Affinity
Search your CRM, prep for meetings and update deal records from your AI assistant.
Issue virtual payment cards, set spend limits, pause or permanently close them, and read the full card number.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Privacy.com MCP server lets Claude, ChatGPT or any MCP client issue and manage virtual payment cards on your real Privacy.com account. Its 10 tools create cards, set spend limits, pause, unpause and permanently close them, read the full card number and CVV, and list transactions. Sign-in is OAuth, or an API key.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
mcp:tools, and the RFC 9728 resource descriptor declares no scopes_supported. No boundary falls between listing a transaction and permanently closing a card. Consent is all-or-nothing.create_card does not require a spend limit. spend_limit is optional in Privacy's own tool table. The safeguard is a convention, not a constraint — Privacy's agent instructions ask agents to always set one, which is an admission that nothing forces it.close_card is final. Privacy states in two places that a CLOSED state cannot be undone. There is no MCP tool to reopen a card.get_pan writes a live card number into your transcript. There is no truncated variant, and no way to grant the other nine tools without granting this one.create_card a type of SINGLE_USE, MERCHANT_LOCKED or UNLOCKED; the REST create endpoint and the cards guide both name the third type DIGITAL_WALLET instead. We could not establish from documentation whether these are the same card behind two labels. Privacy's plan page gates the multi-merchant card at Pro and above either way.privacy.com/agent-api-instructions.md is a page of best practices written for agents, covering spend limits, card-type choice and confirmation before closing. We read it as vendor documentation and report it as a finding; its advice is sensible, but a page of directives aimed at models is content your agent may ingest as though it were instruction rather than reference.Yes. create_card issues a live virtual card on your real funding source, and Privacy's own tool table shows spend_limit as optional. A card created without one is uncapped up to your account limits. Privacy's agent instructions tell agents to always set a spend limit, which confirms that the tool does not require one.
Yes, both. get_pan is documented as retrieving the full card number, CVV and expiration for any card token, and Privacy's card schema defines pan as the sixteen digit card number. That output lands in your AI client's conversation history and wherever that history is stored or synced.
One: close_card. Privacy's API reference states that setting a card to a CLOSED state is a final action that cannot be undone. Everything else reverses — pause_card is undone by unpause_card, and update_card_spend_limit and update_card_memo can be set back. Card creation is not reversible either, but a new card can be closed.
One scope, mcp:tools. Privacy's authorization server advertised exactly that single scope on 2026-08-22, and the server's RFC 9728 descriptor declares no scopes_supported at all. So there is no consent-time way to grant listing transactions without also granting card creation, spend-limit changes, PAN retrieval and permanent closure.
Yes. Privacy's MCP documentation states you must be subscribed to a paid Privacy Plan to access the Privacy API. Privacy's own plan summary puts API access on the Plus tier at five dollars a month and above. Free Personal accounts can use virtual cards in the app but not through this connector.
No. None of the 10 tools transfers funds, adds a funding source, or changes which bank account backs a card. Privacy's REST API exposes a list funding sources endpoint that the MCP server does not carry, and its create-card funding_token parameter is absent from the MCP create_card tool. Cards draw on your existing funding source.
Only the last four digits, and only indirectly. Privacy's card object embeds a funding object whose fields are the account nickname, account name and last_four — no routing or full account number anywhere in the schema. There is no MCP tool that lists funding sources, so even that partial view arrives only attached to a card record.
No. Privacy's REST API has a share-card endpoint that emails a recipient a secure link showing the PAN, CVV and expiration, but no MCP tool maps to it. The connector's only outbound path is the card itself: a card an agent creates can be charged by whichever merchant receives the number.
.md variant the host advertises) · retrieved 2026-08-22llms.txt (retrieved 2026-08-22) · retrieved 2026-08-22llms.txt (retrieved 2026-08-22) · retrieved 2026-08-22www.privacy.com, then to a CDN-hosted text file) · retrieved 2026-08-22https://mcp.privacy.com returned 401 on 2026-08-22; RFC 9728 metadata at https://mcp.privacy.com/.well-known/oauth-protected-resource; authorization server metadata at https://api.app.privacy.com/.well-known/oauth-authorization-server · retrieved 2026-08-22Connect Privacy.com once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.