# card_create_card

Issues a new virtual card at the card issuer, funded by a specific bank account. account_id is REQUIRED: set it to the id of the account the card should spend from — it must belong to the same company as params.company_id (get_list_accounts lists the company's accounts; the call is rejected if the account belongs to another company or cannot fund cards). Set params.company_id to the company the card belongs to — the caller's membership is verified server-side, so pass a company the user actually belongs to (get_my_companies lists them). Set params.nickname to the name the user gave the card. Set params.spend_limit_cents to the limit in CENTS, not dollars: a $2,000 limit is 200000. params.spend_interval is REQUIRED whenever you send a limit and the call is rejected without it, so always send both — send SPEND_INTERVAL_MONTHLY when the user names an amount but no period, SPEND_INTERVAL_DAILY for a daily cap, or SPEND_INTERVAL_TRANSACTION for a per-charge cap. Do not send SPEND_INTERVAL_YEARLY: the default issuer does not support it and rejects the call — convert to a monthly amount and say so. Omit both fields only when the user wants no limit at all. Returns the created card, including its id, nickname, status, spend limit, expiry, and billing address; report the id back to the user. The cardholder's name is withheld from tool callers. Creating a card moves no money, but it does provision a real instrument at the issuer and no tool can delete it — only freeze it — so create one card per request and never retry a create that already succeeded. The full card number and CVV are never returned by any tool.

Agent View of the PolicyLayer registry record for `card_create_card`. HTML page: https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/card-create-card

## Facts

- Tool: `card_create_card`
- Server: Lovie Company Formation MCP (`lovie`) — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx.md
- Install: `npx -y lovie`
- Homepage: https://github.com/lovieco/lovie-company-formation-mcp-npx
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 2 (2 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `params` | object | yes |  |
| `accountId` | object | yes | UUID value wrapper. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "card_create_card",
    "arguments": {
      "params": {},
      "accountId": {}
    }
  }
}
```

## Why card_create_card is rated Medium

An AI agent can call card_create_card faster than any human can review: one bad instruction and it creates or modifies resources in Lovie Company Formation MCP by the hundred, each call as confident as the last.

Risk signals: High parameter count (14 properties)

## Use case

AI agents use card_create_card to create or update resources in Lovie Company Formation MCP, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Lovie Company Formation MCP environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Lovie Company Formation MCP:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "card_create_card": {
      "limits": [
        {
          "counter": "card_create_card_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Lovie Company Formation MCP (339)

- `accounting_cancel_schedule` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/accounting-cancel-schedule.md
- `accounting_confirm_statement_match` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/accounting-confirm-statement-match.md
- `accounting_delete_journal_entry` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/accounting-delete-journal-entry.md
- `cap_table_clear_cap_table_stakeholders` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-clear-cap-table-stakeholders.md
- `cap_table_close_cap_table_round` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-close-cap-table-round.md
- `cap_table_delete_cap_table_agreement` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-delete-cap-table-agreement.md
- `cap_table_delete_cap_table_round` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-delete-cap-table-round.md
- `cap_table_delete_cap_table_security` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-delete-cap-table-security.md
- `cap_table_delete_cap_table_stakeholder` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-delete-cap-table-stakeholder.md
- `cap_table_set_cap_table_pipeline_status` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-set-cap-table-pipeline-status.md
- `documents_delete_saved_signature` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/documents-delete-saved-signature.md
- `formation_delete_pending_domain` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/formation-delete-pending-domain.md
- `formation_remove_shareholder` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/formation-remove-shareholder.md
- `signature_void_envelope` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/signature-void-envelope.md
- `trademark_delete_application` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/trademark-delete-application.md
- `vendor_bill_cancel_vendor_bill` — Destructive — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/vendor-bill-cancel-vendor-bill.md
- `accounting_propose_schedules` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/accounting-propose-schedules.md
- `ads_insight_summarize_campaign_window` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/ads-insight-summarize-campaign-window.md
- `banking_refresh_owner_verification` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/banking-refresh-owner-verification.md
- `banking_start_banking_application` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/banking-start-banking-application.md
- `cap_table_record_cap_table_investment` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-record-cap-table-investment.md
- `cap_table_simulate_cap_table_exit` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/cap-table-simulate-cap-table-exit.md
- `draft_payment` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/draft-payment.md
- `equity_onboarding_start` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/equity-onboarding-start.md
- `formation_run_election83b_reminders` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/formation-run-election83b-reminders.md
- `formation_start_formation` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/formation-start-formation.md
- `kyc_start_kyc_inquiry` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/kyc-start-kyc-inquiry.md
- `signature_reconcile_document_state` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/signature-reconcile-document-state.md
- `signature_run_reminders` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/signature-run-reminders.md
- `trademark_run_clearance` — Execute — https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx/trademark-run-clearance.md
- …and 309 more: https://policylayer.com/tools/lovieco-lovie-company-formation-mcp-npx.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=lovieco-lovie-company-formation-mcp-npx · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/lovieco-lovie-company-formation-mcp-npx
