# io.usefulapi/checkoutcom (remote · checkoutcom.usefulapi.io)

Read Checkout.com payments, disputes, reports and payouts.

- Trust score: 18/100 (low)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-04

## Components

- remote · `checkoutcom.usefulapi.io`: 18/100 (this document), [markdown](https://verifymcp.io/servers/io-usefulapi-checkoutcom/checkoutcom.md), [page](https://verifymcp.io/servers/io-usefulapi-checkoutcom/checkoutcom)

## Channel facts

- Endpoint: `https://checkoutcom.usefulapi.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-04.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not yet verified: we couldn't confirm whether this endpoint requires it.
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 429, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 0/100
  - Transport check failed: declared streamable-http, but the endpoint returned HTTP 429.
- **Schema Quality & AI Usability**: 0/100
  - Schema not yet verified: we couldn't read the endpoint's schema, or could read only part of its tool list.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.
- **Tool Safety**: 0/100
  - Tool safety not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.
- **Capabilities**: 0/100
  - Capabilities not yet verified: we couldn't read the endpoint's capabilities.

**Unverified: 5 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the io.usefulapi/checkoutcom MCP server?

io.usefulapi/checkoutcom is a hosted endpoint at https://checkoutcom.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-usefulapi-checkoutcom 'https://checkoutcom.usefulapi.io/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-usefulapi-checkoutcom": {
      "url": "https://checkoutcom.usefulapi.io/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-usefulapi-checkoutcom": {
      "type": "http",
      "url": "https://checkoutcom.usefulapi.io/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-usefulapi-checkoutcom]
url = "https://checkoutcom.usefulapi.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-usefulapi-checkoutcom": {
      "type": "remote",
      "url": "https://checkoutcom.usefulapi.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-usefulapi-checkoutcom --url 'https://checkoutcom.usefulapi.io/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-usefulapi-checkoutcom:
    url: "https://checkoutcom.usefulapi.io/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-usefulapi-checkoutcom": {
      "Transport": "http",
      "Url": "https://checkoutcom.usefulapi.io/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-usefulapi-checkoutcom -t streamable-http -u 'https://checkoutcom.usefulapi.io/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-usefulapi-checkoutcom": {
      "type": "http",
      "url": "https://checkoutcom.usefulapi.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-02 (score 18, −58)

- [security regression] Endpoint reachability: reachable → not serving MCP
- [security regression] Tool safety: pass → unverified
- [security regression] HTTPS: pass → unverified
- [security regression] Authorization: pass → unverified
- [security regression] Transport: pass → fail
- [functional regression] Capabilities: fail → unverified
- [functional regression] Tool coverage: 100 → unverified

### 2026-10-01 (score 76, +48)

- [security improvement] Authorization: unverified → pass
- [security improvement] HTTPS: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [security] First check of Authorization: partial
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Schema quality: fail
- [functional] First check of Destructive annotations: 100
- [functional] First check of Tool coverage: 100

### 2026-09-30 (score 28, +10)

- [security improvement] Transport: fail → pass
- [security] Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the whole tool list to see what that exposes.

### 2026-09-29 (score 18)

First indexed and scored.

## MCP tools (18)

### `checkout_get_payment` (~81 tokens)

Get payment

Get the full details of a payment (or payment session) by its id, e.g. 'pay_...'. Checkout.com: GET /payments/{id}.

Input parameters:

- `id` (string, required): Payment id, e.g. 'pay_mbabizu24mvu3mela5njyhpit4' (or a 'sid_' payment session id).

### `checkout_list_payments` (~81 tokens)

List payments by reference

List your business's payments that match a given reference. Checkout.com: GET /payments (query parameters). For richer filtering use checkout_search_payments.

Input parameters:

- `limit` (integer): Maximum number of payments to return.
- `reference` (string): Return only payments with this reference.
- `skip` (integer): Number of payments to skip (pagination offset).

### `checkout_search_payments` (~116 tokens)

Search payments

Search payments using flexible query filters (this is a READ — it queries, it does not mutate). Checkout.com: POST /payments/search. Pass a `query` filter object and/or paging fields.

Input parameters:

- `limit` (integer): Maximum number of results to return.
- `pagination` (object): Cursor pagination object (e.g. { after, before }) as returned in previous responses.
- `query` (object): Search filter object, e.g. { reference, id, status, currency, amount, from, to }.

### `checkout_get_payment_actions` (~61 tokens)

Get payment actions

List all the actions (authorization, capture, refund, void, etc.) associated with a payment, latest first. Checkout.com: GET /payments/{id}/actions.

Input parameters:

- `id` (string, required): Payment id, e.g. 'pay_...'.

### `checkout_get_payment_link` (~74 tokens)

Get payment link

Retrieve the details and status of a Payment Link by its id, e.g. 'pl_...'. Checkout.com: GET /payment-links/{id}.

Input parameters:

- `id` (string, required): Payment Link id, e.g. 'pl_ok1itj8ykm3eyk1toywr6uwlwe'.

### `checkout_get_customer` (~61 tokens)

Get customer

Get a customer's details (email, name, phone, saved instruments) by id 'cus_...' or by email. Checkout.com: GET /customers/{id}.

Input parameters:

- `id` (string, required): Customer id ('cus_...') or the customer's email address.

### `checkout_get_instrument` (~60 tokens)

Get instrument

Get the details of a saved payment instrument (tokenized card / bank account) by id 'src_...'. Checkout.com: GET /instruments/{id}.

Input parameters:

- `id` (string, required): Instrument id, e.g. 'src_...'.

### `checkout_list_disputes` (~202 tokens)

List disputes

List disputes (chargebacks) against your business, most-recently-modified first, with optional filters. Checkout.com: GET /disputes.

Input parameters:

- `entity_ids` (string): Comma-separated sub-entity ids to filter by (for platforms).
- `from` (string): Only disputes last modified on/after this ISO-8601 timestamp.
- `limit` (integer): Maximum number of disputes to return (default 20).
- `payment_id` (string): Filter to disputes for a specific payment id ('pay_...').
- `skip` (integer): Number of disputes to skip (pagination offset).
- `statuses` (string): Comma-separated dispute statuses to filter by, e.g. 'evidence_required,arbitration'.
- `this_channel_only` (boolean): If true, only return disputes for the authenticating channel.
- `to` (string): Only disputes last modified on/before this ISO-8601 timestamp.

### `checkout_get_dispute` (~67 tokens)

Get dispute

Get all the details of a single dispute (reason code, amount, deadline, evidence status) by id 'dsp_...'. Checkout.com: GET /disputes/{id}.

Input parameters:

- `id` (string, required): Dispute id, e.g. 'dsp_...'.

### `checkout_list_reports` (~106 tokens)

List reports

List the reports available on your account (settlement, payments, etc.) and their details. Checkout.com: GET /reports.

Input parameters:

- `created_after` (string): Only reports created on/after this ISO-8601 timestamp.
- `created_before` (string): Only reports created on/before this ISO-8601 timestamp.
- `entity_id` (string): Filter reports to a specific entity id (for platforms).
- `limit` (integer): Maximum number of reports to return.

### `checkout_get_report` (~57 tokens)

Get report

Get the metadata of a specific report (including its downloadable files) by id 'rpt_...'. Checkout.com: GET /reports/{id}.

Input parameters:

- `id` (string, required): Report id, e.g. 'rpt_...'.

### `checkout_get_forex_rates` (~138 tokens)

Get forex rates

Get the indicative foreign-exchange rates Checkout.com uses (e.g. for card payouts). Checkout.com: GET /forex/rates.

Input parameters:

- `currency_pairs` (string, required): Comma-separated currency pairs, e.g. 'GBPEUR,USDNOK' (required, up to 20 pairs).
- `processing_channel_id` (string): Processing channel id ('pc_...') to scope the rates.
- `product` (string): Product the rates are for, e.g. 'card_payouts'.
- `source` (string, required): Rate source, e.g. 'visa' or 'mastercard' (required).

### `checkout_create_payment` (~398 tokens)

Create payment

CREATES a payment (request an authorization, or an immediate capture) — this MOVES MONEY: it charges a card / payment source. Checkout.com: POST /payments. Provide `amount` (minor units), `currency`, and a `source` object such as { type: 'token', token: 'tok_...' }, { type: 'id', id: 'src_...' } (a saved instrument), or { type: 'customer', id: 'cus_...' }.

Input parameters:

- `amount` (integer, required): Amount in the currency's MINOR units (e.g. 1000 = $10.00; 0 = card verification). Required.
- `capture` (boolean): If true (default for card), capture immediately; if false, authorize only.
- `currency` (string, required): 3-letter ISO currency code, e.g. 'USD', 'GBP', 'EUR'. Required.
- `customer` (object): Customer object to associate/create, e.g. { id:'cus_...' } or { email, name }.
- `description` (string): Description shown on the customer's statement / for your records.
- `idempotency_key` (string): Idempotency key — sent as the Cko-Idempotency-Key header to safely retry.
- `metadata` (object): Arbitrary key/value metadata to attach to the payment.
- `payment_type` (string): Payment type, e.g. 'Regular', 'Recurring', 'MOTO'.
- `processing_channel_id` (string): Processing channel id ('pc_...') to route the payment through.
- `reference` (string): Your reference for the payment (e.g. order id).
- `source` (object, required): Payment source object. Required. E.g. { type:'token', token:'tok_...' }, { type:'id', id:'src_...' }, or { type:'customer', id:'cus_...' }.

### `checkout_capture_payment` (~141 tokens)

Capture payment

CAPTURES a previously authorized payment — this MOVES MONEY: it settles the (full or partial) authorized amount. Checkout.com: POST /payments/{id}/captures.

Input parameters:

- `amount` (integer): Amount to capture in MINOR units (defaults to the full authorized amount).
- `id` (string, required): Payment id to capture, e.g. 'pay_...'. Required.
- `idempotency_key` (string): Idempotency key — sent as the Cko-Idempotency-Key header.
- `metadata` (object): Arbitrary key/value metadata to attach to the capture.
- `reference` (string): Your reference for the capture.

### `checkout_refund_payment` (~138 tokens)

Refund payment

REFUNDS a captured payment — this MOVES MONEY BACK to the customer (full or partial). Checkout.com: POST /payments/{id}/refunds.

Input parameters:

- `amount` (integer): Amount to refund in MINOR units (defaults to the full captured amount).
- `id` (string, required): Payment id to refund, e.g. 'pay_...'. Required.
- `idempotency_key` (string): Idempotency key — sent as the Cko-Idempotency-Key header.
- `metadata` (object): Arbitrary key/value metadata to attach to the refund.
- `reference` (string): Your reference for the refund.

### `checkout_void_payment` (~124 tokens)

Void payment

VOIDS (cancels) a payment that has been authorized but not yet captured — this releases the hold on the customer's funds. Checkout.com: POST /payments/{id}/voids.

Input parameters:

- `id` (string, required): Payment id to void, e.g. 'pay_...'. Required.
- `idempotency_key` (string): Idempotency key — sent as the Cko-Idempotency-Key header.
- `metadata` (object): Arbitrary key/value metadata to attach to the void.
- `reference` (string): Your reference for the void.

### `checkout_create_payment_link` (~268 tokens)

Create payment link

CREATES a hosted Payment Link the customer can pay through — this sets up a way to COLLECT MONEY. Checkout.com: POST /payment-links. Returns a URL to share with the customer.

Input parameters:

- `amount` (integer, required): Amount in MINOR units (e.g. 1000 = $10.00). Required.
- `billing` (object): Billing object, e.g. { address: { country: 'GB' } }.
- `currency` (string, required): 3-letter ISO currency code, e.g. 'USD'. Required.
- `customer` (object): Customer object, e.g. { email, name }.
- `description` (string): Description shown to the customer on the payment page.
- `expires_in` (integer): Seconds until the link expires.
- `idempotency_key` (string): Idempotency key — sent as the Cko-Idempotency-Key header.
- `metadata` (object): Arbitrary key/value metadata to attach to the payment link.
- `products` (array): Line items, each e.g. { name, quantity, unit_price }.
- `reference` (string): Your reference for the payment link (e.g. order id).
- `return_url` (string): URL the customer is returned to after paying.

### `checkout_create_customer` (~162 tokens)

Create customer

CREATES a customer record (which saved instruments and future payments can be attached to). This ADDS data to your account. Checkout.com: POST /customers.

Input parameters:

- `default` (string): Id of the default instrument ('src_...') for this customer.
- `email` (string, required): Customer email address (required, must be unique on the account).
- `idempotency_key` (string): Idempotency key — sent as the Cko-Idempotency-Key header.
- `metadata` (object): Arbitrary key/value metadata to attach to the customer.
- `name` (string): Customer full name.
- `phone` (object): Phone object, e.g. { country_code: '+1', number: '4155552671' }.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-usefulapi-checkoutcom/checkoutcom#diagnostics

## Score history

- 2026-10-04: 18
- 2026-10-03: 18
- 2026-10-02: 18
- 2026-10-01: 76
- 2026-09-30: 28
- 2026-09-29: 18

## Common questions

### What is the io.usefulapi/checkoutcom MCP server?

io.usefulapi/checkoutcom is an MCP server listed in the public MCP registry as io.usefulapi/checkoutcom. Read Checkout.com payments, disputes, reports and payouts. This page covers its hosted endpoint (https://checkoutcom.usefulapi.io/mcp).

### Is the io.usefulapi/checkoutcom MCP server safe to use?

io.usefulapi/checkoutcom scores 18 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.usefulapi/checkoutcom MCP server expose?

io.usefulapi/checkoutcom exposes 18 tools: checkout_get_payment, checkout_list_payments, checkout_search_payments, checkout_get_payment_actions, checkout_get_payment_link, and 13 more. Their descriptions and schemas cost roughly 2,335 tokens of context every time the server is loaded.

### Does the io.usefulapi/checkoutcom MCP server require authentication?

Its publisher declares no required credentials for io.usefulapi/checkoutcom. We have not been able to confirm that against the live endpoint, and a server can require authorisation without declaring it here.

### Is the io.usefulapi/checkoutcom MCP server still maintained?

io.usefulapi/checkoutcom is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://checkoutcom.usefulapi.io/mcp
- Repository: https://github.com/m190/usefulapi-mcp
- Changelog RSS feed: https://verifymcp.io/servers/io-usefulapi-checkoutcom/checkoutcom.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-usefulapi-checkoutcom/checkoutcom.json
- HTML version of this page: https://verifymcp.io/servers/io-usefulapi-checkoutcom/checkoutcom
