# list_payments

List payment history for this account.

Agent View of the PolicyLayer registry record for `list_payments`. HTML page: https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/list-payments

## Facts

- Tool: `list_payments`
- Server: AI Cortex Storage (`https://memory.aic0rt3x.dev/mcp`) — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp.md
- Homepage: https://github.com/https://memory.aic0rt3x.dev/mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 2
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `limit` | integer | no | Max results (default 50, max 100) |
| `offset` | integer | no | Pagination offset (default 0) |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "list_payments",
    "arguments": {}
  }
}
```

## Why list_payments is rated Low

This tool retrieves payment history records, which is a Read operation (queries data with no side effects). However, severity is elevated to 'medium' rather than 'low' because payment history data is sensitive financial information that could reveal transaction patterns, amounts, and account details if misused by an AI agent—though the tool itself does not execute financial transactions or cause destructive changes.

From the tool's own definition: "Tool name 'list_payments' and description 'List payment history for this account' indicate a read-only query operation that retrieves historical payment data without modifying or executing transactions."

## Use case

AI agents call list_payments to retrieve information from AI Cortex Storage without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches AI Cortex Storage:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "list_payments": {}
  }
}
```

## Other tools on AI Cortex Storage (14)

- `delete_memory` — Destructive — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/delete-memory.md
- `revoke_api_key` — Destructive — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/revoke-api-key.md
- `settle_balance` — Financial — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/settle-balance.md
- `submit_feature_request` — Financial — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/submit-feature-request.md
- `get_account` — Read — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/get-account.md
- `get_memory` — Read — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/get-memory.md
- `list_api_keys` — Read — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/list-api-keys.md
- `list_keys` — Read — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/list-keys.md
- `list_namespaces` — Read — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/list-namespaces.md
- `search_by_tag` — Read — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/search-by-tag.md
- `top_memories` — Read — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/top-memories.md
- `create_api_key` — Write — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/create-api-key.md
- `put_memory` — Write — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/put-memory.md
- `submit_exit_feedback` — Write — https://policylayer.com/tools/dev-aic0rt3x-memory-mcp/submit-exit-feedback.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dev-aic0rt3x-memory-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dev-aic0rt3x-memory-mcp
