# la.roki/connect

Verified ROKI Connect payments contract for coding agents: operations, schemas, validator.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** la.roki
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.roki.la/mcp
- **Source:** https://mcp.roki.la
- **Endpoint health:** reachable (last checked 2026-09-26T21:35:31.602Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 10 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-26T21:35:31.602Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

19 declared. Observed from a live `tools/list` probe.
- `roki_search_docs` — Search the official ROKI Connect corpus (integration guide, API operations and schemas) and return ranked excerpts. Use this first when you need any ROKI-specif
- `roki_get_doc_section` — Return the complete text of one section of the integration guide, by number (e.g. "14"), sub-number ("12.1") or title fragment ("webhook").
- `roki_list_operations` — List every operation the API actually exposes, plus the operations that are documented as NOT existing. Call this before writing any integration code so you nev
- `roki_get_operation` — Full detail for one operation: method, path, headers, request schema field table, responses, and worked examples.
- `roki_get_schema` — Return a fully dereferenced JSON Schema by name (e.g. "PaymentCreateRequest", "Payment", "WebhookEvent"). Use it to know the exact field names, types and constr
- `roki_get_error` — Explain an HTTP status or an error message returned by the ROKI API: what it means, the likely cause and what to do. Use this instead of guessing when an integr
- `roki_validate_request` — Validate a payload against the official schema WITHOUT sending it, and check the business rules the API enforces. Critical for this API: it ignores unknown fiel
- `roki_check_result` — Compare the payment the API returned against the body you sent, and report anything that does not match. Every other check here looks at what you SEND. This one
- `roki_get_integration_example` — Return a complete, runnable integration example for a stack: configuration, API client, checkout flow, webhook handler with signature verification, and polling 
- `roki_get_quickstart` — The minimum viable integration sequence, end to end, including the manual portal steps a developer cannot skip.
- `roki_get_authentication_guide` — How authentication works, how the two environments are selected, where credentials come from, and how to store and rotate them safely.
- `roki_get_webhook_guide` — Everything about webhooks: portal registration, event types, payload shape, HMAC signature verification over the raw body, idempotent processing, and the pollin
- `roki_choose_integration_mode` — Decide how to integrate ROKI Connect for a given project (web checkout, embedded card fields, mobile app, invoices or recurring billing) and get the constraints
- `roki_verify_webhook_signature` — Check a ROKI-Signature header against the raw body and the signing secret. When it fails, this does not just say "invalid" - it tries the specific wrong constru
- `roki_scaffold_integration` — Return the full runnable skeleton for a stack: credential storage, API client, checkout flow, webhook handler with signature verification, and the polling fallb
- `roki_audit_integration` — Return the checklist to audit existing ROKI code, ordered by how badly each item fails in production. Use it when reviewing an integration you did not write, or
- `roki_sandbox_try` — Runs a documented operation against the ROKI sandbox using THIS SERVER'S own test credential, and returns the actual response. Use it to prove an integration wo
- `roki_sandbox_info` — Whether the sandbox playground is enabled here, which operations it accepts, its limits, and the sandbox test cards.
- `roki_status` — Server version, corpus contents and freshness. Safe first call to confirm the connection works. Exposes no credentials and no merchant data.

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"connect\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.roki.la/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/la.roki%2Fconnect
- Install plan: https://forgeregistry.com/api/v1/packages/la.roki%2Fconnect/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/la.roki%2Fconnect
- HTML page: https://forgeregistry.com/registry/la.roki%2Fconnect
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
