Stripe MCP server: payments data and catalogue writes that never move money
Stripe ships an official MCP server at mcp.stripe.com whose generic write tool reaches most of the API, refunds and subscription cancellations included, with Stripe's own confirmation on some of them. This guide covers a Stripe MCP server built the other way round: revenue read exactly, catalogue writes created inactive, and nothing that moves money.
What Stripe's official server gives you
Stripe's MCP server is remote at mcp.stripe.com, authorized with OAuth or an agent API key. Beside documentation search and account tools, stripe_api_read and stripe_api_write call Stripe API methods by name — and the supported write methods include creating refunds, cancelling subscriptions and voiding invoices.
- A person confirms some writes. Stripe asks for human confirmation on certain
stripe_api_writeactions, such as refunds and outbound payments, through a link the agent hands back. - Key authentication is changing. From 31 October 2026 Stripe MCP accepts only agent keys or OAuth; full-access secret keys and untagged restricted keys get a 401.
- Connected accounts are reached with a restricted platform key and the
Stripe-Accountheader, not OAuth.
What a full MCP server adds
| Stripe's official server | Agent Planners MCP | |
|---|---|---|
| Stripe tools | Generic read and write over most of the API | 10 reads, 14 writes |
| Refunds, subscription cancellations, invoices | Reachable, some behind confirmation | Not tools, on any lane |
| Catalogue writes | Yes | Customers, products, prices, coupons, promotion codes and payment links — created inactive |
| Revenue figures | Rows to add up | Aggregated per currency, refunds netted, test mode labelled |
| Ad spend in the same session | No | Google Ads, Meta, Microsoft and TikTok on the same key |
tools/list offers 24 Stripe tools of the 1012 on the endpoint (a key that lists its tools on demand reaches the same ones with search_tools and call_tool).How to configure it
- 1Create a key in API & MCP.
tools:readfor revenue and disputes; addtools:writefor catalogue changes. Tools mode needs a paid plan and fails closed. - 2Connect Stripe under Integrations and authorize on Stripe's own domain. The consent screen names
read_write, the scope Stripe grants a Connect platform — no secret key is pasted anywhere. - 3Add the server to Claude Code, Claude Desktop or Codex with the snippet below.
- 4Run
describe_permissions, thenlist_accountsfor the Stripe account id; a test-mode account is labelled TEST.
claude mcp add --transport http agentplanners https://www.agentplanners.com/api/mcp \
--header "Authorization: Bearer ap_live_…"~/.codex/config.toml, with the key in an environment variable rather than the file: [mcp_servers.agentplanners] / url = "…/api/mcp" / bearer_token_env_var = "AGENTPLANNERS_API_KEY".What waits for a person, and what is not built
Every create is inactive: a product is created archived, a price and a promotion code inactive, and a payment link deactivated in the same call. The moment something becomes purchasable or redeemable is always a person's decision.
- Activating a product, price, promotion code or payment link — held in the approval queue for a person on every key mode, never inside a bulk approval.
- Deleting a customer or a coupon — permanent; a customer delete is refused while any subscription that is not canceled, or a non-zero balance, remains.
- Not built at all: charges, payment intents, refunds, payouts, transfers, subscriptions, invoices, balances, disputes and account settings. A call that asks for one is answered with the reason, not "unknown tool".
No raw_request tool — the typed gateway instead
There is no stripe__raw_request. stripe__get is itself an allowlist of Stripe list resources, read with the connection's own token; a raw passthrough would remove that fence for external keys while in-app agents keep it.
The minor-unit trap, and two more
- Stripe amounts are minor units. 1999 is 19.99 in a two-decimal currency and 1999 yen in JPY. Read raw rows with that in mind;
stripe__revenue_summaryconverts with the currency named. - Currencies are never summed. A EUR balance plus a JPY balance is not an amount of money, so every figure here is per currency.
- UTM codes reach the landing page only through a redirect. A payment link hands them to its redirect URL only when it redirects after purchase —
stripe__get_payment_link_urlsays whether yours does.
Use cases
- Reported ROAS against settled revenue — each platform's conversion value beside the charges that succeeded in the same window, refunds netted out.
- Dispute and refund rates by currency — the numbers that make a campaign's return look better than it is.
- Churn already decided — subscriptions still active but set to cancel.
- Anything unusual in payments? —
stripe__detect_anomaliesjudges settled revenue, charge counts, declines and disputes per UTC day against a weekday-aware baseline, in one settlement currency, with the same walk and words as a Stripe alert rule. - A buy page for an ad — a product, price and payment link prepared inactive, with UTM codes, for a person to switch on.
Frequently asked questions
- Is there an official Stripe MCP server?
- Yes. Stripe hosts one at mcp.stripe.com with OAuth or agent-key authentication. Its generic stripe_api_write tool reaches most write methods, refunds and subscription cancellations included, with Stripe asking a person to confirm some of them. Checked September 2026.
- Can this Stripe MCP server issue a refund?
- No. Refunds, charges, payouts, transfers, subscriptions and invoices are not tools here on any lane, whatever the connection's scope; moving money stays a human action in your Stripe Dashboard.
- Why is my Stripe revenue a hundred times too high?
- Almost always minor units: Stripe returns 1999 for 19.99 in a two-decimal currency. stripe__revenue_summary converts per currency; raw rows from stripe__get do not.
- Do I paste a Stripe secret key?
- No. The connection runs over Stripe Connect OAuth on Stripe's own domain, and you can revoke it from your Stripe Dashboard without rotating a key the rest of your stack depends on.