MCP 服务器

Agent Spend Guard — owner-set purchasing guardrails

com.a2awire/agent-spend-guard
支付与金融科技 公开且可连接 MCP 2026-07-28

此 MCP 可以做什么

Evaluates proposed purchases against owner-defined spending rules, records completed transactions, and reports spending and guardrail settings.

spend_guard_check_purchase
Humans: sign up with your email at https://a2awire.com/api-key and create an API key, then hand it to your agent (it sends Authorization: Bearer <key> or X-API-Key with every call). Agents without an account: a reviewable bootstrap script is served at https://a2awire.com/api/v1/connectors/spend-guard/bootstrap.sh (download it, read it, then run it to mint a key). Call BEFORE checkout. Evaluate a proposed purchase (merchant, amount_usd) against the owner's spend rules and recent ledger. Returns a decision (approve, deny, or ask_user), a plain-English reason, the remaining monthly budget when a cap is set, and a check_id. deny means denylisted merchant or over the monthly cap; ask_user means above the per-purchase threshold or a possible duplicate of a purchase in the last 10 minutes. Optional tx_ref is your idempotency key for this purchase; pass the same value to spend_guard_record_purchase afterwards. Appends a check event; checks never consume budget. USD only (the currency argument is kept for forward compatibility; any other value is rejected). Not guest-callable. REST: POST /api/v1/spend-guard/check.
输入模式
{'type': 'object', 'title': 'SpendGuardCheckPurchaseInput', 'required': ['merchant', 'amount_usd'], 'properties': {'tx_ref': {'anyOf': [{'type': 'string', 'maxLength': 200, 'minLength': 1}, {'type': 'null'}], 'title': 'Tx Ref', 'default': None, 'description': 'Optional idempotency key for this purchase; pass the same value to the record call afterwards. Checks are exempt from the uniqueness constraint that applies to recorded purchases.'}, 'category': {'anyOf': [{'type': 'string', 'maxLength': 100}, {'type': 'null'}], 'title': 'Category', 'default': None}, 'currency': {'type': 'string', 'title': 'Currency', 'default': 'USD', 'maxLength': 8, 'description': 'USD only. Kept for forward compatibility; any other value is rejected.'}, 'merchant': {'type': 'string', 'title': 'Merchant', 'maxLength': 200, 'minLength': 1}, 'amount_usd': {'anyOf': [{'type': 'number', 'maximum': 100000.0, 'exclusiveMinimum': 0.0}, {'type': 'string', 'pattern': '^(?!^[-+.]*$)[+-]?0*\\d*\\.?\\d*$'}], 'title': 'Amount Usd'}, 'description': {'anyOf': [{'type': 'string', 'maxLength': 500}, {'type': 'null'}], 'title': 'Description', 'default': None}}, 'description': 'Arguments for ``spend_guard_check_purchase`` (call BEFORE checkout).\n\nThe owner is derived from the authenticated principal, never from the\narguments. ``tx_ref`` is optional here; reuse the same value on\n``spend_guard_record_purchase`` so the check and its record share one\nidempotency key. ``currency`` is USD only; the field is kept for forward\ncompatibility and any other value is rejected.', 'additionalProperties': False}
spend_guard_record_purchase
Humans: sign up with your email at https://a2awire.com/api-key and create an API key, then hand it to your agent (it sends Authorization: Bearer <key> or X-API-Key with every call). Agents without an account: a reviewable bootstrap script is served at https://a2awire.com/api/v1/connectors/spend-guard/bootstrap.sh (download it, read it, then run it to mint a key). Call AFTER checkout. Record a completed purchase in the owner's spend ledger. tx_ref is required and unique per owner: replaying the same tx_ref returns the original record without double counting (recorded_previously is true when the tx_ref was already in your ledger before this call, an idempotent replay; false on first write). Optional check_id links the record to its prior spend_guard_check_purchase; a check_id already recorded returns a conflict error. Returns the recorded event and the month-to-date total. USD only (the currency argument is kept for forward compatibility; any other value is rejected). Not guest-callable. REST: POST /api/v1/spend-guard/record.
幂等
输入模式
{'type': 'object', 'title': 'SpendGuardRecordPurchaseInput', 'required': ['merchant', 'amount_usd', 'tx_ref'], 'properties': {'tx_ref': {'type': 'string', 'title': 'Tx Ref', 'maxLength': 200, 'minLength': 1, 'description': 'Caller idempotency key, unique across your recorded purchases; replays return the original record.'}, 'category': {'anyOf': [{'type': 'string', 'maxLength': 100}, {'type': 'null'}], 'title': 'Category', 'default': None}, 'check_id': {'anyOf': [{'type': 'string', 'format': 'uuid'}, {'type': 'null'}], 'title': 'Check Id', 'default': None, 'description': 'Optional id from spend_guard_check_purchase; at most one record may consume each check.'}, 'currency': {'type': 'string', 'title': 'Currency', 'default': 'USD', 'maxLength': 8, 'description': 'USD only. Kept for forward compatibility; any other value is rejected.'}, 'merchant': {'type': 'string', 'title': 'Merchant', 'maxLength': 200, 'minLength': 1}, 'amount_usd': {'anyOf': [{'type': 'number', 'maximum': 100000.0, 'exclusiveMinimum': 0.0}, {'type': 'string', 'pattern': '^(?!^[-+.]*$)[+-]?0*\\d*\\.?\\d*$'}], 'title': 'Amount Usd'}, 'description': {'anyOf': [{'type': 'string', 'maxLength': 500}, {'type': 'null'}], 'title': 'Description', 'default': None}}, 'description': "Arguments for ``spend_guard_record_purchase`` (call AFTER checkout).\n\n``tx_ref`` is required and unique across your recorded purchases;\n``check_id`` optionally links back to the check that preceded the\npurchase. The response's ``recorded_previously`` is true when this\ntx_ref was already in your ledger before this call (an idempotent\nreplay); false on first write. ``currency`` is USD only; the field is\nkept for forward compatibility and any other value is rejected.", 'additionalProperties': False}
spend_guard_report
Humans: sign up with your email at https://a2awire.com/api-key and create an API key, then hand it to your agent (it sends Authorization: Bearer <key> or X-API-Key with every call). Agents without an account: a reviewable bootstrap script is served at https://a2awire.com/api/v1/connectors/spend-guard/bootstrap.sh (download it, read it, then run it to mint a key). Month-to-date spend summary for the calling owner: total USD recorded, purchase count, top merchants (up to 5), current rules, and remaining monthly budget when a cap is set. Optional month (YYYY-MM) reads a prior month; defaults to the current UTC month. Not guest-callable. REST: GET /api/v1/spend-guard/report.
只读 幂等
输入模式
{'type': 'object', 'title': 'SpendGuardReportInput', 'properties': {'month': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Month', 'default': None, 'description': 'Optional month filter (YYYY-MM); defaults to the current UTC month.'}}, 'description': 'Arguments for ``spend_guard_report`` (no required arguments).', 'additionalProperties': False}
spend_guard_set_rules
Humans: sign up with your email at https://a2awire.com/api-key and create an API key, then hand it to your agent (it sends Authorization: Bearer <key> or X-API-Key with every call). Agents without an account: a reviewable bootstrap script is served at https://a2awire.com/api/v1/connectors/spend-guard/bootstrap.sh (download it, read it, then run it to mint a key). Set the calling owner's spend-guard rules: an optional monthly cap in USD, an optional per-purchase threshold in USD, and an optional exact-match merchant denylist (case-insensitive). Full declaration: omit or null a field to clear that rule. With no rules every check approves (observation mode) and purchases are still recorded. Returns the effective rules. Not guest-callable. REST: PUT /api/v1/spend-guard/rules.
幂等
输入模式
{'type': 'object', 'title': 'SpendGuardSetRulesInput', 'properties': {'monthly_cap_usd': {'anyOf': [{'type': 'number', 'maximum': 100000.0, 'exclusiveMinimum': 0.0}, {'type': 'string', 'pattern': '^(?!^[-+.]*$)[+-]?0*\\d*\\.?\\d*$'}, {'type': 'null'}], 'title': 'Monthly Cap Usd', 'default': None, 'description': 'Cumulative recorded spend per UTC calendar month at or above which checks deny. Null clears the cap.'}, 'merchant_denylist': {'anyOf': [{'type': 'array', 'items': {'type': 'string', 'maxLength': 200, 'minLength': 1}, 'maxItems': 100}, {'type': 'null'}], 'title': 'Merchant Denylist', 'default': None, 'description': 'Exact-match merchant names (case-insensitive) whose purchases are denied, up to 100 entries. Null clears the list.'}, 'per_purchase_threshold_usd': {'anyOf': [{'type': 'number', 'maximum': 100000.0, 'exclusiveMinimum': 0.0}, {'type': 'string', 'pattern': '^(?!^[-+.]*$)[+-]?0*\\d*\\.?\\d*$'}, {'type': 'null'}], 'title': 'Per Purchase Threshold Usd', 'default': None, 'description': 'A single purchase strictly above this amount asks the user first. Null clears the threshold.'}}, 'description': 'Arguments for ``spend_guard_set_rules``.\n\nThe owner is derived from the authenticated principal, never from the\narguments. Full declaration: omit or null a field to clear that rule.', 'additionalProperties': False}
已添加
spend_guard_report
2026年9月24日 02:40
已添加
spend_guard_set_rules
2026年9月24日 02:40
已添加
spend_guard_record_purchase
2026年9月24日 02:40
已添加
spend_guard_check_purchase
2026年9月24日 02:40