com.imbawallet/agent
pkg:npm:@imba_wallet/agent-mcp
IMBA spend MCP: USDT TRC-20 deposit and catalog buy with your key. No withdraw.
- transport:
- remote + stdio
- credential class:
- open
Owner verification
Not yet verified. Verifying proves you control this server and is free, permanently — it never changes a published score.
Start verification →Tools
- create_cardshallow
POST /api/pin/create_card from this agent 2401 USDT. ext_id required. imba_product_id is core.card_product.id. Never payment_source=stars. Never pass client_id.
- get_balanceshallow
GET /api/balance. USDT is the spendable catalog currency.
- get_card_detailsshallow
POST /api/pin/get_card_details for a card this agent owns. PAN/CVV arrive as card_encrypted JWE when jwe_public_key is registered (PATCH webhook). Without that key the number is masked. Never logs raw PAN. cvv defaults true. Never pass client_id.
- get_deposit_addressshallow
POST /api/deposit_address blockchain=tron. Address is issued for the authenticated agent only. Always re-fetch before send. Do not cache. USDT TRC-20 only. 24h unfunded hold.
- get_spend_policyshallow
Forbidden rails and tier rules. Read-only.
- kyt_checkshallow
POST /api/kyt_check. Body network + address only (JWT client). Debits ~0.99 USDT from 2401. Not partner KYT. Never pass client_id. Space catalog calls ~1s apart.
- kyt_check_getshallow
POST /api/kyt_check_get. Own check only (404 otherwise). Never pass client_id.
- kyt_checksshallow
POST /api/kyt_checks. Own history plus quote fields. Space catalog calls ~1s apart. Never pass client_id.
- kyt_quoteshallow
POST /api/kyt_quote (client schema, not /api/client/kyt_* and not partner). Debits 2401 when a check runs. Off unless didit.enabled and didit.agent_api. Does not gate TRON deposit. Space catalog calls ~1s apart.
- list_card_productsshallow
POST /api/card_products. Use id as imba_product_id for create_card. Space catalog calls ~1s apart.
- list_cardsshallow
POST /api/cards for the authenticated agent. No client_id argument.
- list_esim_plansshallow
POST /api/esim/plans. esim_provider=yesim. Optional country ISO2. Use plan id with purchase_esim. Space catalog calls ~1s apart (agent catalog_gap).
- list_gift_offersshallow
POST /api/offers. Optional query string. Then purchase_gift with offer_id + ext_id. Space catalog calls ~1s apart.
- list_notificationsshallow
POST /api/notifications. Agents keep payload.code (never SMS, never Telegram). category=codes for 3-D Secure OTP. Also delivered on webhook field otp if callback_url is set, and optional email. Space catalog calls ~1s apart.
- purchase_esimshallow
POST /api/esim/new_plan5 from this agent 2401. Omit blank/null iccid so SQL takes the new-eSIM path. A set iccid must already belong to this agent. ext_id required. Never Stars.
- purchase_giftshallow
POST /api/purchase. ext_id required. Never payment_source=stars.
- rotate_hmacshallow
POST /auth/v1/agent/hmac/rotate. Previous HMAC dies immediately. Requires an existing callback_url (400 callback_url required before rotate otherwise). Pass callback_url here to PATCH webhook first. Plaintext HMAC is returned once — store it; never a Wallet JWT.
- set_webhookshallow
PATCH /auth/v1/agent/webhook. Sets https callback_url (required before hmac/rotate), optional X25519 jwe_public_key for card_encrypted, optional email for 3DS OTP. Not SMS. HMAC plaintext is shown once when a URL is first accepted.
- topup_cardshallow
POST /api/pin/topup_card from this agent 2401 USDT. card_id must belong to the same agent (SQL owner guard). ext_id required. Never Stars.
Embed this server’s score
Tool count and median score across every tool in this server’s corpus — honest in a way a single cherry-picked tool’s badge wouldn’t be.
[](https://vouch.tools/servers/7ac256dc-c9c4-455a-879f-208e9164e3ce)