la.roki/connect

MCPCommunitylive
v1.0.0la.rokiUnknownAktualisiert vor 1 Mon.

Verified ROKI Connect payments contract for coding agents: operations, schemas, validator.

Endpunkt-Statuslive
geprüft vor 8 Tagen · 275 ms
100 % der letzten 5 Prüfungen haben diesen Endpunkt erreicht
Läuft in
ClaudeCursorCopilotChatGPTGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Automatisch aus öffentlichen Quellen indexiert. Vom Entwickler auf Forge noch nicht verifiziert.Diesen Eintrag beanspruchen →
vor 1 Mon.Letzte Aktualisierung
Paket
Autorla.roki
LizenzUnknown
Version1.0.0
Quellemcp-registry
Trust-Status
B
60/100Gut
✓Im Forge-Index gelistet+10/10
—Publisher-Identität verifiziert+0/30
→ Publisher: für diesen Eintrag ist kein Repository hinterlegt, daher kann `forge publish` die Inhaberschaft nicht automatisch prüfen. Nutze oben „Diesen Eintrag beanspruchen“ — Forge prüft diese Fälle von Hand.
—Domain-Verifizierung+0/10
→ Für diesen Eintragstyp derzeit nicht verfügbar — die Domain-Prüfung läuft heute nur für npm-gestützte Pakete, diese Zeile lässt sich hier also noch nicht erreichen, unabhängig davon, was auf der Domain liegt.
✓Prompt-Injection-Scan · sauber+30/30
✓Obfuskations-/Exfiltrations-Scan · sauber+20/20
StatusVon der Community indexiert
PublisherNicht verifiziert
SignaturNicht signiert
Domain—
Herkunft—
AbhängigkeitenNicht auditiert
Tool-Oberfläche19 Tools · keines privilegiert
Sicherheits-Scan✓ Saubervlive · vor 8 TWie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert17. Aug. 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

19 Tools · keines privilegiert
Live am Endpunkt des Anbieters beobachtet8d ago

Aus einem echten MCP-Handshake initialize → tools/list gegen den deklarierten Endpunkt gelesen. Es wurde nie ein Tool aufgerufen — tools/list ist der lesende Introspektionsaufruf, den das Protokoll dafür vorsieht. Es spiegelt wider, was der Server in diesem Moment angeboten hat; ein gehosteter Endpunkt ist an keine Version gebunden und kann sich ohne Ankündigung ändern.

  • https://mcp.roki.la/mcp19 Tools · 275 ms
roki_search_docsSearch the official ROKI Connect corpus (integration guide, API operations and schemas) and return ranked excerpts. Use this first when you need any ROKI-specific fact. Never answer a ROKI question from memory or from another payment gateway's conventions.

Search the official ROKI Connect corpus (integration guide, API operations and schemas) and return ranked excerpts. Use this first when you need any ROKI-specific fact. Never answer a ROKI question from memory or from another payment gateway's conventions.

ParameterTypBeschreibung
query*stringWhat you need to know, e.g. "webhook signature", "tip fields", "idempotency".
limitintegerMaximum results (default 6).
roki_get_doc_sectionReturn the complete text of one section of the integration guide, by number (e.g. "14"), sub-number ("12.1") or title fragment ("webhook").

Return the complete text of one section of the integration guide, by number (e.g. "14"), sub-number ("12.1") or title fragment ("webhook").

ParameterTypBeschreibung
ref*stringSection number, sub-number, or a fragment of its title.
roki_list_operationsList every operation the API actually exposes, plus the operations that are documented as NOT existing. Call this before writing any integration code so you never invent an endpoint.

List every operation the API actually exposes, plus the operations that are documented as NOT existing. Call this before writing any integration code so you never invent an endpoint.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

roki_get_operationFull detail for one operation: method, path, headers, request schema field table, responses, and worked examples.

Full detail for one operation: method, path, headers, request schema field table, responses, and worked examples.

ParameterTypBeschreibung
operation*stringoperationId (e.g. "createPayment"), or "METHOD /path" (e.g. "POST /payments").
roki_get_schemaReturn a fully dereferenced JSON Schema by name (e.g. "PaymentCreateRequest", "Payment", "WebhookEvent"). Use it to know the exact field names, types and constraints.

Return a fully dereferenced JSON Schema by name (e.g. "PaymentCreateRequest", "Payment", "WebhookEvent"). Use it to know the exact field names, types and constraints.

ParameterTypBeschreibung
namestringSchema name. Omit to list all available schemas.
roki_get_errorExplain an HTTP status or an error message returned by the ROKI API: what it means, the likely cause and what to do. Use this instead of guessing when an integration fails.

Explain an HTTP status or an error message returned by the ROKI API: what it means, the likely cause and what to do. Use this instead of guessing when an integration fails.

ParameterTypBeschreibung
error*stringHTTP status ("422"), or a fragment of the message ("Pago no encontrado", "route could not be found", "sandbox").
roki_validate_requestValidate a payload against the official schema WITHOUT sending it, and check the business rules the API enforces. Critical for this API: it ignores unknown fields and returns 201, so a typo produces a misconfigured payment rather than an error. The response names what it dropped in `warnings`, but…

Validate a payload against the official schema WITHOUT sending it, and check the business rules the API enforces. Critical for this API: it ignores unknown fields and returns 201, so a typo produces a misconfigured payment rather than an error. The response names what it dropped in `warnings`, but…

ParameterTypBeschreibung
operation*stringoperationId, e.g. "createPayment".
payload*objectThe JSON request body you intend to send.
roki_check_resultCompare the payment the API returned against the body you sent, and report anything that does not match. Every other check here looks at what you SEND. This one exists for the errors that survive that: the field name was right and the VALUE was wrong. The API answers 201, `warnings` comes back empt…

Compare the payment the API returned against the body you sent, and report anything that does not match. Every other check here looks at what you SEND. This one exists for the errors that survive that: the field name was right and the VALUE was wrong. The API answers 201, `warnings` comes back empt…

ParameterTypBeschreibung
sent*objectThe JSON request body you sent to POST /payments.
received*objectThe payment object the API returned. Paste the response as-is.
roki_get_integration_exampleReturn a complete, runnable integration example for a stack: configuration, API client, checkout flow, webhook handler with signature verification, and polling fallback.

Return a complete, runnable integration example for a stack: configuration, API client, checkout flow, webhook handler with signature verification, and polling fallback.

ParameterTypBeschreibung
stackstringe.g. "laravel", "php", "node", "express", "python", "fastapi". Omit to list what is available.
roki_get_quickstartThe minimum viable integration sequence, end to end, including the manual portal steps a developer cannot skip.

The minimum viable integration sequence, end to end, including the manual portal steps a developer cannot skip.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

roki_get_authentication_guideHow authentication works, how the two environments are selected, where credentials come from, and how to store and rotate them safely.

How authentication works, how the two environments are selected, where credentials come from, and how to store and rotate them safely.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

roki_get_webhook_guideEverything about webhooks: portal registration, event types, payload shape, HMAC signature verification over the raw body, idempotent processing, and the polling fallback.

Everything about webhooks: portal registration, event types, payload shape, HMAC signature verification over the raw body, idempotent processing, and the polling fallback.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

roki_choose_integration_modeDecide how to integrate ROKI Connect for a given project (web checkout, embedded card fields, mobile app, invoices or recurring billing) and get the constraints that apply before writing code. The modes and the endpoints behind them are read from the corpus, so this answer cannot describe a mode th…

Decide how to integrate ROKI Connect for a given project (web checkout, embedded card fields, mobile app, invoices or recurring billing) and get the constraints that apply before writing code. The modes and the endpoints behind them are read from the corpus, so this answer cannot describe a mode th…

ParameterTypBeschreibung
context*stringWhat the project is: e.g. "Laravel e-commerce checkout", "iOS app", "card fields on my own page", "invoices from an ERP", "monthly subscriptions".
roki_verify_webhook_signatureCheck a ROKI-Signature header against the raw body and the signing secret. When it fails, this does not just say "invalid" - it tries the specific wrong constructions developers actually write and tells you which mistake you made. Use it whenever webhook verification rejects real events. On the sig…

Check a ROKI-Signature header against the raw body and the signing secret. When it fails, this does not just say "invalid" - it tries the specific wrong constructions developers actually write and tells you which mistake you made. Use it whenever webhook verification rejects real events. On the sig…

ParameterTypBeschreibung
raw_body*stringThe EXACT raw request body as received, byte for byte, before any JSON parsing.
signature_header*stringThe full ROKI-Signature header value, e.g. "t=1719234300,v1=8f3c..."
signing_secret*stringThe signing secret from the portal, for the same environment as the event. Held in memory for the duration of the call only: this server logs no tool arguments.
roki_scaffold_integrationReturn the full runnable skeleton for a stack: credential storage, API client, checkout flow, webhook handler with signature verification, and the polling fallback. Use it to start an integration instead of assembling one from memory.

Return the full runnable skeleton for a stack: credential storage, API client, checkout flow, webhook handler with signature verification, and the polling fallback. Use it to start an integration instead of assembling one from memory.

ParameterTypBeschreibung
stack*stringe.g. "laravel", "node", "express", "python", "fastapi", "php".
modestring"hosted" (default), "embedded" or "saved-card".
roki_audit_integrationReturn the checklist to audit existing ROKI code, ordered by how badly each item fails in production. Use it when reviewing an integration you did not write, or before going live.

Return the checklist to audit existing ROKI code, ordered by how badly each item fails in production. Use it when reviewing an integration you did not write, or before going live.

ParameterTypBeschreibung
focusstringOptional area: "webhooks", "security", "payments", "reversals".
roki_sandbox_tryRuns a documented operation against the ROKI sandbox using THIS SERVER'S own test credential, and returns the actual response. Use it to prove an integration works instead of assuming it does - especially after roki_validate_request says a payload is valid. You never supply a key: this server hold…

Runs a documented operation against the ROKI sandbox using THIS SERVER'S own test credential, and returns the actual response. Use it to prove an integration works instead of assuming it does - especially after roki_validate_request says a payload is valid. You never supply a key: this server hold…

ParameterTypBeschreibung
operation*stringoperationId to run, e.g. "createPayment", "getPayment", "voidTransaction".
payloadobjectRequest body for POST operations, or path values such as {"id": 123} / {"transaction_id": "uuid"}.
roki_sandbox_infoWhether the sandbox playground is enabled here, which operations it accepts, its limits, and the sandbox test cards.

Whether the sandbox playground is enabled here, which operations it accepts, its limits, and the sandbox test cards.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

roki_statusServer version, corpus contents and freshness. Safe first call to confirm the connection works. Exposes no credentials and no merchant data.

Server version, corpus contents and freshness. Safe first call to confirm the connection works. Exposes no credentials and no merchant data.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

19 von 19 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Verified ROKI Connect payments contract for coding agents: operations, schemas, validator.

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Keine Abdeckung der Abhängigkeiten

Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.