Pomelo MCP Server

Authentication is OAuth2 client-credentials; the server exchanges and caches the Bearer token automatically. Its 9 documented tools cover user, card.

People connecting this server to Claude, Cursor, VS Code, or another MCP client. The project is written in JavaScript.

One of 127 MCP servers published from codespar/mcp-dev-latam. Stars and repository activity are shared across all of them. See all 127 →

VERIFIED ACTIVE

LAST COMMIT 2026-08-12 · VERIFIED 2026-08-25

MIT · JavaScript servers · how we verify → /methodology

01 · Install Pomelo

before you install - you'll need

Set POMELO_CLIENT_ID, POMELO_CLIENT_SECRET before connecting. POMELO_ENV is optional or environment-specific per the README.

Claude Code

claude mcp add codespar-mcp-dev-latam-packages-banking- -- npx -y @codespar/mcp-pomelo

Claude Desktop / Cursor / VS Code - add to config

{
  "mcpServers": {
    "codespar-mcp-dev-latam-packages-banking-": {
      "command": "npx",
      "args": [
        "-y",
        "@codespar/mcp-pomelo"
      ]
    }
  }
}

Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.

Using another client? Same JSON, different key

Claude Desktop · mcpServers

Cursor · mcpServers

VS Code · servers

Windsurf · mcpServers

Zed · context_servers

Cline · mcpServers

Roo Code · mcpServers

Continue · mcpServers

LibreChat · mcpServers

Gemini CLI · mcpServers

Codex CLI · mcp_servers

Full setup guides: every client.

02 · Evidence

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as local process (stdio) - runs on your machine with your user's permissions

license MIT - declared in the repository

npm package @codespar/mcp-pomelo - published under the repo owner's npm scope (@codespar)

registry namespace io.github.codespar is GitHub-verified and matches the repo owner

03 · What Pomelo can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

What you can build

With this server connected, an agent can create a card-holder identity (POST /users/v1), fetch a user by id, patch user fields (status, contact, address), and fetch a card (masked PAN, status, program).

Capability map

Tools grouped from the project's README - what Pomelo lets an agent do.

User

3 tools - e.g. Create a card-holder identity (POST /users/v1); Fetch a user by id; Patch user fields (status, contact, address)

create_user · get_user · update_user

Card

3 tools - e.g. Issue a VIRTUAL or PHYSICAL card (POST /cards/v1); Fetch a card (masked PAN, status, program); ACTIVE / BLOCKED / DISABLED lifecycle changes

create_card · get_card · update_card_status

read & search

3 tools - e.g. List cards, filterable by user/status; Search the card-transactions feed; Fetch one transaction by id

list_cards · list_transactions · get_transaction

Limitations (from the README)

- Card credentials (full PAN/CVV) are never returned by these tools; Pomelo exposes sensitive data only through its PCI-scoped widgets. - Authorization decisioning (approving each swipe in real time) is a webhook you host, not an API call - pair this server with CodeSpar's governed authorizer if you want mandate checks per transaction.

04 · Who maintains Pomelo

mcp-pomelo is maintained by codespar. We track 127 MCP servers from codespar - 127 actively maintained, 269 combined GitHub stars, oldest repo from Mar 2026. Full record: all servers from codespar.

  1. mcp-asaas MCP server for Asaas - billing automation, Pix, boleto, credit card, subscriptions ★ 269
  2. mcp-omie MCP server for Omie - ERP, customers, products, orders, invoices, financials ★ 269
  3. mcp-sendgrid MCP server for SendGrid - global transactional + marketing email (Twilio-owned) ★ 269
  4. mcp-evolution-api MCP server for Evolution API - WhatsApp messaging, instances, contacts ★ 269
  5. mcp-stripe-acp Stripe ACP - AI agent checkout, payment delegation, products, invoices ★ 269
  6. mcp-mercado-bitcoin MCP server for Mercado Bitcoin - Brazilian crypto exchange, trading, orderbook, withdrawals ★ 269

05 · Facts

category
other - actively maintained as of 2026-08-25.
registry
io.github.codespar/mcp-pomelo (active, first published 2026-07-04)
packages
npm:@codespar/mcp-pomelo

06 · Pomelo FAQ

Is Pomelo still maintained?

Yes - as of 2026-08-25, its last commit was 2026-08-12. We re-verify nightly.

What can Pomelo do?

With this server connected, an agent can create a card-holder identity (POST /users/v1), fetch a user by id, patch user fields (status, contact, address), and fetch a card (masked PAN, status, program).

How do I install Pomelo?

Run `npx -y @codespar/mcp-pomelo`. The README documents 3 environment variables (POMELO_CLIENT_ID, POMELO_CLIENT_SECRET, POMELO_ENV) to set first. Set POMELO_CLIENT_ID, POMELO_CLIENT_SECRET before connecting. POMELO_ENV is optional or environment-specific per the README. You can also paste the ready-made client config above.

Does Pomelo run locally?

Yes - it's a stdio server: it runs on your machine (via npx) with your user's permissions. Your data stays local unless the server itself calls external APIs.

07 · Alternatives to Pomelo

More MCP servers to compare · Cobre · Coordinadora · Epayco · Nequi · Unblockpay

More JavaScript MCP servers · Santander · Sicoob · Stark Bank · Alegra · Bold Co · see all