Skip to content
anavem.com

MCP server

Stripe MCP Server

Official Stripe MCP server for working with supported customers, products, prices, subscriptions, payments and related Stripe resources.

Maintainer
Stripe, Inc.
Licence
MIT for the stripe/ai source repository; Stripe service terms apply to the hosted server
Last release
No standalone GitHub release published; hosted documentation checked 2026-10-04
Last verified Jump to what it can access ↓

Stripe MCP Server connects compatible agents to Stripe APIs and Stripe documentation through a hosted endpoint. Stripe recommends OAuth for interactive clients and Agent API Keys for autonomous clients, with sandbox testing before live access.

Key takeaways

  • The current source lives in the stripe/ai repository.
  • OAuth and Agent API Keys are the current documented authentication paths.
  • Beginning October 31, 2026, Stripe says unsupported full-access or older untagged restricted keys will no longer be accepted by its MCP server.

What is Stripe MCP Server?

Official Stripe MCP server for working with supported customers, products, prices, subscriptions, payments and related Stripe resources. MCP standardizes how a compatible client discovers and invokes tools, but it does not make those tools safe automatically. The client, server, credentials and upstream service remain separate trust boundaries.

What tools does it expose?

  • Search Stripe API methods and retrieve parameter details.
  • Read supported Stripe data through API GET operations.
  • Write supported Stripe data through API POST, PATCH, PUT and DELETE operations.
  • Search Stripe documentation and use supported planning or analytics tools.

The exact catalog can change by release, account, enabled feature or server configuration. Inspect the live tool list and JSON schemas before enabling it. A descriptive tool name is not an authorization control, and a read-sounding operation can still reveal sensitive metadata.

What is a safe first test?

Use Stripe test mode and a restricted key with read access only. Inspect one synthetic customer and product, then revoke the key. Do not enable refunds, cancellations or live-mode access in the first profile.

Use a test account or project, allow only the required tools and record the client configuration, server version and arguments. Verify the result directly in the upstream service. Add write tools only after read-only behavior, authentication expiry, error handling and audit logs have been reviewed.

What data and credentials can it access?

The server can access Stripe account and customer information allowed by OAuth or the Agent API Key. Depending on tools and mode, calls may create financial objects or alter customer billing state.

Credentials should be supplied through the documented OAuth flow, a secret manager or a restricted environment variable, never pasted into prompts or committed to source. The upstream account should expose only the resources required for the pilot.

Which permissions should you grant?

  • A Stripe sandbox only for the pilot.
  • OAuth or an Agent API Key limited to the exact read tools required.
  • Separate explicit approval for every financial write capability.

Prefer project-scoped, read-only or restricted tokens. Where the server offers tool filters, combine them with upstream authorization rather than treating filtering as the only control. Separate development and production identities and rotate test credentials after the evaluation.

What should a security review cover?

  • Never place a Stripe secret key in prompts or committed configuration.
  • Keep live-mode access in a separate audited client profile.
  • Reconcile every write against Stripe’s own event and audit records.

Assume tool results can contain prompt injection or hostile content. Keep approval gates in application code for financial, administrative, destructive or public actions. Apply network restrictions, timeouts, output-size limits and audit logging at the host or gateway layer.

What are the main limitations?

  • Supported API methods and preview tools can change.
  • Financial workflows carry regulatory and customer-impact risk.
  • OAuth sessions and Agent API Keys have different revocation paths.

This is a documentation-based profile checked on 2026-10-04; Anavem did not connect the server or test it against a live account. Tool catalogs, transport support, pricing, licensing and authentication methods can change. Verify the current first-party documentation before installation.

What it can access

An MCP server gives an AI application a set of capabilities, and it can do only what its code and the credentials you give it allow. This is what the listing states, based on the sources below. Anavem does not rate it safe or unsafe: check it against what you plan to use it for.

Permissions it asks for

  • A Stripe sandbox only for the pilot.
  • OAuth or an Agent API Key limited to the exact read tools required.
  • Separate explicit approval for every financial write capability.

Data it can reach

The server can access Stripe account and customer information allowed by OAuth or the Agent API Key. Depending on tools and mode, calls may create financial objects or alter customer billing state.

How it is installed or connected

Follow the current Stripe MCP setup page: use the recommended Stripe agent plugin flow or connect https://mcp.stripe.com directly, then authenticate with OAuth or a sandbox-scoped Agent API Key.

After connecting, enumerate the tools from the MCP client and disable everything outside the pilot. Test with non-production data, confirm how credentials are stored, and keep a documented removal or revocation procedure.

Limitations

  • Supported API methods and preview tools can change.
  • Financial workflows carry regulatory and customer-impact risk.
  • OAuth sessions and Agent API Keys have different revocation paths.
  • Anavem reviewed public documentation but did not connect, authorize or benchmark this server.

Not sure what to look for? Read what to check before installing.

Quick answers

Who maintains this MCP server?
Stripe, Inc.
What can it access?
It asks for: A Stripe sandbox only for the pilot., OAuth or an Agent API Key limited to the exact read tools required., Separate explicit approval for every financial write capability.. The server can access Stripe account and customer information allowed by OAuth or the Agent API Key. Depending on tools and mode, calls may create financial objects or alter customer billing state. We do not label anything safe or unsafe; read the official sources before you install.
What licence does it use?
MIT for the stripe/ai source repository; Stripe service terms apply to the hosted server. Check the terms if you plan to use it commercially.
What are its limitations?
Supported API methods and preview tools can change. Financial workflows carry regulatory and customer-impact risk. OAuth sessions and Agent API Keys have different revocation paths. Anavem reviewed public documentation but did not connect, authorize or benchmark this server.
When was it last released?
No standalone GitHub release published; hosted documentation checked 2026-10-04. Verified Oct 4, 2026.

Sources

Other listings in the same category.

All MCP servers →

AI tools in AI Coding & App Builders

Verified tool profiles in the same category.

See category →