brc_create_payment
Creates a BRC payment from the Payments book. Use supplierId for supplier payments, or analysisCategoryId + accountCode for analysed bank payments. Analysis categories must be from the bank's Payments book (BP01-BP06) and accountCode must match the category. Requires routeToken from brc_route_req...
This record as markdown: /tools/io-github-bigredcloud-red-mcp-server/brc-create-payment.md
What brc_create_payment does on Red by Big Red Cloud
AI agents use brc_create_payment to commit financial operations through Red by Big Red Cloud, usually the final step of a payment, billing, or trading workflow. A call moves real money.
| Parameter | Type | Required | Description |
|---|---|---|---|
note | string | Yes | |
total | number | Yes | |
acCode | string | — | Supplier account code for supplier payments. |
discount | number | — | |
procDate | string | — | Processing date in ISO format. Defaults to entryDate. |
entryDate | string | — | Entry date in ISO format. Defaults to today. |
reference | string | — | |
routeToken | string | Yes | Opaque routeToken from brc_route_request for this action workflow. Required for transactional tools. Routing permission only — does not replace preview-before-p |
supplierId | integer | — | Supplier id for supplier payments. |
accountCode | string | — | Analysis account code matching analysisCategoryId, for example BP01. |
companyName | string | Yes | Company context name, for example YOUR-COMPANY-NAME. |
description | string | — | Analysis line description. |
Parameters from the server's own tool schema.
Why brc_create_payment is rated Critical
brc_create_payment moves real money, and an autonomous agent will call it with the same confidence it calls a search tool. A misread instruction or an injected prompt is all it takes to drain an account or blow a budget.
Risk signalsHigh parameter count (19 properties)
Attacks that exploit this kind of access
The rule that runs brc_create_payment safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Red by Big Red Cloud, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For brc_create_payment, this is the rule to start with:
Any call to brc_create_payment is blocked until a human approves it. The rest of the server keeps working.
The button opens the PolicyLayer dashboard: create your workspace, connect Red by Big Red Cloud, apply this rule, and every brc_create_payment call is checked against it from then on.
Questions about brc_create_payment
Creates a BRC payment from the Payments book. Use supplierId for supplier payments, or analysisCategoryId + accountCode for analysed bank payments. Analysis categories must be from the bank's Payments book (BP01-BP06) and accountCode must match the category. Requires routeToken from brc_route_request for the matching action workflow. Call brc_route_request first with the user's complete original action request. Retain the returned routeToken through lookup, preview, and confirmation, and pass the same token on the final permitted transactional tool call. Never invent a placeholder token. A routeToken is not permission to post — preview-before-posting and confirmWrite/confirmDelete still apply. Also requires confirmCounterpartyExplicit: true once the user has explicitly named or confirmed the customer/supplier in the current conversation. Do not reuse a counterparty from an earlier preview without that confirmation. It is categorised as a Financial tool in the Red by Big Red Cloud MCP Server, which means it involves financial transactions. Block by default and require explicit approval.
brc_create_payment accepts 12 parameters: note, total, acCode, discount, procDate, entryDate, reference, routeToken, supplierId, accountCode, companyName, description. Required: note, total, routeToken, companyName. The full parameter table on this page comes from the server's own tool schema.
Register the Red by Big Red Cloud MCP server in PolicyLayer and add a rule for brc_create_payment: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Red by Big Red Cloud. Nothing to install.
brc_create_payment is a Financial tool with critical risk. Critical-risk tools should be blocked by default and only enabled with explicit human approval.
Yes. Add a rate_limit block to the brc_create_payment rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for brc_create_payment. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
brc_create_payment is provided by the Red by Big Red Cloud MCP server (https://red.bigredcloud.com/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Red by Big Red Cloud, and thousands of servers like it.
Across the catalogue