Agent skill

Privacy.com Virtual Cards

by dylanfeltus in dylanfeltus/skills

Creates, updates, and monitors Privacy.com virtual payment cards with spending limits for an agent making controlled purchases.

MITAuto-check passedBackend & APIs

Install Privacy.com Virtual Cards

skills CLI
$ npx skills add dylanfeltus/skills --skill privacy-cards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dylanfeltus/skills privacy-cards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dylanfeltus/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/privacy-cards .claude/skills/privacy-cards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-cards
GitHub stars
179
Token cost
~2.2k tokens
SKILL.md length
749 words
Files
2
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Creates, updates, and monitors Privacy.com virtual payment cards with spending limits for an agent making controlled purchases.

  • Works in 6 steps: Determine the amount needed (round up to… → Choose card type → Create the card and extract only the… → …
  • Setting up a spend-limited card for one specific purchase
  • SKILL.md covers When to Use, Setup, API Reference and Step-by-Step Instructions, plus 5 more sections
  • Calls curl and python3; reaches api.privacy.com and sandbox.privacy.com; needs PRIVACY_API_KEY and CARD_TOKEN

What it does

A single Privacy.com API, reached with an API key, backs the whole skill: creating a single-use, merchant-locked, or digital-wallet card with an optional spend limit and duration, updating a card's state or limit afterward, and listing cards or their recent transactions. A sandbox base URL is available for testing separately from the production API, and closing a card is explicitly permanent.

When your agent uses it

  • Setting up a spend-limited card for one specific purchase
  • Checking a card's status or recent transactions
  • Pausing or permanently closing a virtual card

Example prompts

  • “Create a single-use card with a $25 limit for this domain purchase.”
  • “Check the transaction history on the card I made yesterday.”
  • “Pause the card tagged for the trial subscription.”

Requirements

  • A Privacy.com account and API key (`PRIVACY_API_KEY`)

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Determine the amount needed (round up to whole dollars)
  2. Choose card type
  3. Create the card and extract only the fields you need. Never log or print the full API response — it contains the full card number (PAN)…
  4. When you need the full card details for checkout, extract them in a separate step that is not logged to chat. Use the card details…
  5. Use these card details to complete the purchase (via browser tool or API)
  6. After purchase, verify with the transactions endpoint

What it can do on your machine

Read from SKILL.md and the folder at commit b97a48f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.privacy.com
    • sandbox.privacy.com

    Also links to:

    • privacy-com.readme.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PRIVACY_API_KEY
    • CARD_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy.com Virtual Cards loads about 2.2k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 749 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dylanfeltus/skills at commit b97a48f, republished under its MIT licence (© dylanfeltus). 749 words, ~2,213 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-cards/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
privacy-cards
description
Create and manage Privacy.com virtual cards for agent spending. Use when an agent needs to make a purchase, buy a domain, pay for a service, or needs a disposable card with a spending limit. Requires a Privacy.com account and API key.

Privacy.com Virtual Cards

Create, manage, and monitor virtual cards via the Privacy.com API. Designed for AI agents that need to make purchases with controlled spending limits.

When to Use

  • Agent needs to buy something (domain, API access, subscription, physical goods)
  • Agent needs a disposable card for a one-time purchase
  • User wants to create a spend-limited card for a specific merchant
  • User asks to check card status or recent transactions
  • User wants to pause or close a card

Setup

Requires the PRIVACY_API_KEY environment variable. Get an API key from your Privacy.com account settings.

Plans and card limits:

  • Free: 12 cards/month
  • Pro ($10/mo): 36 cards/month
  • Premium ($25/mo): 60 cards/month

Sandbox: Use https://sandbox.privacy.com/v1 for testing. Production: https://api.privacy.com/v1.

API Reference

Base URL: https://api.privacy.com/v1 Auth Header: Authorization: api-key YOUR_API_KEY Content-Type: application/json

All monetary amounts are in cents (e.g., $25.00 = 2500).

Create a Card
POST https://api.privacy.com/v1/cards

{
  "type": "SINGLE_USE",
  "memo": "Domain purchase - example.com",
  "spend_limit": 2500,
  "spend_limit_duration": "TRANSACTION",
  "state": "OPEN"
}

Parameters:

FieldRequiredDescription
typeYesSINGLE_USE (auto-closes after one charge), MERCHANT_LOCKED (locks to first merchant), DIGITAL_WALLET (Apple/Google Pay)
memoNoLabel for the card (what it's for)
spend_limitNoMax spend in cents. Must be whole dollars (e.g., 2500 not 2550)
spend_limit_durationNoTRANSACTION (per charge), MONTHLY, ANNUALLY, FOREVER
stateNoOPEN (ready to use) or PAUSED
exp_monthNoTwo-digit expiry month (auto-generated if omitted)
exp_yearNoFour-digit expiry year (auto-generated if omitted)

Response includes: pan (16-digit card number), cvv, exp_month, exp_year, token (card ID), last_four.

Update a Card
PATCH https://api.privacy.com/v1/cards/{card_token}

{
  "state": "PAUSED",
  "spend_limit": 5000,
  "memo": "Updated memo"
}

Can update: state, memo, spend_limit, spend_limit_duration, funding_token.

Setting state to CLOSED is permanent and cannot be undone.

Get Card(s)
GET https://api.privacy.com/v1/cards/{card_token}
GET https://api.privacy.com/v1/cards
GET https://api.privacy.com/v1/cards?begin=2024-01-01&end=2024-12-31&page=1&page_size=50

Query parameters: begin, end (date filters), page, page_size (pagination).

List Transactions
GET https://api.privacy.com/v1/transactions?card_token={token}&result=APPROVED&page=1&page_size=50

Query parameters:

FieldDescription
card_tokenFilter by card
resultAPPROVED or decline reason
pagePage number (1-indexed)
page_sizeResults per page
beginStart date (YYYY-MM-DD)
endEnd date (YYYY-MM-DD)

Transaction statuses: PENDING, SETTLING, SETTLED, VOIDED, BOUNCED, DECLINED

Step-by-Step Instructions

Creating a Card for an Agent Purchase
  1. Determine the amount needed (round up to whole dollars)
  2. Choose card type:
    • One-time purchase? Use SINGLE_USE
    • Recurring at one merchant (e.g., subscription)? Use MERCHANT_LOCKED
  3. Create the card and extract only the fields you need. Never log or print the full API response — it contains the full card number (PAN) and CVV which must not appear in chat logs or transcripts.
bash
# Create card and extract only safe fields for logging
RESPONSE=$(curl -s https://api.privacy.com/v1/cards \
  -X POST \
  -H "Authorization: api-key $PRIVACY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "SINGLE_USE",
    "memo": "Purpose of purchase",
    "spend_limit": AMOUNT_IN_CENTS,
    "spend_limit_duration": "TRANSACTION",
    "state": "OPEN"
  }')

# Log only safe fields (no PAN/CVV)
echo "$RESPONSE" | python3 -c "
import sys, json
card = json.load(sys.stdin)
print(json.dumps({
  'token': card.get('token'),
  'last_four': card.get('last_four'),
  'exp_month': card.get('exp_month'),
  'exp_year': card.get('exp_year'),
  'spend_limit': card.get('spend_limit'),
  'state': card.get('state'),
  'memo': card.get('memo')
}, indent=2))
"
  1. When you need the full card details for checkout, extract them in a separate step that is not logged to chat. Use the card details directly in the browser tool or API call without printing them.
bash
# Extract card details for checkout (DO NOT print to chat)
PAN=$(echo "$RESPONSE" | python3 -c "import sys,json; print(json.load(sys.stdin)['pan'])")
CVV=$(echo "$RESPONSE" | python3 -c "import sys,json; print(json.load(sys.stdin)['cvv'])")
EXP_MONTH=$(echo "$RESPONSE" | python3 -c "import sys,json; print(json.load(sys.stdin)['exp_month'])")
EXP_YEAR=$(echo "$RESPONSE" | python3 -c "import sys,json; print(json.load(sys.stdin)['exp_year'])")
  1. Use these card details to complete the purchase (via browser tool or API)
  2. After purchase, verify with the transactions endpoint
Checking a Card's Status
bash
curl -s https://api.privacy.com/v1/cards/CARD_TOKEN \
  -H "Authorization: api-key $PRIVACY_API_KEY"
Pausing a Card (Temporarily Disable)
bash
curl -s https://api.privacy.com/v1/cards/CARD_TOKEN \
  -X PATCH \
  -H "Authorization: api-key $PRIVACY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"state": "PAUSED"}'
Closing a Card (Permanent)
bash
curl -s https://api.privacy.com/v1/cards/CARD_TOKEN \
  -X PATCH \
  -H "Authorization: api-key $PRIVACY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"state": "CLOSED"}'
Viewing Recent Transactions
bash
curl -s "https://api.privacy.com/v1/transactions?page=1&page_size=10" \
  -H "Authorization: api-key $PRIVACY_API_KEY"
Show full SKILL.md (307 more words)Show less

Safety Rules

  1. Always confirm the purchase amount and purpose with the user before creating a card, unless the user has pre-approved the spend (e.g., "buy this domain" with a known price).
  2. Use SINGLE_USE by default. Only use MERCHANT_LOCKED if explicitly needed for recurring charges.
  3. Set the spend limit as close to the expected amount as possible. Round up to the next whole dollar, but don't over-allocate (e.g., $12.99 item = $13.00 = 1300 cents).
  4. Close or pause cards after use. SINGLE_USE cards auto-close, but MERCHANT_LOCKED cards stay open. Close them when no longer needed.
  5. Never log, print, or display the full PAN or CVV in chat, logs, or tool output. The raw API response contains sensitive card data (PAN, CVV) that must not appear in transcripts. Always parse the response and extract only safe fields (token, last_four, memo, spend_limit, state) for logging. Use full card details only in the checkout step, never echoed to chat.
  6. Include a descriptive memo on every card so the user can identify what it was for in their Privacy.com dashboard.

Output Format

When creating a card, report to the user:

Created Privacy.com card (****1234)
Type: Single-use
Limit: $25.00
Memo: Domain purchase - example.com
Status: Ready to use

When listing transactions:

Recent transactions:

1. $12.99 at NAMECHEAP.COM - SETTLED (Jan 15, 2024)
   Card: ****1234 (Domain purchase)

2. $49.00 at GITHUB.COM - PENDING (Jan 14, 2024)
   Card: ****5678 (GitHub Pro subscription)

Error Handling

  • 401 Unauthorized: API key is invalid or missing. Check PRIVACY_API_KEY env var.
  • 403 Forbidden: Account may need verification or doesn't have API access.
  • 429 Rate Limited: Back off and retry after a short delay.
  • Card creation fails: May have hit the monthly card limit for the plan tier. Inform the user.
  • Amount not in whole dollars: The API requires spend_limit in whole-dollar increments (in cents). Round up.

Sandbox Testing

For testing without real money, use the sandbox environment:

  • Base URL: https://sandbox.privacy.com/v1
  • Simulate transactions: POST https://sandbox.privacy.com/v1/simulate/authorize and POST https://sandbox.privacy.com/v1/simulate/clearing
  • Sandbox cards work identically to production but no real charges occur.

Data Source

Privacy.com Developer API - RESTful API, requires API key from a Privacy.com account.

© dylanfeltus, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in privacy-cards of dylanfeltus/skills.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit b97a48f

Compare with similar skills

Privacy.com Virtual Cards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy.com Virtual Cards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy.com Virtual Cards this skilldylanfeltus/skills179—~2.2kAutomated safety check: PassMIT
QuickBooks Online Integrationhewi333/Mom-n-Pop-Skills122—~1.9kAutomated safety check: PassMIT
PayRam Payment AnalyticsPayRam/payram-mcp158—~4.1kAutomated safety check: PassNone
Billing Automationwshobson/agents40k13 repos~473Automated safety check: PassMIT
Stripe Best Practicesfossasia/eventyay1.7k1 repos~1.7kAutomated safety check: PassApache-2.0
Pinme Uniwebpayglitternetwork/pinme3.8k—~7.3kAutomated safety check: PassMIT

Similar skills

  • QuickBooks Online Integration

    hewi333/Mom-n-Pop-Skills

    Connects a small business to QuickBooks Online for customers, estimates, invoices and payments, using Intuit OAuth 2.0 with token refresh and sandbox or production setups.

    122 GitHub stars~1.9k tokensUpdated 28 days ago
    Backend & APIsAuto-check passed
  • PayRam Payment Analytics

    PayRam/payram-mcp

    Queries a PayRam server's dashboard data through its REST APIs with a Bearer token: payment search, daily volume, unswept balances, sweep history and on-ramp metrics.

    158 GitHub stars~4.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 13 repos~473 tokens
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    fossasia/eventyay

    Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents)…

    1.7k GitHub starsUsed in 1 repo~1.7k tokens
    Backend & APIsAuto-check passed
  • Pinme Uniwebpay

    glitternetwork/pinme

    A skill your agent uses when generating, modifying, or reviewing PinMe Worker (Cloudflare Worker TypeScript) code that accepts payments through UniwebPay — payment links, products/prices, checkout…

    3.8k GitHub stars~7.3k tokensUpdated 28 days ago
    Backend & APIsAuto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Backend & APIsAuto-check passed

More from dylanfeltus/skills

All 10 skills in this repo
  • App Store Intelligence

    dylanfeltus/skills

    Looks up app details, ratings and reviews and searches the iOS and Mac App Stores through Apple's free iTunes APIs, with a web-search fallback for Google Play.

    179 GitHub stars~2k tokensUpdated 22 days ago
    Auto-check passed
  • AI Image Creative Direction

    dylanfeltus/skills

    Gives prompt templates, a model-selection guide and anti-generic rules for AI-generated visuals: hero images, feature illustrations, OG cards, icons and backgrounds.

    179 GitHub stars~2.6k tokensUpdated 22 days ago
    Auto-check passed
  • Design Token Generator

    dylanfeltus/skills

    Generates type scales, color palettes, spacing systems, WCAG contrast checks and dark mode palettes from formulas, as CSS custom properties, a Tailwind config or JSON tokens.

    179 GitHub stars~2.9k tokensUpdated 22 days ago
    Auto-check passed
  • Hacker News Search

    dylanfeltus/skills

    Searches and monitors Hacker News stories, comments and users through the free Algolia HN Search API, with tag, points and date filters.

    179 GitHub stars~1.7k tokensUpdated 22 days ago
    Auto-check passed
  • Framer Motion (Motion) patterns for React: spring presets, staggers, layout animations, micro-interactions, scroll effects and page transitions, with performance rules.

    179 GitHub stars~3k tokensUpdated 22 days ago
    Auto-check passed
  • Looks up Product Hunt launches, products and makers through its GraphQL API: daily top posts, topic browsing and per-post details, using a free developer token.

    179 GitHub stars~1.7k tokensUpdated 22 days ago
    Auto-check passed

Questions about Privacy.com Virtual Cards

What does Privacy.com Virtual Cards do?

Creates, updates, and monitors Privacy.com virtual payment cards with spending limits for an agent making controlled purchases. com API, reached with an API key, backs the whole skill: creating a single-use, merchant-locked, or digital-wallet card with an optional spend limit and duration, updating a card's state or limit afterward, and listing cards or their recent transactions. A sandbox base URL is available for testing separately from the production API, and closing a card is explicitly permanent.

When should I use Privacy.com Virtual Cards?

Privacy.com Virtual Cards fits situations like: setting up a spend-limited card for one specific purchase; checking a card's status or recent transactions; pausing or permanently closing a virtual card.

How do I install Privacy.com Virtual Cards in Claude Code?

Run `npx skills add dylanfeltus/skills --skill privacy-cards -a claude-code`. Or copy the skill folder (privacy-cards in dylanfeltus/skills) into .claude/skills/privacy-cards in your project. Claude Code loads it when a task matches its description.

How do I install Privacy.com Virtual Cards in Codex?

Run `npx skills add dylanfeltus/skills --skill privacy-cards -a codex`. Or copy the skill folder (privacy-cards in dylanfeltus/skills) into .agents/skills/privacy-cards in your project. Codex loads it when a task matches its description.

Can I use Privacy.com Virtual Cards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dylanfeltus/skills --skill privacy-cards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-cards, .gemini/skills/privacy-cards, .github/skills/privacy-cards and .opencode/skills/privacy-cards in your project.

What does Privacy.com Virtual Cards need to run?

Going by SKILL.md and its folder, Privacy.com Virtual Cards needs the command-line tools its instructions call (curl and python3) and credentials named PRIVACY_API_KEY and CARD_TOKEN. Our summary lists: A Privacy.com account and API key (`PRIVACY_API_KEY`).

Does Privacy.com Virtual Cards access the network?

SKILL.md names 3 domains. In commands or code: api.privacy.com and sandbox.privacy.com; the agent is likely to contact these when it follows the instructions. As links in the text: privacy-com.readme.io. This is read from the text; nothing was executed.

Is Privacy.com Virtual Cards safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy.com Virtual Cards use?

Privacy.com Virtual Cards is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy.com Virtual Cards use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy.com Virtual Cards?

Skills that share tags, products or a category with Privacy.com Virtual Cards: QuickBooks Online Integration (hewi333/Mom-n-Pop-Skills, 122 stars), PayRam Payment Analytics (PayRam/payram-mcp, 158 stars), Billing Automation (wshobson/agents, 40k stars) and Stripe Best Practices (fossasia/eventyay, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy.com Virtual Cards?

dylanfeltus (a GitHub user) maintains it in dylanfeltus/skills, which has 179 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 17, 2026.

Source: dylanfeltus/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.