ROKI Connect

Verified ROKI Connect payments contract for coding agents: operations, schemas, validator.

Should I use this

Quality & Safety

B
Description quality
94%
Schema completeness
76%
Naming quality
80%
Poisoning risk
100%
Permission match
80%
Protocol compliance
100%

Findings (5)

  • LOWTool 'roki_get_doc_section' description lacks action verbin roki_get_doc_section
  • LOWTool 'roki_get_operation' description lacks action verbin roki_get_operation
  • LOWTool 'roki_get_authentication_guide' description lacks action verbin roki_get_authentication_guide
  • LOWTool 'roki_get_webhook_guide' suggests web access but openWorldHint=falsein roki_get_webhook_guide
  • LOWTool 'roki_verify_webhook_signature' suggests web access but openWorldHint=falsein roki_verify_webhook_signature

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~2,947Tokens (tool definitions)
~730 BTypical response size
Significant attention impact (2.30% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "connect": {
      "url": "https://mcp.roki.la/mcp"
    }
  }
}

Remote endpoints

https://mcp.roki.la/mcpstreamable-http

What it can do

Tool inventory

Tools (19)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢roki_search_docs(query, limit)

Search the official ROKI Connect corpus (integration guide, API operations and schemas) and return ranked excerpts. Use this first when you need any ROKI-specific fact. Never answer a ROKI question from memory or from another payment gateway's conventions.

Input Schema

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "minLength": 2,
      "description": "What you need to know, e.g. \"webhook signature\", \"tip fields\", \"idempotency\"."
    },
    "limit": {
      "description": "Maximum results (default 6).",
      "type": "integer",
      "minimum": 1,
      "maximum": 15
    }
  },
  "required": [
    "query"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_get_doc_section(ref)

Return the complete text of one section of the integration guide, by number (e.g. "14"), sub-number ("12.1") or title fragment ("webhook").

Input Schema

{
  "type": "object",
  "properties": {
    "ref": {
      "type": "string",
      "description": "Section number, sub-number, or a fragment of its title."
    }
  },
  "required": [
    "ref"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_list_operations

List every operation the API actually exposes, plus the operations that are documented as NOT existing. Call this before writing any integration code so you never invent an endpoint.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_get_operation(operation)

Full detail for one operation: method, path, headers, request schema field table, responses, and worked examples.

Input Schema

{
  "type": "object",
  "properties": {
    "operation": {
      "type": "string",
      "description": "operationId (e.g. \"createPayment\"), or \"METHOD /path\" (e.g. \"POST /payments\")."
    }
  },
  "required": [
    "operation"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_get_schema(name)

Return a fully dereferenced JSON Schema by name (e.g. "PaymentCreateRequest", "Payment", "WebhookEvent"). Use it to know the exact field names, types and constraints.

Input Schema

{
  "type": "object",
  "properties": {
    "name": {
      "description": "Schema name. Omit to list all available schemas.",
      "type": "string"
    }
  },
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_get_error(error)

Explain an HTTP status or an error message returned by the ROKI API: what it means, the likely cause and what to do. Use this instead of guessing when an integration fails.

Input Schema

{
  "type": "object",
  "properties": {
    "error": {
      "type": "string",
      "description": "HTTP status (\"422\"), or a fragment of the message (\"Pago no encontrado\", \"route could not be found\", \"sandbox\")."
    }
  },
  "required": [
    "error"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_validate_request(operation, payload)

Validate a payload against the official schema WITHOUT sending it, and check the business rules the API enforces. Critical for this API: it ignores unknown fields and returns 201, so a typo produces a misconfigured payment rather than an error. The response names what it dropped in `warnings`, but by then the payment exists - validating here means it is never created. Always validate before writing or shipping integration code.

Input Schema

{
  "type": "object",
  "properties": {
    "operation": {
      "type": "string",
      "description": "operationId, e.g. \"createPayment\"."
    },
    "payload": {
      "type": "object",
      "propertyNames": {
        "type": "string"
      },
      "additionalProperties": {},
      "description": "The JSON request body you intend to send."
    }
  },
  "required": [
    "operation",
    "payload"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_check_result(sent, received)

Compare the payment the API returned against the body you sent, and report anything that does not match. Every other check here looks at what you SEND. This one exists for the errors that survive that: the field name was right and the VALUE was wrong. The API answers 201, `warnings` comes back empty because there was nothing to warn about, and the merchant charged something else. Catches the amount off by a factor of 100, fee pass-through asked for and returned as zero, tax that was not applied, `expires_at` already in the past because it was sent as UTC instead of Honduras time, a total that does not add up, and a `transaction_id` parsed as a number. Run it after every createPayment while you are building, and in your own tests afterwards.

Input Schema

{
  "type": "object",
  "properties": {
    "sent": {
      "type": "object",
      "propertyNames": {
        "type": "string"
      },
      "additionalProperties": {},
      "description": "The JSON request body you sent to POST /payments."
    },
    "received": {
      "type": "object",
      "propertyNames": {
        "type": "string"
      },
      "additionalProperties": {},
      "description": "The payment object the API returned. Paste the response as-is."
    }
  },
  "required": [
    "sent",
    "received"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_get_integration_example(stack)

Return a complete, runnable integration example for a stack: configuration, API client, checkout flow, webhook handler with signature verification, and polling fallback.

Input Schema

{
  "type": "object",
  "properties": {
    "stack": {
      "description": "e.g. \"laravel\", \"php\", \"node\", \"express\", \"python\", \"fastapi\". Omit to list what is available.",
      "type": "string"
    }
  },
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_get_quickstart

The minimum viable integration sequence, end to end, including the manual portal steps a developer cannot skip.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_get_authentication_guide

How authentication works, how the two environments are selected, where credentials come from, and how to store and rotate them safely.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_get_webhook_guide

Everything about webhooks: portal registration, event types, payload shape, HMAC signature verification over the raw body, idempotent processing, and the polling fallback.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_choose_integration_mode(context)

Decide how to integrate ROKI Connect for a given project (web checkout, embedded card fields, mobile app, invoices or recurring billing) and get the constraints that apply before writing code. The modes and the endpoints behind them are read from the corpus, so this answer cannot describe a mode the API no longer has - or miss one it gained.

Input Schema

{
  "type": "object",
  "properties": {
    "context": {
      "type": "string",
      "description": "What the project is: e.g. \"Laravel e-commerce checkout\", \"iOS app\", \"card fields on my own page\", \"invoices from an ERP\", \"monthly subscriptions\"."
    }
  },
  "required": [
    "context"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_verify_webhook_signature(raw_body, signature_header, signing_secret)

Check a ROKI-Signature header against the raw body and the signing secret. When it fails, this does not just say "invalid" - it tries the specific wrong constructions developers actually write and tells you which mistake you made. Use it whenever webhook verification rejects real events. On the signing secret: this is ROKI's own server and ROKI issued that secret, so sending it here discloses nothing new. It is used to recompute the HMAC and is never stored, logged or counted.

Input Schema

{
  "type": "object",
  "properties": {
    "raw_body": {
      "type": "string",
      "description": "The EXACT raw request body as received, byte for byte, before any JSON parsing."
    },
    "signature_header": {
      "type": "string",
      "description": "The full ROKI-Signature header value, e.g. \"t=1719234300,v1=8f3c...\""
    },
    "signing_secret": {
      "type": "string",
      "description": "The signing secret from the portal, for the same environment as the event. Held in memory for the duration of the call only: this server logs no tool arguments."
    }
  },
  "required": [
    "raw_body",
    "signature_header",
    "signing_secret"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_scaffold_integration(stack, mode)

Return the full runnable skeleton for a stack: credential storage, API client, checkout flow, webhook handler with signature verification, and the polling fallback. Use it to start an integration instead of assembling one from memory.

Input Schema

{
  "type": "object",
  "properties": {
    "stack": {
      "type": "string",
      "description": "e.g. \"laravel\", \"node\", \"express\", \"python\", \"fastapi\", \"php\"."
    },
    "mode": {
      "description": "\"hosted\" (default), \"embedded\" or \"saved-card\".",
      "type": "string"
    }
  },
  "required": [
    "stack"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_audit_integration(focus)

Return the checklist to audit existing ROKI code, ordered by how badly each item fails in production. Use it when reviewing an integration you did not write, or before going live.

Input Schema

{
  "type": "object",
  "properties": {
    "focus": {
      "description": "Optional area: \"webhooks\", \"security\", \"payments\", \"reversals\".",
      "type": "string"
    }
  },
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪roki_sandbox_try(operation, payload)

Runs a documented operation against the ROKI sandbox using THIS SERVER'S own test credential, and returns the actual response. Use it to prove an integration works instead of assuming it does - especially after roki_validate_request says a payload is valid. You never supply a key: this server holds a sandbox-only credential and refuses to run against production. Amounts are capped and links expire quickly, because the sandbox is shared.

Input Schema

{
  "type": "object",
  "properties": {
    "operation": {
      "type": "string",
      "description": "operationId to run, e.g. \"createPayment\", \"getPayment\", \"voidTransaction\"."
    },
    "payload": {
      "description": "Request body for POST operations, or path values such as {\"id\": 123} / {\"transaction_id\": \"uuid\"}.",
      "type": "object",
      "propertyNames": {
        "type": "string"
      },
      "additionalProperties": {}
    }
  },
  "required": [
    "operation"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_sandbox_info

Whether the sandbox playground is enabled here, which operations it accepts, its limits, and the sandbox test cards.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢roki_status

Server version, corpus contents and freshness. Safe first call to confirm the connection works. Exposes no credentials and no merchant data.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}

Recommended Prompts

search_research
Search for information about [topic] using ROKI Connect
Expected tools: roki_search_docs
find_specific
Find [specific item] using ROKI Connect
Expected tools: roki_search_docs
retrieve_data
Get details about [item] from ROKI Connect
Expected tools: roki_get_doc_section
fetch_info
Fetch [information type] using ROKI Connect
Expected tools: roki_get_doc_section
list_items
List all [items] available in ROKI Connect
Expected tools: roki_list_operations

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded19 tools
verifiedversion not recorded19 tools