Stripe Agent Toolkit MCP Server

mcp.stripe.com · Agent-Commerce Infrastructure modeIntegrated

Last probed 2026-10-07 04:17 UTC · Provisional

Stripe Agent Toolkit MCP Server — Official remote MCP server exposing Stripe payments/billing tools to agents.

75 / 100triageInterrupt Score(range 44–94 · 9 properties unassessed)How much automated use this service interrupts — the badge-driving metric. Unassessed properties are provisionally scored at 50%; evidence-graded successes at 25%.
Custody / RiskUnknown
ConfidenceProvisional

Verdict: Partially — an AI agent can use Stripe Agent Toolkit MCP Server, but activate is blocked — Signup page loads a CAPTCHA widget — automated signup may be blocked (unverified).

  1. DiscoverIncomplete
  2. ActivateBlocked
  3. OperateIncompletegated by Activate
  4. ManageNot yet probedgated by Activate

Capability parity

Each stage answers one question about what an agent can do unattended. Stages are ordered by the credential-gateway dependency: Activate issues the keys that unlock Operate and Manage. A row marked “Not yet probed” means no probe has tried that capability yet — a different ledger from the “unassessed” properties under Findings, where no probe tier capable of catching that interrupt has run.

Discover

Can an agent find and read it, no account?

Incomplete

Assessment incomplete - not yet probed: Read pricing & limits without login.

  • Be found by a retrieval agentEasy

    Retrieval access present.

    Evidence
    Path tried
    robots.txt / sitemap / discovery headers
    Where it stalled
    completed
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
    Backing checks
    retrieval_bot_access, sitemap_xml, link_header_discovery
  • Read what it does and how to use itEasy

    Machine-readable docs present.

    Evidence
    Path tried
    llms.txt / AGENTS.md / schema.org / docs
    Where it stalled
    completed
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
    Backing checks
    llms_txt, markdown_content, content_signals
  • Read pricing & limits without loginNot yet probed

    Public pricing was not confirmed - the page was absent, gated, or unreadable.

Activate

Can an agent sign up and walk away with the keys it needs?

Blocked

Assessment incomplete - not yet probed: Obtain an API / MCP access credential; Obtain a management / admin key.

  • Create an account self-serveBlocked

    Signup page loads a CAPTCHA widget — automated signup may be blocked (unverified).

    CAPTCHA / bot-challenge blocks this.

    Evidence
    Path tried
    signup flow
    Where it stalled
    verification step
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
    • CAPTCHA / bot-challengeSignupSignup page loads a recaptcha CAPTCHA widget (matched: iframe[src*="recaptcha"]); widget presence does not prove automation is challenged — unverified.
  • Obtain an API / MCP access credentialNot yet probed

    No self-serve credential signal detected - key issuance not yet probed.

  • Obtain a management / admin keyNot yet probed

    No scoped or administrative key path was confirmed after activation.

  • Accept the terms without a bot-banEasy

    No bot-prohibition signal found.

    Evidence
    Path tried
    ToS / policy scan
    Where it stalled
    completed
    Evidence tier
    Tier 0 (passive scan)
    Verification
    Evidence-only — graded from passive signal, not live-verified.

Operate

Can an agent do the service's actual jobs — call, transact, pay?

Incomplete

Assessment incomplete - not yet probed: Pay via an agent rail (x402 / ACP / AP2).

Gated by Activate — the credential this stage needs isn't issued unattended, so these rows may be unreachable even where they read Easy.

  • Call the primary service over MCP / APIEasy

    Machine interface present — evidence-only, not live-verified.

    Gated by Activate — the credential this needs isn't issued unattended.

    Evidence
    Path tried
    API / MCP / browser
    Where it stalled
    completed
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
    Backing checks
    webmcp
  • Complete a transaction / checkoutNot applicable

    Integrated tool — the API call is the transaction, no separate checkout.

    Gated by Activate — the credential this needs isn't issued unattended.

  • Pay via an agent rail (x402 / ACP / AP2)Not yet probed

    No agent-payment metadata detected - payment rails not yet probed.

    Gated by Activate — the credential this needs isn't issued unattended.

Manage

Can an agent administer the account and provision resources?

Not yet probed

No probe has attempted this stage yet: Provision / scale / tear down a service; Change account details / set budget / rotate keys; View usage & billing; Cancel / export / delete (offboard).

Gated by Activate — the credential this stage needs isn't issued unattended, so these rows may be unreachable even where they read Easy.

  • Provision / scale / tear down a serviceNot yet probed

    Not probed - provisioning is not part of the probe suite yet.

    Gated by Activate — the credential this needs isn't issued unattended.

  • Change account details / set budget / rotate keysNot yet probed

    Not probed - account admin is not part of the probe suite yet.

    Gated by Activate — the credential this needs isn't issued unattended.

  • View usage & billingNot yet probed

    Authenticated usage and billing access was not confirmed.

    Gated by Activate — the credential this needs isn't issued unattended.

  • Cancel / export / delete (offboard)Not yet probed

    No self-serve cancellation, export, or deletion path was confirmed.

    Gated by Activate — the credential this needs isn't issued unattended.

Interrupt tier: Moderate-Interrupt — derived from 1 finding; interrupt score 75 / 100 — the badge-driving metric. (range 44–94 · 9 unassessed)

Every tool starts at 100. Each interrupt found subtracts a penalty of base weight × timing × hardness × evidence — the multiplier values below come from the same rubric tables the score is computed with. New snapshots also provisionally subtract 50% of the full worst-case tax for each unassessed property and 25% for evidence-graded successes not live-verified by Tier 2.

Property coverage

A check only counts as clean when a probe tier capable of detecting that interrupt actually ran and found nothing. Not tested ≠ clean.

PropertyStageStateEvidenceRequired
CAPTCHA / bot-challengeactivate failedActive finding — itemized in the penalty matrix below. Tier 0 assesses this property.no
SSO-only signup, no API-key issuanceactivate partialSome coverage exists, but the available evidence is incomplete. Tier 1 assesses this property.no
Mandatory phone verification callactivate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Mailed physical code (postal)activate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
“Contact sales” wall (no self-serve path)activate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Manual approval queueactivate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
ToS clause banning automated/bot accessdiscover unassessedTier 0 (passive scan) ran but did not gather enough evidence to claim clean. Tier 0 assesses this property.no
Rate-limit-triggered manual reviewmanage unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
One-time account / payment-method provisioningmanage unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Identity / KYC verificationactivate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Crypto wallet / key-custody setupoperate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Email OTP verificationactivate successNone found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property.no
SMS / phone OTP verificationactivate successNone found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property.no
Mandatory redirect to vendor’s own siteoperate successNone found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property.no
No Machine Interfaceoperate successNone found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property.yes
Interrupt foundBase weight× Timing× Hardness× Evidence= Penalty
Starting score100
CAPTCHA / bot-challengeSignupSignup page loads a recaptcha CAPTCHA widget (matched: iframe[src*="recaptcha"]); widget presence does not prove automation is challenged — unverified.6×1one-time setup×2.5hard×0.8Tier 1 (unauth probe)inferred−6
Total penalty−6
Full unknown tax 213 — capped at 25 (point score uses 50% of the capped value)−213
Evidence-graded tax (successes not live-verified by a Tier 2 probe) 34.4 — capped at 25 (point score uses 25% of the capped value)−34.4
Raw score = 100 − 6 = 94
Point score = 94 − 50% × 25 − 25% × 25 = 75.3 → 75
75

inferred = detected from passive signals, not a directly observed interrupt — penalized at half weight

What would make this Easy

One concrete change per blocker found. These are the diffs between this listing's current parity and an unattended agent path.

How we scored this

Machine-readability checks 47 / 100

Four check groups, equal weight: machine interfaces, browsing efficiency, element discoverability, and discovery/agent access. Each check carries an evidence grade (proven / plausible / emerging) — an honesty label that never weights the score. What these mean →

  • Unauthenticated API error is structured JSONplausibleFound — api.stripe.com/ (HTTP 404)
  • Unauthenticated API returns auth guidance (401/403 or documented)plausibleNot provided
  • API exposes rate-limit headersplausibleNot provided
  • API key obtainable without human interactionplausibleNot checked — API documentation host reachable (https://docs.stripe.com/) — reachability is not evidence of unattended key issuance
  • llms.txtemergingFound — docs.stripe.com/llms.txt (90.1 KB, 511 links)
  • llms-full.txtemergingNot provided
  • AGENTS.mdemergingNot provided
  • A2A agent cardemergingNot provided
  • MCP server (well-known or official registry)plausibleNot provided
  • OpenAPI/Swagger specplausibleNot provided
  • Rate-limit headersplausibleNot provided
  • Structured JSON error responsesplausibleNot provided
  • OAuth authorization-server metadata (RFC 8414)provenNot provided
  • API catalog (RFC 9727) (emerging)emergingNot provided
  • Agent-payment discovery (x402 / UCP) (emerging)emergingNot provided
  • Lean HTML transfer sizeplausibleNot provided
  • Manageable DOM sizeplausible1248 DOM nodes (threshold 1500)
  • High content-to-markup densityplausibleNot provided
  • Content readable without JS executionprovenraw HTML holds 93% of rendered text (8600 vs 9236 chars; threshold 40%)
  • Clean-content alternate (RSS/Atom/feed/markdown)plausibleNot provided
  • Serves markdown on Accept: text/markdownplausiblereturned text/markdown; charset=utf-8
  • Interactive elements are semanticplausibleNot provided
  • Form fields have accessible namesplausible1/1 named (100%)
  • Inputs carry autocomplete hintsplausibleNot provided
  • WebMCP tools (modelContext API)emerging4 tool(s) registered via the modelContext API during page load
  • AI retrieval/search fetchers allowed (robots.txt)provenno retrieval-fetcher blocks in robots.txt
  • Sitemap (indexability)plausibleFound — docs.stripe.com/sitemap.xml
  • schema.org JSON-LD in raw HTMLplausibleNot provided
  • Content-Signal directives (robots.txt)emergingai-train=yes, search=yes, ai-input=yes
  • Web Bot Auth key directory (emerging)emergingNot provided
  • Discovery Link headers on homepage (emerging)emergingrel=service-meta
  • Pricing visible without loginNot provided
  • robots.txt AI-crawler accessplausibleno AI-crawler blocks in robots.txt

Evidence & history

Last probed 2026-10-07 04:17 UTC. The raw JSON is the archival record.

DateScoreBadgeRubric version
2026-10-07 04:17 UTC75Moderate-Interrupt (current)rubric v2026.4
2026-10-07 04:17 UTC75Moderate-Interruptrubric v2026.4
2026-09-07 01:51 UTC69Moderate-Interruptrubric v2026.4
2026-09-07 01:46 UTC69Moderate-Interruptrubric v2026.4
2026-08-09 23:47 UTC69Moderate-Interruptrubric v2026.4
2026-08-09 23:47 UTC53Moderate-Interruptrubric v2026.4
2026-08-09 17:13 UTC51Moderate-Interruptrubric v2026.4
2026-08-09 05:24 UTC58Moderate-Interruptrubric v2026.3
2026-08-09 05:24 UTC58Moderate-Interruptrubric v2026.3
2026-08-09 05:16 UTC58Moderate-Interruptrubric v2026.3
2026-08-09 05:16 UTC58Moderate-Interruptrubric v2026.3
2026-08-09 05:13 UTC58Moderate-Interruptrubric v2026.3
2026-08-09 05:13 UTC88Low-Interruptrubric v2026.3
2026-08-09 03:14 UTC88Low-Interruptrubric v2026.3
2026-08-09 01:48 UTC88Low-Interruptrubric v2026.2
2026-08-09 01:45 UTC88Low-Interruptrubric v2026.2
2026-07-10 07:16 UTC100Low-Interruptrubric v2026.1

Alternatives in Agent-Commerce Infrastructure

Other Agent-Commerce Infrastructure tools in the same mode (integrated), ranked by Overall LLM-Friendliness (the mean of Interrupt Score and Machine-Readability) — comparable to this listing because they share its usage mode.

Embed this rating

Copy this snippet to display your Interrupt Index seal on your site — the seal image and link stay in sync with your latest probe automatically. Pick the variant that matches your site’s theme.

Light (default)

<a href="https://interruptindex.com/tools/stripe-agent-toolkit-mcp-server"><img src="https://interruptindex.com/badge/stripe-agent-toolkit-mcp-server.svg" alt="Stripe Agent Toolkit MCP Server — Interrupt Index agent-readiness rating" height="64"></a>

Dark

<a href="https://interruptindex.com/tools/stripe-agent-toolkit-mcp-server"><img src="https://interruptindex.com/badge/stripe-agent-toolkit-mcp-server.svg?theme=dark" alt="Stripe Agent Toolkit MCP Server — Interrupt Index agent-readiness rating" height="64"></a>