Skip to main content
Stripe hosts an MCP server at https://mcp.stripe.com that gives AI agents read and write access to the Stripe API, plus search across Stripe’s documentation. Connect it to Spojit to look up customers and payments, create invoices or payment links, or investigate disputes inside a workflow.
Spojit does not curate the tool list; Stripe does. For the live set of tools and their parameters, see Stripe’s MCP documentation.

Two ways to connect

Both routes reach the same https://mcp.stripe.com endpoint and expose the same tools. They differ in how Spojit authenticates.

Before you start

A Stripe account. If your organization manages MCP access, an administrator can allow or block it separately for live mode and sandboxes under MCP and CLI access.

Connect with the Stripe connector

1

Create a restricted API key (recommended)

Sign in to the Stripe Dashboard, open Developers → API keys, and click Create restricted key.Restricted keys let you grant only the permissions your workflows actually need (e.g. Read on Customers, Write on Refunds). Stripe strongly recommends this over your full secret key, since an agent with a full key can do anything in your account, including issuing refunds and creating charges.If you absolutely need full access, you can use a standard secret key (sk_live_... or sk_test_...), but treat it like a password.
2

Add the connection in Spojit

Go to Connections in Spojit, click Add Connection, select Stripe (Official MCP), and paste the key into the Secret Key field.Use a test-mode key (sk_test_... or rk_test_...) while you’re building workflows, then swap to a live-mode key when you’re ready to go to production.

Connect as a custom server

Use this route to sign in with OAuth instead of creating a key. Spojit adds it as a custom MCP server.

Server URL

1

Add a custom server

Go to Connections and click Add custom server. Enter a Name such as Stripe and paste the Server URL.
2

Keep Auto authentication

Leave Authentication on Auto, choose a visibility, and click Save & connect.
3

Approve access in Stripe

Stripe opens its OAuth consent page. Sign in, review the requested access, and authorize. Spojit marks the connection Connected and refreshes the token automatically.

Alternative: a restricted key on a custom server

Stripe also accepts a restricted API key as a bearer token. Choose Token instead of Auto, paste the key (rk_...), keep the header Authorization with prefix Bearer, and click Add. Acting on a Connect platform’s connected accounts needs an extra Stripe-Account header on every call. Custom servers send a single authentication header, so connected accounts aren’t supported this way.

Use it in a workflow

Add a Connector node and pick Stripe (Official MCP), or your Stripe server under Custom Servers, then choose Agent Mode or Direct Mode. See Use a custom server in a workflow.

Things to know

  • This is the full Stripe API. Stripe’s hosted MCP exposes their entire surface, including destructive operations (refunds, subscription cancellation, customer deletion). Pair it with a restricted key whose scopes match what your workflows actually do, and prefer test-mode keys during development.
  • Test and live are separate connections. With a key, the prefix decides the environment (sk_test_ versus sk_live_); there is no environment field on the connection. With OAuth, a session granted for a sandbox does not reach live mode. Either way, create one Spojit connection per environment.
  • The key represents your account. A standard secret key has full Stripe API access; a restricted key has whatever scopes you grant when creating it. Treat both like passwords.
  • Some writes need a human. Stripe requires confirmation before certain write actions, such as refunds and outbound payments. The tool returns a link; a person approves it in Stripe, then the action is retried. Approvals expire after 24 hours.
  • Revoke OAuth access in Stripe. Authorized sessions are listed under OAuth sessions in your user settings. Administrators can revoke other members’ sessions from Team and security.
  • MCP endpoint is hosted by Stripe. Availability, rate limits, and the exact tool surface are determined by Stripe. Outages and breaking changes are upstream.

When to use this vs the Spojit Stripe connector

Spojit also offers a separate, curated Stripe connector with a smaller, opinionated tool set tuned for common workflows. Use the hosted MCP server when:
  • You need access to a Stripe API the curated connector doesn’t expose
  • You want the broadest possible surface for an AI agent to work with
Use the Spojit Stripe connector when you want a tighter, lower-token, opinionated set of tools.

Troubleshooting

An administrator may have turned off MCP access for that environment. Check MCP and CLI access in the Dashboard.
Stripe may be waiting for human confirmation. Open the confirmation link the tool returned, approve it, then run the step again.

Learn more