Stripe
Read the Stripe account on the workspace's shared Connector, and run only the API writes an explicit user request allows.
Official endpoint: https://mcp.stripe.com
Product docs: Stripe MCP
This is an independently authored Agent Plugins 1.0 package. It does not copy Stripe's plugin skills, an OpenAI .mcp.json, .app.json, or an API key. plugin.json declares workspace Connector OAuth for the stripe server. mcp.json uses portable streamable-http. See upstream notes.
Installing the package does not authorize Stripe. A workspace administrator authorizes one shared Connector connection; other members use that shared identity and should contact an administrator if it is missing. Tool calls run as the authorizing account, not as each chat user.
This package uses Connector OAuth. It does not store an agent API key or a secret key.
Connector setup
Checked on 2026-10-10, without a user token:
- Unauthenticated
initializereturned 401.WWW-Authenticatenamed protected-resource metadatahttps://mcp.stripe.com/.well-known/oauth-protected-resource. - That document's
resourceishttps://mcp.stripe.com, which matches the MCP URL. Its authorization server ishttps://access.stripe.com/mcp.scopes_supportedismcp. - Authorization-server metadata at
https://access.stripe.com/.well-known/oauth-authorization-server/mcpnames issuerhttps://access.stripe.com/mcp, authorizehttps://access.stripe.com/mcp/oauth2/authorize, tokenhttps://access.stripe.com/mcp/oauth2/token, and registrationhttps://access.stripe.com/mcp/oauth2/register. PKCES256is advertised. The only token endpoint auth method isnone.grant_types_supportedincludesauthorization_codeandrefresh_token.scopes_supportedismcp. - Minimum OAuth scope:
mcp. That is the only scope advertised by the protected-resource metadata and the authorization-server metadata. - Write tools require an explicit user request and host approval. Stripe also documents its own confirmation step for some
stripe_api_writeactions.
The redirect URI must be the Xpert Connector callback. This package does not invent that URI. Connected-account calls that need a restricted API key and a Stripe-Account header are outside this OAuth package.
Icon
The icon is the public favicon https://stripe.com/favicon.ico. The Codex Stripe manifest at commit 1dc195897af4161d039b80d8471ec0a10c9bbc89 does not declare a license, so its assets/logo.png and skills are not copied.
Skill
stripe-workspace names tools from the Stripe MCP docs checked on 2026-10-10. Live schemas win. An authenticated tools/list was not available while writing this package.
Usability test
Without a completed Stripe OAuth grant, tool calls against a real account cannot be verified. Do not write an API key, client id, client secret, or token into the repository or the chat.
- Pack:
corepack pnpm quickstart --pack --output-dir /tmp/xpert-agent-plugins stripe - Publish the ZIP, or install with platform parameters already configured:
corepack pnpm quickstart --install --platform-root "$XPERT_PLATFORM_ROOT" --api-url "$XPERT_API_URL" --org-id "$XPERT_ORG_ID" --workspace-id "$XPERT_WORKSPACE_ID" stripe - An administrator completes Connector OAuth with the callback URL shown on the form. Request the discovered scope
mcp. Prefer a Stripe sandbox for the first connection. - A workspace administrator authorizes one shared Connector connection from workspace Connector settings. Other members use that shared identity and should contact an administrator if it is missing. Prefer a Stripe sandbox for the first connection.
- After authorization, ask for the live tool names. Use only names present in that schema.
- Read-only smoke: when listed, call
get_stripe_account_infoorstripe_api_readfor a list the tester names. Do not callstripe_api_write. - Skill smoke: ask to summarize products or customers the authorizing account can already see. If tools are unavailable, an administrator authorizes the shared Connector; other members contact an administrator.
- Without credentials, or without an explicit user request and host approval, do not verify refunds, subscription changes, or Treasury money movement.
Verification
Checked on 2026-10-10. corepack pnpm test in agent-plugins covers the manifest, Connector declaration, and ZIP allowlist. Live Stripe consent was not run. On 2026-10-10, corepack pnpm test:lifecycle --platform-root "$XPERT_PLATFORM_ROOT" passed with XPERT_PLATFORM_ROOT set to the host checkout containing packages/server-ai/src/agent-plugin/agent-plugin-parser.ts (Node v22.14.0, pnpm 10.24.0). This package's result was PASS stripe: distributed ZIP, production parser, digest, Skills and MCP binding.