This server acts on your fiat account. To give an agent its own crypto wallet, use the Agentic Wallet MCP server. To let an assistant read these docs, use the Docs MCP server. See AI and MCP servers to compare them.
The MCP server is available in production only for now. Try the quote step on small amounts first.
Sign in
Both act on the same business account and follow your team permissions. A teammate who can’t create payouts in the dashboard can’t create them through MCP either.
OAuth sign-in:
- Enter your Yativo account email.
- Enter the 6-digit code sent to that email.
- If you use two-factor authentication, enter the code from your authenticator app.
- Review what the app can do and click Allow access.
Connect a client
claude.ai and Claude Desktop
- Open Settings → Connectors → Add custom connector.
- Name it Yativo and enter
https://api.yativo.com/mcp. - Click Connect, sign in and click Allow access.
Claude Code
With OAuth:/mcp, select yativo and choose Authenticate.
With an API key, from a whitelisted IP:
Cursor
Add to~/.cursor/mcp.json, or .cursor/mcp.json in a project. Cursor opens the Yativo sign-in page:
"headers": { "X-Api-Key": "yativo_pk_...", "X-Api-Secret": "yativo_sk_..." }.
VS Code
Add to.vscode/mcp.json. VS Code opens the Yativo sign-in page:
Other clients
Any client that supports Streamable HTTP can connect, either with the two API-key headers or through MCP OAuth. The server advertises OAuth at/.well-known/oauth-protected-resource/mcp and supports dynamic client registration and PKCE (S256).
Tools
Read-only tools are marked
readOnlyHint. create-payout is marked destructiveHint, so MCP clients ask you to approve each call.
Balances are in major units: 1250.5 means 1,250.50. usd_equivalent uses a live reference rate, is for display only, and is null when no rate is available.
get-wallet-balances
Sending payouts
create-payout runs the same checks as a payout through the REST API: team permissions, KYC, limits, fees and idempotency. Your wallet is debited as soon as the payout is accepted.
The server tells the assistant to follow this flow and to wait for your confirmation before sending:
1
Find the beneficiary
list-beneficiaries returns each beneficiary’s saved payment methods under payment_object. The payment method’s id is payment_method_id, its gateway_id is the quote’s payout_method_id, and the beneficiary’s customer_id is used in both.2
Quote
get-payout-quote shows the rate, fees, total debit and the amount the beneficiary receives.3
Confirm
The assistant shows you the quote and beneficiary and waits for your approval.
4
Send
create-payout with a new idempotency_key, such as a UUID.5
Track
get-payout with the returned payout_id, or your webhooks.create-payout with the same idempotency_key returns the original payout and never sends a second one. A failed payout, for example below the method’s minimum, returns isError: true with the reason, and your wallet isn’t left debited.
Example prompts
- “What’s my current Yativo balance in each currency?”
- “Show my last 10 payouts that failed and summarise why.”
- “Which payout methods do you support for CLP?”
- “Quote sending 200 USD to Rick’s Chilean bank account.”
- “Send it.” (after reviewing the quote)
Call the server directly
You can test with any HTTP client. Send one JSON-RPC request perPOST:
Errors
Sign-in errors are plain HTTP responses in the standard Yativo error format, not JSON-RPC:
Every
401 includes a WWW-Authenticate header that OAuth clients use to start or renew sign-in automatically.
Once signed in, tool errors come back as a normal result with isError: true and the reason as text, so the assistant can act on it. Invalid arguments, such as per_page above 50, are reported the same way.
Rate limits
Each account can make 60 MCP requests per minute. Everyinitialize, tools/list and tools/call counts. Payouts are also subject to the API’s own rate limits.
Manage connected apps
Apps connected with OAuth belong to the person who approved them. List connected apps:GET /api/v1/mcp/connections
DELETE /api/v1/mcp/connections/{client_id}
client_id returns 404 Connection not found.
Clients that use an API key are disconnected by revoking the key.
Security best practices
- Keep approval prompts on. Don’t set
create-payoutto “always allow”. - Use team permissions. Connect assistants as teammates with the least access they need.
- One connection or key per assistant or machine. Label keys, for example “Cursor – Ana’s laptop”, and disconnect apps you no longer use.
- Keep secrets out of repositories. Use OAuth sign-in, environment variables or your client’s secret storage.
- Treat tool output as sensitive. Beneficiary data includes names, emails and bank details. Only connect AI apps your company allows to process that data.
FAQ
Can the assistant send money without asking me?
Can the assistant send money without asking me?
The server tells the assistant to quote first and wait for your confirmation, and MCP clients ask you to approve each
create-payout call. Keep that prompt on.What if the assistant retries a payout?
What if the assistant retries a payout?
With the same
idempotency_key you get the original payout back, and nothing is sent twice.Can teammates use it?
Can teammates use it?
Yes. Each teammate signs in with OAuth and acts on the business account with their own permissions. API keys act as the business account owner.
Which data can the assistant see?
Which data can the assistant see?
Only the account you signed in to, or that owns the API key: its wallets, payouts, deposits and beneficiaries, plus the public list of payout methods.

