# Payments MCP Servers: 3 Compared and What They Automate

> Stripe and PayPal run official remote MCP servers, and Lago ships an open-source one for billing you host yourself. I compared endpoints, auth, tools and approval rules, and worked out which money tasks an agent should never touch.

**Source:** https://mcpplaygroundonline.com/blog/payments-mcp-servers  
**Author:** Nikhil Tiwari  
**Published:** 2026-10-09  
**Category:** Comparison  
**Reading time:** 11 min read  
**Topics:** payments MCP servers, Stripe MCP server, PayPal MCP server, Lago MCP server, open source billing MCP server, Stripe agent API key, refund with AI agent, billing automation with MCP, best MCP server for payments, is it safe to connect Stripe to an AI agent, payment MCP security

---

TL;DR

-   **Stripe and PayPal run official remote MCP servers.** Lago's billing server is open source (MIT) and runs on your own infrastructure
-   **Stripe deadline: from 31 October 2026**, its MCP server rejects full-access secret keys. Switch to OAuth or an agent API key now
-   **Stripe is the only one that forces human approval** on refunds and outbound payments, server-side
-   PayPal exposes **40+ tools** across invoices, orders, disputes and subscriptions, with a **separate sandbox endpoint**
-   The win is **investigation and reporting**. Refunds, cancellations and dispute decisions stay with a human

Table of Contents

1.  [What Is a Payments MCP Server?](#what-is)
2.  [The 3 Servers Compared](#servers)
3.  [Payment Work You Can Automate](#operations)
4.  [How to Pick a Server](#how-to-pick)
5.  [The Blast-Radius Problem](#blast-radius)
6.  [How MCP Playground Helps](#playground)
7.  [FAQ](#faq)

Of every MCP server you can connect, **payments MCP servers carry the highest stakes**. A bad tool call here does not break a build. It moves money.

I connected three. **Stripe** and **PayPal** are the two most teams already use. **Lago** is the open-source billing platform you can host yourself.

They look similar in a tool list. **They are not similar in what stops a mistake.**

One requires a human click before a refund. The other two leave that to your client.

There is also a deadline. **From 31 October 2026, Stripe's MCP server stops accepting full-access secret keys.** If your agent uses one, it breaks in a few weeks.

This guide covers what each server can do, which payment tasks are safe to hand to an agent, and the guardrails I would not skip.

Every endpoint below comes from the vendor's own documentation, checked in October 2026.

## What Is a Payments MCP Server?

A _payments MCP server_ exposes your payment or billing account as tools an AI model can call. Customers, charges, invoices, subscriptions, refunds and disputes.

New to the protocol? Start with [what the Model Context Protocol is](/blog/what-is-model-context-protocol). The short version: **MCP is a standard way for a model to discover and call external tools**.

The value is answering questions your dashboard makes slow. **"Why did this customer's renewal fail?"** takes four clicks in a dashboard and one prompt in chat.

## The 3 Payments MCP Servers Compared

Here is the side-by-side. **Endpoints are quoted from each vendor's documentation**, not from a directory listing.

Server

Endpoint

Auth

Server-side approval?

**Stripe**

`mcp.stripe.com`

OAuth or agent API key

Yes — refunds and outbound payments

**PayPal**

`mcp.paypal.com` (sandbox: `mcp.sandbox.paypal.com`)

Client ID and secret, or access token

No — client-side only

**Lago** (open source)

Self-run Docker image

Lago API key

No — client-side only

None of these servers charge for MCP access. **The last column is the one that matters**, because it decides what happens when your model gets a refund wrong.

### 1\. Stripe MCP Server

Stripe runs the **most carefully designed payments MCP server I have tested**. The endpoint is `https://mcp.stripe.com` over streamable HTTP.

```
claude mcp add --transport http stripe https://mcp.stripe.com/
```

Then run `/mcp` in Claude Code to finish OAuth. On the consent page you **pick which live accounts and sandboxes to grant**, with different permissions for each.

The tool design is smart. Instead of one tool per endpoint, **four generic tools cover most of the API**: `stripe_api_search`, `stripe_api_details`, `stripe_api_read` and `stripe_api_write`.

The model searches for a method, reads its parameters, then calls it. That keeps the tool list small while still reaching customers, invoices, subscriptions, refunds, disputes and more.

Extras include `stripe_analytics` for metrics and reports, `search_stripe_documentation`, and `stripe_implementation_planner` for building integrations.

Here is the feature I wish every server had. **Stripe requires human confirmation for certain writes**, including refunds and outbound payments. This happens on Stripe's side, not your client's.

The agent returns a URL. You open it, review the request, and approve. The agent retries with an approval token. **Unapproved requests expire after 24 hours.**

#### The 31 October 2026 key change

For clients without OAuth, Stripe now wants an _agent API key_. These carry an Agent badge in the Dashboard and only the permissions you give them.

**From 31 October 2026, full-access secret keys and untagged restricted keys get a 401.** Swap them for an agent key, or reconnect with OAuth, before then.

Admins can turn MCP access on or off for the whole team, separately for live mode and sandboxes. **Every tool call shows up in Workbench logs.**

Setup details are on our [Stripe MCP server page](/mcp-servers/stripe).

### 2\. PayPal MCP Server

PayPal runs a remote server at `https://mcp.paypal.com`. The detail I like: **there is a separate sandbox server** at `https://mcp.sandbox.paypal.com`.

That makes it trivial to build and test an agent against fake money first. Both offer SSE and streamable HTTP paths.

There is also a local option, `npx @paypal/mcp --tools=all`, with an access token in `PAYPAL_ACCESS_TOKEN`. It comes from PayPal's agent toolkit, which is **open source under Apache-2.0**.

PayPal went the opposite way to Stripe. **It exposes 40+ named tools**, one per action:

-   **Invoices:** `create_invoice`, `send_invoice`, `send_invoice_reminder`, `cancel_sent_invoice`, recurring series and more
-   **Payments:** `create_order`, `pay_order`, `create_refund`, `get_refund`
-   **Disputes:** `list_disputes`, `get_dispute`, `accept_dispute_claim`
-   **Subscriptions:** plans, `create_subscription`, `update_subscription`, `cancel_subscription`
-   **Reporting:** `list_transactions`, `get_merchant_insights`
-   **Shipping and catalog:** shipment tracking and product tools

Named tools are easier to read and easier to block. **You can deny `create_refund` in your client** without touching anything else.

One tool deserves a warning. `accept_dispute_claim` concedes a dispute. **Once accepted, the money is gone.** I block it in every client config.

Setup details are on our [PayPal MCP server page](/mcp-servers/paypal).

### 3\. Lago MCP Server (Open Source)

Lago is the free pick. It is an **open-source billing platform** for usage-based and subscription pricing, and its MCP server is MIT-licensed and written in Rust.

Be clear on what it is.

**Lago is not a payment processor.** It meters usage, builds invoices and handles credit notes, then hands payment collection to Stripe, Adyen or another processor.

So it fits teams that already own their billing logic and do not want it locked inside one vendor.

You run the server yourself from the `getlago/lago-mcp-server` Docker image. Set `LAGO_API_KEY`, and point `LAGO_API_URL` at Lago Cloud (US or EU) or your own instance.

**Self-host both Lago and the MCP server** and your billing data never touches a SaaS vendor. It still goes to your model provider, of course.

The server exposes 40+ tools. Highlights:

-   `ask_lago_analytics` — revenue and usage questions in plain English
-   `preview_invoice` — "what would this customer pay under this usage?"
-   `retry_invoice_payment` and `retry_invoice` — rerun failed collection
-   `create_credit_note`, `void_invoice`, `delete_invoice` — the dangerous ones
-   `list_api_logs` and `list_activity_logs` — audit trail for debugging integrations

The repo marks every write tool clearly, which helps when you build a deny list. **Nothing stops a write server-side**, so that list is your job.

Before you connect any of these to a live account, check which write tools it actually exposes. [Test any MCP server free →](/mcp-test-server)

## Payment Work You Can Automate With Payments MCP Servers

The rule is simple. **Read freely, write carefully, move money never** without a human in the loop.

### Failed Payment Investigation

The best use case. Find the failed charge, read the decline code, check the payment method and the customer's history, and explain it.

```
Customer cus_123 says their renewal failed. Find the most
recent failed charge or invoice payment, explain the decline
reason in plain English, and list what the customer can do.
Read only. Do not retry, refund or update anything.
```

That turns a support ticket into a ready answer. **Support teams love this one.**

### Revenue and Churn Questions

Stripe's `stripe_analytics`, PayPal's `get_merchant_insights` and Lago's `ask_lago_analytics` all answer "what changed last month?" without a SQL export.

Ask for the numbers **and the query or filter used**. Revenue figures you cannot trace back are worse than none.

### Dispute Evidence Gathering

The agent reads the dispute, pulls the order, the shipment tracking and the customer's history, and drafts your evidence.

It drafts. You submit. **The decision to accept or fight stays with a person.**

### Invoice Chasing

List overdue invoices, group them by customer, and draft reminders. PayPal's `send_invoice_reminder` can send them once you approve the list.

### Pricing What-Ifs

Lago's `preview_invoice` is great for "what would a customer on this usage pay under the new plan?" It changes nothing.

### What Not to Automate

-   **Refunds without approval.** Stripe enforces this for you. On PayPal and Lago, enforce it in your client
-   **Accepting disputes.** `accept_dispute_claim` is irreversible
-   **Cancelling subscriptions.** A churn-saving offer beats a polite cancellation
-   **Voiding invoices or changing prices.** Both ripple into accounting and tax
-   **Outbound payments.** Stripe's Treasury tools can send money. Keep them out of autonomous agents

### Chaining Payments With Other Servers

Payments plus a support or CRM server is where this gets useful. The agent reads a ticket, checks billing, and drafts a reply with the real facts.

I built that in [the AI customer success stack with Stripe, Slack and Linear](/blog/ai-customer-success-stripe-slack-linear-setup), and an order manager in [the Stripe e-commerce recipe](/blog/ecommerce-order-manager-stripe-shopify-mcp-recipe).

## How to Pick a Payments MCP Server

You use the server for the processor you already have. If you run more than one, here is how I would weigh them:

1.  **Want guardrails you cannot misconfigure?** Stripe, because refunds need approval on Stripe's side
2.  **Want to build against fake money first?** PayPal, with its dedicated sandbox endpoint
3.  **Own your billing logic, or need to self-host?** Lago's open-source server on your own infrastructure
4.  **Need per-tool deny lists?** PayPal and Lago, where every action is a named tool

## The Blast-Radius Problem With Payments MCP Servers

Hosting MCP servers cost you uptime. **Payments MCP servers cost you money**, and usually someone else's.

The obvious risk is a wrong refund or a cancelled subscription. The less obvious one is **prompt injection through customer data**.

Customer names, invoice memos, order notes and dispute messages are all written by people outside your company. **Any of them can carry instructions for your agent.**

Stripe says so directly in its docs: turn on tool approval and take care when combining Stripe with other MCP servers.

Then there is PII. Card numbers stay out of these APIs, but names, emails and addresses do not. **All of it lands in model context.**

Five things that help:

-   **Build in sandbox.** Stripe sandboxes, PayPal's sandbox endpoint, or a Lago test instance
-   **One key per agent, minimum permissions.** A Stripe agent key for a support bot should not be able to create prices
-   **Deny the irreversible tools.** Refunds, dispute acceptance, cancellations and voids
-   **Never auto-approve writes** on a payments server, even in a demo
-   **Log every call.** Stripe has Workbench. For the others, your client or gateway has to do it

The OWASP MCP Top 10 covers this under excessive permissions and prompt injection. Running a fork of any of these servers? [Scan your MCP server →](/mcp-security-scanner)

## How MCP Playground Can Help

Before connecting a payments MCP server to a live account, connect it to a sandbox and look closely.

[The MCP server tester](/mcp-test-server) lists every tool with its schema, so you can see exactly which ones write.

[MCP Agent Studio](/mcp-agent-studio) runs real prompts and shows each tool call with its full JSON arguments.

That shows you **whether the model reached for a refund when you asked for an explanation**, before any real money is involved.

You can also compare models on the same prompt. Some stay read-only when told. Some do not.

## Frequently Asked Questions

**Do Stripe and PayPal have official MCP servers?+**

Yes. Stripe runs a remote MCP server at mcp.stripe.com with OAuth or agent API keys. PayPal runs one at mcp.paypal.com, plus a sandbox server at mcp.sandbox.paypal.com and a local npx @paypal/mcp package.

**What changes for Stripe MCP on 31 October 2026?+**

From that date the Stripe MCP server no longer accepts full-access secret keys or restricted keys without the Agent tag. Requests with those keys get a 401. Create an agent API key with only the permissions your agent needs, or reconnect with OAuth.

**Can an AI agent issue refunds through MCP?+**

Yes, but it should not do so unattended. Stripe requires a human to approve refunds and outbound payments through a confirmation link. PayPal and Lago have no server-side approval, so deny or require confirmation for refund tools in your MCP client.

**Is there an open-source payments MCP server?+**

Lago, an open-source billing platform, ships an MIT-licensed MCP server you run from a Docker image against Lago Cloud or a self-hosted instance. PayPal's agent toolkit is also open source under Apache-2.0, though it connects to PayPal's own service.

**Do payments MCP servers expose card numbers to the model?+**

No. These APIs return card details like brand and last four digits, not full card numbers. They do return customer names, emails and addresses, and all of that goes into the model's context.

## Conclusion

Stripe has the strongest guardrails, PayPal has the clearest sandbox story, and Lago is the open-source option for teams that own their billing.

Point them at investigation and reporting first. Keep a human on every refund, cancellation and dispute. And if you use a Stripe secret key, replace it before 31 October.

Before connecting one to a live account, list its tools in sandbox and watch a few calls run. [Test any MCP server free →](/mcp-test-server)

## Frequently asked questions

### Do Stripe and PayPal have official MCP servers?

Yes. Stripe runs a remote MCP server at mcp.stripe.com with OAuth or agent API keys. PayPal runs one at mcp.paypal.com, plus a sandbox server at mcp.sandbox.paypal.com and a local npx @paypal/mcp package.

### What changes for Stripe MCP on 31 October 2026?

From that date the Stripe MCP server no longer accepts full-access secret keys or restricted keys without the Agent tag. Requests with those keys get a 401. Create an agent API key with only the permissions your agent needs, or reconnect with OAuth.

### Can an AI agent issue refunds through MCP?

Yes, but it should not do so unattended. Stripe requires a human to approve refunds and outbound payments through a confirmation link. PayPal and Lago have no server-side approval, so deny or require confirmation for refund tools in your MCP client.

### Is there an open-source payments MCP server?

Lago, an open-source billing platform, ships an MIT-licensed MCP server you run from a Docker image against Lago Cloud or a self-hosted instance. PayPal's agent toolkit is also open source under Apache-2.0, though it connects to PayPal's own service.

### Do payments MCP servers expose card numbers to the model?

No. These APIs return card details like brand and last four digits, not full card numbers. They do return customer names, emails and addresses, and all of that goes into the model's context.


---

_Canonical page: https://mcpplaygroundonline.com/blog/payments-mcp-servers — MCP Playground (mcpplaygroundonline.com), the free browser-based tool for testing MCP servers and building AI agents._
