# monapay-mcp

MCP server cho MONA Pay — để Claude Code / Cursor / Codex tạo QR, tra giao dịch, cấu hình webhook MONA Pay ngay trong lúc code. MONA Pay là API ngân hàng và dịch vụ xác nhận thanh toán tự động của The MONA Group.

- **Type:** MCP server
- **Trust:** 10/100 (F), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.6.2
- **Author:** MONA Software
- **License:** MIT
- **npm:** monapay-mcp
- **Source:** https://github.com/mona-software/monapay-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

10/100 (F), scored on the package rubric
- Publisher verified: no
- Install scripts: not scanned
- Prompt-injection scan: not run
- Obfuscation scan: not run

## Security scan

Not scanned. This is a coverage gap, not a clean result — Forge asserts nothing about this entry's security posture.

## Tools

Tool surface: not scanned yet — tool surface unknown.

## Install

**Verdict: review** — Installable, but 2 things to check first: Forge has not scanned this entry, so nothing is known about its contents either way.
**Cautions** (coverage gaps and advisories — never blocking)
- Forge has not scanned this entry, so nothing is known about its contents either way.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"monapay\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"monapay-mcp\"\n      ],\n      \"env\": {\n        \"MONAPAY_CLIENT_SECRET\": \"<YOUR_MONAPAY_CLIENT_SECRET>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `MONAPAY_CLIENT_SECRET` — Monapay Client Secret (required)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 1 credential (1 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Moderate to critical — not scanned yet — tool surface unknown. Known so far: holds an oauth grant; runs on your machine.
- Floor 23, ceiling 79 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/monapay-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/monapay-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/monapay-mcp
- HTML page: https://forgeregistry.com/registry/monapay-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
