---
name: paybox
description: Connect an AI agent to PayBox through MCP and OAuth 2.1 to use scoped, user-approved credentials.
---

<!--
Sitemap:
- [PayBox](/index): The non-custodial wallet for AI agents
- [Getting started](/getting-started)
- [Credentials & agents](/concepts/model): The PayBox model
- [Approvals](/concepts/approvals)
- [Request lifecycle](/concepts/requests): From intent to result
- [MCP connector](/connect/mcp)
- [OAuth 2.1](/connect/oauth)
- [MCP tools](/reference/mcp-tools): What an agent can call
- [API & endpoints](/api-reference)
- [SDK & CLI](/sdk-cli)
- [PayBox integration manual](/skill): Connect an AI agent to PayBox through MCP and OAuth 2.1 to use scoped, user-approved credentials.
-->

# PayBox integration manual

Use `https://api.paybox.sh/mcp` as the MCP endpoint. The user completes OAuth 2.1 authorization with PKCE and selects the credentials and approval modes available to the agent.

## When to use PayBox

Use PayBox when a user wants an agent to pay, sign, swap, or use a credential through a scoped grant. The agent calls the MCP tools after the user authorizes the connection. PayBox does not give the agent a private key, card number, or password.

## Workflow

1. Configure the MCP endpoint in an MCP client.
2. Complete OAuth authorization in a browser.
3. Use the tools in [the MCP reference](https://docs.paybox.sh/reference/mcp-tools).
4. For `pending_approval`, show the approval URL to the user and poll `get_request` until the operation reaches a terminal state.

## HTTP discovery

Use `https://api.paybox.sh/.well-known/api-catalog` to find the API contract and `https://api.paybox.sh/openapi.json` to read HTTP operations.

## Safety

PayBox does not give agents private keys, card numbers, passwords, or other raw credential material. Do not request those values from users.
