https://mcp.agentcard.sh/mcp with the user’s connection token (or a buy_token for org-owned accounts).
Behavior: read-only, idempotent.
What it does
The user’s wallet: every live card they hold, with IDs, last four digits, expiry, balance, and status, plusvaultCards: the user’s OWN cards stored in their Agentcard vault (display fields only; a vaulted card pays through buy with a Face ID approval and never exposes a number). Start here to find available cards; if none are returned, call create_card. When the shared wallet is enabled, wallet lists every card across all connected apps and companies, each tagged with its source (kind personal/company, the issuing app, and the company where applicable); cards created by another app or company are read-only from this session: get_card_details and close_card will not work on them.