Focxle: virtual cards, spend limits and procurement for AI agents
warningsfocxle.com
Virtual cards and spend budgets for AI agent procurement: SaaS, API and subscription checkout.
https://focxle.com/api/v1/mcp/cardsWebsiteOAuthMCP 2024-11-05v1.0.0last checked 22 Sep 2026spoke MCP on 100% of 5 checks (30 days)initialize in 248 msWill my client connect?
Decided from what the probe found at the endpoint, and from what each client's own documentation says it can complete. Every row carries the day that documentation was read.
✕Claude CodeNot supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
Claude Code docs · read on 2026-08-30
✕Claude (claude.ai & Desktop)Not supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
Claude (claude.ai & Desktop) docs · read on 2026-08-30
✕ChatGPTNot supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
ChatGPT docs · read on 2026-08-30
✕CursorNot supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
Cursor docs · read on 2026-08-30
✕VS Code (Copilot)Not supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
VS Code (Copilot) docs · read on 2026-08-30
How to authenticate
Checked against the endpoint by our probe on 22 Sep 2026. These are the capabilities the server advertises, not a prediction about any particular client.
| Scheme | OAuth |
|---|---|
| Issuer | https://focxle.com |
| Dynamic client registration | ✓Advertised (RFC 7591) |
| Client ID Metadata Document | ✕Not advertised |
| PKCE | ✕None advertised MCP requires S256; a client that implements only that has no method in common with this server. |
| Grant types | client_credentials |
| Protected-resource metadata | ✓Published (RFC 9728) |
| Anonymous access | Handshake succeeds; 7 tools listable |
| Credentials demanded in prose | ✕card_get_virtual These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error. |
What the probe found
1 of the 7 tools listed anonymously say in their own descriptions that they need an account or a key (card_get_virtual), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.
A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.
The server exposes a public surface before authorization: card_get_virtual, spend_request_approval, agent_register, payment_record, spend_check_limit, trust_check_agent, payment_history_mine.
Tools
Contract history
Watch this server
Save its public contract as a baseline and manage breaking-change email alerts.
Set up a watchOwn this server?
Sign in to claim this listing by proving control of its host.
Status badge
Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.
[](https://mcpi.app/servers/focxle-virtual-cards-spend-limits-and-procurement-for-ai-agents)