Back to Blog
ComparisonOct 9, 202611 min read

Payments MCP Servers: 3 Compared and What They Automate

NT

Nikhil Tiwari

MCP Playground

TL;DR

  • Stripe and PayPal run official remote MCP servers. Lago's billing server is open source (MIT) and runs on your own infrastructure
  • Stripe deadline: from 31 October 2026, its MCP server rejects full-access secret keys. Switch to OAuth or an agent API key now
  • Stripe is the only one that forces human approval on refunds and outbound payments, server-side
  • PayPal exposes 40+ tools across invoices, orders, disputes and subscriptions, with a separate sandbox endpoint
  • The win is investigation and reporting. Refunds, cancellations and dispute decisions stay with a human

Of every MCP server you can connect, payments MCP servers carry the highest stakes. A bad tool call here does not break a build. It moves money.

I connected three. Stripe and PayPal are the two most teams already use. Lago is the open-source billing platform you can host yourself.

They look similar in a tool list. They are not similar in what stops a mistake.

One requires a human click before a refund. The other two leave that to your client.

There is also a deadline. From 31 October 2026, Stripe's MCP server stops accepting full-access secret keys. If your agent uses one, it breaks in a few weeks.

This guide covers what each server can do, which payment tasks are safe to hand to an agent, and the guardrails I would not skip.

Every endpoint below comes from the vendor's own documentation, checked in October 2026.

What Is a Payments MCP Server?

A payments MCP server exposes your payment or billing account as tools an AI model can call. Customers, charges, invoices, subscriptions, refunds and disputes.

New to the protocol? Start with what the Model Context Protocol is. The short version: MCP is a standard way for a model to discover and call external tools.

The value is answering questions your dashboard makes slow. "Why did this customer's renewal fail?" takes four clicks in a dashboard and one prompt in chat.

The 3 Payments MCP Servers Compared

Here is the side-by-side. Endpoints are quoted from each vendor's documentation, not from a directory listing.

Server Endpoint Auth Server-side approval?
Stripe mcp.stripe.com OAuth or agent API key Yes — refunds and outbound payments
PayPal mcp.paypal.com (sandbox: mcp.sandbox.paypal.com) Client ID and secret, or access token No — client-side only
Lago (open source) Self-run Docker image Lago API key No — client-side only

None of these servers charge for MCP access. The last column is the one that matters, because it decides what happens when your model gets a refund wrong.

1. Stripe MCP Server

Stripe runs the most carefully designed payments MCP server I have tested. The endpoint is https://mcp.stripe.com over streamable HTTP.

claude mcp add --transport http stripe https://mcp.stripe.com/

Then run /mcp in Claude Code to finish OAuth. On the consent page you pick which live accounts and sandboxes to grant, with different permissions for each.

The tool design is smart. Instead of one tool per endpoint, four generic tools cover most of the API: stripe_api_search, stripe_api_details, stripe_api_read and stripe_api_write.

The model searches for a method, reads its parameters, then calls it. That keeps the tool list small while still reaching customers, invoices, subscriptions, refunds, disputes and more.

Extras include stripe_analytics for metrics and reports, search_stripe_documentation, and stripe_implementation_planner for building integrations.

Here is the feature I wish every server had. Stripe requires human confirmation for certain writes, including refunds and outbound payments. This happens on Stripe's side, not your client's.

The agent returns a URL. You open it, review the request, and approve. The agent retries with an approval token. Unapproved requests expire after 24 hours.

The 31 October 2026 key change

For clients without OAuth, Stripe now wants an agent API key. These carry an Agent badge in the Dashboard and only the permissions you give them.

From 31 October 2026, full-access secret keys and untagged restricted keys get a 401. Swap them for an agent key, or reconnect with OAuth, before then.

Admins can turn MCP access on or off for the whole team, separately for live mode and sandboxes. Every tool call shows up in Workbench logs.

Setup details are on our Stripe MCP server page.

2. PayPal MCP Server

PayPal runs a remote server at https://mcp.paypal.com. The detail I like: there is a separate sandbox server at https://mcp.sandbox.paypal.com.

That makes it trivial to build and test an agent against fake money first. Both offer SSE and streamable HTTP paths.

There is also a local option, npx @paypal/mcp --tools=all, with an access token in PAYPAL_ACCESS_TOKEN. It comes from PayPal's agent toolkit, which is open source under Apache-2.0.

PayPal went the opposite way to Stripe. It exposes 40+ named tools, one per action:

  • Invoices: create_invoice, send_invoice, send_invoice_reminder, cancel_sent_invoice, recurring series and more
  • Payments: create_order, pay_order, create_refund, get_refund
  • Disputes: list_disputes, get_dispute, accept_dispute_claim
  • Subscriptions: plans, create_subscription, update_subscription, cancel_subscription
  • Reporting: list_transactions, get_merchant_insights
  • Shipping and catalog: shipment tracking and product tools

Named tools are easier to read and easier to block. You can deny create_refund in your client without touching anything else.

One tool deserves a warning. accept_dispute_claim concedes a dispute. Once accepted, the money is gone. I block it in every client config.

Setup details are on our PayPal MCP server page.

3. Lago MCP Server (Open Source)

Lago is the free pick. It is an open-source billing platform for usage-based and subscription pricing, and its MCP server is MIT-licensed and written in Rust.

Be clear on what it is.

Lago is not a payment processor. It meters usage, builds invoices and handles credit notes, then hands payment collection to Stripe, Adyen or another processor.

So it fits teams that already own their billing logic and do not want it locked inside one vendor.

You run the server yourself from the getlago/lago-mcp-server Docker image. Set LAGO_API_KEY, and point LAGO_API_URL at Lago Cloud (US or EU) or your own instance.

Self-host both Lago and the MCP server and your billing data never touches a SaaS vendor. It still goes to your model provider, of course.

The server exposes 40+ tools. Highlights:

  • ask_lago_analytics — revenue and usage questions in plain English
  • preview_invoice — "what would this customer pay under this usage?"
  • retry_invoice_payment and retry_invoice — rerun failed collection
  • create_credit_note, void_invoice, delete_invoice — the dangerous ones
  • list_api_logs and list_activity_logs — audit trail for debugging integrations

The repo marks every write tool clearly, which helps when you build a deny list. Nothing stops a write server-side, so that list is your job.

Before you connect any of these to a live account, check which write tools it actually exposes. Test any MCP server free →

Payment Work You Can Automate With Payments MCP Servers

The rule is simple. Read freely, write carefully, move money never without a human in the loop.

Failed Payment Investigation

The best use case. Find the failed charge, read the decline code, check the payment method and the customer's history, and explain it.

Customer cus_123 says their renewal failed. Find the most
recent failed charge or invoice payment, explain the decline
reason in plain English, and list what the customer can do.
Read only. Do not retry, refund or update anything.

That turns a support ticket into a ready answer. Support teams love this one.

Revenue and Churn Questions

Stripe's stripe_analytics, PayPal's get_merchant_insights and Lago's ask_lago_analytics all answer "what changed last month?" without a SQL export.

Ask for the numbers and the query or filter used. Revenue figures you cannot trace back are worse than none.

Dispute Evidence Gathering

The agent reads the dispute, pulls the order, the shipment tracking and the customer's history, and drafts your evidence.

It drafts. You submit. The decision to accept or fight stays with a person.

Invoice Chasing

List overdue invoices, group them by customer, and draft reminders. PayPal's send_invoice_reminder can send them once you approve the list.

Pricing What-Ifs

Lago's preview_invoice is great for "what would a customer on this usage pay under the new plan?" It changes nothing.

What Not to Automate

  • Refunds without approval. Stripe enforces this for you. On PayPal and Lago, enforce it in your client
  • Accepting disputes. accept_dispute_claim is irreversible
  • Cancelling subscriptions. A churn-saving offer beats a polite cancellation
  • Voiding invoices or changing prices. Both ripple into accounting and tax
  • Outbound payments. Stripe's Treasury tools can send money. Keep them out of autonomous agents

Chaining Payments With Other Servers

Payments plus a support or CRM server is where this gets useful. The agent reads a ticket, checks billing, and drafts a reply with the real facts.

I built that in the AI customer success stack with Stripe, Slack and Linear, and an order manager in the Stripe e-commerce recipe.

How to Pick a Payments MCP Server

You use the server for the processor you already have. If you run more than one, here is how I would weigh them:

  1. Want guardrails you cannot misconfigure? Stripe, because refunds need approval on Stripe's side
  2. Want to build against fake money first? PayPal, with its dedicated sandbox endpoint
  3. Own your billing logic, or need to self-host? Lago's open-source server on your own infrastructure
  4. Need per-tool deny lists? PayPal and Lago, where every action is a named tool

The Blast-Radius Problem With Payments MCP Servers

Hosting MCP servers cost you uptime. Payments MCP servers cost you money, and usually someone else's.

The obvious risk is a wrong refund or a cancelled subscription. The less obvious one is prompt injection through customer data.

Customer names, invoice memos, order notes and dispute messages are all written by people outside your company. Any of them can carry instructions for your agent.

Stripe says so directly in its docs: turn on tool approval and take care when combining Stripe with other MCP servers.

Then there is PII. Card numbers stay out of these APIs, but names, emails and addresses do not. All of it lands in model context.

Five things that help:

  • Build in sandbox. Stripe sandboxes, PayPal's sandbox endpoint, or a Lago test instance
  • One key per agent, minimum permissions. A Stripe agent key for a support bot should not be able to create prices
  • Deny the irreversible tools. Refunds, dispute acceptance, cancellations and voids
  • Never auto-approve writes on a payments server, even in a demo
  • Log every call. Stripe has Workbench. For the others, your client or gateway has to do it

The OWASP MCP Top 10 covers this under excessive permissions and prompt injection. Running a fork of any of these servers? Scan your MCP server →

How MCP Playground Can Help

Before connecting a payments MCP server to a live account, connect it to a sandbox and look closely.

The MCP server tester lists every tool with its schema, so you can see exactly which ones write.

MCP Agent Studio runs real prompts and shows each tool call with its full JSON arguments.

That shows you whether the model reached for a refund when you asked for an explanation, before any real money is involved.

You can also compare models on the same prompt. Some stay read-only when told. Some do not.

Frequently Asked Questions

Do Stripe and PayPal have official MCP servers?+
Yes. Stripe runs a remote MCP server at mcp.stripe.com with OAuth or agent API keys. PayPal runs one at mcp.paypal.com, plus a sandbox server at mcp.sandbox.paypal.com and a local npx @paypal/mcp package.
What changes for Stripe MCP on 31 October 2026?+
From that date the Stripe MCP server no longer accepts full-access secret keys or restricted keys without the Agent tag. Requests with those keys get a 401. Create an agent API key with only the permissions your agent needs, or reconnect with OAuth.
Can an AI agent issue refunds through MCP?+
Yes, but it should not do so unattended. Stripe requires a human to approve refunds and outbound payments through a confirmation link. PayPal and Lago have no server-side approval, so deny or require confirmation for refund tools in your MCP client.
Is there an open-source payments MCP server?+
Lago, an open-source billing platform, ships an MIT-licensed MCP server you run from a Docker image against Lago Cloud or a self-hosted instance. PayPal's agent toolkit is also open source under Apache-2.0, though it connects to PayPal's own service.
Do payments MCP servers expose card numbers to the model?+
No. These APIs return card details like brand and last four digits, not full card numbers. They do return customer names, emails and addresses, and all of that goes into the model's context.

Conclusion

Stripe has the strongest guardrails, PayPal has the clearest sandbox story, and Lago is the open-source option for teams that own their billing.

Point them at investigation and reporting first. Keep a human on every refund, cancellation and dispute. And if you use a Stripe secret key, replace it before 31 October.

Before connecting one to a live account, list its tools in sandbox and watch a few calls run. Test any MCP server free →

NT

Written by Nikhil Tiwari

15+ years in product development. AI enthusiast building developer tools that make complex technologies accessible to everyone.

Build, compare & ship MCP agents

Connect any MCP server, run evals on it, compare 60+ models side-by-side, deploy hosted servers, and save reusable agents you can export as an API — all in your browser.

Try for Free →
Payments MCP Servers: 3 Compared and What They Automate