YYuno WalletDeveloper docs

MCP

Tool reference

The Wallet MCP tools and the order in which an agent should call them.

An agent should always use the tool results as its source of truth. It must not request a card number in chat or assume an authorization is active before you approve it.

Recommended order

  1. 1

    get_account — inspect account readiness, cards, connected agent, and authorizations.

  2. 2

    get_payment_setup_link — create a safe Wallet link when a card is needed.

  3. 3

    create_authorization — propose the exact authorization for your approval.

  4. 4

    get_authorization — read the authorization status and approval URL.

  5. 5

    check_purchase — evaluate a proposed purchase intent without issuing or reserving anything.

  6. 6

    issue_temporary_card — reserve approved mock budget and issue a purchase-bound temporary synthetic credential.

Tool behavior

get_accountReturns Wallet readiness and next steps.
get_payment_setup_linkReturns a user-owned Wallet URL for secure card setup.
create_authorizationCreates a draft authorization and returns a unique approval URL.
get_authorizationReturns the current authorization state, scope, and remaining allowance.
check_purchaseEvaluates a proposed purchase intent. It issues nothing, reserves nothing, and contacts nobody.
issue_temporary_cardAtomically reserves approved budget and returns a short-lived, purchase-bound synthetic card. No merchant, processor, or payment network is contacted.

OAuth scopes

A connected agent holds wallet:read wallet:authorize wallet:purchase wallet:credentials. The last one, wallet:credentials, is new: it covers the Visa Intelligent Commerce tools that ask Visa for a network credential and report its outcome.

wallet:readRead the account, authorizations, and results.
wallet:authorizePropose an authorization for your approval.
wallet:purchaseEvaluate an intent and issue a temporary mock card.
wallet:credentialsIssue a Visa network credential for an authenticated purchase instruction and report its outcome.

Read every result

Tool responses include a status and a next step. A draft authorization needs your approval. A refused purchase must be corrected by changing the proposed request or creating a new authorization that you approve; an agent should never silently retry an unchanged refusal.

Temporary-card contract

issue_temporary_card takes the approved authorization ID, amount, currency, idempotency key, a merchant with name, URL, and country, and a cart with summary, hash, and items. Merchant category is optional.

{
  "authorization_id": "auth_example",
  "merchant": {
    "name": "Example",
    "url": "https://example.test/checkout",
    "country": "US",
    "category": null
  },
  "amount_minor": 2500,
  "currency": "USD",
  "cart": {
    "summary": "Example item",
    "hash": "sha256:cart-example",
    "items": [
      {"name": "Example item", "quantity": 1, "unit_amount_minor": 2500}
    ]
  },
  "idempotency_key": "issue-example-1"
}

A successful response has this shape:

{
  "status": "issued",
  "mock_only": true,
  "authorization_id": "auth_example",
  "credential_id": "mockcard_example",
  "temporary_card": {
    "number": "0000004827319056",
    "expiration_month": "09",
    "expiration_year": "2026",
    "security_code": "123",
    "expires_at": "2026-09-16T15:05:00Z",
    "namespace": "000000",
    "mock_only": true,
    "non_chargeable": true
  },
  "purchase_binding": {
    "merchant_host": "example.test",
    "amount_minor": 2500,
    "currency": "USD",
    "cart_hash": "sha256:cart-example",
    "binding_hash": "sha256:example-binding-digest"
  },
  "remaining_budget_minor": 7500,
  "explanation": "Synthetic mock credential issued; no purchase was made.",
  "next_tool": "get_authorization"
}

The credential expires after five minutes or sooner when the authorization expires. The same key and identical input replay the same still-valid card with replayed: true and do not reserve budget twice. A changed input conflicts. A second key for the same active intent is refused with TEMPORARY_CARD_ALREADY_ISSUED; retry the original key or wait for expiry. Expired, revoked, or unlinked replays return no card and never extend or replace it. Expiry releases the reservation.