Money and confirmation
What asks for the MCP's two-step confirmation (money and deletions) and what runs on the first call. The summary, the confirmation code that lasts 10 minutes, works once and is tied to the same values, the dry run before issuing certificates, Claude's own permission prompt and an example conversation.
The assistant does what you ask right away, as if you had clicked in the dashboard. The exception is anything that touches money and anything that deletes: there, Memberfy does nothing on the first call. It returns a summary with the real values, and only acts after your explicit yes, given in the conversation itself.
What asks for confirmation
| What | Tools | What the summary shows |
|---|---|---|
| Coupons | create_coupon, update_coupon, update_coupon_status, delete_coupon | The code, the discount, the duration, the validity, the products; what changes |
| Price | update_price | The current price and the new one |
| Payouts | request_payout, cancel_payout | The amount, the payout fee and the balance |
| Subscriptions | cancel_subscription, create_manual_subscription, update_subscription | The person, the plan and what changes (complimentary, discount, extension, add-on) |
| Last chance (downsell) | create_downsell_offer, update_downsell_offer, delete_downsell_offer | The add-on, the discount and how long it lasts |
| Your own subscription | manage_my_subscription, change_my_plan, cancel_scheduled_plan_change | What will happen to your subscription and to what you pay; on a plan change, how much is charged now to the saved card, the next charge, the extensions, the contract and the coupon |
| Deletions | every tool whose name starts with delete_, remove_, revoke_, withdraw_ or cancel_ | What will be deleted, removed, revoked or withdrawn |
Deletions include delete_post, delete_comment, delete_section, delete_space, delete_event, delete_course, delete_course_module, delete_lesson, delete_gallery_image, delete_group, delete_tag, delete_product, delete_plan, delete_certificate, delete_call_for_papers, delete_call_track and delete_call_event_date, plus remove_member, remove_call_owner, remove_track_reviewer, revoke_certificate and withdraw_proposal. The list for each subject, with the Asks to confirm badge, is in Tools.
What runs on the first call
Everything else, with the Changes badge: creating and editing posts, events, courses, plans and products as drafts, publishing, inviting people, changing someone's role, changing the community settings, changing who sees a space, issuing, resending and retrying certificates, deciding and negotiating call-for-papers proposals, inviting reviewers and speakers, and changing a plan (update_plan).
Memberfy doesn't hold these back, because you can check and fix them in the dashboard or by asking again. What protects you here is the assistant's own permission prompt (see The assistant's permission) and Memberfy's instructions, which tell the assistant to show beforehand who will get an e-mail.
Issuing certificates: the dry run first
issue_certificate sends an e-mail to each person. That's why it has a dry run mode (dry_run: true): it issues nothing and returns how many people receive one, who is left out and why (for example, who already has a valid certificate from that template). The assistant runs the dry run, shows the result and only then issues, calling again without the dry run. See issue_certificate.
For invites, ask the same way: "show me the list before inviting". The assistant puts the list together in the conversation and only calls
invite_membersafter your ok.
How the confirmation works
- The first call doesn't act. Memberfy builds a summary with the real values, reading what it needs (the product's current price, the balance, the subscription), and returns a confirmation code with it, starting with
mfy_cf_. The response tells the assistant: "Nothing has been done yet. Show the summary to the person and ask for an explicit yes." - The assistant shows the summary and asks whether it can go ahead.
- You reply. "Yes" goes ahead. "No", or a change request ("make it 25% instead of 30%"), starts over.
- The second call carries the code, with exactly the same values. Memberfy checks it and only then runs it.
The code's rules
| Rule | Why |
|---|---|
| Lasts 10 minutes | Yesterday's yes doesn't count for today |
| Works once | A retry, or two calls at the same time, don't run the action twice |
| Tied to the same values | If any value changes between the summary and the run (another discount, another payout amount), the code is refused. You confirmed a summary, and that summary is what happens |
| Tied to the connection and the tool | One assistant's code doesn't work in another, and a coupon's code doesn't work for a payout |
If any rule fails, the response is: "Invalid, expired or already used confirmation, or different arguments. Call … without confirmation_token to get a new summary." Nothing happens, and the assistant starts again, with a new summary.
An example conversation
You: Create a 30% Black Friday coupon, first charge only, for the Growth plan, up to 100 uses, valid until 11/30.
Assistant: (calls
list_productsto find the Growth options, thencreate_couponwithout confirmation) Before I create it, please check:
- Code: BLACK30
- Discount: 30%, first charge only
- Uses: up to 100
- Validity: from now until 11/30/2026
- Products: Growth · Monthly and Growth · Annual
Shall I create it?
You: Go ahead.
Assistant: (calls
create_couponagain, with the same values and the code) Done: the coupon BLACK30 is active. Anyone who subscribes to Growth by 11/30 gets 30% off the first charge.
Had you replied "make it 25%", the assistant would call create_coupon again without a code, with 25%, and show a new summary. The code from the 30% summary would no longer work.
The assistant's permission
Besides Memberfy's confirmation, the assistant itself asks for your permission before using a tool that changes something. In Claude.ai, that prompt shows up in the conversation and belongs to Claude, not Memberfy: it applies to any connector, and the money and deletion tools are flagged as destructive, so Claude warns more prominently.
If being asked on every action gets in the way, you can set a tool as always allowed:
- In the conversation itself, when Claude asks for permission, it usually offers the option to always allow that tool.
- In the connector settings, under Settings › Connectors, open Memberfy: the list shows the tools, and for each one you can choose whether Claude asks first or uses it directly. The exact option names are Claude's and may change.
Setting a tool as always allowed does not turn off Memberfy's confirmation: a money or deletion tool still returns the summary first and only acts after your yes. So it makes sense to always allow the read-only and everyday tools (posts, events, courses) and keep the prompt for the ones that e-mail other people, such as invite_members and issue_certificate.
ChatGPT has a similar approval prompt, also its own. See Connect Claude and Connect ChatGPT.
Good practices
- Read the summary, not the question. The summary comes from Memberfy, with the values that will apply; the question is the assistant's.
- Confirm one at a time. For several coupons or several deletions, ask for a summary of each.
- Be wary of a "yes" you didn't give. The assistant should only repeat the call after you reply. If it runs without asking, disconnect it and review the connection's history (see Security and limits).
Frequently asked questions
What if I take more than 10 minutes to reply? The code expires. Say "yes" anyway: the assistant gets the refusal, asks for a new summary and shows it again.
Can the assistant confirm on its own? Technically, the code reaches it. Memberfy's instructions tell it to wait for your explicit yes, and assistants follow them. That's why the golden rule is: anything that touches money or deletes, you read and reply to.
Does inviting a class ask for confirmation? Not from Memberfy: the invite goes out on the first call. Claude still asks for its own permission, unless the tool is set as always allowed, and Memberfy's instructions tell the assistant to show beforehand who will get the e-mail. To be sure, ask "show me the list before inviting".
Does changing someone's role or the settings ask for confirmation? No. Both run on the first call and can be undone in the dashboard or by asking again. An owner's role can still only be changed by another owner.
Does publishing a product require confirmation?
No. publish_product puts on sale what you've already reviewed as a draft, like the button in the dashboard. Changing a price or creating a discount does.