- POSTOff · moves money
create_push
Send a payment prompt
- GETTool
get_push
Check a payment prompt
- POSTOff · moves money
send_payout
Send a payout
- GETTool
get_payout
Check a payout
- GETTool
get_transaction
Look up a transaction
- POSTOff · moves money
reverse_transaction
Reverse a transaction
- GETTool
get_balance
Read your balances
Model Context Protocol
Your APIs as tools for AI agents.
MCP is an open standard that lets an AI assistant find out what a server can do and then do it. This portal publishes one MCP server for each API group. Connect an assistant and it can call the sandbox with your app's token.
- 5
- servers, one per group
- 8
- operations offered as tools
- 3
- operations off: they move money
01How it works
One server per group, built from the specs.
If you have not used MCP before, this is all there is to it. The assistant asks the server for its list of tools. Each tool has a name, a description and a list of inputs. When the assistant decides a tool would help, it sends the tool's name and the inputs as JSON, and reads the JSON that comes back.
You do not write or host anything. The servers are already running at the addresses below.
- One server per group
- Each API group has its own address,
https://devportal.softwaregroup.com/api/mcp/<group-slug>. Connect only the groups your assistant needs. - Built from the same specs
- The tool list is generated from the OpenAPI specs that also produce the reference pages and the sandbox. When a spec changes, the tools change with it.
- One operation, one tool
- Each operation maps to one tool. Its inputs are the operation's path parameters, query parameters and body fields in one flat list, with the same names, types and required fields as the reference.
- Same token, same rules
- Tool calls carry the same one-hour bearer token as the REST API. Your app must be subscribed to the group whose server it connects to. Rate limits count tool calls and REST calls together. Each tool call is written to your request log, marked
via MCP. - Money stays off
- Operations that move money are left out of the tool list unless an operator switches them on. An assistant cannot call a tool that is not listed. Today
create_pushis one of them. - Sandbox by default
- These servers answer from the sandbox. Magic values in the inputs pick the outcome, as they do over REST. The
X-Lango-Scenarioheader is not read on tool calls. See the scenarios - Production, when you are ready
- Once an app has gone live, the same servers exist at
https://devportal.softwaregroup.com/api/live/mcp/<group-slug>, and a production token in place of a sandbox one. Tool calls then run through the built-in gateway exactly like a REST call: the same app, group and plan checks, and the same request log. See Console, MCP servers for the exact address of each of your servers.
02Servers and their tools
What an assistant will find.
This list is read from the live catalog. Tool names are the operation ids in snake case. A struck-through name is an operation the server does not list.
- POSTTool
create_verification
Verify a person
- GETTool
get_verification
Fetch a past verification
- POSTTool
send_sms
Send a text message
- GETTool
get_sms
Check a message
- POSTOff · moves money
create_push
Send a payment prompt
- GETTool
get_push
Check a payment prompt
- POSTTool
send_sms
Send a text message
- GETTool
get_sms
Check a message
- GETTool
get_transaction
Look up a transaction
- POSTOff · moves money
reverse_transaction
Reverse a transaction
- GETTool
get_balance
Read your balances
TreasuryPartners only
3 tools · 2 off
https://devportal.softwaregroup.com/api/mcp/treasury
- POSTOff · moves money
send_payout
Send a payout
- GETTool
get_payout
Check a payout
- GETTool
get_transaction
Look up a transaction
- POSTOff · moves money
reverse_transaction
Reverse a transaction
- GETTool
get_balance
Read your balances
03Connect an assistant
Connect in three steps.
Step 1
Get a token
Use the consumer key and secret of an app that is subscribed to the group. It is the same token request you make for the REST API.
The token lasts one hour.
# Needs jq. Puts the token in $LANGO_TOKEN for the next steps. export LANGO_TOKEN=$(curl -s -X POST 'https://devportal.softwaregroup.com/api/sandbox/oauth/v1/token' \ -u "$LANGO_KEY:$LANGO_SECRET" \ -d 'grant_type=client_credentials' | jq -r .access_token)Step 2
Add the server
The examples use the Payments server. Swap in the address of any server from the list above.
Most MCP clients read the JSON form. It needs three things:
typeset tohttp, theurl, and theAuthorizationheader.When the token expires the server answers
401 INVALID_TOKEN. Get a new token and update the header. In Claude Code that meansclaude mcp remove lango-payments, then the add command again.claude mcp add --transport http lango-payments https://devportal.softwaregroup.com/api/mcp/payments \ --header "Authorization: Bearer $LANGO_TOKEN"Step 3
Check it by hand
An MCP server is plain JSON-RPC over HTTP, so you can test it with curl before you involve an assistant.
tools/listshows exactly what the assistant will see, input schemas included.A tool result carries the API's JSON answer. If the API answered 400 or above, the result has
isError: true.curl -s -X POST 'https://devportal.softwaregroup.com/api/mcp/payments' \ -H "Authorization: Bearer $LANGO_TOKEN" \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
04For the record
What the servers speak.
Your MCP client handles these details. They are here for when you write your own client, or when something does not connect.
- Transport
- Streamable HTTP, stateless. Every POST gets one JSON response. There is no session to keep.
- Protocol version
- 2025-06-18
- Methods
- initialize · ping · tools/list · tools/call
- GET requests
- Answered with 405. The servers do not open a stream of their own.
- Tool hints
- readOnlyHint is true for GET operations. destructiveHint is true for operations that move money.
- Tool results
- The API's JSON answer, as text and as structuredContent.
- Unknown tool
- JSON-RPC error -32602. Operations that are switched off answer the same way.
- Callbacks
- Tools for operations that answer by callback still send the callback to your callbackUrl or your app's default.
- Production
- The same tools at /api/live/mcp/<group-slug>, authenticated with a production token, logged with channel mcp.
Connect an assistant to the sandbox.
Create an app, subscribe it to a group and connect the group's server. Everything the assistant does shows up in your request log.