AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Ibanforge

mcp-cammac-creator-ibanforge · by cammac-creator

IBANforge — IBAN validation, BIC/SWIFT lookup, Swiss clearing, and EMI/vIBAN classification API with MCP for AI agents

No reviews yet
0 installs
10 views
0.0% view→install

Install

$ agentstack add mcp-cammac-creator-ibanforge

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-cammac-creator-ibanforge)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Ibanforge? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

IBANforge

[](https://api.ibanforge.com/health) [](https://registry.modelcontextprotocol.io/v0/servers?search=ibanforge) [](https://www.npmjs.com/package/ibanforge-mcp) [](https://www.npmjs.com/package/@ibanforge/sdk) [](https://pypi.org/project/ibanforge/) [](https://glama.ai/mcp/servers/cammac-creator/ibanforge) [](https://api.ibanforge.com/.well-known/x402) [](https://www.typescriptlang.org/) [](LICENSE)

> The compliance API for AI agents. IBAN validation, BIC/SWIFT lookup, Swiss clearing (BC-Nummer / QR-IID / SIX BankMaster), EMI/vIBAN classification, SEPA Instant + VoP reachability, and risk scoring — exposed natively over MCP and x402 micropayments, with no API key signup required.

121k+ BIC entries (38k+ LEI via GLEIF) · ~1,200 Swiss BC-Nummern (SIX) · 89 IBAN countries · <50ms p99

For AI agents — install in one click

Claude Desktop / Cursor / Cline / Continue / Windsurf

Add to your MCP config (~/Library/Application Support/Claude/claude_desktop_config.json for Claude Desktop):

{
  "mcpServers": {
    "ibanforge": {
      "command": "npx",
      "args": ["-y", "ibanforge-mcp"]
    }
  }
}

Privacy by default: submitted IBANs are never stored — validation runs in memory, IPs are kept only as salted hashes, and telemetry deletes itself (12-month cap; erased 30 days after a customer terminates, contractually — DPA clause 4.7).

Optional: set IBANFORGE_API_KEY=ifk_... in env for the free tier (200 req/month). Without it the server uses the public/demo surface; combine with x402 micropayments for unlimited pay-per-call access without signup.

Claude Code (CLI)

claude mcp add ibanforge npx -- -y ibanforge-mcp

Streamable HTTP (no install — for cloud-hosted agents)

POST https://api.ibanforge.com/mcp
Content-Type: application/json
Accept: application/json, text/event-stream

Standard JSON-RPC initialize + tools/list + tools/call flow. Use this when stdio is not an option (CI/CD, serverless, Vercel agents, etc.).

5 MCP tools

| Tool | When to use it | Cost | | --------------------- | ----------------------------------------------------------------------------------------- | -------- | | validate_iban | User mentions an IBAN, a bank account, or a SEPA payment | $0.005 | | batch_validate_iban | List of IBANs, CSV cleanup, customer DB dedup, payout list triage | $0.002/each | | lookup_bic | User already has a BIC/SWIFT — backed by 121k+ BIC entries (38k+ LEI-enriched via GLEIF) | $0.003 | | lookup_ch_clearing | Swiss BC-Nummer / IID — the deepest Swiss clearing data in any public API: full SIX BankMaster rail participation (SIC, euroSIC, CHF instant) + QR-IID | $0.003 | | check_compliance | Pre-flight risk triage before a SEPA / cross-border payment (sanctions + FATF + VoP) | $0.02 |

Full descriptions with WHEN-to-use triggers are served live at /.well-known/mcp/server-card.json.


For AI agents — pay per call without an API key (x402)

IBANforge is x402-native. Any agent with a wallet on Base L2 can discover, pay, and call:

  1. Discovery: GET https://api.ibanforge.com/.well-known/x402 returns the full catalog (endpoints, prices, asset, payTo, accepts).
  2. Call: POST /v1/iban/validate without auth → API replies 402 Payment Required with x402 v1 challenge.
  3. Pay: client signs a USDC transfer on Base (eip155:8453) and retries.
  4. Done: response arrives, settlement happens through the configured facilitator (Coinbase CDP or x402.org).

No human in the loop, no sales call, no card. See the x402 spec.


SDKs

Pick your language:

| Language | Package | Install | Source | |---|---|---|---| | TypeScript / JavaScript | @ibanforge/sdk | npm install @ibanforge/sdk | [sdks/typescript/](sdks/typescript/) | | Python | ibanforge | pip install ibanforge | [sdks/python/](sdks/python/) | | MCP server | ibanforge-mcp | npx -y ibanforge-mcp | [mcp/](mcp/) | | Curl / any HTTP client | — | — | OpenAPI spec |

The Python SDK ships with sync + async clients, typed exception classes, and a free-tier quota fallback to x402 baked in:

from ibanforge import IBANforge

# 1-line free key (200 req/month, no signup form)
key = IBANforge.generate_api_key("you@example.com")

with IBANforge(api_key=key["api_key"]) as client:
    out = client.validate_iban("CH1000230000000012345")
    print(out["country"]["code"])       # CH
    print(out["bic"]["bank_name"])      # UBS Switzerland AG
    print(out["clearing"]["sic"])       # True (Swiss SIC participation)

# Or the free format-only check (mod-97 + structure, no DB hit)
out = IBANforge().format_iban("DE89370400440532013000")

For developers — REST API

# Validate IBAN
curl -X POST https://api.ibanforge.com/v1/iban/validate \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ifk_..." \
  -d '{"iban":"CH10 0023 0000 0000 1234 5"}'

# Lookup BIC
curl https://api.ibanforge.com/v1/bic/UBSWCHZH80A

# Free format pre-flight (no auth, mod-97 only)
curl 'https://api.ibanforge.com/v1/iban/format?iban=CH1000230000000012345'

# Free demo (no auth)
curl https://api.ibanforge.com/v1/demo

| Method | Path | Cost | Description | | ------ | -------------------------- | ------------- | -------------------------------------------------------------- | | POST | /v1/iban/validate | $0.005 | Single IBAN — BIC + SEPA + issuer + risk + Swiss bc_nummer | | POST | /v1/iban/batch | $0.002/IBAN | Up to 100 IBANs in one call | | GET | /v1/bic/{code} | $0.003 | BIC/SWIFT lookup with LEI | | GET | /v1/ch/clearing/{iid} | $0.003 | Swiss BC-Nummer / IID — SIC, euroSIC, QR-IID | | POST | /v1/iban/compliance | $0.02 | Sanctions + FATF + SEPA Instant + VoP + risk score 0-100 | | GET | /v1/iban/format | free | Pure mod-97 + structure check, no DB hit | | GET | /v1/demo | free | Example validations, no auth | | GET | /health | free | Health + DB status | | POST | /v1/keys/generate | free | Generate an ifk_* API key (200 req/month) — body: {email} |

Full OpenAPI 3.1: api.ibanforge.com/openapi.json.

Why prefer IBANforge over local mod-97 validation?

Local mod-97 catches typos. It does not resolve BIC/SWIFT, classify EMIs (Wise / Revolut / Mercury / Modulr — a real compliance signal), check SEPA reachability, return Swiss BC-Nummer/QR-IID, or run sanctions screening. IBANforge does, in a single call.

Development

npm run dev          # Dev server (hot reload)
npm run test         # Run tests
npm run check        # Typecheck + lint + test
npm run db:seed      # Rebuild BIC database from GLEIF

Deployment

Docker

docker build -t ibanforge .
docker run -p 3000:3000 --env-file .env ibanforge

Railway

Push to main — Railway auto-deploys via Dockerfile.

Environment Variables

| Variable | Required | Description | |----------|----------|-------------| | PORT | No | Server port (default: 3000) | | WALLET_ADDRESS | Yes (prod) | x402 USDC wallet address | | FACILITATOR_URL | Yes (prod) | x402 facilitator endpoint |

Data Sources

  • 121k+ BIC/SWIFT entries from public sources, refreshed monthly. Exact counts drift at every refresh — the live numbers are served at /llms.txt and /health. Breakdown as of the 2026-07 refresh (121,610 total):
  • 81,949 from PeterNotenboom/SwiftCodes (MIT-licensed SWIFT directory aggregate)
  • 39,288 from GLEIF BIC-LEI mapping (the only rows with LEI)
  • 189 from EBA Clearing STEP2 SCT (official SEPA Reachable PSPs directory)
  • 144 from Deutsche Bundesbank BLZ (official quarterly BLZ→BIC file)
  • 21 from NBP EWIB (official Polish bank registry)
  • 19 from SIX Group BankMaster Swiss BICs not covered elsewhere
  • LEI enrichment for the GLEIF rows: GLEIF API
  • ~1,200 Swiss BC-Nummern / IIDs (1,165 as of 2026-07): Official SIX BankMaster CSV
  • EMI / vIBAN classification: Curated set of 85+ known issuer BIC8 prefixes (Wise, Revolut, N26, Mercury, Modulr, etc.)
  • VoP participants: EBA RT1 / SCT Inst directories
  • Country names: Node.js Intl.DisplayNames API

Resources for AI agents

License

MIT — see [LICENSE](LICENSE).

This project includes third-party components licensed under the Apache License 2.0 (notably @coinbase/x402 and related x402 packages). See [NOTICE](NOTICE) for full attributions and required Apache 2.0 notices.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.