Stack · Backend engineering

API delivery desk

Designs the endpoint, wires the auth and the payment, and reviews the shape before it is public and permanent.

Built for: The team shipping the first version of an API that other people will build against — and cannot quietly rename next month.

Install all 12 parts

The button opens the checkout, where 7 servers and 5 skills are listed one by one with what each does to the bill — free, already yours, monthly or a one-off licence. Nothing is charged until you confirm it there, in Stripe’s own card frame on that page rather than a redirect, and each paid member keeps its own budget cap.

$0/mo
7 servers at their publishers’ prices, with one-off licences spread over 12 months
$0
the free-tier version keeps 7 servers and 2 skills — 28 of the 28 tools
$0
5 skills with no monthly cost, plus $182 paid once
63.7k
tokens of context the skills add to every session
01 · Outcome

What your agent can do with this

The reason to buy a stack rather than five listings: each line below needs more than one member connected at the same time.

  1. 01

    Review a REST design against security, resilience and operational rules while it is still a document.

  2. 02

    Read the schema behind the endpoint on a read-only Postgres connection and keep the response honest about it.

  3. 03

    Wire OAuth 2.1 with PKCE and refresh, and a Stripe checkout, from the same desk that wrote the route.

  4. 04

    Deploy the service to Railway and read back what the platform says about it.

02 · Assembly

The assembly, part by part

What each part contributes, and why it was picked over the obvious alternative. Prices and permissions are read from the listings, so nothing here can disagree with the catalogue.

7 servers5 skills28 tools
SU01

Utilities against the Supabase project behind the API — the fastest way to check what the platform is doing before blaming your own route.

24 read4 writeruns on your machine A v0.7.0 credential not declared · runs locally
Free
$0 of the monthly total
RE02
Resend MCP server Email by gui-wf

Emails, domains and templates through the Resend API: every API grows a transactional mail obligation by the second week.

read/write split not recordedruns on your machine A v1.0.1 credential not declared · runs locally
Free
$0 of the monthly total
PO03

Read-only access to the data the endpoint returns, with row caps and statement timeouts, so design questions get real answers.

read/write split not recordedruns on your machine A v0.4.2 credential not declared · runs locally
Free
$0 of the monthly total
GI04

The route, the spec and the review live in the same repository; this is the desk's way in and out of it.

read/write split not recordedruns on your machine A v1.8.0 credential not declared · runs locally
Free
$0 of the monthly total
OP05
Openai MCP server AI & Agents by @mzxrai

The OpenAI API as a plain dependency, for the endpoints that call a model and now need their own timeouts and costs.

read/write split not recordedruns on your machine A v0.1.1 credential not declared · runs locally
Free
$0 of the monthly total
RA06

Manages the Railway infrastructure the service runs on, so deploying is part of the same session rather than a different tool.

read/write split not recordedruns on your machine A v1.3.0 credential not declared · runs locally
Free
$0 of the monthly total
ST07

Read-only access to Stripe data via an API key — enough to answer what a customer is on, without the ability to charge them.

read/write split not recordedruns on your machine A v0.1.0 credential not declared · runs locally
Free
$0 of the monthly total
and the instructions that drive them A skill is a prompt file, not a server: it adds context and a procedure, never a tool or a permission of its own.
RE08
Review API Design Agent skill Guardrail by psenger

Reviews the design while it is still cheap to change: security, resilience, pagination, errors, versioning — the list a public API is judged on later.

30.1k tokens of context never asks for a write 15 files · CC-BY-4.0 v1.0.0 needs no server of its own
Free
no monthly cost
OA09
OAuth Agent skill Workflow by mcollina

Implements the authorisation-code-with-PKCE, client-credentials and refresh flows properly, which is where hand-written auth usually goes wrong.

1.9k tokens of context never asks for a write 2 files · MIT needs no server of its own
$99
$8.25 of the monthly total
ST10
Stripe Agent skill Workflow by sundial-org

The integration side of payments — payments, subscriptions, invoices and customers — kept to Stripe's own current patterns.

200 tokens of context never asks for a write 1 files · CC0-1.0 needs no server of its own
Free
no monthly cost
UC11
UCP Checkout REST Agent skill Expertise by OrcaQubits

A worked checkout contract over REST, with idempotency and status transitions, for teams building the commerce half of the API.

1.1k tokens of context never asks for a write 1 files · MIT needs no server of its own
$59
$4.92 of the monthly total
ME12
Mem0 Agent skill Expertise by mem0ai

For the endpoint that has to remember a user between calls: a memory layer added deliberately, rather than a growing prompt.

30.4k tokens of context never asks for a write 13 files · Apache-2.0 v3.0.0 needs no server of its own
$24
$2.00 of the monthly total
03 · Cost

What it costs, and on what assumption

Every member is a subscription or a licence bought once, so the monthly figure is a price rather than an estimate: what moves it is adding or dropping a member, not how hard the stack is worked. The one assumption is that a one-off licence is spread over a year so it can sit in the same column as a subscription.

PartWhat you are paying forMonthly, as quoted
Supabase Utils Free
Resend Free
Postgres Free
Gitlab Free
Openai Free
Railway Free
Stripe Connect Free
Skills
Review API Design Free · context cost only
OAuth $99 · $8.25/mo over 12 months $8.25/mo
Stripe Free · context cost only
UCP Checkout REST $59 · $4.92/mo over 12 months $4.92/mo
Mem0 $24 · $2.00/mo over 12 months $2.00/mo
Everything above $0 of servers plus $15 of skills, the same in a quiet month and a busy one $15/mo

Subscriptions at their monthly plan price; one-off licences spread over 12 months. One-off purchases in this stack total $182 — OAuth $99, UCP Checkout REST $59, Mem0 $24 — paid once and spread here so they sit in the same column as a subscription. Everything arrives on one mcprush invoice, taken by Stripe from the card on your account, not one per publisher — mcprush.com is the merchant of record and each publisher is paid out of it.

The free-tier version$0/mo

Install only these and the bill is nothing: 7 servers and 2 skills, 28 of the 28 tools.

Left out, and what goes with it:

  • OAuth · $99Implements the authorisation-code-with-PKCE, client-credentials and refresh flows properly, which is where hand-written auth usually goes wrong.
  • UCP Checkout REST · $59A worked checkout contract over REST, with idempotency and status transitions, for teams building the commerce half of the API.
  • Mem0 · $24For the endpoint that has to remember a user between calls: a memory layer added deliberately, rather than a growing prompt.
What moves the bill
Flat every month$0 · 0 subscriptions
Carries a call allowancenothing
Paid once$182
Traffic assumed5k calls / month

Nothing in this stack carries a call allowance, so nothing here can run out before the month does. The bill is decided when you install it, not when you use it.

Budget caps are set per install and enforced at the gateway, so a retry loop is refused at the cap rather than left to run through an allowance overnight.

04 · Setup

Setting it up, in order

One step per part, in the order they are useful: connect what the work reads before what it writes, and install the skills that decide how the work is done last. Each step is a command you can read before you run it.

1
Read-only database first
Point Postgres at a replica before the first design session. An API design conversation that guesses at the schema produces a contract that does not survive the data.
2
Two Stripe keys, two jobs
The read-only pack reads customers and revenue; the payment skill wires the integration in your code. Never give the reading side a live secret key.
3
Set the Railway project
Scope the token to one project. This desk manages the service it built, not the rest of the estate.
4
Agree the words before the routes
The OpenAPI glossary is installed first on purpose: half of API review disagreements are two people using 'resource' to mean different things.
One command12 parts
npx mcprush@latest stack add api-delivery

Nothing in this stack installs from one command today: 12 members are either paid, run from its own source, or a skill with its own command — the steps above name each one. Nothing is connected until you approve it.

Before you start
  • 7 members have not declared what credential they need — check each one’s own page before you start.
  • What this stack can write is not recorded — 6 members of 7 have no imported tool surface. Section 05 says what is known before you approve anything.
  • 7 members can run on your own machine instead of ours, if you would rather they did.
05 · Permissions

What the whole stack can reach

Installed together, these tool surfaces add up. It is the first thing a security reviewer asks for, so what has been counted — and what nobody has counted yet — is on the page rather than in a PDF.

tools that only read
Which tools read and which write is counted from the surface a publisher imports, and 6 members of 7 have no imported tool surface.
tools that can change something
Not recorded, and not estimated: a total added up from the members that have a surface would be read as the whole stack’s. The table below is what is known, member by member.
0
tools that reach the network
28 of the 28 never leave your machine — they belong to the local members.
Who grants the write accessnot recorded
MemberTool surfaceWrite tools
Supabase Utils imported 4
Gitlab not imported not recorded
Openai not imported not recorded
Postgres not imported not recorded
Railway not imported not recorded
Resend not imported not recorded
Stripe Connect not imported not recorded
Reading the number

A stack's blast radius is the union of its members, not the worst of them. That union cannot be taken here, because 6 members of 7 have no imported tool surface — so the figure a review asks for is missing rather than low, and a member marked not imported is one nobody has counted rather than one that cannot write.

Tools in total28
Write sharenot recorded
Members that can writeat least 1 of 7
Surface imported1 of 7 members
06 · Swaps

Sensible swaps

A stack is a default, not a verdict. These are the substitutions the maintainer would make, and what each one costs or saves.

For an API that ships as functions rather than as a service, the Vercel server manages the same deploy from the same desk.

same money at 5k calls the same 0 tools both grade A

Transactional mail is one interchangeable dependency; take whichever account you already have domains verified on, and the API code changes in one place.

same money at 5k calls the same 0 tools both grade A
07 · Limits

Where this stack stops

Written by the maintainer, kept on the page rather than in a support thread.

  • It cannot approve its own design. The review skill produces findings; whether the API ships with them open is a person's call.

  • The Stripe member here is read-only access to Stripe data — the desk can read customers and charges, and cannot move money.

  • It does not write your client SDKs. The glossary keeps the terminology consistent; generating and publishing packages is outside this stack.

08 · Maintenance

Who keeps this current

A stack has an owner: whoever keeps it re-checks the combination when a member changes, and the members themselves are published by the people named on each row.

Maintainer
mcprush
Publishes this stack only
Version
null
Set by the curator
Member installs
none yet
Added up across the parts. Nothing counts installs of the set as one thing.
Member rating
No reviews yet
None of the parts has been reviewed, and neither has the stack.
Composition
7 + 5
7 servers, 5 skills
Nearby

Stacks that share parts with this one

All 20 stacks