{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "adyen-mcp-server",
    "name": "Adyen MCP server",
    "vendor": "Adyen N.V.",
    "vendorUrl": "https://www.adyen.com",
    "kind": "mcp",
    "category": "payment-platforms",
    "summary": "Adyen's official MCP server lets an AI client call Adyen's Checkout, Management, Legal Entity Management and Balance Platform APIs with a merchant's API key. It runs locally over stdio through `npx @adyen/mcp` and is labelled alpha.",
    "url": "https://www.anchorterminal.com/tools/adyen-mcp-server",
    "markdownUrl": "https://www.anchorterminal.com/tools/adyen-mcp-server.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/adyen-mcp-server.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/adyen-mcp-server.json",
    "repo": "https://github.com/Adyen/adyen-mcp",
    "license": "MIT for the server. The Adyen APIs it calls are a closed service under a merchant agreement and the Adyen Terms and Conditions",
    "transports": [
      "stdio"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "@adyen/mcp"
      }
    ],
    "auth": "api-key",
    "authNotes": "The server needs an Adyen API key, read from `ADYEN_API_KEY` or the `--adyenApiKey` flag, and sends it to Adyen through `@adyen/api-library`. A person creates the key in the Customer Area under Developers, API credentials. Each credential has roles that set what it may do, and a company-level credential reaches every linked merchant account. Generating a new key leaves the old one active for 24 hours. The README lists 16 roles for the full tool set and advises a new credential used only for the server, with roles cut to the tools in use.",
    "pricing": "usage",
    "pricingNotes": "The server is free and MIT. Adyen charges for live payments, a fixed processing fee of $0.13 per transaction plus a fee set by the payment method, with no setup or monthly fee per the pricing page. Many methods are listed at interchange plus 0.60%. The pricing FAQ says a minimum invoice applies depending on industry or business model, through sales. A developer test account is free through a signup form, and Adyen says it does not guarantee approval as a customer (checked 2026-10-09).",
    "priceSummary": "$0.13 / tx",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the MCP docs page, the repository or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 38,
    "popularity": {
      "githubStars": 27,
      "npmWeekly": 168,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.adyen.com/development-resources/mcp-server",
    "llmsTxt": "https://docs.adyen.com/llms.txt",
    "capabilities": [
      "payments.checkout",
      "payments.card"
    ],
    "tags": [
      "official",
      "local",
      "open-source",
      "mcp",
      "api-key",
      "sandbox",
      "alpha",
      "typescript",
      "llms-txt",
      "status-page"
    ],
    "lastRelease": "2026-08-24",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 60.3,
      "grade": "C",
      "agentReady": false,
      "rank": 471,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 56,
        "maintenance": 42,
        "payments": 35,
        "reliability": 65,
        "schema": 73,
        "security": 63,
        "transparency": 83
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 65,
          "points": 13,
          "reason": "Read on the local-software lines, because the server runs on the owner's machine over stdio. It installs from the official npm package `@adyen/mcp`, published from GitHub Actions with a provenance attestation, with Node 18 or later stated (20). The repository has a test workflow on every push and four vitest files of 959 lines. GitHub's API refused us before we read the latest run, so a passing result is unconfirmed (18 of 25). One bug report is open, filed on 7 October 2026 and unanswered on the day, about refunds repeated after a timeout. Earlier issues were answered within three days (19 of 25). Releases are tagged by version with notes on GitHub and a breaking-change category in the release template, but there is no changelog file and 0.6.0 reports itself as 0.4.0 (8 of 15). The README is headed alpha and the version is 0.6.0 (0)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 73,
          "points": 11.86,
          "reason": "Every tool is registered with a zod shape that the MCP SDK turns into JSON Schema (25). docs.adyen.com has an llms.txt and a Markdown twin of every page, the MCP page included (10). Descriptions give arguments, returns, notes and an example, and several say when to pick another tool. Some are wrong. `refund_payment` names `paymentPspReference` where the schema has `pspReference` and omits the required `reference`, and `cancel_payment` points to reversal tools that do not exist (12 of 20). Terminal tools have enums and described fields. The checkout tools take currency, country and status as free strings (9 of 15). Each description has an example. No error reference for the tools was found, though Adyen documents HTTP status and error codes for the APIs (8 of 15). Releases are versioned with notes on GitHub, while the docs page was last modified on 11 June 2025 and names two of the four APIs covered (9 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 56,
          "points": 9.1,
          "reason": "The default loads 38 tools (5), and `--tools` takes a comma-separated subset, which the README advises (8 back, 13 of 25). Terminal list tools take `pageNumber` and `pageSize` and filters. Other tools return the raw API response as one JSON string with no size control (11 of 20). Failures come back as readable text with the API's message, sanitised since 0.5.0, but without `isError` and with no documented codes (8 of 20). All 38 tools carry read-only, destructive and idempotent hints, checked by a test. No POST tool sends an idempotency key, although the API supports one (13 of 20). The test environment is the default and the checkout tools need two to five fields. The server ships for Node only (11 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 63,
          "points": 11.03,
          "reason": "The credential is an Adyen API key on a web service user with roles and company or merchant scope, replaceable at any time with 24 hours of overlap. The docs page still shows the key on the command line, and 0.6.0 added the environment variable and a warning for live use (26 of 30). `--tools` and roles narrow what the server can do, the test environment is the default, and writes are annotated. No read-only switch and no confirmation step for refunds or terminal changes was found (11 of 20). Tools return webhook settings, user records and payment data written by other people, and no guidance on untrusted content was found (3 of 15). The Customer Area keeps API logs of each request and response for 30 days (12 of 15). Adyen has a responsible disclosure policy with a 60-day fix target and a hall of fame, its terms commit to PCI DSS certification, and the repository runs CodeQL. security.txt expired on 31 December 2025, the repository has no security policy file, and no bug bounty was found (11 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 35,
          "points": 4.38,
          "reason": "The server is free, so pricing is read on the Adyen account it needs. No x402, MPP or L402 in the docs page, the repository or the pricing page (0). The pricing page lists per-transaction fees without a login, $0.13 plus the payment method's fee, with no setup or monthly fee (20). A developer test account is free through a signup form. The form's fields are drawn by script, so whether it asks for a card was not read, and a minimum invoice applies to live accounts (15 of 20). A person has to sign up, and live accounts go through sales (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 42,
          "points": 3.68,
          "reason": "0.6.0 was published on 24 August 2026, 46 days before this check (20 of 30). It is the only release in the last 90 days, with 0.5.0 on 22 April (0). Maintainers answered two outside issues within one and three days in September and merged dependency updates on 11 September. Two outside pull requests from July were still open, and the 7 October bug report had no reply after two days (15 of 25). The repository has no `server.json` or `mcpName`, and the one page of the official registry we could read listed only a third party's Adyen server (0). Renovate, CodeQL, lint and test workflows run, and npm publishing uses provenance. `@adyen/api-library` is pinned at version 27 while an update to 32 waits (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "note": "editorial 72, provenance 93",
          "reason": "The server is MIT on GitHub (30). It runs locally and sends requests only to Adyen's APIs. Adyen's privacy statement of 4 August 2025 and a sub-processor list of 1 July 2026 are public. We did not read retention periods, and nothing addresses MCP use (20 of 30). Adyen documents API versioning and what counts as a breaking change. The server has no deprecation policy and is labelled alpha (8 of 20). No telemetry code was found in the source. The server sets the application name `adyen-mcp-server 0.4.0` on its API requests, which the README does not mention (14 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The default loads 38 tools (5), and `--tools` takes a comma-separated subset, which the README advises (8 back, 13 of 25). Terminal list tools take `pageNumber` and `pageSize` and filters. Other tools return the raw API response as one JSON string with no size control (11 of 20). Failures come back as readable text with the API's message, sanitised since 0.5.0, but without `isError` and with no documented codes (8 of 20). All 38 tools carry read-only, destructive and idempotent hints, checked by a test. No POST tool sends an idempotency key, although the API supports one (13 of 20). The test environment is the default and the checkout tools need two to five fields. The server ships for Node only (11 of 15).",
          "maintenance": "0.6.0 was published on 24 August 2026, 46 days before this check (20 of 30). It is the only release in the last 90 days, with 0.5.0 on 22 April (0). Maintainers answered two outside issues within one and three days in September and merged dependency updates on 11 September. Two outside pull requests from July were still open, and the 7 October bug report had no reply after two days (15 of 25). The repository has no `server.json` or `mcpName`, and the one page of the official registry we could read listed only a third party's Adyen server (0). Renovate, CodeQL, lint and test workflows run, and npm publishing uses provenance. `@adyen/api-library` is pinned at version 27 while an update to 32 waits (7 of 10).",
          "payments": "The server is free, so pricing is read on the Adyen account it needs. No x402, MPP or L402 in the docs page, the repository or the pricing page (0). The pricing page lists per-transaction fees without a login, $0.13 plus the payment method's fee, with no setup or monthly fee (20). A developer test account is free through a signup form. The form's fields are drawn by script, so whether it asks for a card was not read, and a minimum invoice applies to live accounts (15 of 20). A person has to sign up, and live accounts go through sales (0).",
          "reliability": "Read on the local-software lines, because the server runs on the owner's machine over stdio. It installs from the official npm package `@adyen/mcp`, published from GitHub Actions with a provenance attestation, with Node 18 or later stated (20). The repository has a test workflow on every push and four vitest files of 959 lines. GitHub's API refused us before we read the latest run, so a passing result is unconfirmed (18 of 25). One bug report is open, filed on 7 October 2026 and unanswered on the day, about refunds repeated after a timeout. Earlier issues were answered within three days (19 of 25). Releases are tagged by version with notes on GitHub and a breaking-change category in the release template, but there is no changelog file and 0.6.0 reports itself as 0.4.0 (8 of 15). The README is headed alpha and the version is 0.6.0 (0).",
          "schema": "Every tool is registered with a zod shape that the MCP SDK turns into JSON Schema (25). docs.adyen.com has an llms.txt and a Markdown twin of every page, the MCP page included (10). Descriptions give arguments, returns, notes and an example, and several say when to pick another tool. Some are wrong. `refund_payment` names `paymentPspReference` where the schema has `pspReference` and omits the required `reference`, and `cancel_payment` points to reversal tools that do not exist (12 of 20). Terminal tools have enums and described fields. The checkout tools take currency, country and status as free strings (9 of 15). Each description has an example. No error reference for the tools was found, though Adyen documents HTTP status and error codes for the APIs (8 of 15). Releases are versioned with notes on GitHub, while the docs page was last modified on 11 June 2025 and names two of the four APIs covered (9 of 15).",
          "security": "The credential is an Adyen API key on a web service user with roles and company or merchant scope, replaceable at any time with 24 hours of overlap. The docs page still shows the key on the command line, and 0.6.0 added the environment variable and a warning for live use (26 of 30). `--tools` and roles narrow what the server can do, the test environment is the default, and writes are annotated. No read-only switch and no confirmation step for refunds or terminal changes was found (11 of 20). Tools return webhook settings, user records and payment data written by other people, and no guidance on untrusted content was found (3 of 15). The Customer Area keeps API logs of each request and response for 30 days (12 of 15). Adyen has a responsible disclosure policy with a 60-day fix target and a hall of fame, its terms commit to PCI DSS certification, and the repository runs CodeQL. security.txt expired on 31 December 2025, the repository has no security policy file, and no bug bounty was found (11 of 20).",
          "transparency": "The server is MIT on GitHub (30). It runs locally and sends requests only to Adyen's APIs. Adyen's privacy statement of 4 August 2025 and a sub-processor list of 1 July 2026 are public. We did not read retention periods, and nothing addresses MCP use (20 of 30). Adyen documents API versioning and what counts as a breaking change. The server has no deprecation policy and is labelled alpha (8 of 20). No telemetry code was found in the source. The server sets the application name `adyen-mcp-server 0.4.0` on its API requests, which the README does not mention (14 of 20)."
        },
        "sources": [
          {
            "what": "MCP server docs page (Markdown twin)",
            "url": "https://docs.adyen.com/development-resources/mcp-server.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server repository (clone at b65825d)",
            "url": "https://github.com/Adyen/adyen-mcp",
            "seen": "2026-10-09"
          },
          {
            "what": "GitHub releases",
            "url": "https://github.com/Adyen/adyen-mcp/releases",
            "seen": "2026-10-09"
          },
          {
            "what": "GitHub issues, including 141 and 149",
            "url": "https://github.com/Adyen/adyen-mcp/issues",
            "seen": "2026-10-09"
          },
          {
            "what": "npm, @adyen/mcp versions",
            "url": "https://registry.npmjs.org/@adyen%2fmcp",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@adyen/mcp",
            "seen": "2026-10-09"
          },
          {
            "what": "official MCP registry search (first page only)",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=adyen",
            "seen": "2026-10-09"
          },
          {
            "what": "docs llms.txt",
            "url": "https://docs.adyen.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "API idempotency",
            "url": "https://docs.adyen.com/development-resources/api-idempotency",
            "seen": "2026-10-09"
          },
          {
            "what": "API credentials",
            "url": "https://docs.adyen.com/development-resources/api-credentials",
            "seen": "2026-10-09"
          },
          {
            "what": "API versioning",
            "url": "https://docs.adyen.com/development-resources/versioning",
            "seen": "2026-10-09"
          },
          {
            "what": "HTTP status codes",
            "url": "https://docs.adyen.com/development-resources/response-handling",
            "seen": "2026-10-09"
          },
          {
            "what": "API logs",
            "url": "https://docs.adyen.com/development-resources/logs-resources/api-logs",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://www.adyen.com/pricing",
            "seen": "2026-10-09"
          },
          {
            "what": "test account signup",
            "url": "https://www.adyen.com/signup",
            "seen": "2026-10-09"
          },
          {
            "what": "Adyen Terms and Conditions",
            "url": "https://www.adyen.com/legal/adyen-terms-and-conditions",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy statement",
            "url": "https://www.adyen.com/privacy-policy",
            "seen": "2026-10-09"
          },
          {
            "what": "sub-processor list",
            "url": "https://www.adyen.com/legal/list-of-adyen-subprocessors",
            "seen": "2026-10-09"
          },
          {
            "what": "responsible disclosure policy",
            "url": "https://www.adyen.com/policies-and-disclaimer/responsible-disclosure",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt",
            "url": "https://www.adyen.com/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://status.adyen.com",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP for adyen.com",
            "url": "https://rdap.verisign.com/com/v1/domain/adyen.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the result of the latest CI run on the default branch, because GitHub's API rate limit refused the request",
          "unchecked: whether an Adyen-namespaced entry exists in the official MCP registry. One search page was read and three later requests timed out or errored. The repository has no `server.json`",
          "unchecked: the status page's component list and incident history, which are drawn by script",
          "unchecked: the fields of the test account signup form, drawn by script, so whether it asks for a card",
          "unchecked: retention periods in the privacy statement, Adyen's certifications beyond the PCI DSS line in the terms, and any bug bounty",
          "unchecked: published API rate limit numbers. None were found in the docs index, which was searched by title only",
          "The lead said the tools cover the Checkout and Management APIs. The source also has Legal Entity Management tools and `get_account_holder` on the Balance Platform configuration API",
          "The pricing page shows payment method names as images, so the 0.60% markup could not be tied to named methods in the text we read",
          "Whether Adyen will change `refund_payment` after issue 149. A September 2026 issue on retry safety was closed as not an issue"
        ]
      },
      "negative": 0,
      "verdict": "All 38 tools carry read-only, destructive and idempotent annotations, and `--tools` loads a subset under an API credential limited by roles. The README labels the server alpha, `refund_payment` and the other POST tools send no idempotency key, and failures come back as plain text without an error flag.",
      "bestFor": "An Adyen merchant's developer or operations staff who want an assistant to create payment links and sessions, look up terminals, webhooks, users and credentials, and change terminal settings, with a person watching writes.",
      "strengths": [
        "All 38 tools carry `readOnlyHint`, `destructiveHint` and `idempotentHint`, and a test asserts every tool is classified (27 read-only, 11 writes, 6 marked destructive)",
        "`--tools` loads a named subset, and the README advises a dedicated API credential whose roles match only the tools in use",
        "The server defaults to Adyen's test environment, and live use needs both `--env=LIVE` and the account's live URL prefix",
        "MIT source with four test files, CodeQL and Renovate, published to npm from GitHub Actions with a provenance attestation",
        "Adyen's Customer Area keeps API logs of every request and response for 30 days, which cover calls the server makes"
      ],
      "weaknesses": [
        "The README is headed alpha, the package is at 0.6.0, and the server reports itself as version 0.4.0",
        "`refund_payment`, `cancel_payment` and `create_payment_links` send no `idempotency-key` header, although Adyen's API accepts one on POST requests",
        "Tool failures return as text such as `Failed to refund payment. Error: ...` without `isError`, and no tool reads a payment's refunds",
        "The `refund_payment` description names `paymentPspReference` while the schema field is `pspReference`, and omits the required `reference`",
        "One release in the 90 days to 9 October 2026, and the docs page, last modified 11 June 2025, still passes the key on the command line"
      ],
      "agentNotes": [
        "Set `ADYEN_API_KEY` in the environment and start with `npx -y @adyen/mcp --env=TEST`. The `--adyenApiKey` flag in the docs page puts the key in the process list",
        "Pass `--tools=` with only the tool names the task needs. The default loads all 38, and the terminal settings schema alone is about 29 KB of source",
        "Call `refund_payment` with `pspReference`, `currency`, `value`, `merchantAccount` and `reference`. The description's `paymentPspReference` is not the field name",
        "Treat a `Failed to ...` reply from a write tool as outcome unknown, not as failure. Do not repeat a refund without checking the Customer Area or the REFUND webhook",
        "Give amounts in minor units (1099 for 10.99 EUR). Live use needs `--env=LIVE --livePrefix=` with the prefix from the live Customer Area"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 60.3
        }
      ],
      "editorialScores": {
        "ergonomics": 56,
        "maintenance": 42,
        "payments": 35,
        "reliability": 65,
        "schema": 73,
        "security": 63,
        "transparency": 72
      },
      "provenanceScore": 93
    },
    "connect": {
      "install": "npx -y @adyen/mcp --env=TEST",
      "config": {
        "servers": {
          "adyen-mcp-server": {
            "args": [
              "-y",
              "@adyen/mcp",
              "--env=TEST"
            ],
            "command": "npx",
            "env": {
              "ADYEN_API_KEY": "${ADYEN_API_KEY}"
            },
            "type": "stdio"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/payments.checkout",
      "tool": "https://letme.dev/adyen-mcp-server"
    },
    "notable": [
      "The README is headed `Adyen MCP Server - Alpha` and the npm package is at 0.6.0, published 24 August 2026 (https://github.com/Adyen/adyen-mcp)",
      "Release 0.6.0 added `readOnlyHint`, `destructiveHint` and `idempotentHint` annotations to every tool and the `ADYEN_API_KEY` environment variable (https://github.com/Adyen/adyen-mcp/releases)",
      "The source registers 38 tools across four Adyen APIs, Checkout, Management, Legal Entity Management and Balance Platform configuration. The docs page names only Checkout and Management (https://docs.adyen.com/development-resources/mcp-server)",
      "Write tools include `refund_payment`, `cancel_payment`, `create_payment_links`, `create_payment_session`, `reassign_terminal`, `update_terminal_settings` and `create_terminal_action` (https://github.com/Adyen/adyen-mcp/blob/main/typescript/src/tools/tools.ts)",
      "An open issue of 7 October 2026 reports that `refund_payment` sends no idempotency key and reports a timed-out refund as failed. The source confirms no key is sent (https://github.com/Adyen/adyen-mcp/issues/149)",
      "Every Markdown page on docs.adyen.com opens with a block addressed to LLMs about which SDK version numbers to write. We recorded it and did not act on it (https://docs.adyen.com/development-resources/mcp-server.md)",
      "Adyen's terms commit to commercially reasonable efforts at 99.9% quarterly uptime of the payment interface (https://www.adyen.com/legal/adyen-terms-and-conditions)"
    ],
    "area": "payments",
    "details": [
      {
        "label": "Surface",
        "value": "Local stdio MCP server, `@adyen/mcp` 0.6.0 on npm, Node 18 or later, built on `@adyen/api-library` and `@modelcontextprotocol/sdk`. No hosted endpoint"
      },
      {
        "label": "Tools",
        "value": "38. Checkout (sessions, payment methods, payment links, refund, cancel), Management (merchant accounts, terminals, Android apps and certificates, terminal actions and settings, webhooks, payment method settings, users, API credentials, allowed origins), Legal Entity Management (`get_legal_entity`, `create_hosted_onboarding_link`) and `get_account_holder`"
      },
      {
        "label": "Annotations",
        "value": "27 tools read-only, 11 writes. Six writes marked destructive, `refund_payment`, `cancel_payment`, `update_payment_link`, `create_terminal_action`, `reassign_terminal` and `update_terminal_settings`"
      },
      {
        "label": "Options",
        "value": "`--env` TEST (default) or LIVE, `--livePrefix` for live, `--tools` for a comma-separated subset, `ADYEN_API_KEY` or `--adyenApiKey`"
      },
      {
        "label": "Credentials",
        "value": "Adyen API key on a web service credential with roles, company or merchant scope. A regenerated key leaves the old one active for 24 hours"
      },
      {
        "label": "Errors",
        "value": "Failures return as text, `Failed to ... Error: \u003cmessage\u003e`, without `isError`. Release 0.5.0 stopped response headers and bodies leaking into messages, with tests"
      },
      {
        "label": "Idempotency",
        "value": "Adyen's API accepts an `idempotency-key` header of up to 64 characters on POST requests. The server sends none"
      },
      {
        "label": "Releases",
        "value": "Ten npm versions from 0.0.0 on 26 May 2025. 0.4.0 on 24 November 2025, 0.5.0 on 22 April 2026, 0.6.0 on 24 August 2026. Notes on GitHub releases, no changelog file"
      },
      {
        "label": "Repository",
        "value": "27 stars, 15 forks, last commit 11 September 2026. Four vitest files, CodeQL, ESLint and Renovate. npm publish with provenance from GitHub Actions"
      },
      {
        "label": "Logs",
        "value": "API logs in the Customer Area show every JSON API request and response for 30 days, for users with the Merchant admin or Technical integrator role"
      },
      {
        "label": "Fees",
        "value": "$0.13 per transaction plus the payment method's fee, no setup or monthly fee, a minimum invoice by industry through sales"
      },
      {
        "label": "Disclosure",
        "value": "Responsible disclosure policy with acknowledgement in 72 hours and a fix within 60 days. security.txt expired on 31 December 2025"
      }
    ],
    "unitPrices": [
      {
        "item": "Adyen processing fee, added to each payment method's own fee",
        "unit": "tx",
        "usd": 0.13
      }
    ],
    "provenance": {
      "legalEntity": "Adyen N.V.",
      "domain": "adyen.com",
      "domainRegistered": "2006-11-05",
      "endpointOnVendorDomain": true,
      "terms": "https://www.adyen.com/legal/adyen-terms-and-conditions",
      "privacy": "https://www.adyen.com/privacy-policy",
      "statusPage": "https://status.adyen.com",
      "changelog": "https://github.com/Adyen/adyen-mcp/releases",
      "securityTxt": "expired",
      "checked": "2026-10-09",
      "notes": [
        "The Adyen Terms and Conditions (last update 1 November 2023) supplement the merchant agreement and name Adyen N.V., Dutch Chamber of Commerce number 34259528, Simon Carmiggeltstraat 6-50, Amsterdam. The server's source is MIT.",
        "The privacy statement (version of 4 August 2025) covers processing where Adyen is the data controller. Adyen publishes a sub-processor list last updated 1 July 2026 at https://www.adyen.com/legal/list-of-adyen-subprocessors.",
        "The server runs on the owner's machine and calls Adyen's API hosts through `@adyen/api-library`. There is no hosted MCP endpoint.",
        "www.adyen.com/.well-known/security.txt carries `Expires: 2025-12-31T22:59:00.000Z`, so it had expired on the day. It names responsibledisclosure@adyen.com and the responsible disclosure policy.",
        "status.adyen.com showed 99.999% uptime for the last 30 days. Its component list and incident history are drawn by script and were not read.",
        "RDAP for adyen.com gives a registration date of 2006-11-05."
      ],
      "score": 93,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Adyen N.V.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "adyen.com, registered 2006-11-05 (19 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "adyen.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.adyen.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.adyen.com/legal/adyen-terms-and-conditions",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2023-11-01",
          "words": 13741,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last update 1 November 2023",
              "says": "Last updated 2023-11-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "and (iii) where required to do so pursuant to Applicable Law, or in order to comply with a legal order or decision of a court of law, governmental or law enforcement agency, regulatory body, or administrative authority."
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…towards Merchant for breach of contract, tort or under any other legal theory in any calendar year is limited to an amount equal to the total Processing Fees paid by Merchant to Adyen during the previous full calendar year (or if no Services were provided in the previous calendar year, the total Processing Fees paid i…",
              "says": "Capped at the fees paid in the year before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Where a published change negatively affects a material portion of the Merchant Products and Services, Merchant may terminate the Agreement by providing one (1) month’s written notice to Adyen with reasonable substantiation of such material impact."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Adyen may, from time to time, change these Terms and Conditions by providing at least thirty (30) days’ prior written notice to Merchant (“Change Notice”).",
              "says": "Gives thirty days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Following any such decisions of the relevant Acquirer and/or Scheme Owner, Adyen may be required to block Merchant from further use of a Payment Method or impose additional restrictions or conditions on Merchant’s continued use of such Payment Method."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Adyen will use commercially reasonable efforts to achieve a quarterly-average minimum uptime of 99.9% of the Payment Interface, as measured by its ability to receive Transaction messages.",
              "says": "Names 99.9% availability"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "Adyen may use de-identified and/or aggregated Transaction data and KYC information to optimize Adyen's products and services, which may include payment performance, fraud prevention, network analysis, and training machine learning models.",
              "costsPoints": true
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "All disputes arising out of or in connection with the Agreement and these Terms and Conditions, including their validity, interpretation, enforceability, or fulfillment, will be finally settled in a confidential manner in accordance with the Rules of Arbitration"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Adyen may use the merchant's name and standard logo on its website, in sales materials and in other publications to name the merchant as a customer.",
              "quote": "Merchant agrees that its name and standard logo (as published by Merchant) may be used by Adyen to refer to Merchant as a customer of Adyen on Adyen’s website, sales materials and in other publications."
            },
            {
              "date": "2026-10-08",
              "text": "Adyen may raise prices for its services on its own decision with three months' notice, and the merchant may terminate during that notice period.",
              "quote": "Adyen is unilaterally entitled to raise the prices for its Services, including, but not limited to, the prices of Payment Devices and/or accessories thereto, with three (3) months’ prior notice."
            },
            {
              "date": "2026-10-08",
              "text": "After the agreement ends, Adyen releases the reserve it withholds from settlements gradually, with full release generally about six months later unless specific potential liabilities remain.",
              "quote": "Generally, an MPL Reserve will be fully released to Merchant approximately six (6) months following the effective date termination of the Agreement or the date that Adyen stops processing for Merchant, as applicable"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.adyen.com/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-08-04",
          "words": 2256,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Version as of August 4, 2025.",
              "says": "Last updated 2025-08-04"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This includes, as applicable, the categories of personal data we have collected, the sources from which we collected that personal data, the business or commercial purposes for which we collected, “sold”, and “shared” that personal data, the categories of personal data that we “sold”, “shared”, or disclosed to third p…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will only keep your data for as long as we reasonably need to for the purposes listed above, or as otherwise required by law."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "…that personal data, the business or commercial purposes for which we collected, “sold”, and “shared” that personal data, the categories of personal data that we “sold”, “shared”, or disclosed to third parties for business purposes and the categories of third parties to whom we “sold”, “shared”, or disclosed personal d…"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "…which we collected that personal data, the business or commercial purposes for which we collected, “sold”, and “shared” that personal data, the categories of personal data that we “sold”, “shared”, or disclosed to third parties for business purposes and the categories of third parties to whom we “sold”, “shared”, or d…"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Right to access: You may have the right to ask us for the specific personal data that we have collected from you in a portable and (where technically possible) usable format."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "Questions, comments, requests, or complaints concerning this privacy statement or the way we process your personal data are welcomed and can be addressed to our Data Protection Officer at dpo@adyen.com or Simon Carmiggeltstraat 5-60, 1011 DJ Amsterdam, the Netherlands, or to lgpd@adyen.com if you are located in Brazil.",
              "says": "dpo@adyen.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "When we transfer data to our Adyen group companies, the transfers are protected by an intragroup agreement containing Standard Contractual Clauses.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Adyen reserves the right to use de-identified or aggregated data for any purpose without limitation and says it will not attempt to re-identify it.",
              "quote": "We reserve the right to use de-identified or aggregated data for any purpose without limitation, and we will not attempt to re-identify the information."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/adyen-mcp-server.json",
    "live": {
      "slug": "adyen-mcp-server",
      "vendorStatus": {
        "page": "https://status.adyen.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:57:34.759368723Z"
      },
      "updatedAt": "2026-10-09T07:57:34.759368723Z"
    }
  }
}
