MCP

Stripe MCP server: payments data and catalogue writes that never move money

TL;DR

Stripe ships an official MCP server at mcp.stripe.com whose generic write tool reaches most of the API, refunds and subscription cancellations included, with Stripe's own confirmation on some of them. This guide covers a Stripe MCP server built the other way round: revenue read exactly, catalogue writes created inactive, and nothing that moves money.

What Stripe's official server gives you

Stripe's MCP server is remote at mcp.stripe.com, authorized with OAuth or an agent API key. Beside documentation search and account tools, stripe_api_read and stripe_api_write call Stripe API methods by name — and the supported write methods include creating refunds, cancelling subscriptions and voiding invoices.

  • A person confirms some writes. Stripe asks for human confirmation on certain stripe_api_write actions, such as refunds and outbound payments, through a link the agent hands back.
  • Key authentication is changing. From 31 October 2026 Stripe MCP accepts only agent keys or OAuth; full-access secret keys and untagged restricted keys get a 401.
  • Connected accounts are reached with a restricted platform key and the Stripe-Account header, not OAuth.
Stripe's server is the right tool for building a Stripe integration or running one account from chat. The rest of this page is about Stripe as the ground truth for what ads earned, read by an agent that should not be able to issue a refund.

What a full MCP server adds

Stripe's official serverAgent Planners MCP
Stripe toolsGeneric read and write over most of the API10 reads, 14 writes
Refunds, subscription cancellations, invoicesReachable, some behind confirmationNot tools, on any lane
Catalogue writesYesCustomers, products, prices, coupons, promotion codes and payment links — created inactive
Revenue figuresRows to add upAggregated per currency, refunds netted, test mode labelled
Ad spend in the same sessionNoGoogle Ads, Meta, Microsoft and TikTok on the same key
Counted from the tool registry, which the MCP catalogue matches one for one: tools/list offers 24 Stripe tools of the 1012 on the endpoint (a key that lists its tools on demand reaches the same ones with search_tools and call_tool).

How to configure it

  1. 1Create a key in API & MCP. tools:read for revenue and disputes; add tools:write for catalogue changes. Tools mode needs a paid plan and fails closed.
  2. 2Connect Stripe under Integrations and authorize on Stripe's own domain. The consent screen names read_write, the scope Stripe grants a Connect platform — no secret key is pasted anywhere.
  3. 3Add the server to Claude Code, Claude Desktop or Codex with the snippet below.
  4. 4Run describe_permissions, then list_accounts for the Stripe account id; a test-mode account is labelled TEST.
bash
claude mcp add --transport http agentplanners https://www.agentplanners.com/api/mcp \
  --header "Authorization: Bearer ap_live_…"
Codex uses the same endpoint from ~/.codex/config.toml, with the key in an environment variable rather than the file: [mcp_servers.agentplanners] / url = "…/api/mcp" / bearer_token_env_var = "AGENTPLANNERS_API_KEY".

What waits for a person, and what is not built

Every create is inactive: a product is created archived, a price and a promotion code inactive, and a payment link deactivated in the same call. The moment something becomes purchasable or redeemable is always a person's decision.

  • Activating a product, price, promotion code or payment link — held in the approval queue for a person on every key mode, never inside a bulk approval.
  • Deleting a customer or a coupon — permanent; a customer delete is refused while any subscription that is not canceled, or a non-zero balance, remains.
  • Not built at all: charges, payment intents, refunds, payouts, transfers, subscriptions, invoices, balances, disputes and account settings. A call that asks for one is answered with the reason, not "unknown tool".
Money arguments are major units — 19.99 means 19.99 — converted once with the currency's own decimals and capped per call.

No raw_request tool — the typed gateway instead

There is no stripe__raw_request. stripe__get is itself an allowlist of Stripe list resources, read with the connection's own token; a raw passthrough would remove that fence for external keys while in-app agents keep it.

The minor-unit trap, and two more

  • Stripe amounts are minor units. 1999 is 19.99 in a two-decimal currency and 1999 yen in JPY. Read raw rows with that in mind; stripe__revenue_summary converts with the currency named.
  • Currencies are never summed. A EUR balance plus a JPY balance is not an amount of money, so every figure here is per currency.
  • UTM codes reach the landing page only through a redirect. A payment link hands them to its redirect URL only when it redirects after purchase — stripe__get_payment_link_url says whether yours does.
Test mode is labelled TEST in the account list and in every result, because test revenue that reads like live revenue is the worst thing a payments connector can produce.

Use cases

  • Reported ROAS against settled revenue — each platform's conversion value beside the charges that succeeded in the same window, refunds netted out.
  • Dispute and refund rates by currency — the numbers that make a campaign's return look better than it is.
  • Churn already decided — subscriptions still active but set to cancel.
  • Anything unusual in payments? — stripe__detect_anomalies judges settled revenue, charge counts, declines and disputes per UTC day against a weekday-aware baseline, in one settlement currency, with the same walk and words as a Stripe alert rule.
  • A buy page for an ad — a product, price and payment link prepared inactive, with UTM codes, for a person to switch on.

Frequently asked questions

Is there an official Stripe MCP server?
Yes. Stripe hosts one at mcp.stripe.com with OAuth or agent-key authentication. Its generic stripe_api_write tool reaches most write methods, refunds and subscription cancellations included, with Stripe asking a person to confirm some of them. Checked September 2026.
Can this Stripe MCP server issue a refund?
No. Refunds, charges, payouts, transfers, subscriptions and invoices are not tools here on any lane, whatever the connection's scope; moving money stays a human action in your Stripe Dashboard.
Why is my Stripe revenue a hundred times too high?
Almost always minor units: Stripe returns 1999 for 19.99 in a two-decimal currency. stripe__revenue_summary converts per currency; raw rows from stripe__get do not.
Do I paste a Stripe secret key?
No. The connection runs over Stripe Connect OAuth on Stripe's own domain, and you can revoke it from your Stripe Dashboard without rotating a key the rest of your stack depends on.
Put a human-approved agent on your ad ops

Start free — 2,500 credits a month, no credit card. Reads are free; every write waits for you.

Related reading