Server profile · Evaluated September 2026

Stripe MCP

Stripe’s first-party MCP gives AI agents structured access to Stripe documentation and a broad Stripe API surface through a compact search/details/read/write tool architecture. It is unusually capable and token-efficient, but the same generic write layer can represent financially consequential actions.

PaymentsRemote + Local packageOAuth / Agent API KeyFinancial writes
Publisher
Stripe
First-party
Hosted tools
≈10
Compact meta-tool architecture
Transport
Streamable HTTP
Hosted endpoint
Authentication
OAuth / Agent key
Permission-scoped
Schema overhead
≈3K–6K
Estimated tokens/session
Write capability
Broad
Financial impact possible

Start with Decision, Safety, Tokens and Fit. Use Setup for client connection details and External Sources for the official documentation, pricing pages and supporting references used for this profile.

Should you use Stripe MCP?

Best for

Developers, billing/support teams and internal agents that need Stripe context plus tightly scoped account actions, preferably tested in sandbox first.

Think twice when

The agent will operate unattended in live mode, can perform broad writes, or a mistaken retry could duplicate a payment or another financially consequential action.

Main advantage

Broad first-party Stripe API coverage through a compact MCP surface, with OAuth/agent-key permissions, human confirmation for selected sensitive actions and Workbench audit visibility.

Main tradeoff

stripe_api_write is token-efficient but concentrates many possible mutations behind one generic tool, so a small tool count does not imply narrow authority.

MCPVerdict view

Stripe MCP is strongest as a controlled financial and developer tool. Its architecture is efficient and well maintained, but live write access should be constrained with the smallest permissions, stable retry identity, auditing and human review for consequential actions.

Why Stripe MCP scores 78/100

The 78/100 score is weighted around the failure that matters most for this server: an agent performs a financial action the user did not intend, or repeats an intended operation as a new action. Stripe has unusually strong mitigations, but the remaining failure modes are too consequential to average away.

Universal parameterScoreFinding
Effectiveness90Broad first-party API and documentation access covers real development, billing and support workflows.
Reliability73Historical pagination and protocol/interoperability issues matter when financial data must be complete.
Safety77Strong authorization and confirmation controls are offset by broad generic write authority.
Efficiency90Search/details/read/write meta-tools avoid injecting hundreds of Stripe endpoint schemas.
Compatibility72Major clients are documented, but current-spec compatibility is not fully verified.
Maintainability94First-party service with active Stripe maintenance.
Setup friction91Hosted OAuth and documented client commands make normal setup straightforward.

Stripe-specific parameters

ParameterScoreWhy it matters
Money-movement containment82Human confirmation materially improves refund/outbound-payment safety, but not every write is approval-gated.
Permission minimization91OAuth and scoped agent credentials create a strong Stripe-side security boundary.
Retry/idempotency safety62Agent-level retries can become new logical operations if business identity is not preserved.
Data completeness70Historical pagination defects make silent partial results an important category risk.
Auditability91Workbench can identify MCP-originated activity and OAuth-user attribution.
Write-surface clarity68One generic write tool can proxy many consequential Stripe API mutations.
Prompt-injection containment75External confirmation helps, but customer-controlled Stripe content can still become untrusted model input.
Connected-account isolation80Explicit account targeting is useful, while selecting the wrong account remains operationally consequential.

What is Stripe MCP?

Stripe MCP is Stripe’s first-party Model Context Protocol server for giving compatible AI agents structured access to Stripe documentation, account data and supported Stripe API operations.

The main hosted endpoint is https://mcp.stripe.com. Stripe also maintains the @stripe/mcp local package as an alternate stdio path.

The central architectural change is that the hosted server no longer needs one MCP tool for every Stripe operation. Instead, the agent can search the Stripe API, fetch a method’s exact parameters, then invoke a general read or write tool.

AI clientClaude / Cursor / Codex
Stripe MCPtool layer
Stripe APIoperation discovery
Stripe accountscoped authority
Result / approvalreturn to agent

What tools does Stripe MCP expose?

The current hosted documentation uses a compact high-level tool set. Exact preview availability can change, but the architecture centers on generalized API discovery and execution instead of dozens of endpoint-specific MCP schemas.

ToolAuthorityPurpose
stripe_api_searchReadFind relevant Stripe API methods by keyword or intent.
stripe_api_detailsReadRetrieve the exact method and parameter schema for a selected Stripe API operation.
stripe_api_readReadExecute supported Stripe API GET operations.
stripe_api_writeWriteExecute supported POST, PATCH, PUT and DELETE operations.
get_stripe_account_infoReadRetrieve current Stripe account information.
stripe_analyticsReadQuery metrics and, where available, Sigma-backed analysis.
get_balance_summaryReadRetrieve Stripe/Treasury balance summaries.
search_stripe_documentationReadSearch Stripe documentation and support material.
stripe_implementation_plannerReadHelp choose Stripe products and implementation paths.
send_stripe_mcp_feedbackWriteSend feedback about the MCP experience.
Fewer tools does not mean less authority

stripe_api_write can represent many underlying Stripe mutations. The current architecture is more schema-efficient, but the effective action surface is much larger than the raw MCP tool count.

What can Stripe MCP do?

Stripe MCP can search Stripe’s API and documentation, retrieve financial and billing objects, create or modify supported resources, analyze Stripe data and help an agent plan Stripe implementations.

WorkflowExamplesTypical authority
CustomersList, retrieve, create and update customer records.Read / Write
PaymentsInspect charges, PaymentIntents and payment methods.Read
RefundsInspect and create refunds.Read / High-risk write
BillingCreate, finalize, void or inspect invoices.Read / Write
SubscriptionsCreate, retrieve, update and cancel subscriptions.Read / Write
Products & pricesCreate and update products and prices.Read / Write
CheckoutCreate or inspect Checkout Sessions and payment links.Read / Write
DisputesRetrieve and update dispute information.Read / Write
TaxInspect calculations and modify supported tax settings.Read / Write
Account operationsBalances, payouts and other account data.Read; some writes may be sensitive
Developer supportSearch docs, find methods and retrieve exact parameters.Read
Implementation planningChoose relevant Stripe products and integration approaches.Read

Where the server creates the most value

The safest high-value workflow is development and support: let the agent search current Stripe documentation, inspect account state and explain what is happening. Write workflows add value when they are permission-scoped and operationally reviewed.

Is Stripe MCP safe?

Stripe MCP has strong first-party security controls, but live write access remains consequential. OAuth, Agent API Keys, sandbox separation, revocable sessions, Workbench auditing and human confirmation reduce risk. They do not turn a broad financial write surface into a low-risk capability.

Safety layerWhat it controls
OAuthWhich Stripe account/environment an interactive user authorizes.
Agent API KeyPersistent permissions for autonomous or server-side agents.
Human confirmationExternal approval for selected sensitive financial writes.
SandboxSeparates testing from live financial activity.
Session controlsAllow OAuth sessions to be inspected or revoked.
WorkbenchProvides visibility into MCP-originated API traffic and user attribution.
Connected-account targetingTargets a specific Connect account via the Stripe-Account flow.

Which actions require human confirmation?

Stripe documents human confirmation for certain sensitive stripe_api_write operations, including refunds and outbound payments. The agent receives an approval URL, the user reviews the action, Stripe issues an approval token, and the agent retries the approved operation. Approval expires after 24 hours.

The important wording is “certain.” Human confirmation is not documented as a universal gate for every state-changing API operation.

Agent proposessensitive write
Stripe returnsapproval URL
User reviewsexact action
Stripe issuesapproval token
Agent retriesapproved call

How does Stripe MCP authentication work?

OAuth for interactive use

OAuth is the preferred path for interactive clients. The authorization flow can scope access to Stripe accounts and environments, while sessions can be inspected or revoked by users or administrators.

Agent API Keys for autonomous clients

Stripe now directs non-interactive clients toward Agent API Keys. The key should grant only the permissions the agent actually needs and should be stored in an environment variable rather than hard-coded into client configuration.

October 31, 2026 authentication change

Stripe states that full-access secret keys and non-Agent Restricted API Keys will no longer be accepted for normal Stripe MCP authentication after October 31, 2026. Existing autonomous clients should migrate to Agent API Keys or OAuth.

Connected accounts use a different path

When acting on behalf of a Stripe Connect account, Stripe documents a restricted credential plus the Stripe-Account header rather than ordinary OAuth delegation. The target account therefore becomes an explicit operational boundary.

What are the main risks of Stripe MCP?

Broad generic write authority

stripe_api_write is efficient because the model does not need every Stripe write schema in context. The same abstraction means one tool can potentially represent refunds, subscription changes, invoice mutations, Checkout operations, tax updates and other supported modifications.

Permission is not the same as policy

A credential can say an agent may perform refunds. That does not inherently express a business policy such as “one refund, for this exact payment, below $100, once today.” The scan did not find a universal per-agent action-envelope system documented across all writes.

Agent-level retries can duplicate financial work

Stripe API idempotency protects correctly identified retries. An orchestration layer can still create a new logical operation if it loses the original business identity after a timeout and invokes the tool again as a fresh action.

Write beginspayment action
Response uncertaintimeout / failure
Agent retriesnew logical request
New identitynew idempotency context
Potential duplicatefinancial impact

Prompt injection matters more when multiple tools are connected

Stripe objects can contain customer-controlled names, metadata and descriptions. An agent that simultaneously has Stripe write access plus browser, email, Slack or filesystem tools can expose a larger cross-tool attack surface. Stripe explicitly recommends human confirmation and caution when combining MCP servers.

Incomplete data can be dangerous

2026 issue evidence included pagination problems where list calls returned only the first page or ignored pagination parameters. A visibly failed query is easier to detect than a partial result that looks complete, especially in billing audits or financial analysis.

Which AI clients work with Stripe MCP?

Stripe currently documents direct setup paths for major MCP clients and provides the hosted endpoint for other compatible clients.

ClientStripe pathAuthentication / note
ClaudeOfficial Stripe connectorOAuth
Claude CodeRemote MCPOAuth or Agent API Key
CursorRemote MCPOAuth or Agent API Key
CodexRemote MCPOAuth or Agent API Key
ChatGPTOfficial Stripe plugin / MCP pathOAuth
VS CodeRemote HTTP MCPOAuth or supported bearer-token flow
OpenCode / Antigravity / othersGeneric compatible-client pathUse the hosted endpoint when the client supports the required MCP transport/authentication.
Client query ≠ separate entity by default

“Stripe MCP Cursor,” “Stripe MCP Claude,” “Stripe MCP Codex” and similar searches describe compatibility/setup attributes of the same Stripe MCP entity. They only justify separate child pages when the setup/troubleshooting query network becomes large enough to need its own context.

How do you set up Stripe MCP?

Stripe recommends its agent setup flow where supported because it can configure MCP together with Stripe’s agent skills.

npm install -g @stripe/cli@latest
stripe agent setup

Cursor

{
  "mcpServers": {
    "stripe": {
      "url": "https://mcp.stripe.com"
    }
  }
}

Claude Code

claude mcp add --transport http stripe https://mcp.stripe.com/

Codex

codex mcp add stripe --url https://mcp.stripe.com

Other compatible clients

Use the hosted endpoint https://mcp.stripe.com and complete OAuth when the client supports it. For non-interactive clients, store the Agent API Key in an environment variable and keep permissions as narrow as possible.

Verify before live mode

  1. Connect to a Stripe sandbox first.
  2. Confirm the authenticated account/environment.
  3. Run a read-only customer or payment lookup.
  4. Verify pagination on a result set large enough to require it.
  5. Create a harmless sandbox resource.
  6. Test one sensitive action and confirm the external approval flow.
  7. Deliberately retry a write and inspect idempotency behavior.
  8. Confirm the MCP request and user attribution in Workbench.
  9. Only then consider a narrowly scoped live credential.

Is Stripe MCP the same as Stripe’s agentic payments system?

No. Stripe MCP gives an AI agent access to Stripe APIs, Stripe account resources and Stripe knowledge. Stripe’s Agentic Commerce products solve the separate problem of letting agents participate in commerce using scoped payment credentials and checkout infrastructure.

Stripe technologyMain purpose
Stripe MCPGive AI agents structured Stripe API/documentation access and supported account actions.
Shared Payment TokensLet an agent initiate a payment using scoped permission without exposing the buyer’s underlying payment credentials.
Agentic Commerce SuiteInfrastructure for businesses and agents participating in AI-mediated commerce.
Agent SkillsReusable Stripe instructions/best practices that guide agent behavior.

Shared Payment Tokens can be scoped by seller, time and amount. That makes them more directly aligned with delegated purchasing authority than MCP itself. Stripe MCP can participate in agent-driven financial workflows, but it is not the payment credential or agentic-commerce protocol.

How many tokens does Stripe MCP use?

MCPVerdict estimates the current Stripe MCP tool-schema overhead at approximately 3,000–6,000 input tokens per initialized session. The figure is an estimate until a current authenticated tools/list payload is captured and tokenized with the exact target model.

The larger variable is returned data. Customer lists, subscription objects, invoices, documentation results and analytics can add many more tokens than the static tool definitions.

Context layerEstimated usageWhat changes it
Tool schemas≈3K–6K input tokens/sessionCurrent tool descriptions, client serialization and tokenizer.
Simple read workflowTask-dependentNumber and size of returned Stripe objects.
Documentation/API discoveryTask-dependentSearch results and method-detail payloads.
Realistic sandbox evaluation≈40K input + 10K outputMultiple reads, writes, pagination, confirmation, retry and auditing tests.

Why the current architecture saves context

The efficient sequence is:

stripe_api_search → stripe_api_details → stripe_api_read/write

The agent retrieves the operation schema only when it needs it instead of carrying dozens or hundreds of Stripe operation definitions in every request. This is the main reason Stripe MCP scores 90/100 for efficiency.

Token-efficiency paradox

Stripe MCP became lighter by consolidating endpoint-specific tools into generic API tools. That lowers schema overhead while increasing the authority represented by each generic tool—especially stripe_api_write.

How much does Stripe MCP cost with current AI models?

The table separates two things: the cost of loading an estimated 3K–6K Stripe MCP schema and the cost of a more realistic 40K input + 10K output multi-step sandbox evaluation.

Prices below use standard uncached API rates available on September 27, 2026. They exclude caching, batch discounts, regional uplifts, tool-specific fees, long-context premiums and normal Stripe product/transaction fees.

Current modelInput / 1MOutput / 1M3K–6K schema load40K + 10K run
GPT-6 Astra
OpenAI
$5.00$25.00$0.015–$0.030$0.4500
GPT-6 Sol
OpenAI
$1.00$5.00$0.003–$0.006$0.0900
GPT-6 Luna
OpenAI
$0.05$0.25$0.00015–$0.00030$0.0045
GPT-5.6 Sol
OpenAI
$4.00$20.00$0.012–$0.024$0.3600
GPT-5.6 Terra
OpenAI
$2.00$12.00$0.006–$0.012$0.2000
GPT-5.6 Luna
OpenAI
$0.20$1.20$0.0006–$0.0012$0.0200
Claude Fable 5.1
Anthropic
$10.00$50.00$0.030–$0.060$0.9000
Claude Sonnet 5
Anthropic
$2.00$10.00$0.006–$0.012$0.1800
Claude Haiku 4.5
Anthropic
$1.00$5.00$0.003–$0.006$0.0900
Gemini 3.8 Flash
Google
$0.75$3.75$0.00225–$0.00450$0.0675
Gemini 3.5 Flash
Google
$1.50$9.00$0.0045–$0.0090$0.1500
Gemini 3.5 Flash-Lite
Google
$0.30$2.50$0.0009–$0.0018$0.0370
Grok 4.7
xAI
$2.00$6.00$0.006–$0.012$0.1400
Grok 4.3
xAI
$1.25$2.50$0.00375–$0.00750$0.0750
Mistral Medium 3.5
Mistral
$1.50$7.50$0.0045–$0.0090$0.1350

How the calculation works

Schema load: 3,000–6,000 × model input rate.

Evaluation run: 40,000 × input rate + 10,000 × output rate.

The model bill is usually small compared with the potential operational cost of a bad live action. A mistaken refund, duplicate payment or wrong connected-account mutation can dominate the economic risk even when the AI call costs only cents.

OpenAI GPT-6 rates above use the short-context Standard prices shown on OpenAI’s current API pricing page. GPT-5.6 Sol/Terra/Luna use their current standard rates. Gemini 3.8 Flash uses Google’s introductory rate through December 31, 2026. Provider links are listed in External Sources.

Who is Stripe MCP best for?

Strong fit

High-value use cases

  • Building and debugging Stripe integrations.
  • Customer and payment investigation.
  • Billing/support workflows.
  • Read-heavy financial/account analysis.
  • Controlled invoice, subscription and payment-link operations.
  • Human-approved refunds and other selected sensitive actions.
  • Connect support with deliberate account targeting.
Poor fit

Where risk dominates

  • Unattended live-mode financial agents.
  • Broad credentials with unnecessary write access.
  • Workflows that treat uncertain responses as new operations.
  • Cross-tool agents exposed to untrusted account content without strong approval boundaries.
  • Financial reporting that does not verify pagination/completeness.
  • Teams expecting MCP permissions alone to enforce business-specific amount/count policies.

What are Stripe MCP’s main limitations?

LimitationWhy it matters
Broad stripe_api_write authorityOne tool can represent many consequential API mutations.
Human confirmation covers selected writesNot every state change is documented as externally approval-gated.
No universal action envelopeCredential permission does not automatically encode task-level amount/count limits.
Agent retry riskA new logical invocation can bypass the intent of network-level idempotency.
Prompt injection exposureUser-controlled Stripe content can enter the model context.
Connected-account targetingA wrong account header can affect the wrong merchant/account.
Historical pagination defectsPartial datasets can look complete.
Current MCP-spec adoption unverifiedStrict clients can expose interoperability differences.

Stripe MCP technical details

Show the full technical profile
AttributeEvaluated value
PublisherStripe
TypeFirst-party hosted MCP + local npm package
Hosted endpointhttps://mcp.stripe.com
Hosted transportStreamable HTTP
Interactive authenticationOAuth
Autonomous authenticationAgent API Key
Connected-account pathRestricted credential + Stripe-Account header
Local package@stripe/mcp 0.3.3 in the evaluated snapshot
Hosted implementation licenseProprietary service
Local repository/package licenseMIT in the evaluated snapshot
Approximate hosted tool surface≈10 high-level tools
Read capabilityYes
Write capabilityYes — broad, permission-dependent
Human confirmationSelected sensitive writes
AuditabilityWorkbench MCP filtering / OAuth-user attribution
Estimated schema tokens≈3K–6K
Scan gradeC
Overall score78/100
ConfidenceModerate
MCP 2026-07-28 adoptionNot verified in the evaluation snapshot

Stripe MCP evidence and sources

These direct sources support the findings below. Documentation describes supported behavior; issue reports describe individual observations. Neither establishes a universal success rate.

  1. Authentication and account scope: Stripe’s MCP documentation covers setup and connected-account access. Connected-account calls require a restricted API key and the Stripe-Account header; OAuth is not supported for that path. Read source ↗
  2. Operational audit trail: Stripe’s MCP guide links to Workbench documentation for inspecting MCP tool-call logs. Review the logs alongside the action taken and account used. Read source ↗
  3. Official project reference: The former agent-toolkit repository now redirects to Stripe’s ai repository. Use the current official project and MCP documentation when evaluating implementation details. Read source ↗

Historical incident summaries without a verified original source are omitted from this evidence list. Scores and token estimates elsewhere in this profile remain the supplied editorial assessment, not independently reproduced benchmarks.

External sources

These are the primary external references used to verify the current Stripe MCP architecture, authentication, client setup, agentic-commerce distinction and model-pricing calculations. Links open in a new tab.

Frequently asked questions

Does Stripe have an official MCP server?

Yes. Stripe operates the hosted MCP endpoint at https://mcp.stripe.com and documents first-party setup for major AI clients.

Is Stripe MCP free?

Stripe does not charge a separate fee for the MCP connection itself in the evaluated profile. Normal Stripe product/transaction fees and the connected AI model’s token charges still apply.

Can Stripe MCP create refunds?

Yes. Refunds are supported through the write surface, and Stripe documents human confirmation for selected sensitive operations including refunds.

Can Claude use Stripe MCP?

Yes. Stripe provides an official Claude connector and separately documents Claude Code as a remote MCP client.

Can Cursor use Stripe MCP?

Yes. Cursor can connect directly to the hosted Stripe MCP endpoint through its MCP configuration.

Can Codex use Stripe MCP?

Yes. Stripe documents direct Codex setup using the hosted MCP endpoint, with OAuth or Agent API Key authentication depending on the workflow.

Does Stripe MCP work with OpenCode or Antigravity?

Stripe’s main documentation does not provide dedicated setup sections for both clients. They fit the generic-client path when the client supports Stripe’s remote MCP transport and authentication requirements.

Is Stripe MCP the same as agentic payments?

No. MCP exposes Stripe tools and account/API capabilities to an agent. Stripe’s Agentic Commerce products and Shared Payment Tokens provide separate infrastructure for delegated purchasing and AI-mediated commerce.

How much context does Stripe MCP use?

MCPVerdict estimates roughly 3K–6K tokens for the current compact tool-schema surface. Actual tasks can use much more because Stripe objects, docs, analytics and conversation history add context.

Is Stripe MCP safe for fully autonomous live payments?

The server has strong controls, but MCPVerdict’s Conditional rating reflects broad write authority, retry/idempotency risk and the lack of a universal action-envelope policy across every write. Narrow permissions, sandbox validation and human review remain the safer operating model.

Evaluating this for a team?

Check the choice against your workflow, clients, permissions, deployment, and alternatives.

Team evaluation
Cookie policy · Disclaimer