Setting up the Stripe MCP Server
Connect the Stripe MCP Server via an agent plug-in or manually with OAuth, and deliberately safeguard tool calls.
- Skill Road
- Setting up the Stripe MCP Server
Published on 09.09.2026
The Stripe MCP Server runs exclusively as a hosted remote service at mcp.stripe.com. Stripe offers an automated setup path via a plug-in as well as manual configuration for clients without plug-in support.
Recommended: setup via agent plug-in
Install the Stripe CLI and run the setup assistant:
npm install -g @stripe/cli@latest
stripe agent setup
The command automatically detects which supported agent is installed locally, configures the MCP server accordingly, and installs the associated skills. Stripe then handles updates automatically without manual configuration changes.
Manual setup
If your MCP client doesn't support plug-ins, you can also register the server by hand. In Claude Code:
claude mcp add --transport http stripe https://mcp.stripe.com
In Cursor via ~/.cursor/mcp.json:
{
"mcpServers": {
"stripe": { "url": "https://mcp.stripe.com" }
}
}
On the first call, the client opens Stripe's OAuth consent page. Confirm access for your own Stripe account there.
Managing access and sessions
Authorized clients appear in the Stripe Dashboard under user settings as OAuth sessions and can be individually revoked there. Administrators can additionally control MCP access centrally in the Dashboard — separately for live mode and sandbox environments.
Safeguarding tool calls
The server exposes both read and write API tools (stripe_api_read, stripe_api_write) that can change real payment and customer data. Stripe explicitly recommends enabling human confirmation for tool calls and watching for prompt injection attempts when using multiple MCP servers at once — for example via manipulated content from searched documents. For automated workflows, a restricted API key instead of full OAuth account access is recommended where possible.
Verifying the setup
After connecting, test with a harmless, read-only task, such as "Show me my Stripe account information" or "Search Stripe documentation for webhooks." Only allow write actions once this works reliably.
Common setup issues
If the OAuth consent page doesn't open automatically, check whether the client is blocking pop-ups or whether the URL needs to be copied manually from the console output. If plug-in setup fails with a Stripe CLI error, check stripe --version first to confirm the installation completed fully.
A quick reinstall of the CLI usually resolves version-mismatch errors faster than trying to patch an existing broken installation.
For marketplaces and connected accounts
Anyone working on behalf of connected accounts via Stripe Connect should use a restricted API key for that specific connected account rather than their own platform credentials for the agent. That keeps access scoped exactly to the account the agent should actually work on, instead of accidentally reaching the entire platform.
Following the principle of least privilege here also makes it much easier to audit later which agent actions touched which merchant account, should a review ever be needed.
Source: docs.stripe.com/mcp, checked on 2026-09-06.
Frequently asked questions
Can I self-host the Stripe MCP Server?
No. Stripe exclusively operates the MCP server itself at mcp.stripe.com; there is no open-source server component for running it yourself.
What does the Stripe MCP Server cost?
The server itself does not incur separate costs. A Stripe account is required; Stripe's usual transaction-based fees for payment processing apply independently of the MCP server.
What is the fastest way to set up the server?
Using Stripe's recommended agent plug-in: `npm install -g @stripe/cli@latest` followed by `stripe agent setup`. The command automatically detects the installed agent and configures the server and skills accordingly.
Can the agent trigger payments or change data through the MCP server?
Yes, the stripe_api_write tool can execute write API calls (POST, PATCH, PUT, DELETE). Stripe therefore explicitly recommends enabling human confirmation for tool calls.
How do I revoke a connected client's access?
Open the list of OAuth sessions in the Stripe Dashboard under user settings, select the client, and choose "Revoke access" from the overflow menu. Administrators can additionally manage sessions for other team members.