Setting up the PayPal MCP Server
Connect the PayPal MCP Server locally via npx or as a hosted remote server via OAuth, and deliberately safeguard write access.
- Skill Road
- Setting up the PayPal MCP Server
Published on 23.09.2026
The PayPal MCP Server can be run in two ways: as a locally started process with your own access token, or as a hosted remote server where the client connects via OAuth using your own PayPal account.
Local setup
Local operation only needs Node.js version 18 or later and a PayPal access token from the PayPal Developer Dashboard. The configuration in your MCP client looks like this:
{
"mcpServers": {
"paypal": {
"command": "npx",
"args": ["-y", "@paypal/mcp", "--tools=all"],
"env": {
"PAYPAL_ACCESS_TOKEN": "YOUR_PAYPAL_ACCESS_TOKEN",
"PAYPAL_ENVIRONMENT": "SANDBOX"
}
}
}
}
For initial testing, PAYPAL_ENVIRONMENT should be set to SANDBOX and the token should come from a PayPal developer account, so no real payments are triggered.
Hosted remote server
If you don't want to run a local process, connect instead through PayPal's hosted server. For the sandbox environment:
{
"mcpServers": {
"paypal-mcp-server": {
"command": "npx",
"args": ["mcp-remote", "https://mcp.sandbox.paypal.com/http"]
}
}
}
For production, replace mcp.sandbox.paypal.com with mcp.paypal.com. Instead of Streamable HTTP (/http), the SSE endpoint (/sse) can also be used if your client prefers that.
OAuth sign-in
On the first connection to the remote server, the PayPal login page opens. After signing in with your own PayPal account and confirming the requested permissions, the MCP client needs to be restarted for the connection to become active.
Moving from sandbox to production
Switching from the test to the production environment requires a regular PayPal business account instead of a developer account, plus real credentials. It's a good idea to only make this switch once every tool you need has been reliably tested in the sandbox.
Safeguarding write access
Alongside read tools, the server also provides write tools, for example to send invoices or issue refunds. Where the MCP client you're using supports it, human confirmation should be enabled for such actions to avoid accidental business actions or ones triggered by manipulated input.
Common setup issues
If the connection to the remote server stays inactive after OAuth sign-in, per the provider, clearing the local authentication cache with rm -rf ~/.mcp-auth and reconnecting helps. For the local variant, it's worth first checking node --version to confirm that at least version 18 is installed.
Source: developer.paypal.com/ai-tools/mcp-server, checked on 2026-09-23.
Frequently asked questions
Do I need a business account for the PayPal MCP Server?
For initial testing, a PayPal developer account with sandbox credentials is enough. Production use with real payments requires a regular PayPal business account.
Do I have to host the server myself?
No. Besides the local installation via npx, PayPal also offers a self-hosted remote server at mcp.paypal.com that connects via OAuth using your own account.
What does the PayPal MCP Server cost?
The server itself does not incur separate costs. A PayPal account is required; PayPal's usual transaction-based fees for payment processing apply independently of the MCP server.
Can the agent trigger payments or refunds through the server?
Yes, the tool set includes write actions such as capturing payments and issuing refunds. For production use, human confirmation of such actions in the MCP client is therefore recommended.
How does the local server differ from the hosted one?
The local server runs as its own process with a directly configured access token, while the hosted server runs on PayPal infrastructure and uses OAuth sign-in instead of a fixed token.