{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "category": "payment-platforms",
    "endpoint": "https://imbawallet.com/mcp/spend",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/imbawallet-agent.json",
    "kind": "mcp",
    "listed": "indexed",
    "liveUrl": "https://www.anchorterminal.com/api/v1/live/imbawallet-agent.json",
    "markdownUrl": "https://www.anchorterminal.com/tools/imbawallet-agent.md",
    "mcpTools": {
      "check": {
        "checker": "anchor-check/1.0",
        "totalTokens": 2738,
        "counts": {
          "error": 0,
          "note": 1,
          "warn": 13
        },
        "findings": [
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "create_card",
            "message": "6 parameters without a description: birth_date, country, first_name, imba_product_id, last_name, phone",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "get_card_details",
            "message": "none of its 2 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "kyt_check",
            "message": "none of its 3 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "kyt_check_get",
            "message": "its one parameter, id, has no description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "kyt_checks",
            "message": "none of its 2 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "list_esim_plans",
            "message": "none of its 2 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "list_gift_offers",
            "message": "its one parameter, query, has no description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "list_notifications",
            "message": "none of its 4 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "purchase_esim",
            "message": "none of its 4 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "purchase_gift",
            "message": "none of its 5 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "rotate_hmac",
            "message": "none of its 3 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "set_webhook",
            "message": "none of its 3 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC11",
            "severity": "warn",
            "tool": "topup_card",
            "message": "none of its 3 parameters has a description",
            "fix": "Describe each one: format, units, an example, and what happens when it's left out."
          },
          {
            "rule": "TC24",
            "severity": "note",
            "message": "19 of 19 tools have no outputSchema",
            "fix": "Declare outputSchema for tools that return structured data, and return structuredContent that matches it."
          }
        ]
      },
      "checkedAt": "2026-10-04T22:23:06Z",
      "count": 19,
      "schemaTokens": 2738,
      "status": "ok",
      "tools": [
        {
          "name": "get_spend_policy",
          "title": "Spend policy",
          "description": "Forbidden rails and tier rules. Allowed catalog: Visa prepaid, travel eSIM, gift cards, paid KYT address screen. Read-only.",
          "inputSchema": {
            "properties": {},
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "get_deposit_address",
          "title": "USDT TRC-20 deposit address",
          "description": "POST /api/deposit_address blockchain=tron. Address is issued for the authenticated agent only. Always re-fetch before send. Do not cache. USDT TRC-20 only. 24h unfunded hold.",
          "inputSchema": {
            "properties": {},
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": false,
            "readOnlyHint": false
          }
        },
        {
          "name": "get_balance",
          "title": "Ledger 2401 balance",
          "description": "GET /api/balance. USDT is the spendable catalog currency.",
          "inputSchema": {
            "properties": {},
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "list_cards",
          "title": "List cards",
          "description": "POST /api/cards for the authenticated agent. No client_id argument.",
          "inputSchema": {
            "properties": {},
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "list_card_products",
          "title": "List card products",
          "description": "POST /api/card_products. Use id as imba_product_id for create_card (Visa prepaid). Space catalog calls ~1s apart.",
          "inputSchema": {
            "properties": {},
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "list_gift_offers",
          "title": "List gift offers",
          "description": "POST /api/offers. Live gift catalog (~20k positions / ~2k unique: Apple, Google Play, Steam, games, travel, retail). Optional query string. Then purchase_gift with offer_id + ext_id. Space catalog calls ~1s apart. Do not assume a SKU.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "query": {
                "maxLength": 64,
                "type": "string"
              }
            },
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "list_esim_plans",
          "title": "List eSIM plans",
          "description": "POST /api/esim/plans. Travel/data eSIM. esim_provider=yesim. Optional country ISO2. Use plan id with purchase_esim. Space catalog calls ~1s apart (agent catalog_gap).",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "country": {
                "maxLength": 8,
                "type": "string"
              },
              "esim_provider": {
                "maxLength": 32,
                "type": "string"
              }
            },
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "create_card",
          "title": "Buy a virtual card",
          "description": "Issue a Visa/MasterCard prepaid from this agent 2401 USDT so the agent can pay merchants that require a card (airlines, hotels, SaaS, datacenter/GPU clouds). POST /api/pin/create_card. ext_id required. imba_product_id is core.card_product.id. Never payment_source=stars. Never pass client_id. IMBA does not create the booking.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "birth_date": {
                "maxLength": 32,
                "type": "string"
              },
              "country": {
                "maxLength": 8,
                "type": "string"
              },
              "email": {
                "description": "Cardholder KYC email, not the agent 3DS mailbox.",
                "maxLength": 254,
                "type": "string"
              },
              "ext_id": {
                "description": "Idempotency key. Reuse the same id to retry the same order.",
                "maxLength": 128,
                "minLength": 1,
                "type": "string"
              },
              "first_name": {
                "maxLength": 64,
                "type": "string"
              },
              "imba_product_id": {
                "exclusiveMinimum": 0,
                "maximum": 9007199254740991,
                "type": "integer"
              },
              "last_name": {
                "maxLength": 64,
                "type": "string"
              },
              "phone": {
                "maxLength": 32,
                "type": "string"
              }
            },
            "required": [
              "imba_product_id",
              "ext_id"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": true,
            "idempotentHint": true,
            "readOnlyHint": false
          }
        },
        {
          "name": "topup_card",
          "title": "Top up a card",
          "description": "POST /api/pin/topup_card from this agent 2401 USDT. card_id must belong to the same agent (SQL owner guard). ext_id required. Never Stars.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "amount": {
                "exclusiveMinimum": 0,
                "maximum": 1000000,
                "type": "number"
              },
              "card_id": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "ext_id": {
                "maxLength": 128,
                "minLength": 1,
                "type": "string"
              }
            },
            "required": [
              "card_id",
              "amount",
              "ext_id"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": true,
            "idempotentHint": true,
            "readOnlyHint": false
          }
        },
        {
          "name": "purchase_gift",
          "title": "Buy a gift card",
          "description": "POST /api/purchase. Buy a brand gift code (Apple, Steam, Google Play, … — live list). ext_id required. Never payment_source=stars.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "expected_price": {
                "additionalProperties": {
                  "type": "number"
                },
                "propertyNames": {
                  "maxLength": 32,
                  "type": "string"
                },
                "type": "object"
              },
              "ext_id": {
                "maxLength": 128,
                "minLength": 1,
                "type": "string"
              },
              "offer_id": {
                "maxLength": 128,
                "minLength": 1,
                "type": "string"
              },
              "payment_source": {
                "maxLength": 32,
                "type": "string"
              },
              "required_fields": {
                "additionalProperties": {
                  "maxLength": 512,
                  "type": "string"
                },
                "propertyNames": {
                  "maxLength": 64,
                  "type": "string"
                },
                "type": "object"
              }
            },
            "required": [
              "offer_id",
              "ext_id"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": true,
            "idempotentHint": true,
            "readOnlyHint": false
          }
        },
        {
          "name": "purchase_esim",
          "title": "Buy an eSIM plan",
          "description": "POST /api/esim/new_plan5. Buy a travel/data eSIM plan from this agent 2401. Omit blank/null iccid so SQL takes the new-eSIM path. A set iccid must already belong to this agent. ext_id required. Never Stars.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "ext_id": {
                "maxLength": 128,
                "minLength": 1,
                "type": "string"
              },
              "iccid": {
                "maxLength": 32,
                "type": "string"
              },
              "payment_source": {
                "maxLength": 32,
                "type": "string"
              },
              "plan_id": {
                "maxLength": 64,
                "minLength": 1,
                "type": "string"
              }
            },
            "required": [
              "plan_id",
              "ext_id"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": true,
            "idempotentHint": true,
            "readOnlyHint": false
          }
        },
        {
          "name": "get_card_details",
          "title": "Card payment credentials",
          "description": "POST /api/pin/get_card_details for a card this agent owns. Needed to present PAN at merchant checkout (airline, datacenter, SaaS). PAN/CVV arrive as card_encrypted JWE when jwe_public_key is registered (PATCH webhook). Without that key the number is masked. Never logs raw PAN. cvv defaults true. Never pass client_id.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "card_id": {
                "maxLength": 256,
                "minLength": 1,
                "type": "string"
              },
              "cvv": {
                "type": "boolean"
              }
            },
            "required": [
              "card_id"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "list_notifications",
          "title": "Inbox and 3DS OTP",
          "description": "POST /api/notifications. Poll this when a Visa payment asks for 3-D Secure. Agents keep payload.code (never SMS, never Telegram). category=codes for 3-D Secure OTP. Also delivered on webhook field otp if callback_url is set, and optional email. Space catalog calls ~1s apart.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "category": {
                "enum": [
                  "all",
                  "codes",
                  "support",
                  "tx"
                ],
                "type": "string"
              },
              "limit": {
                "maximum": 100,
                "minimum": 1,
                "type": "integer"
              },
              "prev_id": {
                "maximum": 9007199254740991,
                "minimum": -9007199254740991,
                "type": "integer"
              },
              "prev_ts": {
                "type": "number"
              }
            },
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "set_webhook",
          "title": "Set callback URL / JWE / OTP email",
          "description": "PATCH /auth/v1/agent/webhook. Sets https callback_url (required before hmac/rotate), optional X25519 jwe_public_key for card_encrypted, optional email for 3DS OTP. Not SMS. HMAC plaintext is shown once when a URL is first accepted.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "callback_url": {
                "maxLength": 512,
                "type": "string"
              },
              "email": {
                "maxLength": 254,
                "type": "string"
              },
              "jwe_public_key": {
                "maxLength": 4096,
                "type": "string"
              }
            },
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": false
          }
        },
        {
          "name": "rotate_hmac",
          "title": "Rotate webhook HMAC",
          "description": "POST /auth/v1/agent/hmac/rotate. Previous HMAC dies immediately. Requires an existing callback_url (400 callback_url required before rotate otherwise). Pass callback_url here to PATCH webhook first. Plaintext HMAC is returned once — store it; never a Wallet JWT.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "callback_url": {
                "maxLength": 512,
                "type": "string"
              },
              "email": {
                "maxLength": 254,
                "type": "string"
              },
              "jwe_public_key": {
                "maxLength": 4096,
                "type": "string"
              }
            },
            "type": "object"
          },
          "annotations": {
            "destructiveHint": true,
            "idempotentHint": false,
            "readOnlyHint": false
          }
        },
        {
          "name": "kyt_quote",
          "title": "KYT price",
          "description": "POST /api/kyt_quote. Price for a paid crypto-address screen (Didit). Debit is on kyt_check (~0.99 USDT from 2401), not on quote. Off unless didit.enabled and didit.agent_api. Does not gate TRON deposit. Not /api/client/kyt_* and not partner. Space ~1s.",
          "inputSchema": {
            "properties": {},
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "kyt_check",
          "title": "Paid KYT check",
          "description": "Screen a crypto address for dirt (sanctions / mixer exposure). Use BEFORE you accept a TRC-20 send, or AFTER a wallet is blocked and the reason is unclear. POST /api/kyt_check. Body: network (tron_usdt | eth | btc) + address. Debits ~0.99 USDT from 2401. Returns a report — does not gate deposit, does not ban or unblock. TON is not in this catalog. Never pass client_id. Space ~1s.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "address": {
                "maxLength": 128,
                "minLength": 8,
                "type": "string"
              },
              "network": {
                "maxLength": 32,
                "minLength": 2,
                "type": "string"
              },
              "refresh": {
                "type": "boolean"
              }
            },
            "required": [
              "network",
              "address"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": true,
            "idempotentHint": false,
            "readOnlyHint": false
          }
        },
        {
          "name": "kyt_check_get",
          "title": "KYT check by id",
          "description": "POST /api/kyt_check_get. Poll until the report is ready. Own check only (404 otherwise). Use after kyt_check when a wallet was blocked and you need the dirt report. Never pass client_id.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "id": {
                "exclusiveMinimum": 0,
                "maximum": 9007199254740991,
                "type": "integer"
              }
            },
            "required": [
              "id"
            ],
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        },
        {
          "name": "kyt_checks",
          "title": "KYT history",
          "description": "POST /api/kyt_checks. Own KYT history plus quote fields. Use to find a past address check. Space ~1s. Never pass client_id.",
          "inputSchema": {
            "$schema": "https://json-schema.org/draft/2020-12/schema",
            "properties": {
              "last_id": {
                "exclusiveMinimum": 0,
                "maximum": 9007199254740991,
                "type": "integer"
              },
              "limit": {
                "maximum": 100,
                "minimum": 1,
                "type": "integer"
              }
            },
            "type": "object"
          },
          "annotations": {
            "destructiveHint": false,
            "idempotentHint": true,
            "readOnlyHint": true
          }
        }
      ]
    },
    "name": "IMBA Agent Spend",
    "note": "Indexed from the official MCP registry: facts and our own checks, not reviewed, so no score, grade or rank.",
    "packages": [
      {
        "registryType": "npm",
        "identifier": "@imba_wallet/agent-mcp",
        "version": "0.1.4",
        "transport": "stdio"
      }
    ],
    "pageJsonUrl": "https://www.anchorterminal.com/tools/imbawallet-agent.json",
    "popularity": {
      "npmWeekly": 47
    },
    "registryName": "com.imbawallet/agent",
    "remotes": [
      {
        "type": "streamable-http",
        "url": "https://imbawallet.com/mcp/spend"
      }
    ],
    "repository": "https://github.com/IMBAwallet/IMBA_front",
    "reviewed": false,
    "slug": "imbawallet-agent",
    "source": "the official MCP registry",
    "sourceUrl": "https://registry.modelcontextprotocol.io/v0.1/servers?search=com.imbawallet/agent",
    "summary": "IMBA spend MCP: USDT TRC-20 deposit and catalog buy with your key. No withdraw.",
    "updatedAt": "2026-08-31T15:57:31Z",
    "url": "https://www.anchorterminal.com/tools/imbawallet-agent",
    "vendor": "imbawallet.com",
    "vendorUrl": "https://imbawallet.com/agent_api_about_en.html",
    "version": "0.1.4",
    "websiteUrl": "https://imbawallet.com/agent_api_about_en.html",
    "where": "both",
    "why": [
      "vendor"
    ]
  }
}
