43
/ 100
1 month ago
glama

MCPSpend

Real-time cost observability for Model Context Protocol tool calls. Wraps any MCP server, attributesspend per tool/project/customer. Free 25K calls/month. EU-hosted, GDPR-ready, MIT.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: RESEND_API_KEY, COOLIFY_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 8 credentials: APP_ENCRYPTION_KEY, COOLIFY_TOKEN, DEPLOY_SECRET, JWT_SECRET, MCPSPEND_API_KEY, RESEND_API_KEY, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configADMIN_NOTIFY_EMAIL
🔐 secretAPP_ENCRYPTION_KEYSecrets at rest AES-256-GCM ()
configCALENDAR_BOOKING_URL
configCOOLIFY_INTERNAL_URL
🔐 secretCOOLIFY_TOKEN
configDASHBOARD_URL
🔐 secretDEPLOY_SECRET
configEMAIL_FROM
configEMAIL_REPLY_TO
🔐 secretJWT_SECRET
configMCPSPEND_AGENT_NAME
🔐 secretMCPSPEND_API_KEY
configMCPSPEND_COMPAT_ENDPOINT
configMCPSPEND_CONFIG
configMCPSPEND_CUSTOMER_LABEL
configMCPSPEND_DISABLED
configMCPSPEND_ENDPOINT
configMCPSPEND_MODEL
configMCPSPEND_NO_TELEMETRY
configMCPSPEND_PROJECT_ID
configNEXT_PUBLIC_API_URL
configPORT
configREDIS_URL
🔐 secretRESEND_API_KEY
configSTRIPE_PRICE_ENT
configSTRIPE_PRICE_ENT_YEARLY
configSTRIPE_PRICE_PRO
configSTRIPE_PRICE_PRO_YEARLY
configSTRIPE_PRICE_TEAM
configSTRIPE_PRICE_TEAM_YEARLY
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
configSUPER_ADMIN_EMAILS
configXDG_CONFIG_HOME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/andreisirbu91-lab-mcpspend-1nbraw)](https://m8ven.ai/mcp/andreisirbu91-lab-mcpspend-1nbraw)
commit: c26010feded1f468fc006d10fa4d44424cd21729
code hash: c2376cac2e5b63f413a88435c7302a2a465fc1f02aac37a2c886ad414aef7868
verified: 6/10/2026, 11:13:23 AM
view raw JSON →