MCP server
How access works#
Access is self-service: there is no registration form and no manual approval. The merchant installs the connector with the server URL and, in the authorization window, signs in with the same credentials as their Tilopay account (email and password) and confirms the verification code Tilopay sends. That automatically creates the assistant user, ties it to the merchant, and registers the merchant's API credentials encrypted on the server side.
Three things worth knowing:
- The session is authorized with the Tilopay dashboard email and password, plus the verification code. The assistant never sees or stores that password: the connection runs on OAuth 2.0.
- Because the user is tied to one merchant, the agent only reaches the data and the operations of that merchant.
- The merchant never pastes its
apiKey,apiUserorapiPasswordinto the MCP client.
The merchant API credentials live encrypted on the Tilopay server and are decrypted on every call. They are not pasted into the MCP client, nor into the assistant configuration file, and they are never handed to the model. That is the security argument behind the whole design.
Connection#
The server is https://mcp.tilopay.com/mcp. To connect:
- Add the server in the MCP client with that URL.
- The client discovers authentication from the 401 with
WWW-Authenticate, which points to/.well-known/oauth-protected-resource. - The client registers dynamically and opens the authorization screen.
- The user signs in with their Tilopay account credentials, confirms the verification code and sees a consent screen with the application requesting access, the return URL and the permissions.
- On approval, the client is connected.
The model is OAuth 2.0 with authorization_code and refresh_token. The client discovers the
identity provider endpoints on its own: the only thing to configure is the server URL.
From the most used MCP clients#
- Claude (desktop and web): add a remote connector with the server URL and complete sign-in in the window it opens. Connect with Claude
- ChatGPT: add the server as a remote connector with that same URL; authorization completes in the browser.
- Cursor, VS Code and other editors: declare a remote HTTP MCP server with the URL, with no token in the configuration file; the editor opens the browser to authorize.
- Your own client: use an MCP client with Streamable HTTP transport and OAuth 2.0 support with dynamic registration. The sequence is the one above: 401, discovery, registration, authorization, connection.
The transport is Streamable HTTP. The available tools are listed by group: sales and transactions, payment links, catalog, contacts, recurring billing, support and diagnostics. The banking API (BaaS) group is enabled on request and only works for users with Tilopay banking API credentials. Before connecting an agent, read what it can do.
Last verified: 2026-09-23 · Owner: equipo-integraciones