PayNow

AI Assistants (MCP)

Connect your AI Assistant such as Claude, ChatGPT, Codex or Cursor to your store so it can look things up and make changes for you.

Once it is connected, you can ask for things in plain English and it does them in your store. It can also read these guides, so it can answer questions about how PayNow works.

Every app connects to the same address:

Text
https://api.paynow.gg/mcp

Two ways to connect

Sign in with PayNowAPI key
Works inClaude, Claude Code, ChatGPT, Codex, CursorClaude Code, Codex, Cursor
StoresAny you tick when you sign inExactly one, the store the key belongs to
What it can doWhat you allow when you sign in, never more than your own roleEverything the key's role allows, and nothing else
Turn it offRemove it from Connected AppsDelete the key

Sign in is the right choice for most people. You approve it in a browser, pick your stores and permissions on one screen, and there is no secret to look after.

Use an API key when you want the assistant locked to a single store with a role you built just for it, or when it runs somewhere that cannot open a sign-in page, such as a script or a shared project.

Connect by signing in

Add PayNow in your app using the steps below. A PayNow sign-in page then opens. Sign in, tick the stores you want it to reach, and choose what it may read and change.

Add the server:

Bash
claude mcp add --transport http paynow https://api.paynow.gg/mcp

Then start Claude Code, type /mcp, choose PayNow and sign in.

This adds it to the current project only. Add --scope user to the command to have it in every project.

Connect with an API key

  1. Create a role for the assistant under Access → Roles, with only the permissions it needs. See Roles.
  2. Create a key under Integrations → API Keys and give it that role. Name it after where it runs, such as claude-code-laptop. See API Keys.
  3. Save the key in an environment variable on your computer rather than pasting it into a settings file. On macOS and Linux that is export NAME="value" in your shell profile. On Windows it is setx NAME "value", then open a new terminal.
  4. Set your app to send the key in the Authorization header, with APIKey and a space in front of it.

The key can do everything its role can do, in that store. There is no PayNow sign-in or approval screen, and anyone who gets hold of the key has the same access, so give the role as little as the job needs. The rules in Keeping keys safe all apply.

Add this to .mcp.json in your project folder:

JSON
{
  "mcpServers": {
    "paynow": {
      "type": "http",
      "url": "https://api.paynow.gg/mcp",
      "headers": {
        "Authorization": "APIKey ${PAYNOW_API_KEY}"
      }
    }
  }
}

Set PAYNOW_API_KEY to your key before starting Claude Code. Claude Code fills in ${PAYNOW_API_KEY} when it starts, so the key itself never goes in the file and the file is safe to commit. The first time it loads the server, Claude Code asks you to approve it.

Claude on the web and desktop, and ChatGPT's developer mode, only offer sign-in for custom servers, so there is nowhere to put a key. Use sign-in there.

Any other app works if it can connect to a remote or HTTP MCP server. Use sign-in if it offers it. Otherwise, set the header Authorization to APIKey followed by your key. If it only offers to run a program on your computer, it cannot connect to PayNow.

Things to ask

  • How is my store revenue holding up this month?
  • How many customers used PayPal to check out this month?
  • Create a 20% sale called WEEKEND that expires Monday.
  • How do tier groups work?
  • Vibecode me a minecraft template for my new SMP

Read before you approve

This is your real store. The assistant can perform dangerous actions, and customers see it straight away. Most apps ask you to approve a change before making it, but that is up to the app and its settings, not something PayNow can promise. Check how yours behaves before you rely on it.

If you just want to see what it can do, connect a store with no real customers, or use an API key whose role can only read.

Turn it off

  • Signed in: go to Connected Apps in your account settings and remove it. That revokes its access to every store you ticked.
  • API key: delete the key under Integrations → API Keys. It stops working straight away.

Removing the server in your assistan's settings only stops that app from using it, so do both if you want it fully gone. Anything it already changed stays changed.