'ext_id'], 'properties': {'ext_id': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'offer_id': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'expected_price': {'type': 'object', 'propertyNames': {'type': 'string', 'maxLength': 32}, 'additionalProperties': {'type': 'number'}}, 'payment_source': {'type': 'string', 'maxLength': 32}, 'required_fields': {'type': 'object', 'propertyNames': {'type': 'string', 'maxLength': 64}, 'additionalProperties': {'type': 'string', 'maxLength': 512}}}}
rotate_hmac
Rotate webhook HMAC
POST /auth/v1/agent/hmac/rotate. Previous HMAC dies immediately. Requires an existing callback_url (400 callback_url required before rotate otherwise). Pass callback_url here to PATCH webhook first. Plaintext HMAC is returned once — store it; never a Wallet JWT.
Destructivo
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'email': {'type': 'string', 'maxLength': 254}, 'callback_url': {'type': 'string', 'maxLength': 512}, 'jwe_public_key': {'type': 'string', 'maxLength': 4096}}}
set_webhook
Set callback URL / JWE / OTP email
PATCH /auth/v1/agent/webhook. Sets https callback_url (required before hmac/rotate), optional X25519 jwe_public_key for card_encrypted, optional email for 3DS OTP. Not SMS. HMAC plaintext is shown once when a URL is first accepted.
Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'email': {'type': 'string', 'maxLength': 254}, 'callback_url': {'type': 'string', 'maxLength': 512}, 'jwe_public_key': {'type': 'string', 'maxLength': 4096}}}
topup_card
Top up a card
POST /api/pin/topup_card from this agent 2401 USDT. card_id must belong to the same agent (SQL owner guard). ext_id required. Never Stars.
Destructivo Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['card_id', 'amount', 'ext_id'], 'properties': {'amount': {'type': 'number', 'maximum': 1000000, 'exclusiveMinimum': 0}, 'ext_id': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'card_id': {'type': 'string', 'maxLength': 256, 'minLength': 1}}}
Añadido
kyt_checks
17 de September de 2026 a las 12:35
Añadido
kyt_check_get
17 de September de 2026 a las 12:35
Añadido
kyt_check
17 de September de 2026 a las 12:35
Añadido
kyt_quote
17 de September de 2026 a las 12:35
Añadido
rotate_hmac
17 de September de 2026 a las 12:35
Añadido
set_webhook
17 de September de 2026 a las 12:35
Añadido
list_notifications
17 de September de 2026 a las 12:35
Añadido
get_card_details
17 de September de 2026 a las 12:35
Añadido
purchase_esim
17 de September de 2026 a las 12:35
Añadido
purchase_gift
17 de September de 2026 a las 12:35
Añadido
topup_card
17 de September de 2026 a las 12:35
Añadido
create_card
17 de September de 2026 a las 12:35
Añadido
list_esim_plans
17 de September de 2026 a las 12:35
Añadido
list_gift_offers
17 de September de 2026 a las 12:35
Añadido
list_card_products
17 de September de 2026 a las 12:35
Añadido
list_cards
17 de September de 2026 a las 12:35
Añadido
get_balance
17 de September de 2026 a las 12:35
Añadido
get_deposit_address
17 de September de 2026 a las 12:35
Añadido
get_spend_policy
17 de September de 2026 a las 12:35