https://mcp.agentcard.sh/mcp with the user’s connection token (or a buy_token for org-owned accounts).
Behavior: read-only, idempotent.
What it does
The user’s cards: every live card they hold, with IDs, last four digits, expiry, balance, and status, plusvaultCards: the user’s OWN cards stored in their Agentcard vault (display fields only; a vaulted card pays through buy with an approval on the user’s device (their passkey or master password) and never exposes a number). Start here to find available cards; if none are returned, call create_card. Cards created by another app or company are read-only from this session: get_card_details and close_card will not work on them.