# Money and confirmation

> What asks for the MCP's two-step confirmation (money and deletions) and what runs on the first call. The summary, the confirmation code that lasts 10 minutes, works once and is tied to the same values, the dry run before issuing certificates, Claude's own permission prompt and an example conversation.

The assistant does what you ask right away, as if you had clicked in the dashboard. The exception is anything that **touches money** and anything that **deletes**: there, Memberfy does nothing on the first call. It returns a summary with the real values, and only acts after your explicit yes, given in the conversation itself.

## What asks for confirmation

| What | Tools | What the summary shows |
|---|---|---|
| Coupons | `create_coupon`, `update_coupon`, `update_coupon_status`, `delete_coupon` | The code, the discount, the duration, the validity, the products; what changes |
| Price | `update_price` | The current price and the new one |
| Payouts | `request_payout`, `cancel_payout` | The amount, the payout fee and the balance |
| Subscriptions | `cancel_subscription`, `create_manual_subscription`, `update_subscription` | The person, the plan and what changes (complimentary, discount, extension, add-on) |
| Last chance (downsell) | `create_downsell_offer`, `update_downsell_offer`, `delete_downsell_offer` | The add-on, the discount and how long it lasts |
| Your own subscription | `manage_my_subscription`, `change_my_plan`, `cancel_scheduled_plan_change` | What will happen to your subscription and to what you pay; on a plan change, how much is charged now to the saved card, the next charge, the extensions, the contract and the coupon |
| Deletions | every tool whose name starts with `delete_`, `remove_`, `revoke_`, `withdraw_` or `cancel_` | What will be deleted, removed, revoked or withdrawn |

Deletions include `delete_post`, `delete_comment`, `delete_section`, `delete_space`, `delete_event`, `delete_course`, `delete_course_module`, `delete_lesson`, `delete_gallery_image`, `delete_group`, `delete_tag`, `delete_product`, `delete_plan`, `delete_certificate`, `delete_call_for_papers`, `delete_call_track` and `delete_call_event_date`, plus `remove_member`, `remove_call_owner`, `remove_track_reviewer`, `revoke_certificate` and `withdraw_proposal`. The list for each subject, with the <span class="tool-kind tool-kind-confirm">Asks to confirm</span> badge, is in [Tools](/mcp/ferramentas#all-tools).

## What runs on the first call

Everything else, with the <span class="tool-kind tool-kind-write">Changes</span> badge: creating and editing posts, events, courses, plans and products as drafts, publishing, **inviting** people, **changing someone's role**, changing the **community settings**, changing **who sees a space**, **issuing, resending and retrying certificates**, deciding and negotiating call-for-papers proposals, inviting reviewers and speakers, and changing a plan (`update_plan`).

Memberfy doesn't hold these back, because you can check and fix them in the dashboard or by asking again. What protects you here is the assistant's own permission prompt (see [The assistant's permission](#the-assistant-s-permission)) and Memberfy's instructions, which tell the assistant to show beforehand who will get an e-mail.

### Issuing certificates: the dry run first

`issue_certificate` sends an e-mail to each person. That's why it has a **dry run** mode (`dry_run: true`): it issues nothing and returns how many people receive one, who is left out and why (for example, who already has a valid certificate from that template). The assistant runs the dry run, shows the result and only then issues, calling again without the dry run. See [`issue_certificate`](/mcp/ferramentas-certificados#issue-certificate).

> [!TIP]
> For invites, ask the same way: *"show me the list before inviting"*. The assistant puts the list together in the conversation and only calls `invite_members` after your ok.

## How the confirmation works

<div class="flow">
<div class="flow-row"><span class="flow-label">1st call</span><span class="flow-node">The assistant asks for the action</span><span class="flow-arrow">→</span><span class="flow-node">Memberfy does nothing and returns the summary and a code</span></div>
<div class="flow-row"><span class="flow-label">You</span><span class="flow-node">Read the summary</span><span class="flow-arrow">→</span><span class="flow-node">Say yes, or ask for a change</span></div>
<div class="flow-row"><span class="flow-label">2nd call</span><span class="flow-node">The assistant repeats it with the code</span><span class="flow-arrow">→</span><span class="flow-node">Memberfy checks and runs it</span></div>
</div>

1. **The first call doesn't act.** Memberfy builds a **summary** with the real values, reading what it needs (the product's current price, the balance, the subscription), and returns a **confirmation code** with it, starting with `mfy_cf_`. The response tells the assistant: *"Nothing has been done yet. Show the summary to the person and ask for an explicit yes."*
2. **The assistant shows the summary** and asks whether it can go ahead.
3. **You reply.** "Yes" goes ahead. "No", or a change request ("make it 25% instead of 30%"), starts over.
4. **The second call carries the code**, with exactly the same values. Memberfy checks it and only then runs it.

### The code's rules

| Rule | Why |
|---|---|
| Lasts **10 minutes** | Yesterday's yes doesn't count for today |
| Works **once** | A retry, or two calls at the same time, don't run the action twice |
| Tied to **the same values** | If any value changes between the summary and the run (another discount, another payout amount), the code is refused. You confirmed a summary, and that summary is what happens |
| Tied to the **connection** and the **tool** | One assistant's code doesn't work in another, and a coupon's code doesn't work for a payout |

If any rule fails, the response is: *"Invalid, expired or already used confirmation, or different arguments. Call … without confirmation_token to get a new summary."* Nothing happens, and the assistant starts again, with a new summary.

## An example conversation

> **You:** Create a 30% Black Friday coupon, first charge only, for the Growth plan, up to 100 uses, valid until 11/30.
>
> **Assistant:** *(calls `list_products` to find the Growth options, then `create_coupon` without confirmation)*
> Before I create it, please check:
> - **Code:** BLACK30
> - **Discount:** 30%, first charge only
> - **Uses:** up to 100
> - **Validity:** from now until 11/30/2026
> - **Products:** Growth · Monthly and Growth · Annual
>
> Shall I create it?
>
> **You:** Go ahead.
>
> **Assistant:** *(calls `create_coupon` again, with the same values and the code)*
> Done: the coupon **BLACK30** is active. Anyone who subscribes to Growth by 11/30 gets 30% off the first charge.

Had you replied "make it 25%", the assistant would call `create_coupon` again **without** a code, with 25%, and show a new summary. The code from the 30% summary would no longer work.

## The assistant's permission

Besides Memberfy's confirmation, the assistant itself asks for your permission before using a tool that changes something. In Claude.ai, that prompt shows up in the conversation and belongs to Claude, not Memberfy: it applies to any connector, and the money and deletion tools are flagged as destructive, so Claude warns more prominently.

If being asked on every action gets in the way, you can set a tool as always allowed:

- **In the conversation itself**, when Claude asks for permission, it usually offers the option to always allow that tool.
- **In the connector settings**, under **Settings › Connectors**, open **Memberfy**: the list shows the tools, and for each one you can choose whether Claude asks first or uses it directly. The exact option names are Claude's and may change.

Setting a tool as always allowed does **not** turn off Memberfy's confirmation: a money or deletion tool still returns the summary first and only acts after your yes. So it makes sense to always allow the read-only and everyday tools (posts, events, courses) and keep the prompt for the ones that e-mail other people, such as `invite_members` and `issue_certificate`.

ChatGPT has a similar approval prompt, also its own. See [Connect Claude](/mcp/conectar-o-claude) and [Connect ChatGPT](/mcp/conectar-o-chatgpt).

## Good practices

- **Read the summary, not the question.** The summary comes from Memberfy, with the values that will apply; the question is the assistant's.
- **Confirm one at a time.** For several coupons or several deletions, ask for a summary of each.
- **Be wary of a "yes" you didn't give.** The assistant should only repeat the call after you reply. If it runs without asking, disconnect it and review the connection's history (see [Security and limits](/mcp/seguranca#audit)).

## Frequently asked questions

**What if I take more than 10 minutes to reply?**
The code expires. Say "yes" anyway: the assistant gets the refusal, asks for a new summary and shows it again.

**Can the assistant confirm on its own?**
Technically, the code reaches it. Memberfy's instructions tell it to wait for your explicit yes, and assistants follow them. That's why the golden rule is: anything that touches money or deletes, you read and reply to.

**Does inviting a class ask for confirmation?**
Not from Memberfy: the invite goes out on the first call. Claude still asks for its own permission, unless the tool is set as always allowed, and Memberfy's instructions tell the assistant to show beforehand who will get the e-mail. To be sure, ask *"show me the list before inviting"*.

**Does changing someone's role or the settings ask for confirmation?**
No. Both run on the first call and can be undone in the dashboard or by asking again. An owner's role can still only be changed by another owner.

**Does publishing a product require confirmation?**
No. `publish_product` puts on sale what you've already reviewed as a draft, like the button in the dashboard. Changing a price or creating a discount does.

## Related

- [Tools](/mcp/ferramentas#ask-for-confirmation)
- [Security and limits](/mcp/seguranca)
