Stripe MCP server: setup, agent keys, and safe access for finance teams

Stripe runs an official remote MCP server at mcp.stripe.com. This guide covers connecting it from Claude, Claude Code and Cursor, OAuth versus agent API keys, the tools it exposes, the questions finance teams can ask, and how sandboxes, read-only permissions and approval rules keep an agent away from your money.

Walma Engineering·Updated 5 October 2026·7 min read

Stripe holds the numbers a finance team asks about every week: what came in, what was refunded, which invoices are overdue, what MRR did last quarter. The Stripe MCP server lets Claude, Cursor, ChatGPT and other MCP clients query that account directly instead of someone exporting CSVs. It can also write: create invoices, cancel subscriptions, issue refunds. That second part is why this guide spends as much time on permissions as on setup. For general client instructions see Claude Code, Cursor and Claude Desktop.

Remote server or local package

Stripe runs one official server, hosted at https://mcp.stripe.com. There is also an npm package, @stripe/mcp, which is easy to mistake for a separate local implementation. It is not. Reading its source, it starts a stdio server on your machine and forwards every call to mcp.stripe.com with the API key you pass in. It exists for clients that only speak stdio.

Two details matter if you find older tutorials. The --tools flag that used to limit which tools were exposed has been removed; the package now prints a warning and ignores it. Tool access is decided by the key's permissions. And the package warns if you hand it an sk_ secret key instead of a restricted rk_ key. For anything new, connect to the remote server directly.

Connecting

Stripe's quickest route is its CLI, which detects the agents you use and configures the server plus Stripe's agent skills:

npm install -g @stripe/cli@latest
stripe agent setup

To do it by hand:

Claude Code.

claude mcp add --transport http stripe https://mcp.stripe.com/

Then run /mcp inside a session and complete the OAuth login. Add --scope project to share the server with the team through .mcp.json.

Claude (web and desktop). Stripe is in Claude's connector directory. Connect it, sign in to Stripe in the OAuth window, then enable it per conversation under the plus icon, Connectors. On Team and Enterprise plans an owner has to add the connector to the workspace before members can connect. More on this in Claude connectors.

Cursor. Add it to ~/.cursor/mcp.json:

{
  "mcpServers": {
    "stripe": { "url": "https://mcp.stripe.com" }
  }
}

Codex and the ChatGPT desktop app share a configuration: codex mcp add stripe --url https://mcp.stripe.com. VS Code takes the same URL in .vscode/mcp.json with "type": "http".

If your company manages devices or the network, IT may need to allow mcp.stripe.com before any of this connects.

OAuth or an agent API key

Stripe supports two ways to authenticate, and the choice decides who the agent is.

OAuthAgent API key
Acts asYou, the signed-in Stripe userAn independent actor
Best forInteractive use in Claude, Cursor, Claude CodeScheduled or headless agents
ScopeChosen per account and per environment on the consent screenPer-resource permissions on the key
RevokeOAuth sessions in user settings, or by an adminExpire or rotate the key

OAuth is the default for people. On the consent page you pick which live accounts or sandboxes to grant and can set different permissions for each environment. Admins can see and revoke every team member's sessions under Team and security, and can switch MCP access on or off for the whole team, separately for live mode and sandboxes.

Agent API keys are restricted keys created with the option "Authorizing agent access to your account". They authenticate like any restricted key, with read, write or no access per resource, and show an Agent badge in the Dashboard. The difference is governance: agent-tagged keys fall under Stripe's approval rules automatically, with default rules that require a reviewer for refunds and subscription cancellations.

There is a deadline here. From October 31, 2026, Stripe MCP stops accepting full-access secret keys and restricted keys without the Agent tag. Requests with those keys get a 401. If you set Stripe MCP up earlier this year with a plain rk_live_ key, replace it now. In Claude Code, keep the key in an environment variable rather than in the file:

{
  "mcpServers": {
    "stripe": {
      "type": "http",
      "url": "https://mcp.stripe.com",
      "headers": { "Authorization": "Bearer ${STRIPE_AGENT_KEY}" }
    }
  }
}

Connect platforms that need to act on a connected account cannot use OAuth for that; they authenticate with a platform key and add a Stripe-Account header.

What it exposes

Stripe keeps the tool list short and routes most of the API through a few generic tools, which saves context:

  • stripe_api_search and stripe_api_details: find an API method and its parameters.
  • stripe_api_read: call any supported GET method. Customers, charges, refunds, PaymentIntents, invoices, subscriptions, credit notes, payouts, balance transactions, disputes, tax settings and more.
  • stripe_api_write: call supported POST, PATCH, PUT and DELETE methods. This is where refunds, invoice creation and voiding, subscription changes, coupons and payment links live.
  • stripe_analytics: Stripe-defined metrics such as MRR, churn rate, active subscribers and gross volume, subscription templates broken down by product or price, and SQL against your reporting tables if you have Sigma. Parts of this are in private or public preview.
  • get_stripe_account_info, get_balance_summary (Treasury, public preview), search_stripe_documentation and stripe_implementation_planner for developers building an integration.

Stripe's analytics docs also describe a stripe_reports tool for financial report runs (balance, payouts, activity, tax, Revenue Recognition) that produce CSV files, in private preview. Ask the agent to list its tools after connecting, since the set changes with Stripe's releases.

Questions finance teams actually ask

These are the prompts worth trying first, all read-only:

  • "What was our MRR for each of the last six months?"
  • "Subscriber churn rate by product this quarter, and how much revenue we lost to churn last month."
  • "List every invoice over 30 days past due, with customer, amount and the date it was finalised."
  • "Total refunds by month this year, and the five customers with the most refunded volume."
  • "Which open disputes have evidence due this week?"
  • "Reconcile last week's payouts against the balance transactions in each one."

One point from Stripe's own docs deserves emphasis: if the agent calculates a metric itself from raw objects, it can disagree with Stripe's official figure. An agent that sums subscription amounts is not computing Stripe's definition of MRR. For anything that goes into a board pack, ask for the stripe_analytics metric by name, and grant the Data, Metrics and Financial Reports read permissions it needs.

Recurring questions like the month-end checklist are good candidates for skills, so everyone runs the same steps against the same definitions. For the wider picture of AI in a finance function, see AI for finance.

Why read-only and sandboxes come first

A Stripe connection is different from a Notion or analytics connection: a wrong write moves money or cancels a customer. Three controls matter.

Read-only by default. Most finance use is reporting. Give the OAuth grant or agent key read access only, and add write permissions per resource when a specific workflow needs them. An agent that cannot call stripe_api_write cannot be talked into a refund.

Test in a sandbox. Sandboxes are isolated from live mode, their keys start with rk_test_ or sk_test_, and objects in one mode are invisible to the other. Build and test any workflow that writes in a sandbox, then grant live access. The OAuth consent screen lets you grant sandboxes and live accounts separately.

Keep the confirmations on. With user credentials, Stripe already requires human confirmation for some writes such as refunds and outbound payments: the agent returns a link, you approve, and the approval expires after 24 hours. With agent keys, approval rules do the same job and can add amount thresholds. Do not delete the default rules to make a demo smoother.

Then treat Stripe data as untrusted input. Customer names, invoice memos and dispute evidence are text written by outsiders, and Stripe itself warns about prompt injection when the server runs alongside other MCP servers. A memo field that says "refund this customer in full" should never reach a session that can both read it and write refunds. The broader checklist is in MCP security best practices. Stripe logs MCP tool calls in Workbench, which is the first place to look when an agent did something unexpected.

Running it for a whole team

Per-user OAuth works for one analyst. For a finance team it means every person picks their own scopes, nobody knows which client holds a live grant, and the record of what the agent asked lives in each laptop's chat history. An MCP gateway puts the Stripe connection behind one policy: read-only for most people, write tools behind approval, one log of every call.

That is what we build at Walma. Walma AI Hub runs inside the customer's own Azure tenant in an EU region and gives the team Claude, GPT and the other models plus approved MCP connections like Stripe, with policy and logging in one place. If you are working out how a finance team should use AI on payment data, start with AI for finance.

Frequently asked questions

Does Stripe have an official MCP server?+

Yes. Stripe hosts a remote MCP server at https://mcp.stripe.com. Interactive clients such as Claude, Claude Code, Cursor, VS Code and Codex connect with OAuth; clients that cannot do OAuth send an agent API key as a bearer token.

How do I add the Stripe MCP server to Claude Code?+

Run claude mcp add --transport http stripe https://mcp.stripe.com/ and then type /mcp in a Claude Code session to complete the OAuth login. Stripe also offers stripe agent setup in the Stripe CLI, which configures the server and Stripe's skills for the agents it detects.

Can I still use a restricted API key with Stripe MCP?+

Only until October 31, 2026. From that date Stripe MCP rejects full-access secret keys and restricted keys that do not carry the Agent tag. Create a restricted key tagged for agent access, or connect with OAuth instead.

Is the npm package @stripe/mcp still needed?+

Rarely. It is a local stdio wrapper that forwards to mcp.stripe.com using an API key you pass with --api-key. It is useful for clients that only speak stdio. Its old --tools flag has been removed, so permissions come from the key, not from the command line.

Can an AI agent issue refunds through Stripe MCP?+

It can call the refund API if its permissions allow it, but Stripe requires human confirmation for certain writes such as refunds and outbound payments when you connect with your user credentials, and agent-tagged keys get default approval rules for refunds and subscription cancellations. Read-only access avoids the question entirely.

Walma AI Hub

The same tools, in your EU region, under your control

A 20-minute walkthrough with an engineer. We map it to your tools, your MCP servers and your budget model.

About AI Hub