AI Assistants (MCP)
Connect your AI Assistant such as Claude, ChatGPT, Codex or Cursor to your store so it can look things up and make changes for you.
Once it is connected, you can ask for things in plain English and it does them in your store. It can also read these guides, so it can answer questions about how PayNow works.
Every app connects to the same address:
https://api.paynow.gg/mcpTwo ways to connect
| Sign in with PayNow | API key | |
|---|---|---|
| Works in | Claude, Claude Code, ChatGPT, Codex, Cursor | Claude Code, Codex, Cursor |
| Stores | Any you tick when you sign in | Exactly one, the store the key belongs to |
| What it can do | What you allow when you sign in, never more than your own role | Everything the key's role allows, and nothing else |
| Turn it off | Remove it from Connected Apps | Delete the key |
Sign in is the right choice for most people. You approve it in a browser, pick your stores and permissions on one screen, and there is no secret to look after.
Use an API key when you want the assistant locked to a single store with a role you built just for it, or when it runs somewhere that cannot open a sign-in page, such as a script or a shared project.
Connect by signing in
Add PayNow in your app using the steps below. A PayNow sign-in page then opens. Sign in, tick the stores you want it to reach, and choose what it may read and change.
Add the server:
claude mcp add --transport http paynow https://api.paynow.gg/mcpThen start Claude Code, type /mcp, choose PayNow and sign in.
This adds it to the current project only. Add --scope user to the command to have it in every project.
Connect with an API key
- Create a role for the assistant under Access → Roles, with only the permissions it needs. See Roles.
- Create a key under Integrations → API Keys and give it that role. Name it after where it runs, such as
claude-code-laptop. See API Keys. - Save the key in an environment variable on your computer rather than pasting it into a settings file. On macOS and Linux that is
export NAME="value"in your shell profile. On Windows it issetx NAME "value", then open a new terminal. - Set your app to send the key in the
Authorizationheader, withAPIKeyand a space in front of it.
The key can do everything its role can do, in that store. There is no PayNow sign-in or approval screen, and anyone who gets hold of the key has the same access, so give the role as little as the job needs. The rules in Keeping keys safe all apply.
Add this to .mcp.json in your project folder:
{
"mcpServers": {
"paynow": {
"type": "http",
"url": "https://api.paynow.gg/mcp",
"headers": {
"Authorization": "APIKey ${PAYNOW_API_KEY}"
}
}
}
}Set PAYNOW_API_KEY to your key before starting Claude Code. Claude Code fills in ${PAYNOW_API_KEY} when it starts, so the key itself never goes in the file and the file is safe to commit. The first time it loads the server, Claude Code asks you to approve it.
Claude on the web and desktop, and ChatGPT's developer mode, only offer sign-in for custom servers, so there is nowhere to put a key. Use sign-in there.
Any other app works if it can connect to a remote or HTTP MCP server. Use sign-in if it offers it. Otherwise, set the header Authorization to APIKey followed by your key. If it only offers to run a program on your computer, it cannot connect to PayNow.
Things to ask
- How is my store revenue holding up this month?
- How many customers used PayPal to check out this month?
- Create a 20% sale called WEEKEND that expires Monday.
- How do tier groups work?
- Vibecode me a minecraft template for my new SMP
Read before you approve
This is your real store. The assistant can perform dangerous actions, and customers see it straight away. Most apps ask you to approve a change before making it, but that is up to the app and its settings, not something PayNow can promise. Check how yours behaves before you rely on it.
If you just want to see what it can do, connect a store with no real customers, or use an API key whose role can only read.
Turn it off
- Signed in: go to Connected Apps in your account settings and remove it. That revokes its access to every store you ticked.
- API key: delete the key under Integrations → API Keys. It stops working straight away.
Removing the server in your assistan's settings only stops that app from using it, so do both if you want it fully gone. Anything it already changed stays changed.