card_create_card
Issues a new virtual card at the card issuer, funded by a specific bank account. account_id is REQUIRED: set it to the id of the account the card should spend from — it must belong to the same company as params.company_id (get_list_accounts lists the company's accounts; the call is rejected if th...
This record as markdown: /tools/lovieco-lovie-company-formation-mcp-npx/card-create-card.md
What card_create_card does on Lovie Company Formation MCP
AI agents use card_create_card to create or update resources in Lovie Company Formation MCP, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Lovie Company Formation MCP environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
params | object | Yes | |
accountId | object | Yes | UUID value wrapper. |
Parameters from the server's own tool schema.
Why card_create_card is rated Medium
An AI agent can call card_create_card faster than any human can review: one bad instruction and it creates or modifies resources in Lovie Company Formation MCP by the hundred, each call as confident as the last.
Risk signalsHigh parameter count (14 properties)
Attacks that exploit this kind of access
The rule that runs card_create_card safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Lovie Company Formation MCP, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For card_create_card, this is the rule to start with:
card_create_card stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Lovie Company Formation MCP, apply this rule, and every card_create_card call is checked against it from then on.
Questions about card_create_card
Issues a new virtual card at the card issuer, funded by a specific bank account. account_id is REQUIRED: set it to the id of the account the card should spend from — it must belong to the same company as params.company_id (get_list_accounts lists the company's accounts; the call is rejected if the account belongs to another company or cannot fund cards). Set params.company_id to the company the card belongs to — the caller's membership is verified server-side, so pass a company the user actually belongs to (get_my_companies lists them). Set params.nickname to the name the user gave the card. Set params.spend_limit_cents to the limit in CENTS, not dollars: a $2,000 limit is 200000. params.spend_interval is REQUIRED whenever you send a limit and the call is rejected without it, so always send both — send SPEND_INTERVAL_MONTHLY when the user names an amount but no period, SPEND_INTERVAL_DAILY for a daily cap, or SPEND_INTERVAL_TRANSACTION for a per-charge cap. Do not send SPEND_INTERVAL_YEARLY: the default issuer does not support it and rejects the call — convert to a monthly amount and say so. Omit both fields only when the user wants no limit at all. Returns the created card, including its id, nickname, status, spend limit, expiry, and billing address; report the id back to the user. The cardholder's name is withheld from tool callers. Creating a card moves no money, but it does provision a real instrument at the issuer and no tool can delete it — only freeze it — so create one card per request and never retry a create that already succeeded. The full card number and CVV are never returned by any tool. It is categorised as a Write tool in the Lovie Company Formation MCP MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
card_create_card accepts 2 parameters: params, accountId. Required: params, accountId. The full parameter table on this page comes from the server's own tool schema.
Register the Lovie Company Formation MCP server in PolicyLayer and add a rule for card_create_card: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Lovie Company Formation MCP. Nothing to install.
card_create_card is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the card_create_card rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for card_create_card. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
card_create_card is provided by the Lovie Company Formation MCP server (lovie). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Lovie Company Formation, and thousands of servers like it.
This server
Across the catalogue