Mandalo for Muse
Live now — Muse’s own directory listing pending
Let your Muse send the payment link.
Mandalo speaks Muse’s language over MCP. Ask Muse to bill a customer, and it hands the job to Mandalo — a secure Stripe link comes back, and the receipt trail lands in your dashboard like always.
How it works
Muse briefs. Mandalo bills. You confirm.
- 1
Ask Muse
“Send my customer a payment link for the $150 lawn job, and text me when it's paid.” Muse knows Mandalo handles payment requests and hands over the details.
- 2
Mandalo prepares, you confirm
Mandalo builds the request — amount, description, a 7-day expiry — and returns a confirmation. Muse has to show it to you and get an explicit yes before anything is created.
- 3
Customer pays, Muse can check
Your customer pays by card, Apple Pay, or Google Pay — no app, no account. Muse can check status, list recent links, or pull a summary any time you ask.
What’s supported
Five actions. Nothing hidden.
Phase one is deliberately narrow — enough for Muse to request and track a payment, and no more.
Check account status
Is the merchant verified and ready to accept payments, what the platform fee is, and how many links are left in today's quota.
Create a payment link
Two steps by design: prepare returns a confirmation to show the customer's contact, amount, and description; commit only runs after explicit approval.
Check a link's status
Pending, paid, refunded, or expired for one payment link, plus the amount and recipient it was sent to.
List payment links
Recent requests, filterable by status and date range, paginated so a long history doesn't come back all at once.
Get a payment summary
Requested, collected, and refunded totals for a date range — the current collection state, not a payout statement.
No customer search, no charging a saved card, and no resending a link through the connector yet — those come later.
Connect
One MCP server, OAuth to sign in
Add the Mandalo MCP server
Mandalo exposes one streamable HTTP endpoint. Point Muse at it and sign in with your existing Mandalo merchant login — no API key to copy anywhere.
{
"mcp_servers": {
"mandalo": {
"transport": "streamable_http",
"url": "https://getmandalo.net/api/connector/v1/mcp",
"enabled": true
}
}
}What connecting looks like
- 1. Your agent registers itself. No signup form, no waiting on us — any MCP client can call our registration endpoint and get its own credentials automatically (RFC 7591).
- 2. Authorize. It sends you to Mandalo’s own login and consent screen — OAuth 2.1 with mandatory PKCE, the same identity you already use on the dashboard. You’ll see exactly which app is asking, by name, before you approve it.
- 3. Scope it down. Grants are scoped to account status, reading links, and creating links — never all three by accident.
- 4. Disconnect any time. Turn access on or off, or revoke a connection, from Connected apps in your merchant dashboard.
/.well-known/oauth-authorization-server for any client that supports RFC 8414.Set it up together
About 5 minutes, you and your agent as a team
Every step says who does it — you, or your agent.
You — get a Mandalo merchant account.
The connector acts on your merchant account, so you need one before anything else. Create your free account — takes about 2 minutes. Already have one? Skip ahead.
You — turn on AI agent access.
Sign in and flip the toggle at Connected apps. Skip this and your agent’s approval link won’t work — it’ll say “expired” even though it isn’t.
You — point your agent here.
Tell your agent to connect to Mandalo and give it the MCP URL:
https://getmandalo.net/api/connector/v1/mcp. It registers itself automatically — nothing for you to copy, paste, or configure.You — sign in first, then approve.
Sign in to Mandalo in your browser before tapping the link your agent sends you — the request only lasts 10 minutes, and signing in first skips a detour through the login page. You’ll see your agent’s name and exactly what it’s asking for. Approve it — this is the only step that touches your password, and your agent never sees it.
You, only if your agent has no callback server — paste back the URL.
Some agents take you straight back into their own app. If yours instead lands you back on this page with extra text in the address bar (
?code=...), copy the full address and paste it back to your agent — there’s a copy button waiting for you right there.Your agent — confirms you’re live.
It runs a quick read-only check and tells you it’s connected. Now ask it to create a payment link.
For AI agents
If you’re an agent reading this, here’s everything you need
A copy-pasteable reference: endpoints, the registration and auth flow in order, the five tools, and the rules that matter. No other page or docs lookup should be required to integrate.
# Mandalo MCP connector — agent integration reference
MCP endpoint (streamable HTTP): https://getmandalo.net/api/connector/v1/mcp
Discovery (RFC 8414): https://getmandalo.net/.well-known/oauth-authorization-server
Protected resource metadata (RFC 9728): https://getmandalo.net/.well-known/oauth-protected-resource
## 1. Register a client (once per agent/app, not per merchant)
POST https://getmandalo.net/api/oauth/register
Content-Type: application/json
{
"client_name": "Your Agent Name",
"redirect_uris": ["https://your-agent.example/callback"],
"scope": "account:read links:read links:write",
"token_endpoint_auth_method": "none"
}
-> 201 { "client_id": "...", "token_endpoint_auth_method": "none", ... }
This is self-service (RFC 7591 Dynamic Client Registration) — no approval
queue, no waiting on Mandalo. Use "client_secret_basic" instead of "none" if
your agent can hold a secret; you'll get a one-time "client_secret" back.
## 2. Authorize (once per merchant who wants to connect you)
Send the merchant's browser to:
GET /api/oauth/authorize?response_type=code&client_id=<id>&redirect_uri=<uri>
&scope=<space-separated scopes>&state=<random>&code_challenge=<S256 of verifier>
&code_challenge_method=S256&resource=https://getmandalo.net/api/connector/v1/mcp
PKCE (S256) is mandatory. The merchant signs in with their own Mandalo login
and sees your app's name before approving it — nothing is silent. Tell the
merchant to sign in to getmandalo.net first, in the same browser, before
tapping the link — the authorization request lasts only 10 minutes, and
signing in first avoids spending part of that window on a login detour.
No callback server? Many agents have no public HTTPS endpoint to receive the
redirect. Register "https://getmandalo.net/muse" as your redirect_uri instead
(this page shows a "copy this back to your agent" box whenever it loads with
a ?code= param). After the merchant approves, have them copy the full URL
from their address bar and paste it back to you; extract "code" and exchange
it exactly as below.
## 3. Exchange the authorization code
POST /api/oauth/token (application/x-www-form-urlencoded)
grant_type=authorization_code&client_id=<id>&code=<code>&redirect_uri=<uri>
&code_verifier=<verifier>&resource=<same resource>
-> { "access_token", "refresh_token", "expires_in": 900, "scope": "..." }
Access tokens last 15 minutes. Refresh tokens rotate and last 30 days inside
a 180-day grant (refresh_token grant_type at the same endpoint).
## 4. Call the MCP tools
Authorization: Bearer <access_token> at the MCP endpoint. Five tools:
- get_account_status (scope: account:read)
- create_payment_link (scope: links:write) — two-phase: "prepare"
returns a confirmation (amount, recipient, description, fee) that you
MUST show the user verbatim and get an explicit yes for; "commit" with the
same operation_id then actually creates it. Never infer approval.
- get_payment_link_status (scope: links:read)
- list_payment_links (scope: links:read)
- get_payment_summary (scope: links:read)
## Rules that matter
- Amounts are integer USD cents. Links expire 7 days after creation.
- $1.50 fee to the merchant per successful payment; no fee to connect.
- The merchant can disconnect your access at any time (Connected apps in
their dashboard) — tokens die immediately, not at next expiry.
- A registered client that no merchant has approved cannot read or touch
anything; approval is per merchant, per app, explicit, and revocable.Live today for any MCP agent — Muse’s own directory is separate
Any MCP-capable AI agent — Claude, ChatGPT, Muse, or your own — can connect to Mandalo right now: it registers itself automatically, you approve it by name, and it’s ready to create payment links. We’ve also submitted Mandalo for Muse’s own connector directory, which would make connecting from inside Muse a single tap instead of pasting in a URL — that listing review is what’s still pending, not general access.
- Deployed at getmandalo.net, running the same authorization server, MCP endpoint, and Stripe checkout as the rest of Mandalo.
- OAuth 2.1 with mandatory PKCE — you sign in with your own Mandalo login, your AI agent never sees your password.
- Any MCP client can register itself automatically (no operator or Meta approval needed) — that's a standard called Dynamic Client Registration.
- You choose whether to turn connector access on for your own account, any time, from Connected apps in your dashboard.
- Once Muse's own directory listing clears, connecting from inside Muse becomes a single tap instead of pasting in the MCP URL.
Want in early? Ask about the pilot and we’ll let you know the moment it opens up.
FAQ
Common questions
Is this an official Meta integration?
No. Mandalo is an independent product and isn't affiliated with or endorsed by Meta. Muse is a trademark of Meta Platforms, Inc. We built this connector to the published Model Context Protocol and OAuth standards, and submitted it for review to be listed in Muse's own connector directory — that listing is still pending.
What does it cost to use from Muse?
The same as using Mandalo directly: $1.50 per successful payment plus Stripe's standard processing fees. There's no extra fee for going through Muse, and no monthly fee either.
Can Muse charge my customer without me approving it?
No. Creating a payment link is a two-step action — prepare returns a confirmation with the amount, recipient, and description, and your agent has to show it and get your explicit approval before commit actually creates the link.
What can my AI agent see about my account?
Only what the five supported actions return: account readiness, and the status, list, and summary of your own payment requests. No card numbers, no saved-payment details, and nothing from other merchants.
Do I have to wait for Meta to approve this before I can use it?
No. Meta's review only decides whether Mandalo shows up automatically inside Muse's own connector directory — a convenience for one-tap setup inside Muse specifically. It doesn't gate the connector itself: any MCP-compatible agent, including Muse configured manually, can connect today.
Does my AI agent need Mandalo's approval to connect?
No. Any MCP client can register itself automatically the first time it connects, following the OAuth Dynamic Client Registration standard (RFC 7591) — there's no signup form or approval queue on our end for the agent itself. The only approval required is yours: you have to see the app by name and explicitly allow it at the consent screen, and you can turn connector access on or off for your account any time.
Do I have to use Muse to use Mandalo?
Not at all. The connector is opt-in and sits alongside the regular dashboard — everything you can do at getmandalo.net still works exactly the same if you never connect an AI agent.
What isn't supported yet?
There's no customer search, no charging a saved card, and no resending a link through the connector yet. Those are on the list for later phases, not phase one.
Give your Muse a way to get you paid.
Set up Mandalo today and connect any MCP agent right now — no need to wait for the Muse directory listing to clear review.
Muse is a trademark of Meta Platforms, Inc. Mandalo is an independent product and is not affiliated with or endorsed by Meta.