Stripe MCP
Stripe’s first-party MCP gives AI agents structured access to Stripe documentation and a broad Stripe API surface through a compact search/details/read/write tool architecture. It is unusually capable and token-efficient, but the same generic write layer can represent financially consequential actions.
Start with Decision, Safety, Tokens and Fit. Use Setup for client connection details and External Sources for the official documentation, pricing pages and supporting references used for this profile.
Should you use Stripe MCP?
Developers, billing/support teams and internal agents that need Stripe context plus tightly scoped account actions, preferably tested in sandbox first.
The agent will operate unattended in live mode, can perform broad writes, or a mistaken retry could duplicate a payment or another financially consequential action.
Broad first-party Stripe API coverage through a compact MCP surface, with OAuth/agent-key permissions, human confirmation for selected sensitive actions and Workbench audit visibility.
stripe_api_write is token-efficient but concentrates many possible mutations behind one generic tool, so a small tool count does not imply narrow authority.
Stripe MCP is strongest as a controlled financial and developer tool. Its architecture is efficient and well maintained, but live write access should be constrained with the smallest permissions, stable retry identity, auditing and human review for consequential actions.
Why Stripe MCP scores 78/100
The 78/100 score is weighted around the failure that matters most for this server: an agent performs a financial action the user did not intend, or repeats an intended operation as a new action. Stripe has unusually strong mitigations, but the remaining failure modes are too consequential to average away.
| Universal parameter | Score | Finding |
|---|---|---|
| Effectiveness | 90 | Broad first-party API and documentation access covers real development, billing and support workflows. |
| Reliability | 73 | Historical pagination and protocol/interoperability issues matter when financial data must be complete. |
| Safety | 77 | Strong authorization and confirmation controls are offset by broad generic write authority. |
| Efficiency | 90 | Search/details/read/write meta-tools avoid injecting hundreds of Stripe endpoint schemas. |
| Compatibility | 72 | Major clients are documented, but current-spec compatibility is not fully verified. |
| Maintainability | 94 | First-party service with active Stripe maintenance. |
| Setup friction | 91 | Hosted OAuth and documented client commands make normal setup straightforward. |
Stripe-specific parameters
| Parameter | Score | Why it matters |
|---|---|---|
| Money-movement containment | 82 | Human confirmation materially improves refund/outbound-payment safety, but not every write is approval-gated. |
| Permission minimization | 91 | OAuth and scoped agent credentials create a strong Stripe-side security boundary. |
| Retry/idempotency safety | 62 | Agent-level retries can become new logical operations if business identity is not preserved. |
| Data completeness | 70 | Historical pagination defects make silent partial results an important category risk. |
| Auditability | 91 | Workbench can identify MCP-originated activity and OAuth-user attribution. |
| Write-surface clarity | 68 | One generic write tool can proxy many consequential Stripe API mutations. |
| Prompt-injection containment | 75 | External confirmation helps, but customer-controlled Stripe content can still become untrusted model input. |
| Connected-account isolation | 80 | Explicit account targeting is useful, while selecting the wrong account remains operationally consequential. |
What is Stripe MCP?
Stripe MCP is Stripe’s first-party Model Context Protocol server for giving compatible AI agents structured access to Stripe documentation, account data and supported Stripe API operations.
The main hosted endpoint is https://mcp.stripe.com. Stripe also maintains the @stripe/mcp local package as an alternate stdio path.
The central architectural change is that the hosted server no longer needs one MCP tool for every Stripe operation. Instead, the agent can search the Stripe API, fetch a method’s exact parameters, then invoke a general read or write tool.
What tools does Stripe MCP expose?
The current hosted documentation uses a compact high-level tool set. Exact preview availability can change, but the architecture centers on generalized API discovery and execution instead of dozens of endpoint-specific MCP schemas.
| Tool | Authority | Purpose |
|---|---|---|
stripe_api_search | Read | Find relevant Stripe API methods by keyword or intent. |
stripe_api_details | Read | Retrieve the exact method and parameter schema for a selected Stripe API operation. |
stripe_api_read | Read | Execute supported Stripe API GET operations. |
stripe_api_write | Write | Execute supported POST, PATCH, PUT and DELETE operations. |
get_stripe_account_info | Read | Retrieve current Stripe account information. |
stripe_analytics | Read | Query metrics and, where available, Sigma-backed analysis. |
get_balance_summary | Read | Retrieve Stripe/Treasury balance summaries. |
search_stripe_documentation | Read | Search Stripe documentation and support material. |
stripe_implementation_planner | Read | Help choose Stripe products and implementation paths. |
send_stripe_mcp_feedback | Write | Send feedback about the MCP experience. |
stripe_api_write can represent many underlying Stripe mutations. The current architecture is more schema-efficient, but the effective action surface is much larger than the raw MCP tool count.
What can Stripe MCP do?
Stripe MCP can search Stripe’s API and documentation, retrieve financial and billing objects, create or modify supported resources, analyze Stripe data and help an agent plan Stripe implementations.
| Workflow | Examples | Typical authority |
|---|---|---|
| Customers | List, retrieve, create and update customer records. | Read / Write |
| Payments | Inspect charges, PaymentIntents and payment methods. | Read |
| Refunds | Inspect and create refunds. | Read / High-risk write |
| Billing | Create, finalize, void or inspect invoices. | Read / Write |
| Subscriptions | Create, retrieve, update and cancel subscriptions. | Read / Write |
| Products & prices | Create and update products and prices. | Read / Write |
| Checkout | Create or inspect Checkout Sessions and payment links. | Read / Write |
| Disputes | Retrieve and update dispute information. | Read / Write |
| Tax | Inspect calculations and modify supported tax settings. | Read / Write |
| Account operations | Balances, payouts and other account data. | Read; some writes may be sensitive |
| Developer support | Search docs, find methods and retrieve exact parameters. | Read |
| Implementation planning | Choose relevant Stripe products and integration approaches. | Read |
Where the server creates the most value
The safest high-value workflow is development and support: let the agent search current Stripe documentation, inspect account state and explain what is happening. Write workflows add value when they are permission-scoped and operationally reviewed.
Is Stripe MCP safe?
Stripe MCP has strong first-party security controls, but live write access remains consequential. OAuth, Agent API Keys, sandbox separation, revocable sessions, Workbench auditing and human confirmation reduce risk. They do not turn a broad financial write surface into a low-risk capability.
| Safety layer | What it controls |
|---|---|
| OAuth | Which Stripe account/environment an interactive user authorizes. |
| Agent API Key | Persistent permissions for autonomous or server-side agents. |
| Human confirmation | External approval for selected sensitive financial writes. |
| Sandbox | Separates testing from live financial activity. |
| Session controls | Allow OAuth sessions to be inspected or revoked. |
| Workbench | Provides visibility into MCP-originated API traffic and user attribution. |
| Connected-account targeting | Targets a specific Connect account via the Stripe-Account flow. |
Which actions require human confirmation?
Stripe documents human confirmation for certain sensitive stripe_api_write operations, including refunds and outbound payments. The agent receives an approval URL, the user reviews the action, Stripe issues an approval token, and the agent retries the approved operation. Approval expires after 24 hours.
The important wording is “certain.” Human confirmation is not documented as a universal gate for every state-changing API operation.
How does Stripe MCP authentication work?
OAuth for interactive use
OAuth is the preferred path for interactive clients. The authorization flow can scope access to Stripe accounts and environments, while sessions can be inspected or revoked by users or administrators.
Agent API Keys for autonomous clients
Stripe now directs non-interactive clients toward Agent API Keys. The key should grant only the permissions the agent actually needs and should be stored in an environment variable rather than hard-coded into client configuration.
Stripe states that full-access secret keys and non-Agent Restricted API Keys will no longer be accepted for normal Stripe MCP authentication after October 31, 2026. Existing autonomous clients should migrate to Agent API Keys or OAuth.
Connected accounts use a different path
When acting on behalf of a Stripe Connect account, Stripe documents a restricted credential plus the Stripe-Account header rather than ordinary OAuth delegation. The target account therefore becomes an explicit operational boundary.
What are the main risks of Stripe MCP?
Broad generic write authority
stripe_api_write is efficient because the model does not need every Stripe write schema in context. The same abstraction means one tool can potentially represent refunds, subscription changes, invoice mutations, Checkout operations, tax updates and other supported modifications.
Permission is not the same as policy
A credential can say an agent may perform refunds. That does not inherently express a business policy such as “one refund, for this exact payment, below $100, once today.” The scan did not find a universal per-agent action-envelope system documented across all writes.
Agent-level retries can duplicate financial work
Stripe API idempotency protects correctly identified retries. An orchestration layer can still create a new logical operation if it loses the original business identity after a timeout and invokes the tool again as a fresh action.
Prompt injection matters more when multiple tools are connected
Stripe objects can contain customer-controlled names, metadata and descriptions. An agent that simultaneously has Stripe write access plus browser, email, Slack or filesystem tools can expose a larger cross-tool attack surface. Stripe explicitly recommends human confirmation and caution when combining MCP servers.
Incomplete data can be dangerous
2026 issue evidence included pagination problems where list calls returned only the first page or ignored pagination parameters. A visibly failed query is easier to detect than a partial result that looks complete, especially in billing audits or financial analysis.
Which AI clients work with Stripe MCP?
Stripe currently documents direct setup paths for major MCP clients and provides the hosted endpoint for other compatible clients.
| Client | Stripe path | Authentication / note |
|---|---|---|
| Claude | Official Stripe connector | OAuth |
| Claude Code | Remote MCP | OAuth or Agent API Key |
| Cursor | Remote MCP | OAuth or Agent API Key |
| Codex | Remote MCP | OAuth or Agent API Key |
| ChatGPT | Official Stripe plugin / MCP path | OAuth |
| VS Code | Remote HTTP MCP | OAuth or supported bearer-token flow |
| OpenCode / Antigravity / others | Generic compatible-client path | Use the hosted endpoint when the client supports the required MCP transport/authentication. |
“Stripe MCP Cursor,” “Stripe MCP Claude,” “Stripe MCP Codex” and similar searches describe compatibility/setup attributes of the same Stripe MCP entity. They only justify separate child pages when the setup/troubleshooting query network becomes large enough to need its own context.
How do you set up Stripe MCP?
Stripe recommends its agent setup flow where supported because it can configure MCP together with Stripe’s agent skills.
npm install -g @stripe/cli@latest
stripe agent setupCursor
{
"mcpServers": {
"stripe": {
"url": "https://mcp.stripe.com"
}
}
}Claude Code
claude mcp add --transport http stripe https://mcp.stripe.com/Codex
codex mcp add stripe --url https://mcp.stripe.comOther compatible clients
Use the hosted endpoint https://mcp.stripe.com and complete OAuth when the client supports it. For non-interactive clients, store the Agent API Key in an environment variable and keep permissions as narrow as possible.
Verify before live mode
- Connect to a Stripe sandbox first.
- Confirm the authenticated account/environment.
- Run a read-only customer or payment lookup.
- Verify pagination on a result set large enough to require it.
- Create a harmless sandbox resource.
- Test one sensitive action and confirm the external approval flow.
- Deliberately retry a write and inspect idempotency behavior.
- Confirm the MCP request and user attribution in Workbench.
- Only then consider a narrowly scoped live credential.
Is Stripe MCP the same as Stripe’s agentic payments system?
No. Stripe MCP gives an AI agent access to Stripe APIs, Stripe account resources and Stripe knowledge. Stripe’s Agentic Commerce products solve the separate problem of letting agents participate in commerce using scoped payment credentials and checkout infrastructure.
| Stripe technology | Main purpose |
|---|---|
| Stripe MCP | Give AI agents structured Stripe API/documentation access and supported account actions. |
| Shared Payment Tokens | Let an agent initiate a payment using scoped permission without exposing the buyer’s underlying payment credentials. |
| Agentic Commerce Suite | Infrastructure for businesses and agents participating in AI-mediated commerce. |
| Agent Skills | Reusable Stripe instructions/best practices that guide agent behavior. |
Shared Payment Tokens can be scoped by seller, time and amount. That makes them more directly aligned with delegated purchasing authority than MCP itself. Stripe MCP can participate in agent-driven financial workflows, but it is not the payment credential or agentic-commerce protocol.
How many tokens does Stripe MCP use?
MCPVerdict estimates the current Stripe MCP tool-schema overhead at approximately 3,000–6,000 input tokens per initialized session. The figure is an estimate until a current authenticated tools/list payload is captured and tokenized with the exact target model.
The larger variable is returned data. Customer lists, subscription objects, invoices, documentation results and analytics can add many more tokens than the static tool definitions.
| Context layer | Estimated usage | What changes it |
|---|---|---|
| Tool schemas | ≈3K–6K input tokens/session | Current tool descriptions, client serialization and tokenizer. |
| Simple read workflow | Task-dependent | Number and size of returned Stripe objects. |
| Documentation/API discovery | Task-dependent | Search results and method-detail payloads. |
| Realistic sandbox evaluation | ≈40K input + 10K output | Multiple reads, writes, pagination, confirmation, retry and auditing tests. |
Why the current architecture saves context
The efficient sequence is:
stripe_api_search→stripe_api_details→stripe_api_read/write
The agent retrieves the operation schema only when it needs it instead of carrying dozens or hundreds of Stripe operation definitions in every request. This is the main reason Stripe MCP scores 90/100 for efficiency.
Stripe MCP became lighter by consolidating endpoint-specific tools into generic API tools. That lowers schema overhead while increasing the authority represented by each generic tool—especially stripe_api_write.
How much does Stripe MCP cost with current AI models?
The table separates two things: the cost of loading an estimated 3K–6K Stripe MCP schema and the cost of a more realistic 40K input + 10K output multi-step sandbox evaluation.
Prices below use standard uncached API rates available on September 27, 2026. They exclude caching, batch discounts, regional uplifts, tool-specific fees, long-context premiums and normal Stripe product/transaction fees.
| Current model | Input / 1M | Output / 1M | 3K–6K schema load | 40K + 10K run |
|---|---|---|---|---|
| GPT-6 Astra OpenAI | $5.00 | $25.00 | $0.015–$0.030 | $0.4500 |
| GPT-6 Sol OpenAI | $1.00 | $5.00 | $0.003–$0.006 | $0.0900 |
| GPT-6 Luna OpenAI | $0.05 | $0.25 | $0.00015–$0.00030 | $0.0045 |
| GPT-5.6 Sol OpenAI | $4.00 | $20.00 | $0.012–$0.024 | $0.3600 |
| GPT-5.6 Terra OpenAI | $2.00 | $12.00 | $0.006–$0.012 | $0.2000 |
| GPT-5.6 Luna OpenAI | $0.20 | $1.20 | $0.0006–$0.0012 | $0.0200 |
| Claude Fable 5.1 Anthropic | $10.00 | $50.00 | $0.030–$0.060 | $0.9000 |
| Claude Sonnet 5 Anthropic | $2.00 | $10.00 | $0.006–$0.012 | $0.1800 |
| Claude Haiku 4.5 Anthropic | $1.00 | $5.00 | $0.003–$0.006 | $0.0900 |
| Gemini 3.8 Flash | $0.75 | $3.75 | $0.00225–$0.00450 | $0.0675 |
| Gemini 3.5 Flash | $1.50 | $9.00 | $0.0045–$0.0090 | $0.1500 |
| Gemini 3.5 Flash-Lite | $0.30 | $2.50 | $0.0009–$0.0018 | $0.0370 |
| Grok 4.7 xAI | $2.00 | $6.00 | $0.006–$0.012 | $0.1400 |
| Grok 4.3 xAI | $1.25 | $2.50 | $0.00375–$0.00750 | $0.0750 |
| Mistral Medium 3.5 Mistral | $1.50 | $7.50 | $0.0045–$0.0090 | $0.1350 |
How the calculation works
Schema load: 3,000–6,000 × model input rate.
Evaluation run: 40,000 × input rate + 10,000 × output rate.
The model bill is usually small compared with the potential operational cost of a bad live action. A mistaken refund, duplicate payment or wrong connected-account mutation can dominate the economic risk even when the AI call costs only cents.
OpenAI GPT-6 rates above use the short-context Standard prices shown on OpenAI’s current API pricing page. GPT-5.6 Sol/Terra/Luna use their current standard rates. Gemini 3.8 Flash uses Google’s introductory rate through December 31, 2026. Provider links are listed in External Sources.
Who is Stripe MCP best for?
High-value use cases
- Building and debugging Stripe integrations.
- Customer and payment investigation.
- Billing/support workflows.
- Read-heavy financial/account analysis.
- Controlled invoice, subscription and payment-link operations.
- Human-approved refunds and other selected sensitive actions.
- Connect support with deliberate account targeting.
Where risk dominates
- Unattended live-mode financial agents.
- Broad credentials with unnecessary write access.
- Workflows that treat uncertain responses as new operations.
- Cross-tool agents exposed to untrusted account content without strong approval boundaries.
- Financial reporting that does not verify pagination/completeness.
- Teams expecting MCP permissions alone to enforce business-specific amount/count policies.
What are Stripe MCP’s main limitations?
| Limitation | Why it matters |
|---|---|
Broad stripe_api_write authority | One tool can represent many consequential API mutations. |
| Human confirmation covers selected writes | Not every state change is documented as externally approval-gated. |
| No universal action envelope | Credential permission does not automatically encode task-level amount/count limits. |
| Agent retry risk | A new logical invocation can bypass the intent of network-level idempotency. |
| Prompt injection exposure | User-controlled Stripe content can enter the model context. |
| Connected-account targeting | A wrong account header can affect the wrong merchant/account. |
| Historical pagination defects | Partial datasets can look complete. |
| Current MCP-spec adoption unverified | Strict clients can expose interoperability differences. |
Stripe MCP technical details
Show the full technical profile
| Attribute | Evaluated value |
|---|---|
| Publisher | Stripe |
| Type | First-party hosted MCP + local npm package |
| Hosted endpoint | https://mcp.stripe.com |
| Hosted transport | Streamable HTTP |
| Interactive authentication | OAuth |
| Autonomous authentication | Agent API Key |
| Connected-account path | Restricted credential + Stripe-Account header |
| Local package | @stripe/mcp 0.3.3 in the evaluated snapshot |
| Hosted implementation license | Proprietary service |
| Local repository/package license | MIT in the evaluated snapshot |
| Approximate hosted tool surface | ≈10 high-level tools |
| Read capability | Yes |
| Write capability | Yes — broad, permission-dependent |
| Human confirmation | Selected sensitive writes |
| Auditability | Workbench MCP filtering / OAuth-user attribution |
| Estimated schema tokens | ≈3K–6K |
| Scan grade | C |
| Overall score | 78/100 |
| Confidence | Moderate |
| MCP 2026-07-28 adoption | Not verified in the evaluation snapshot |
Stripe MCP evidence and sources
These direct sources support the findings below. Documentation describes supported behavior; issue reports describe individual observations. Neither establishes a universal success rate.
- Authentication and account scope: Stripe’s MCP documentation covers setup and connected-account access. Connected-account calls require a restricted API key and the Stripe-Account header; OAuth is not supported for that path. Read source ↗
- Operational audit trail: Stripe’s MCP guide links to Workbench documentation for inspecting MCP tool-call logs. Review the logs alongside the action taken and account used. Read source ↗
- Official project reference: The former agent-toolkit repository now redirects to Stripe’s ai repository. Use the current official project and MCP documentation when evaluating implementation details. Read source ↗
Historical incident summaries without a verified original source are omitted from this evidence list. Scores and token estimates elsewhere in this profile remain the supplied editorial assessment, not independently reproduced benchmarks.
External sources
These are the primary external references used to verify the current Stripe MCP architecture, authentication, client setup, agentic-commerce distinction and model-pricing calculations. Links open in a new tab.
Frequently asked questions
Does Stripe have an official MCP server?
Yes. Stripe operates the hosted MCP endpoint at https://mcp.stripe.com and documents first-party setup for major AI clients.
Is Stripe MCP free?
Stripe does not charge a separate fee for the MCP connection itself in the evaluated profile. Normal Stripe product/transaction fees and the connected AI model’s token charges still apply.
Can Stripe MCP create refunds?
Yes. Refunds are supported through the write surface, and Stripe documents human confirmation for selected sensitive operations including refunds.
Can Claude use Stripe MCP?
Yes. Stripe provides an official Claude connector and separately documents Claude Code as a remote MCP client.
Can Cursor use Stripe MCP?
Yes. Cursor can connect directly to the hosted Stripe MCP endpoint through its MCP configuration.
Can Codex use Stripe MCP?
Yes. Stripe documents direct Codex setup using the hosted MCP endpoint, with OAuth or Agent API Key authentication depending on the workflow.
Does Stripe MCP work with OpenCode or Antigravity?
Stripe’s main documentation does not provide dedicated setup sections for both clients. They fit the generic-client path when the client supports Stripe’s remote MCP transport and authentication requirements.
Is Stripe MCP the same as agentic payments?
No. MCP exposes Stripe tools and account/API capabilities to an agent. Stripe’s Agentic Commerce products and Shared Payment Tokens provide separate infrastructure for delegated purchasing and AI-mediated commerce.
How much context does Stripe MCP use?
MCPVerdict estimates roughly 3K–6K tokens for the current compact tool-schema surface. Actual tasks can use much more because Stripe objects, docs, analytics and conversation history add context.
Is Stripe MCP safe for fully autonomous live payments?
The server has strong controls, but MCPVerdict’s Conditional rating reflects broad write authority, retry/idempotency risk and the lack of a universal action-envelope policy across every write. Narrow permissions, sandbox validation and human review remain the safer operating model.