Set up the Chargefy test key in this project and make a sample call.
Create a webhook endpoint to confirm payments.
Review my Chargefy integration before I ship it to production.
In Codex and Cursor, install the Chargefy skills
and connect MCP directly. The plugin with the reviewer is specific to Claude
Code and Cowork. For Claude Desktop and ChatGPT, follow the MCP guide.
What the plugin does
Three things:- Teaches the assistant how to integrate Chargefy. It loads ready-made instructions, called skills, about payments, billing, and platforms, plus focused guidance on keys, checkout, webhooks, API conventions, and sandbox testing. They kick in on their own when the subject comes up in the conversation.
- Reviews the code before it ships. A reviewer looks for the mistakes that slip past human review and only show up in production, such as a webhook that does not verify the signature.
- Protects your secret key. If a production key ends up in a file headed for Git, the assistant warns you right away.
The skills
The plugin includes the same four skills distributed for Codex, Cursor, and other agents. The reviewer, credential hook, and MCP configuration are plugin extras. See all four skills and examples. You do not need to call a skill by name: just describe what you want. If you prefer, they also work as commands, for example/chargefy:chargefy-payments.
Integration reviewer
Ask “review this Chargefy integration” and the reviewer reads the code looking for the five mistakes that cause the most trouble in production:- Webhook without signature verification, or verifying a body that has already gone through a parser and been reserialized. In both cases, anyone can send a fake event to your system.
- Charge without an
Idempotency-Key, or with a new key on every attempt. A retry can charge the customer twice. - Secret key in code that reaches the browser. The key leaks to anyone who opens the page’s source code.
- Redirect treated as payment confirmation. The buyer landing on the success page does not prove they paid. Only the webhook does.
- Retry on the
502 payment_result_unconfirmederror. That error means “I do not know whether the charge went through”. Repeating the call can charge again.
@chargefy:integration-reviewer.
Secret-key protection
When a production key (ch_live_...) is written to a file that Git tracks, the assistant gets a warning and fixes it before moving on. Your local .env, which Git ignores, does not trigger a warning, because that is exactly where the key belongs. The key is never shown in full.
Connecting to MCP
The plugin ships with thehttps://mcp.chargefy.io server already configured. For the assistant to see your account’s data, all that is left is to authorize:
1
Open the MCP menu
In Claude Code, type
/mcp and select chargefy.2
Authenticate
Choose Authenticate. The browser opens the Chargefy sign-in screen.
3
Choose organization and environment
Select the organization and set the access for test and for production.
Start with test and read only.
Keeping it current
1
Update the marketplace
claude plugin marketplace update chargefy fetches the latest published
version.2
Update the plugin
claude plugin update chargefy applies the new version.3
Remove it whenever you want
claude plugin uninstall chargefy uninstalls the plugin. The MCP
authorization stays valid until you revoke it under Developers → Agents.Open source
The plugin is MIT-licensed and lives at chargefy-io/claude-plugin. Its content is generated from the code that runs in production. Found a mistake? Open an issue in the repository or talk to support.Keep going
Chargefy MCP
Connect other assistants to the same server.
Access and permissions
Organization, environments, read, write and revocation.
Tools and operations
What the assistant can execute on each connection.
Sandbox
Deterministic test cards and scenarios.

