IMBA Agent Spend
IMBA spend MCP: USDT TRC-20 deposit and catalog buy with your key. No withdraw.
사용해야 할까요
품질 및 안전성
발견 사항 (2)
- LOWlist_cards에서
- LOWtopup_card에서
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"agent": {
"command": "npx",
"args": [
"@imba_wallet/agent-mcp"
]
}
}
}실행 가능한 패키지
0.1.4stdio원격 엔드포인트
https://imbawallet.com/mcp/spendstreamable-http할 수 있는 일
도구 목록
도구 (19)
🟢get_spend_policy
Forbidden rails and tier rules. Allowed catalog: Visa prepaid, travel eSIM, gift cards, paid KYT address screen. Read-only.
입력 스키마
{
"type": "object",
"properties": {}
}🟡get_deposit_address
POST /api/deposit_address blockchain=tron. Address is issued for the authenticated agent only. Always re-fetch before send. Do not cache. USDT TRC-20 only. 24h unfunded hold.
입력 스키마
{
"type": "object",
"properties": {}
}🟢get_balance
GET /api/balance. USDT is the spendable catalog currency.
입력 스키마
{
"type": "object",
"properties": {}
}🟢list_cards
POST /api/cards for the authenticated agent. No client_id argument.
입력 스키마
{
"type": "object",
"properties": {}
}🟢list_card_products
POST /api/card_products. Use id as imba_product_id for create_card (Visa prepaid). Space catalog calls ~1s apart.
입력 스키마
{
"type": "object",
"properties": {}
}🟢list_gift_offers(query)
POST /api/offers. Live gift catalog (~20k positions / ~2k unique: Apple, Google Play, Steam, games, travel, retail). Optional query string. Then purchase_gift with offer_id + ext_id. Space catalog calls ~1s apart. Do not assume a SKU.
입력 스키마
{
"type": "object",
"properties": {
"query": {
"type": "string",
"maxLength": 64
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_esim_plans(country, esim_provider)
POST /api/esim/plans. Travel/data eSIM. esim_provider=yesim. Optional country ISO2. Use plan id with purchase_esim. Space catalog calls ~1s apart (agent catalog_gap).
입력 스키마
{
"type": "object",
"properties": {
"country": {
"type": "string",
"maxLength": 8
},
"esim_provider": {
"type": "string",
"maxLength": 32
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🔴create_card(imba_product_id, ext_id, email, phone, first_name, ...)
Issue a Visa/MasterCard prepaid from this agent 2401 USDT so the agent can pay merchants that require a card (airlines, hotels, SaaS, datacenter/GPU clouds). POST /api/pin/create_card. ext_id required. imba_product_id is core.card_product.id. Never payment_source=stars. Never pass client_id. IMBA does not create the booking.
입력 스키마
{
"type": "object",
"properties": {
"imba_product_id": {
"type": "integer",
"exclusiveMinimum": 0,
"maximum": 9007199254740991
},
"ext_id": {
"type": "string",
"minLength": 1,
"maxLength": 128,
"description": "Idempotency key. Reuse the same id to retry the same order."
},
"email": {
"description": "Cardholder KYC email, not the agent 3DS mailbox.",
"type": "string",
"maxLength": 254
},
"phone": {
"type": "string",
"maxLength": 32
},
"first_name": {
"type": "string",
"maxLength": 64
},
"last_name": {
"type": "string",
"maxLength": 64
},
"birth_date": {
"type": "string",
"maxLength": 32
},
"country": {
"type": "string",
"maxLength": 8
}
},
"required": [
"imba_product_id",
"ext_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🔴topup_card(card_id, amount, ext_id)
POST /api/pin/topup_card from this agent 2401 USDT. card_id must belong to the same agent (SQL owner guard). ext_id required. Never Stars.
입력 스키마
{
"type": "object",
"properties": {
"card_id": {
"type": "string",
"minLength": 1,
"maxLength": 256
},
"amount": {
"type": "number",
"exclusiveMinimum": 0,
"maximum": 1000000
},
"ext_id": {
"type": "string",
"minLength": 1,
"maxLength": 128
}
},
"required": [
"card_id",
"amount",
"ext_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🔴purchase_gift(offer_id, ext_id, required_fields, expected_price, payment_source)
POST /api/purchase. Buy a brand gift code (Apple, Steam, Google Play, … — live list). ext_id required. Never payment_source=stars.
입력 스키마
{
"type": "object",
"properties": {
"offer_id": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"ext_id": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"required_fields": {
"type": "object",
"propertyNames": {
"type": "string",
"maxLength": 64
},
"additionalProperties": {
"type": "string",
"maxLength": 512
}
},
"expected_price": {
"type": "object",
"propertyNames": {
"type": "string",
"maxLength": 32
},
"additionalProperties": {
"type": "number"
}
},
"payment_source": {
"type": "string",
"maxLength": 32
}
},
"required": [
"offer_id",
"ext_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🔴purchase_esim(plan_id, ext_id, iccid, payment_source)
POST /api/esim/new_plan5. Buy a travel/data eSIM plan from this agent 2401. Omit blank/null iccid so SQL takes the new-eSIM path. A set iccid must already belong to this agent. ext_id required. Never Stars.
입력 스키마
{
"type": "object",
"properties": {
"plan_id": {
"type": "string",
"minLength": 1,
"maxLength": 64
},
"ext_id": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"iccid": {
"type": "string",
"maxLength": 32
},
"payment_source": {
"type": "string",
"maxLength": 32
}
},
"required": [
"plan_id",
"ext_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢get_card_details(card_id, cvv)
POST /api/pin/get_card_details for a card this agent owns. Needed to present PAN at merchant checkout (airline, datacenter, SaaS). PAN/CVV arrive as card_encrypted JWE when jwe_public_key is registered (PATCH webhook). Without that key the number is masked. Never logs raw PAN. cvv defaults true. Never pass client_id.
입력 스키마
{
"type": "object",
"properties": {
"card_id": {
"type": "string",
"minLength": 1,
"maxLength": 256
},
"cvv": {
"type": "boolean"
}
},
"required": [
"card_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢list_notifications(category, limit, prev_ts, prev_id)
POST /api/notifications. Poll this when a Visa payment asks for 3-D Secure. Agents keep payload.code (never SMS, never Telegram). category=codes for 3-D Secure OTP. Also delivered on webhook field otp if callback_url is set, and optional email. Space catalog calls ~1s apart.
입력 스키마
{
"type": "object",
"properties": {
"category": {
"type": "string",
"enum": [
"all",
"codes",
"support",
"tx"
]
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 100
},
"prev_ts": {
"type": "number"
},
"prev_id": {
"type": "integer",
"minimum": -9007199254740991,
"maximum": 9007199254740991
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟡set_webhook(callback_url, jwe_public_key, email)
PATCH /auth/v1/agent/webhook. Sets https callback_url (required before hmac/rotate), optional X25519 jwe_public_key for card_encrypted, optional email for 3DS OTP. Not SMS. HMAC plaintext is shown once when a URL is first accepted.
입력 스키마
{
"type": "object",
"properties": {
"callback_url": {
"type": "string",
"maxLength": 512
},
"jwe_public_key": {
"type": "string",
"maxLength": 4096
},
"email": {
"type": "string",
"maxLength": 254
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🔴rotate_hmac(callback_url, jwe_public_key, email)
POST /auth/v1/agent/hmac/rotate. Previous HMAC dies immediately. Requires an existing callback_url (400 callback_url required before rotate otherwise). Pass callback_url here to PATCH webhook first. Plaintext HMAC is returned once — store it; never a Wallet JWT.
입력 스키마
{
"type": "object",
"properties": {
"callback_url": {
"type": "string",
"maxLength": 512
},
"jwe_public_key": {
"type": "string",
"maxLength": 4096
},
"email": {
"type": "string",
"maxLength": 254
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢kyt_quote
POST /api/kyt_quote. Price for a paid crypto-address screen (Didit). Debit is on kyt_check (~0.99 USDT from 2401), not on quote. Off unless didit.enabled and didit.agent_api. Does not gate TRON deposit. Not /api/client/kyt_* and not partner. Space ~1s.
입력 스키마
{
"type": "object",
"properties": {}
}🔴kyt_check(network, address, refresh)
Screen a crypto address for dirt (sanctions / mixer exposure). Use BEFORE you accept a TRC-20 send, or AFTER a wallet is blocked and the reason is unclear. POST /api/kyt_check. Body: network (tron_usdt | eth | btc) + address. Debits ~0.99 USDT from 2401. Returns a report — does not gate deposit, does not ban or unblock. TON is not in this catalog. Never pass client_id. Space ~1s.
입력 스키마
{
"type": "object",
"properties": {
"network": {
"type": "string",
"minLength": 2,
"maxLength": 32
},
"address": {
"type": "string",
"minLength": 8,
"maxLength": 128
},
"refresh": {
"type": "boolean"
}
},
"required": [
"network",
"address"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢kyt_check_get(id)
POST /api/kyt_check_get. Poll until the report is ready. Own check only (404 otherwise). Use after kyt_check when a wallet was blocked and you need the dirt report. Never pass client_id.
입력 스키마
{
"type": "object",
"properties": {
"id": {
"type": "integer",
"exclusiveMinimum": 0,
"maximum": 9007199254740991
}
},
"required": [
"id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢kyt_checks(limit, last_id)
POST /api/kyt_checks. Own KYT history plus quote fields. Use to find a past address check. Space ~1s. Never pass client_id.
입력 스키마
{
"type": "object",
"properties": {
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 100
},
"last_id": {
"type": "integer",
"exclusiveMinimum": 0,
"maximum": 9007199254740991
}
},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}커뮤니티
증거