Square MCP server, with a policy gate.
Connect Square to any MCP client through one OAuth-protected URL, with writes gated behind grants you can revoke per agent.
https://app.gentkey.com/mcpclaude.ai (web & mobile) · Claude Code · Cursor · any MCP clientWhat’s free, what needs a grant.
Reads: The two API-discovery tools — service and type schemas — work with no grant. Actual data reads don't: every real API call runs through one make_api_request tool that can also write, so it stays gated even for GET-shaped calls.
Writes: Grant mcp-square.write and every actual API call opens — catalog, orders, payments, reads and writes alike; revoke it per agent surface any time.
Gentkey proxies the official Square MCP server (https://mcp.squareup.com/mcp) — you get the vendor’s own tools, with custody, gating, and audit added in front.
| Grant | What it governs |
|---|---|
mcp-square.write | make_api_request — every actual Square API call, reads included, because one tool multiplexes the whole API |
Connect once, use everywhere.
Sign in at gentkey.com, add Square (oauth), then point each client at your endpoint. Every client completes a standard OAuth flow and lands in your Gentkey — your connections, nobody else’s.
claude.ai (web & mobile)
- Settings → Connectors
- Add custom connector
- Paste
https://app.gentkey.com/mcpand finish the OAuth prompt
Claude Code
claude mcp add --transport http \
gentkey https://app.gentkey.com/mcpCursor
// .cursor/mcp.json
{
"mcpServers": {
"gentkey": { "url": "https://app.gentkey.com/mcp" }
}
}Things agents do with Square here.
- What did the store sell today?
- Add a seasonal item to the catalog at $12.50.
- Which items are low on inventory?
- Refund the last order from this morning.
Custody, gating, and audit — built in.
The model never sees a credential
Your Square token is encrypted at rest and injected server-side at call time. Your stored credential never enters a context window.
Writes need a grant
Anything that changes state needs a capability you granted explicitly — revoke it and the next call is denied.
A trail you can act on
Every decision is attributed to the agent that made it — allowed, denied, or denied by constraint.
Fair questions.
Can I let an agent read sales without letting it refund?
Not for Square — its server routes every real API call, sales reads and refunds alike, through a single make_api_request tool, so an honest read grant can't be carved out of it. Only the API-discovery tools are grant-free. The taxonomy deepens per connector over time: RevenueCat and Superwall already have per-resource grants.
What happens when an agent calls a Square write tool it hasn't been granted?
The call is denied at the gateway — nothing reaches Square — and the denial is recorded in the audit log along with the grant that would have authorized it, so you can decide deliberately instead of finding out later.
Where are my credentials stored?
Encrypted at rest (AES-256-GCM) on Gentkey's server and injected server-side at call time. No credential you store with Gentkey ever enters a model's context window or an agent's config file.
Can I use this from claude.ai's free plan?
Yes — and it's the strongest case for a gateway: free claude.ai accounts currently get a single custom connector, so pointing that one slot at Gentkey puts every connector you've linked behind it.
How do I revoke an agent's access?
Revoke the grant (the next write is denied) or revoke the agent's tokens entirely in one click. Other agents and their grants are untouched — no shared key to rotate.
Is Gentkey affiliated with Square?
No. Gentkey is an independent MCP gateway. Trademarks belong to their owners; where an official Square MCP server exists, Gentkey proxies it and adds custody, gating, and audit on top.
Often connected together.
Cut Square a smaller key.
Sign in, connect Square, and grant your first scoped capability in under a minute.