Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Payments Law EU

REMOTE · MCP.PAYMENTSLAW.EU · SCANNED SEP 25

Read-only query service for EU payments legislation: 51 curated instruments, by provision.

+3 this week 78 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability75
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4167 tokens (~277/item across 15 items; 14 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management87
  • Stability observed for 26 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage89
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 63% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 14 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the Payments Law EU MCP server?

Payments Law EU is a hosted endpoint at https://mcp.paymentslaw.eu/mcp/v1, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.paymentslaw.eu

# add to Claude Code
claude mcp add --transport http eu-paymentslaw-legislation 'https://mcp.paymentslaw.eu/mcp/v1'
// .cursor/mcp.json
{
  "mcpServers": {
    "eu-paymentslaw-legislation": {
      "url": "https://mcp.paymentslaw.eu/mcp/v1"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "eu-paymentslaw-legislation": {
      "type": "http",
      "url": "https://mcp.paymentslaw.eu/mcp/v1"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.eu-paymentslaw-legislation]
url = "https://mcp.paymentslaw.eu/mcp/v1"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "eu-paymentslaw-legislation": {
      "type": "remote",
      "url": "https://mcp.paymentslaw.eu/mcp/v1",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add eu-paymentslaw-legislation --url 'https://mcp.paymentslaw.eu/mcp/v1' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  eu-paymentslaw-legislation:
    url: "https://mcp.paymentslaw.eu/mcp/v1"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "eu-paymentslaw-legislation": {
      "Transport": "http",
      "Url": "https://mcp.paymentslaw.eu/mcp/v1"
    }
  }
}
# add to Vellum
assistant mcp add eu-paymentslaw-legislation -t streamable-http -u 'https://mcp.paymentslaw.eu/mcp/v1'
// mcp.json
{
  "mcpServers": {
    "eu-paymentslaw-legislation": {
      "type": "http",
      "url": "https://mcp.paymentslaw.eu/mcp/v1"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 22 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.

  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

  • 13 Sept 26 +1
    • “fetch” reworded the description of “id” cosmetic

    1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.

  • 11 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.

  • 9 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 25 Sept 2026 · Probed https://mcp.paymentslaw.eu/mcp/v1

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=paymentslaw.eu CN=WE1,O=Google Trust Services,C=US 27 Aug 2026 25 Nov 2026 ECDSA 256 ECDSA-SHA256 ed49c879de1196b50e54212c4a7564cf
SANs: paymentslaw.eu, mcp.paymentslaw.eu, *.mcp.paymentslaw.eu
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.paymentslaw.eu. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
eu. present 35926 8 Verified
paymentslaw.eu. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains; preload
x-content-type-options nosniff

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.paymentslaw.eu/mcp/v1 Verified 200
http (plaintext) http://mcp.paymentslaw.eu/mcp/v1 HTTPS enforced 301 https://mcp.paymentslaw.eu/mcp/v1
MCP tools · 14 exposed · ~3,445 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
compare_versions ~307

Use this to compare an article between the held Commission proposal and Council compromise versions of PSR or PSD3, within the same instrument. Serves the word-level comparison the build published: a pair is servable if and only if a diff artefact exists for it — the PSR and PSD3 proposal↔compromise pairs and nothing else. Every other pair, including every consolidated instrument's pinned as-adopted text, is refused with the URL where that text is published; this service never recomputes a comparison. Pairs match in either direction, and a reversed request is the same artefact with the ops inverted. `changes` reads that artefact structurally — paragraphs added or deleted, figures and durations moved, a heading rewritten — for a caller that needs what KIND of change this was without parsing the word-level ops. It is scoped to the article, not to the page of ops, and locates each entry no more precisely than the served text allows.

NameTypeReqDescription
cursorstring|null––
from_locator––The article on the from side. Alignment is identity on the article number, so naming either side names both.
from_version_idstringyesVersion id one side of the pair.
instrument_idstringyesRegistry id of the instrument, e.g. "psr".
limit–––
to_locator––The article on the to side.
to_version_idstringyesVersion id the other side.
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

fetch ~165

Use this to open and cite an EU legislative provision found by search. OpenAI-compatible retrieval: the full text of one provision by its cite anchor id (e.g. "psd-2 Art 97"), with citation metadata. Accepts only ids this service minted — free-text citations belong to resolve_citation. get_provision returns more: paging, applicability and typed warnings.

NameTypeReqDescription
idstringyesAn id from search, or a cite anchor such as "psd-2 Art 97" or "psd-2 Recital 12", or an instrument id such as "psd-2". An optional version qualifier, e.g. "psr (com-2023-367) Art 105", retains its ed…
NameTypeReqDescription
idstringyes–
metadataobjectyes–
textstringyesThe legal text selected from the provision. Full referenced note bodies travel separately in metadata.source_notes; notes do not alter legal block counts or content_hash.
titlestringyes–
urlstringyes–

No examples provided.

get_defined_term ~374

Use this to read and compare the held legislative definitions of a term, such as payment transaction in PSD2 and PSR. These are source definitions, not a general dictionary or a legal opinion. Every definition verbatim and resolved, clustered by what the text actually says, with the chronological and concurrent views and word-level comparisons between them. Resolution follows the CITED version, never legislative succession: a definition citing a repealed act resolves to that act and is labelled repealed, not silently replaced by its successor's wording. A term the corpus does not define is refused with suggestions — nothing is substituted. references_in gives the reverse edges: which definitions lean on this one.

NameTypeReqDescription
comparison––Which comparisons to compute. "adjacent" (default) compares consecutive distinct clusters in chronological order; {baseline: cluster_id} compares one cluster against every other; {pair: [cite, cite]}…
instrumentstring|null–Narrow the definitions listed to one definer. The clusters, views and comparisons stay corpus-wide: what the term means elsewhere does not change because you asked about one instrument.
on_datestring|null–ISO date. Adds operative_on_date and temporal_state_on_date per definer, and makes the concurrent view that date's rather than the release's.
termstringyesThe defined term, as written in the legislation ("payment account"). Matched exactly after normalisation; a term the corpus does not define is refused with suggestions, never answered with a neighbou…
view––Which text clusters and comparisons run on. "resolved" (default) follows each definition's pointers to its root; "verbatim" uses the text as each instrument prints it.
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

get_instrument ~185

Use this to check an EU instrument's recorded legal status, source version, dates and amendments, including whether a held PSR or PSD3 text is a proposal or compromise. Metadata, dates, lifecycle and application events, and curated relationships. Each relationship names the operative amending or repealing article where curated (openable with get_provision) and the counterpart's legal status at the release. An operative_cite can arrive without an operative_locator: the article is real but the served text has dropped it, and operative_locator_unavailable says so. An amender outside the corpus is named under source_external, whose via_article carries its article. No article index — use list_provisions. Pass on_date for the multi-axis applicability record on that date.

NameTypeReqDescription
instrument_idstringyes–
on_datestring|null–ISO date; returns the full applicability record.
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

get_orientation ~190

Use this for a starting reading order in EU payments legislation when a relevant curated pathway exists. For other subjects use search_legislation. Curated reading pathways into the corpus for a stated audience: ordered waypoints with cite anchors every other tool can open, related defined terms and known pitfalls. The prose is editorial and labelled as such — it maps the reading order, never legal weight. Omit the pathway argument for the catalogue; an unknown id is refused with the catalogue, nothing substituted. Catalogue entries and pathway waypoints paginate whole: follow pagination.next_cursor with the same pathway and limit until complete.

NameTypeReqDescription
cursorstring|null–pagination.next_cursor from this tool; repeat the same pathway and limit.
limit––Maximum catalogue entries or pathway waypoints per page; whole-item byte bounds may return fewer.
pathwaystring|null–Pathway id from the catalogue. Omit for the catalogue.
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

get_provision ~514

Use this to read or quote an EU legislative provision, such as PSD2 Article 97 or RTS-SCA Article 5. Returns the source text of an article, annex or recital as markdown, with its cite anchor, provenance and text-state disclosure. Large provisions paginate by structural block — never truncated silently. version_id is optional: the service serves one text per instrument, and a pinned version id is refused with the URL where it is published. include_correspondences adds the cross-instrument article equivalences — what a PSR article is amended from, or which PSR articles carry a PSD2 article's obligation — each openable by a second call.

NameTypeReqDescription
cursorstring|null–Continue a paginated provision. Bound to the release.
include_correspondencesboolean|null–Off by default. When true, an article carries `correspondences[]`: the cross-instrument article equivalences the corpus publishes — which PSD2 article a PSR article is amended from, and, from the oth…
instrument_idstringyesRegistry id of the instrument, e.g. "psd-2".
locatorobjectyes–
on_datestring|null–ISO date; returns the provision-level applicability view.
version_idstring|null–Omit, or pass "current", for the served text. A pinned version id returns version_not_served with the URL where that text is published.
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

get_source_notes ~191

Use this to read the original legislative footnotes and source-note bodies for a held instrument, including preamble and annex notes. Omit note_key for the paginated inventory; supply an exact returned key to retrieve one. Keys retain source scope because printed markers may repeat. This tool does not infer ownership by a provision. Historical versions return an explicit version_not_served link.

NameTypeReqDescription
cursorstring|null–Continue with the same arguments; bound to this corpus release.
instrument_idstringyesRegistry instrument id.
limit––Notes per page, default 10; complete bodies are never truncated.
note_key––Exact key returned by this tool. Omit to list notes. Printed markers may be reused and are not necessarily unique keys.
version_idstring|null–Omit or use current for the served version; pinned versions return an explicit version_not_served link.
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

list_instruments ~161

Use this to discover which EU instruments are held before a coverage question, or find their registry ids and legal status. Paginated, filterable by status, category, core/supplementary, and by whether an instrument was in force on a given date. For corpus-coverage questions, filter by category here, enumerate each instrument with list_provisions, then open what you need with get_provision.

NameTypeReqDescription
categorystring|null––
cursorstring|null––
in_force_on_datestring|null–ISO date; keeps instruments in force on that date.
is_coreboolean|null––
limit–––
statusstring|null–Legal status at the release, e.g. "in_force".
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

list_provisions ~108

Use this to browse an EU instrument's article, annex or recital index, or enumerate its topic-tagged provisions for a coverage question. Metadata only: each item carries the exact locator get_provision accepts. Articles and annexes by default; pass kind=recital for recitals.

NameTypeReqDescription
chapterstring|null––
cursorstring|null––
instrument_idstringyes–
kind–––
limit–––
topicstring|null––
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

list_version_changes ~227

Use this to browse which articles changed between the held proposal and Council compromise versions of PSR or PSD3. For one article's wording changes use compare_versions. Across the instrument's two published texts, lists every aligned article with its classification, filterable by status, materiality and article range. The editorial materiality markers travel on every response whatever the filters, because they exist precisely where the mechanical classification does not show what matters — a re-scoped defined term changes articles whose text did not change at all. Classifications are mechanical, and the response says on what basis.

NameTypeReqDescription
articles––Article-number range, in legal order.
cursorstring|null––
from_version_idstring|null–Optional; where given, must name the published pair.
instrument_idstringyes–
limit–––
material_onlyboolean|null–Keep only articles carrying an editorial materiality marker.
statusstring|null–One of the classification statuses, e.g. "amended_substantial".
to_version_idstring|null––
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

resolve_citation ~185

Use this to resolve a written EU legal citation, such as Article 97(1) PSD2, into an instrument and provision locator. For a topic rather than a citation, use search_legislation. Ranked candidates with ambiguity flagged and confidence stated: exact (instrument certain, provision found), strong (instrument certain, provision not verified or not named) or ambiguous (more than one reading). A citation of an instrument this corpus does not hold is named, with its CELEX and ELI, rather than guessed at.

NameTypeReqDescription
citationstringyesA citation in any form a reader would write: "Article 97(1) PSD2", "Art. 5a of Regulation (EU) No 910/2014", a CELEX number, an ELI path, or a bare acronym.
cursorstring|null––
limit–––
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

search ~121

Use this to find EU payments legislation on topics such as SCA, open banking and safeguarding in the held PSD2, RTS-SCA, PSD3/PSR and related instruments. OpenAI-compatible search: the top hits as {id, title, url}, where id is the cite anchor fetch accepts. For filters, snippets, scores and paging use search_legislation, which returns more.

NameTypeReqDescription
querystringyesEU payments legislative terms or citation, e.g. "strong customer authentication", "safeguarding" or "Article 97 PSD2".
NameTypeReqDescription
resultsarrayyesTop hits, best first.

No examples provided.

search_defined_terms ~231

Use this to find which EU instruments define a legal term, such as payment transaction or payment account, and where their definitions differ. For definition wording use get_defined_term. A listing: term, definers and divergence flags, with no definition text. Matching is over the term itself, never the definition body. Divergence is judged on the RESOLVED text as well as the verbatim one, because several instruments defining a term by pointing at the same root agree, however differently their pointers read. Pass only_divergent to find where the corpus does not agree with itself.

NameTypeReqDescription
cursorstring|null––
instrumentstring|null–Keep only terms defined in this instrument, e.g. "psd-2".
limit–––
only_divergentboolean|null–Keep only terms whose definers disagree — on the resolved text, the verbatim text, or both.
querystring|null–Term text to match. Matching is over the TERM only, never the definition body. Omit for the full alphabetical listing of every term the corpus defines.
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

search_legislation ~486

Use this to find EU legislative provisions on payment-services questions: strong customer authentication (SCA), dynamic linking, open banking, safeguarding and payment liability. The held corpus includes PSD2, RTS-SCA, PSD3/PSR and DORA. For exact wording use get_provision; for defined-term wording use get_defined_term. This searches held legislation, not national law or regulator guidance. Full-text search across articles, annexes and recitals, ranked in that order of authority. Every hit carries the exact locator get_provision accepts, its cite anchor, the matched passage and why it matched. A citation-shaped query resolves through the citation grammar first; instrument acronyms become ranking hints; initialisms of the corpus's defined terms are expanded. Absence of a result is not evidence that no relevant law exists. The matched passage is a snippet of at most 320 characters, not the provision: open the hit with get_provision before citing it, and echo the cite it serves. topic narrows these hits rather than widening them: a topic-tagged provision whose words the query misses is never reached, so a page of hits is not a sweep. For coverage questions ('everything on X', 'which instruments deal with Y') pick the instruments with list_instruments by category, enumerate each with list_provisions filtered by topic, then open them with get_provision.

NameTypeReqDescription
cursorstring|null––
in_force_on_datestring|null–ISO date; keeps hits from instruments in force on that date, on the same semantics list_instruments uses.
instrument_idstring|null–Restrict to one instrument, e.g. "rts-sca".
kind––Restrict to one source type. Articles, annexes and recitals are all searched by default, ranked in that order of authority.
limit–––
querystringyesEU legislative search terms, e.g. "strong customer authentication", "dynamic linking", "safeguarding" or "DORA ICT risk". Use words expected in the legal text, not an entire advice request. Quoted ph…
topicstring|null–Keep only provisions carrying this topic.
NameTypeReqDescription
corpus_releaseobjectyes–
coverageobjectyes–
data–yes–
derivationsobjectyes–
error–yes–
pagination–yes–
provenanceobjectyes–
warningsarrayyes–

No examples provided.

Common questions

What is the Payments Law EU MCP server?

Payments Law EU is an MCP server listed in the public MCP registry as eu.paymentslaw/legislation. Read-only query service for EU payments legislation: 51 curated instruments, by provision. This page covers its hosted endpoint (https://mcp.paymentslaw.eu/mcp/v1).

Is the Payments Law EU MCP server safe to use?

Payments Law EU scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Payments Law EU MCP server expose?

Payments Law EU exposes 14 tools: get_provision, get_instrument, list_instruments, get_source_notes, list_provisions, and 9 more. Their descriptions and schemas cost roughly 3,445 tokens of context every time the server is loaded.

Does the Payments Law EU MCP server require authentication?

No. We connected to Payments Law EU without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Payments Law EU MCP server still maintained?

Payments Law EU is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.