Wathba

io.github.wathba-orgv2.0.1Updated Oct 1, 2026

Saudi payments, OTP/SMS, KYC, ZATCA e-invoicing and shipping for AI coding agents.

VerifiedStreamable HTTPWeb executableBusiness & CommerceDeveloper Tools

Overview

AI-generated overview

Connects AI coding agents to Wathba's hosted MCP server for Saudi payments, OTP/SMS, KYC, ZATCA e-invoicing and shipping.

What it does
Wathba is the official plugin that links AI coding agents to Wathba's hosted MCP server (R2, R3). Through it, an assistant can reach Wathba services for payments, OTP/SMS, KYC, ZATCA e-invoicing and shipping (R4). The plugin adds a short skill describing how the agent should use the server (R3), and the server exposes a fixed list of tools tracked in contract.json (R40).
When to use it
Use it when building or operating an application that needs Saudi-market services such as payments, OTP/SMS verification, KYC, ZATCA e-invoicing or shipping, and you want an AI coding agent to call those services directly (D1, R4). It suits teams already using Wathba as their provider rather than general-purpose agent work. Skip it if you do not need these services or do not have a Wathba account.
Requirements
A remote Streamable HTTP MCP server at (production) or (development) (R6, R7). No API keys or environment variables are declared; members sign in through the browser via OAuth (R4, R10, R14). Works with Claude Code, Codex, the ChatGPT desktop app, Claude web/Desktop/Cowork and other MCP clients (R3, R18). Network access to the Wathba endpoint is required.
Before you install
Connections receive full agent access to the Wathba account, and the consent page shows what that allows (R32); review it before approving. The plugin itself handles no API keys and sign-in is via browser OAuth (R4), but the tools can trigger payments, send OTP/SMS messages, submit KYC data, issue ZATCA e-invoices and arrange shipping, so actions may move money or send data to third parties. Use either the plugin or a direct connection, not both, or every tool appears twice (R19).

Installation

In SourceWeft

  1. Open Wathba in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "wathba": {
      "type": "http",
      "url": "https://api.wathba.info/mcp"
    }
  }
}

README

Wathba agent plugin

The official Wathba (وثبة) plugin for AI coding agents. It connects Codex, the ChatGPT desktop app, Claude Code and other Agent Plugins clients to Wathba's hosted MCP server, and adds one short skill that tells the agent how to use it. Payments, OTP/SMS, KYC, ZATCA e-invoicing and shipping reach your app through Wathba; the plugin never handles API keys, and members sign in through the browser (OAuth).

EnvironmentBranchInstall idMCP server
Productionmainwathba@wathbahttps://api.wathba.info/mcp
Developmentdevwathba-dev@wathba-developmenthttps://apidev.wathba.info/mcp

Install

Claude Code

text
/plugin marketplace add wathba-org/wathba-plugin/plugin install wathba@wathba

For the development environment, add wathba-org/wathba-plugin#dev and install wathba-dev@wathba-development. Then run /mcp, choose the Wathba server and sign in. To get updates automatically, open /plugin, go to Marketplaces, select the marketplace and choose Enable auto-update.

Codex and the ChatGPT desktop app

sh
codex plugin marketplace add wathba-org/wathba-plugincodex plugin add wathba@wathba

For the development environment, add --ref dev and install wathba-dev@wathba-development. Installing from the app's Plugins page starts sign-in; in a terminal, run codex mcp login wathba (or wathba-dev). Codex checks the marketplace for updates when it starts.

Any other MCP client

Add the remote MCP server URL from the table above with the Streamable HTTP transport; the client discovers Wathba's OAuth settings on its own. Claude (web, Desktop and Cowork) and ChatGPT take it as a custom connector. Use either the plugin or a direct connection, not both, or every Wathba tool appears twice.

How this repository works

Nothing under plugins/, .claude-plugin/, .agents/ or contract.json is edited by hand. They are generated from two sources:

  • plugin.config.json: identities, origins, version, branding and listing text.
  • src/: the shared skill (src/skills/wathba/SKILL.md), the icon, and the README for the dev branch.

scripts/sync.mjs builds one marketplace per environment and enforces the packaging rules: identities, paths, one MCP server per package with no headers or scopes, environment isolation, no credentials, the skill's tool list, and the icon hash.

WorkflowWhenWhat it does
validateEvery PR, push to main, weeklyGenerator rules, version rule, then installs both builds into throwaway Claude Code and Codex homes, then checks the live OAuth metadata
publish-devPush to mainBuilds the development marketplace, verifies it, and publishes it to the dev branch
driftDailyChecks both environments' live OAuth metadata and opens an issue when it stops matching
releasev* tag on mainGitHub release with the plugin ZIP, then the MCP Registry entry

The packages carry no scopes. The Wathba server decides the grant: every connection gets full agent access, and the consent page shows exactly what that allows.

Change the plugin

  1. Edit plugin.config.json or src/.
  2. Run node scripts/sync.mjs check.
  3. If the production package changes, raise version in plugin.config.json. CI refuses a changed package with the same version, because Claude Code updates only when the version changes.
  4. Open a pull request. Every change here reaches members' agents, so the owner's review is required.

contract.json lists the Wathba tools the skill names. The platform's CI reads it and fails a backend change that would remove or rename one of them.

Release production

  1. Merge the change (with its higher version) to main. Plugin installs pick it up from main.
  2. Tag the merge commit v<version> and push the tag. release.yml checks that the tag, config and package agree, attaches the plugin ZIP, server.json and checksums to a GitHub release, then publishes server.json to the official MCP Registry after the owner approves the registry environment.

listing/ holds the material for the Anthropic and OpenAI directories.

Acceptance

docs/acceptance/ records the real host journeys (sign-in, reads, project creation, replay, recovery, update, rollback). A host is listed as supported only after a recorded run.

License

Apache-2.0

Source: README.md at commit a14db87

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v2.0.1LatestOct 1, 2026