# vn.monapay/monapay-mcp (npm · monapay-mcp)

MONA Pay for AI agents: create VietQR, check bank transfers, webhooks & HMAC. Vietnam bank API, VND

- Trust score: 69/100 (medium)
- Change this week: +11
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-26

## Components

- npm · `monapay-mcp`: 69/100 (this document), [markdown](https://verifymcp.io/servers/vn-monapay-monapay-mcp/monapay-mcp.md), [page](https://verifymcp.io/servers/vn-monapay-monapay-mcp/monapay-mcp)

## Channel facts

- Registry: `npm`
- Package: `monapay-mcp`
- Version: `0.6.1`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-26.

- **Supply Chain Security**: 98/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 31 of 95 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 48/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 6 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 83/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 4691 tokens (~91/item across 51 items; 50 tools + 1 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 80/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 41% of tool parameters carry a description.
- **Tool Safety**: 75/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 0 of 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "monapay_delete_webhook" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 52 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### How do I install the vn.monapay/monapay-mcp server?

vn.monapay/monapay-mcp runs locally as an npm package, launched with npx -y monapay-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add vn-monapay-monapay-mcp -- npx -y monapay-mcp
```

### Cursor

```json
{
  "mcpServers": {
    "vn-monapay-monapay-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "monapay-mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "vn-monapay-monapay-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "monapay-mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add vn-monapay-monapay-mcp -- npx -y monapay-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "vn-monapay-monapay-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "monapay-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add vn-monapay-monapay-mcp --command npx --arg -y --arg monapay-mcp
```

### Hermes

```yaml
mcp_servers:
  vn-monapay-monapay-mcp:
    command: "npx"
    args: ["-y", "monapay-mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "vn-monapay-monapay-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "monapay-mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add vn-monapay-monapay-mcp -t stdio -c npx -a -y monapay-mcp
```

### Other

```json
{
  "mcpServers": {
    "vn-monapay-monapay-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "monapay-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-25 (score 69, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-20 (score 69, +11)

- [security improvement] Known CVEs: unverified → pass
- [functional improvement] Dependency health: unverified → 0.85

### 2026-09-19 (score 58)

First indexed and scored.

## MCP tools (50)

### `monapay_me` (~38 tokens)

Hồ sơ tài khoản MONA Pay

Lấy thông tin tài khoản MONA Pay đang đăng nhập (id, tên, trạng thái). / Get current MONA Pay client profile.

### `monapay_whoami` (~40 tokens)

Kiểm tra kết nối MONA Pay

Xác nhận client credentials đang hoạt động, trả tên tài khoản và gói hiện tại. / Verify connection and return account name and plan.

### `monapay_list_bank_accounts` (~35 tokens)

Danh sách tài khoản ngân hàng đã nối

Liệt kê tài khoản ngân hàng (ACB…) đã nối vào MONA Pay. / List linked bank accounts.

### `monapay_list_virtual_accounts` (~57 tokens)

Danh sách tài khoản ảo (VA)

Liệt kê tài khoản ảo thuộc một tài khoản ngân hàng. / List virtual accounts of a bank account.

Input parameters:

- `bank_account_id` (string, required): UUID tài khoản ngân hàng (lấy từ monapay_list_bank_accounts)

### `monapay_link_bank_start` (~262 tokens)

Bắt đầu nối ngân hàng ACB và gửi OTP

Bước 1/4: đăng ký tài khoản ACB + VA. OTP do ngân hàng gửi về điện thoại của người dùng; agent phải HỎI người dùng OTP rồi mới gọi tool xác thực, không được tự đoán. / Step 1/4: register the ACB account and VA. The OTP is sent by the bank to the user’s phone; the agent MUST ASK the user before calling the verification tool and must never guess it.

Input parameters:

- `account_number`: Số tài khoản thanh toán ACB; bắt buộc khi không có bank_account_id
- `bank_account_id` (string): UUID tài khoản ACB đã nối; khi có, API bỏ qua account_number và phone_number
- `customer_type` (string, required): PERS = cá nhân, ORG = tổ chức
- `description` (string): Diễn giải đăng ký VA
- `identifier` (string, required): Nội dung định danh VA, tối đa 10 ký tự không dấu
- `phone_number` (string): Số điện thoại đăng ký với ACB và nhận OTP; bắt buộc khi không có bank_account_id
- `prefix` (string, required): Đầu số VA đã đăng ký với ACB, ví dụ LOC

### `monapay_link_bank_verify_otp` (~133 tokens)

Xác thực OTP và tạo tài khoản ảo ACB

Bước 2/4: OTP do ngân hàng gửi về điện thoại của người dùng, agent phải HỎI người dùng rồi mới gọi tool này; tuyệt đối không tự đoán OTP. / Step 2/4: the OTP is sent by the bank to the user’s phone; the agent MUST ASK the user before calling this tool and must never guess the OTP.

Input parameters:

- `acb_request_id` (string, required): ID yêu cầu ACB trả về từ monapay_link_bank_start
- `code` (string, required): OTP do người dùng cung cấp sau khi nhận từ ACB

### `monapay_notification_register` (~125 tokens)

Đăng ký thông báo tiền vào và gửi OTP lần 2

Bước 3/4: đăng ký nhận thông báo giao dịch tức thì. OTP lần 2 do ngân hàng gửi về điện thoại của người dùng; agent phải HỎI người dùng rồi mới gọi tool xác thực, không được tự đoán. / Step 3/4: register real-time transaction notifications. The second OTP is sent by the bank to the user’s phone; the agent MUST ASK the user before verification and must never guess it.

Input parameters:

- `virtual_account_id` (string, required): ID VA trả về từ monapay_link_bank_verify_otp

### `monapay_notification_verify_otp` (~134 tokens)

Xác thực OTP lần 2 và hoàn tất nhận tiền

Bước 4/4: OTP do ngân hàng gửi về điện thoại của người dùng, agent phải HỎI người dùng rồi mới gọi tool này; tuyệt đối không tự đoán OTP. / Step 4/4: the OTP is sent by the bank to the user’s phone; the agent MUST ASK the user before calling this tool and must never guess the OTP.

Input parameters:

- `acb_request_id` (string, required): ID yêu cầu ACB trả về từ monapay_notification_register
- `code` (string, required): OTP lần 2 do người dùng cung cấp sau khi nhận từ ACB

### `monapay_get_payment_profile` (~38 tokens)

Lấy hồ sơ trang thanh toán

Lấy tên shop, nhận diện và tài khoản mặc định dùng cho trang thanh toán. / Get the hosted-checkout payment profile.

### `monapay_set_payment_profile` (~179 tokens)

Thiết lập hồ sơ trang thanh toán

Tạo hoặc cập nhật tên shop, nhận diện và tài khoản nhận tiền mặc định trước khi tạo checkout. Secret ký redirect chỉ được API trả một lần. / Create or update the hosted-checkout payment profile.

Input parameters:

- `accent_color`
- `beneficiary_name` (string)
- `default_bank_account_id` (string)
- `default_virtual_account_id`
- `display_name` (string)
- `hotline`
- `locale` (string)
- `logo_url`: URL HTTPS của logo, tối đa 512 KB
- `merchant_id` (string)
- `owner_number` (string)
- `owner_type` (string)
- `show_mona_badge` (boolean)
- `support_email`
- `terminal_id` (string)
- `va_prefix` (string)

### `monapay_create_checkout` (~191 tokens)

Tạo link thu tiền

Tạo link thu tiền, đưa link cho khách hoặc chuyển hướng checkout; đợi webhook CHECKOUT_PAID trước khi giao hàng. / Create a hosted checkout link; wait for CHECKOUT_PAID before fulfilment.

Input parameters:

- `amount` (integer, required): Số tiền nguyên VND
- `cancel_url` (string)
- `description` (string)
- `expires_in` (integer)
- `idempotency_key` (string): Khoá chống tạo trùng; bỏ trống để MCP tự sinh UUID
- `metadata` (object)
- `order_code` (string, required)
- `payer_email` (string)
- `payer_name` (string)
- `return_url` (string, required)
- `sandbox` (boolean): true = phiên THỬ với VA sandbox, không tiền thật; dùng được khi chưa nối ngân hàng
- `virtual_account_id` (string)

### `monapay_get_checkout` (~50 tokens)

Lấy một phiên thanh toán

Lấy trạng thái và chi tiết checkout theo ID; nên kiểm tra server-side trước khi giao hàng. / Get a checkout by ID.

Input parameters:

- `checkout_id` (string, required): ID phiên thanh toán

### `monapay_list_checkouts` (~81 tokens)

Danh sách phiên thanh toán

Liệt kê checkout theo trạng thái, mã đơn, khoảng ngày và phân trang. / List and filter hosted checkouts.

Input parameters:

- `from_date` (string)
- `limit` (integer)
- `order_code` (string)
- `page` (integer)
- `status` (string)
- `to_date` (string)

### `monapay_cancel_checkout` (~72 tokens)

Huỷ phiên thanh toán

Huỷ checkout đang pending; checkout đã paid, expired hoặc cancelled không thể huỷ lại. / Cancel a pending checkout.

Input parameters:

- `checkout_id` (string, required): ID phiên thanh toán
- `idempotency_key` (string): Khoá chống tạo trùng; bỏ trống để MCP tự sinh UUID

### `monapay_create_qr` (~237 tokens)

Tạo VietQR động cho đơn hàng

Tạo mã VietQR động điền sẵn số tiền + nội dung cho một đơn hàng qua ACB. Khách quét là tiền vào tài khoản ảo, MONA Pay bắn webhook. / Create a dynamic VietQR for an order.

Input parameters:

- `amount` (integer, required): Số tiền VND (số nguyên)
- `beneficiaryName` (string, required): Tên đơn vị hưởng
- `description` (string): Nội dung chuyển khoản, nên chứa mã đơn
- `loyaltyCode` (string)
- `merchantId` (string, required): Mã merchant (hiển thị ở dashboard mục Tạo QR)
- `orderId` (string, required): Mã đơn hàng của hệ thống anh chị
- `ownerNumber` (string, required): Số tài khoản ACB nhận tiền
- `ownerType` (string): PER cá nhân / ORG doanh nghiệp
- `terminalId` (string)
- `traceNumber` (string)
- `userId` (string)
- `virtualAccountPrefix` (string, required): Đầu số tài khoản ảo đã đăng ký
- `voucherCode` (string)

### `monapay_cancel_qr` (~36 tokens)

Huỷ mã QR

Huỷ một mã VietQR động đã tạo. / Cancel a dynamic QR.

Input parameters:

- `qr_code_id` (string, required)

### `monapay_list_transactions` (~85 tokens)

Tra giao dịch tiền vào

Liệt kê giao dịch tiền vào theo tài khoản ảo, phân trang tối đa 100/trang; dùng để đối soát. / List incoming transactions.

Input parameters:

- `limit` (integer)
- `page` (integer)
- `virtual_account_number` (string, required): Số tài khoản ảo (bắt buộc; lấy từ monapay_list_virtual_accounts)

### `monapay_sandbox_transaction` (~144 tokens)

Tạo giao dịch thử (sandbox, không tốn tiền)

Tạo một giao dịch tiền vào GIẢ: chưa nối ngân hàng thì MONA Pay tự cấp VA sandbox SBX; MONA Pay ghi giao dịch, bắn webhook có chữ ký, gửi Telegram/email/Zalo, khớp checkout như tiền thật, không tính hạn mức. / Create a fake incoming transaction in the sandbox.

Input parameters:

- `amount` (integer)
- `description` (string): Nội dung chuyển khoản giả; ghi order_code của phiên checkout để phiên đó paid
- `virtual_account_number` (string): Số VA đã nối; bỏ trống = MONA Pay tự cấp VA sandbox SBX (không cần nối ngân hàng)

### `monapay_list_webhooks` (~24 tokens)

Danh sách cấu hình webhook

Liệt kê webhook đã cấu hình. / List webhook configs.

### `monapay_create_webhook` (~139 tokens)

Tạo cấu hình webhook

Đăng ký URL nhận webhook khi có tiền vào; khuyến nghị auth_type HMAC_SHA256 + secret_key. / Create a webhook config.

Input parameters:

- `api_key_name` (string): Tên header khi auth_type=API_KEY, mặc định X-Webhook-Secret
- `auth_type` (string)
- `name` (string, required)
- `payload_format` (string)
- `secret_key` (string): Secret ký HMAC hoặc giá trị API key
- `virtual_account_id` (string): Chỉ bắn cho VA này; bỏ trống = mọi tài khoản
- `webhook_url` (string, required)

### `monapay_update_webhook` (~103 tokens)

Sửa cấu hình webhook

Cập nhật webhook (URL, secret, bật/tắt). / Update a webhook config.

Input parameters:

- `api_key_name` (string)
- `auth_type` (string)
- `config_id` (string, required)
- `is_active` (boolean)
- `name` (string)
- `payload_format` (string)
- `secret_key` (string)
- `virtual_account_id` (string)
- `webhook_url` (string)

### `monapay_delete_webhook` (~32 tokens)

Xoá cấu hình webhook

Xoá một webhook config. / Delete a webhook config.

Input parameters:

- `config_id` (string, required)

### `monapay_test_webhook` (~72 tokens)

Bắn webhook thử

MONA Pay gửi một giao dịch giả (is_dummy) tới URL để kiểm tra endpoint + chữ ký. / Send a dummy webhook.

Input parameters:

- `auth_type` (string)
- `secret_key` (string)
- `webhook_url` (string): Bỏ trống = dùng config đã lưu

### `monapay_webhook_logs` (~76 tokens)

Lịch sử gửi webhook

Lịch sử từng lần gửi (HTTP code, thời gian phản hồi, nhãn lỗi). / Webhook delivery logs.

Input parameters:

- `from_date` (string): YYYY-MM-DD
- `limit` (integer)
- `page` (integer)
- `status` (string)
- `to_date` (string)

### `monapay_webhook_stats` (~30 tokens)

Thống kê webhook

Tỷ lệ thành công, P95, phân loại lỗi. / Webhook delivery stats.

### `monapay_list_email_configs` (~39 tokens)

Danh sách cấu hình email

Liệt kê các cấu hình gửi thông báo email và trạng thái xác minh người nhận. / List email notification configs and recipient verification status.

### `monapay_create_email_config` (~166 tokens)

Tạo cấu hình thông báo email

Tạo kênh thông báo email. Sau khi tạo, MONA Pay gửi mã 6 số tới từng địa chỉ; hỏi người dùng mã rồi gọi monapay_verify_email; không tự đoán mã. / Create an email notification config. MONA Pay sends a 6-digit code to each address; ask the user for each code, call monapay_verify_email, and never guess a code.

Input parameters:

- `events` (array): Sự kiện gửi email; luôn phải có TRANSACTION_IN
- `name` (string, required): Tên cấu hình
- `recipients` (array, required): Từ 1 đến 10 địa chỉ nhận email
- `virtual_account_id` (string): Chỉ nhận thông báo cho VA này; bỏ trống = mọi tài khoản

### `monapay_update_email_config` (~118 tokens)

Sửa cấu hình thông báo email

Cập nhật tên, người nhận, sự kiện, VA hoặc trạng thái bật/tắt của cấu hình email. Người nhận mới phải xác minh trước khi cấu hình hoạt động. / Update an email config; new recipients must be verified before activation.

Input parameters:

- `config_id` (string, required): UUID cấu hình email
- `events` (array)
- `is_active` (boolean)
- `name` (string)
- `recipients` (array)
- `virtual_account_id`: UUID VA; null để bỏ giới hạn VA

### `monapay_delete_email_config` (~44 tokens)

Xoá cấu hình thông báo email

Xoá vĩnh viễn một cấu hình email. / Permanently delete an email notification config.

Input parameters:

- `config_id` (string, required): UUID cấu hình email

### `monapay_verify_email` (~105 tokens)

Xác minh địa chỉ nhận email

Xác minh một người nhận bằng đúng mã 6 số người dùng đọc từ hộp thư; phải hỏi người dùng và không tự đoán mã. / Verify a recipient with the exact 6-digit code supplied by the user; never guess it.

Input parameters:

- `code` (string, required): Mã 6 số do người dùng cung cấp
- `config_id` (string, required): UUID cấu hình email
- `email` (string, required): Địa chỉ đang chờ xác minh

### `monapay_resend_email_verification` (~75 tokens)

Gửi lại mã xác minh email

Gửi mã xác minh mới tới một địa chỉ trong cấu hình; giới hạn 5 lần/địa chỉ/giờ. / Resend a verification code, limited to five requests per address per hour.

Input parameters:

- `config_id` (string, required): UUID cấu hình email
- `email` (string, required)

### `monapay_test_email` (~49 tokens)

Gửi thử thông báo email

Gửi email mẫu tới các địa chỉ đã xác minh trong cấu hình. / Send a test notification to verified recipients in a config.

Input parameters:

- `config_id` (string, required): UUID cấu hình email

### `monapay_email_logs` (~102 tokens)

Lịch sử gửi email

Tra meta từng lần gửi email, không chứa nội dung thư; lọc theo cấu hình, trạng thái, sự kiện và ngày. / List email delivery metadata; message bodies are never stored.

Input parameters:

- `config_id` (string)
- `event_type` (string)
- `from_date` (string)
- `limit` (integer)
- `page` (integer)
- `status` (string)
- `to_date` (string)

### `monapay_email_stats` (~62 tokens)

Thống kê gửi email

Lấy tổng số gửi, tỷ lệ thành công, P95 và nhóm lỗi trong khoảng ngày. / Get email delivery totals, success rate, P95 latency and error groups.

Input parameters:

- `from_date` (string)
- `to_date` (string)

### `monapay_list_email_suppressions` (~38 tokens)

Danh sách email bị chặn gửi

Liệt kê địa chỉ bị suppression do bounce, khiếu nại hoặc tắt tay. / List suppressed recipient addresses.

### `monapay_remove_email_suppression` (~56 tokens)

Gỡ chặn gửi tới một email

Gỡ suppression sau khi đã sửa nguyên nhân; client tự chịu trách nhiệm khi gửi lại. / Remove a suppression after fixing its cause; the client accepts responsibility for future sends.

Input parameters:

- `email` (string, required)

### `monapay_list_zalo_groups` (~31 tokens)

Danh sách nhóm Zalo

Liệt kê cấu hình thông báo nhóm Zalo; nhóm phải có bot Gấu Mona.

### `monapay_create_zalo_group` (~175 tokens)

Nối nhóm Zalo

Nối nhóm có bot Gấu Mona bằng group_id 10–25 chữ số lấy từ MONA Account/PMS; Zalo không parse Markdown, nên template phải là text thuần.

Input parameters:

- `events` (array): Các sự kiện gửi vào nhóm Zalo
- `friendly_name` (string, required): Tên dễ nhớ của nhóm
- `group_id` (string, required): group_id gồm 10–25 chữ số, lấy từ MONA Account/PMS
- `is_active` (boolean)
- `message_template` (string): Text thuần; hỗ trợ {amount}, {description}, {virtual_account_number}, {transaction_code}, {transfer_date} và dạng {{...}}
- `virtual_account_id` (string): Chỉ nhận thông báo cho VA này; bỏ trống = mọi tài khoản

### `monapay_update_zalo_group` (~141 tokens)

Sửa nhóm Zalo

Sửa cấu hình nhóm có bot Gấu Mona; group_id lấy từ MONA Account/PMS và template dùng text thuần vì Zalo không parse Markdown.

Input parameters:

- `events` (array)
- `friendly_name` (string)
- `group_id` (string): group_id gồm 10–25 chữ số, lấy từ MONA Account/PMS
- `id` (string, required): ID cấu hình nhóm Zalo do MONA Pay trả về (UUIDv6)
- `is_active` (boolean)
- `message_template` (string): Template text thuần, không dùng Markdown
- `virtual_account_id` (string)

### `monapay_delete_zalo_group` (~47 tokens)

Xoá nhóm Zalo

Xoá một cấu hình thông báo nhóm Zalo.

Input parameters:

- `id` (string, required): ID cấu hình nhóm Zalo do MONA Pay trả về (UUIDv6)

### `monapay_test_zalo_group` (~57 tokens)

Gửi thử vào nhóm Zalo

Gửi tin thử text thuần; nhóm phải có bot Gấu Mona vì Zalo không parse Markdown.

Input parameters:

- `id` (string, required): ID cấu hình nhóm Zalo do MONA Pay trả về (UUIDv6)

### `monapay_zalo_group_logs` (~46 tokens)

Lịch sử gửi nhóm Zalo

Tra lịch sử gửi vào nhóm Zalo, lọc trạng thái thành công hoặc thất bại.

Input parameters:

- `limit` (integer)
- `status` (string)

### `monapay_retry_transaction` (~56 tokens)

Gửi lại thông báo của một giao dịch

Gửi lại webhook hoặc Telegram cho giao dịch đã có. / Re-send webhook/Telegram for a transaction.

Input parameters:

- `target_id` (string)
- `target_type` (string)
- `transaction_id` (string, required)

### `monapay_generate_key` (~43 tokens)

Tạo API key (client_secret)

Sinh client_secret mới (hiện 1 lần) để dùng header X-Client-Secret. / Generate a client secret.

Input parameters:

- `name` (string)

### `monapay_rotate_key` (~71 tokens)

Xoay secret API key hiện tại

Dùng khi secret nghi lộ; xoay key hiện tại bằng X-Client-Secret. Sau khi xoay phải cập nhật MONAPAY_CLIENT_SECRET ở plugin/agent rồi khởi động lại. / Rotate the current API key secret after suspected exposure, then update MONAPAY_CLIENT_SECRET.

### `monapay_verify_signature` (~92 tokens)

Kiểm chữ ký webhook (offline)

Tính và so chữ ký HMAC-SHA256 của một webhook MONA Pay từ raw body + timestamp + secret, không gọi mạng. / Verify a webhook signature locally.

Input parameters:

- `raw_body` (string, required)
- `secret` (string, required)
- `signature` (string, required)
- `skip_time_check` (boolean)
- `timestamp` (string, required)
- `tolerance_sec` (integer)

### `monapay_generate_webhook_snippet` (~55 tokens)

Code mẫu nhận webhook

Trả code mẫu endpoint nhận webhook MONA Pay + verify HMAC đúng chuẩn cho PHP / Node / Python, kèm payload mẫu. / Get a webhook receiver snippet.

Input parameters:

- `language` (string, required)

### `monapay_quickstart` (~104 tokens)

Bat dau nhan tien: kiem tra trang thai va cac buoc tiep theo

DIEM VAO cho y dinh "toi muon nhan tien chuyen khoan tu dong". Goi tool nay TRUOC: no kiem tra tai khoan (da noi ngan hang/VA chua, da co webhook chua) va tra ve cac BUOC TIEP THEO cu the + recipe end-to-end. / Entry point for "I want to receive bank transfers": checks state and returns concrete next steps + recipe.

### `monapay_get_transaction` (~107 tokens)

Tra 1 giao dich theo ma don hoac ID

Tim 1 giao dich tien vao theo transaction_code (ma don, vd DH10234) hoac id trong mot tai khoan ao; dung de kiem "don X da thanh toan chua". / Get one incoming transaction by code/id within a virtual account.

Input parameters:

- `id_or_code` (string, required): transaction_code (ma don vd DH10234) hoac transaction id
- `virtual_account_number` (string, required): So VA (tu monapay_list_virtual_accounts)

### `monapay_get_transactions_summary` (~102 tokens)

Tong tien vao theo khoang (KHONG phai so du vi)

Tong tien vao + so giao dich + du lieu theo ngay trong khoang chon. LUU Y: MONA Pay KHONG giu tien, khong co "so du vi"; day la tong tien da vao tai khoan ngan hang cua ban. / Incoming totals over a date range (MONA Pay holds no wallet balance).

Input parameters:

- `end_date` (string): YYYY-MM-DD
- `start_date` (string): YYYY-MM-DD

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/vn-monapay-monapay-mcp/monapay-mcp#diagnostics

## Score history

- 2026-09-26: 69
- 2026-09-25: 69
- 2026-09-24: 69
- 2026-09-23: 69
- 2026-09-22: 69
- 2026-09-21: 69
- 2026-09-20: 69
- 2026-09-19: 58

## Common questions

### What is the vn.monapay/monapay-mcp server?

vn.monapay/monapay-mcp is listed in the public MCP registry as vn.monapay/monapay-mcp. MONA Pay for AI agents: create VietQR, check bank transfers, webhooks & HMAC. Vietnam bank API, VND. This page covers its npm package (monapay-mcp).

### Is the vn.monapay/monapay-mcp server safe to use?

vn.monapay/monapay-mcp scores 69 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 26 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the vn.monapay/monapay-mcp server expose?

vn.monapay/monapay-mcp exposes 50 tools: monapay_me, monapay_whoami, monapay_list_bank_accounts, monapay_list_virtual_accounts, monapay_link_bank_start, and 45 more. Their descriptions and schemas cost roughly 4,394 tokens of context every time the server is loaded.

### Is the vn.monapay/monapay-mcp server still maintained?

vn.monapay/monapay-mcp is still listed as active in the MCP registry. We last reached this channel on 26 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the vn.monapay/monapay-mcp server under?

vn.monapay/monapay-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/monapay-mcp
- Socket report: https://socket.dev/npm/package/monapay-mcp
- Repository: https://github.com/themonagroup/monapay-mcp
- Website: https://monapay.vn/
- Changelog RSS feed: https://verifymcp.io/servers/vn-monapay-monapay-mcp/monapay-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/vn-monapay-monapay-mcp/monapay-mcp.json
- HTML version of this page: https://verifymcp.io/servers/vn-monapay-monapay-mcp/monapay-mcp
