MCP · for coding agents
Empower agents with auth and payments.
MCP tools to automate auth and pay — your keys and card never leave the vault.
Works inside
Claude Code
Codex
Goose
Cursor
OpenCode
$add Google OAuth in one prompt
squire opening Google Cloud Console · OAuth client, secret…
✓ secret sealed → vault cred_oauth_••••••
# used via the proxy — never shown to the agent
What developers ask
What is Trusty Squire?
Trusty Squire is an MCP server for coding agents. Claude Code, Codex, Cursor, OpenCode, or Goose plans the job; Trusty Squire operates the website, wires up the integration, or completes the purchase — keeping the generated secret or card on the safe side of the boundary.
How does it work?
- Your agent names the outcome — an account, an integration, or a purchase.
- Trusty Squire drives the real signup, setup, or checkout flow.
- The credential or card is encrypted in a write-only vault and injected server-side when used.
If a site requires a phone, hard CAPTCHA, or a decision only you should make, the run stops and tells you instead of guessing.
Magic happens when your agents can sign up, provision, and purchase on your behalf — hard tasks in one prompt.
Trusty Squire can— (tap any task)
›Add Google OAuth to your app
In the backgroundSigns into Google Cloud, creates a project, configures the OAuth consent screen, mints client credentials, and vaults the secret — the client ID drops straight into your config.
Vanilla agents stop atThe Google sign-in, and they can't safely hold the client secret.
›Publish your mobile apps to the App Store & Play Store
In the backgroundSigns into App Store Connect and Play Console, generates and cross-signs the certificates and provisioning profiles, uploads the build, fills the listing, and submits for review.
Vanilla agents stop atThe developer-account 2FA login and the certificate signing.
›Set up Firebase for your project
In the backgroundCreates the Firebase project, enables Auth / Firestore / Storage, generates the service-account key, vaults it, and writes your config files.
Vanilla agents stop atThe Google login, and they can't hold the service-account private key.
›Add Stripe payments
In the backgroundSigns up for Stripe, clears business verification, creates API keys and webhook endpoints, vaults the secret key, and wires the publishable key into your frontend.
Vanilla agents stop atSignup, identity/business verification, and the secret key.
›Buy gifts for your friends and colleagues
In the backgroundReaches out to get their preference and delivery address directly, picks the item, checks out with your card injected server-side and one approval, and ships it.
Vanilla agents stop atThe payment, and they can't get someone's private address without you asking.
›Automate customer email outreach
In the backgroundSigns up for Resend, pulls your customer list from Algolia, runs the daily outreach, and handles the replies that land in your Gmail inbox.
Vanilla agents stop atThe Resend signup — and their own safety filters block automated bulk sending, so the workflow never even starts.
›Run a paid acquisition campaign
In the backgroundSigns up for Google Ads, verifies the business, puts a card on file, launches a search campaign against your keywords, and tunes bids daily against conversions.
Vanilla agents stop atAd-account identity verification, the card on file, and the daily spend decisions no headless agent can self-authorize.
›Wire up product analytics and alerts
In the backgroundSigns up for PostHog and Sentry, installs the keys, connects a Slack webhook, and routes error spikes and funnel drop-offs straight into your channel.
Vanilla agents stop atThe two signups, the Slack OAuth connect, and holding each project's key.
›Onboard a teammate's tool stack
In the backgroundCreates their GitHub, Linear, and Slack seats, pays for each, and sends the invites — so they land ready to work.
Vanilla agents stop atThe admin-console logins, per-seat billing on each tool, and SSO enrollment.
›Book travel or a reservation
In the backgroundSearches and selects, fills the passenger or guest details, pays behind the fence with one approval, and confirms.
Vanilla agents stop atThe payment and the account login.
…and any complex task that stalls at a signup or a payment.
The card is never exposed to the agent, and no charge happens without one human approval. API keys stay vaulted — the raw secret never enters the agent’s context.
Install the squire. Let it handle the rest.
One command. Plugs into your agent of choice. Free to start.