# Square — MCP Server

> Query and act on Square payments, orders, customers and catalogue items from a conversation.

**Source:** https://mcpplaygroundonline.com/mcp-servers/square  
**Transport:** http  
**Requires auth:** Yes

---

## What it does

Instead of a tool per endpoint, the server has three: get_service_info lists the methods a Square service offers, get_type_info returns the parameters a method needs, and make_api_request executes the call. The model works the way a developer reading docs would: discover, check, then call. That keeps the tool list tiny while covering the full API, but it moves the hard part into the model, which has to build a correct request body from the type information. The hosted server uses OAuth and acts on production only. The local server, run with npx, can point at a sandbox and can be made read-only with DISALLOW_WRITES — the right setup while you see what an agent does with a payments API.

## Tools exposed

- get_service_info — discover the methods a Square service offers
- get_type_info — get the parameters a method requires
- make_api_request — execute a call against the Square API

## Example queries you can run

- "What were total sales at the downtown location yesterday, by payment method?"
- "Find the customer with email jane@example.com and list her last five orders."
- "Which catalogue items are out of stock at any location?"
- "Show refunds over $100 issued this week and the orders they belong to."

## Details

- **Recommended model:** anthropic/claude-sonnet-5 — With only three generic tools, the model must build each request body from type information. Sonnet 5 follows the discover-then-call pattern and gets nested fields right.
- **Transport:** http
- **Authentication:** Required — The hosted server uses OAuth with your Square account and acts on production. The local server takes an access token and can target the sandbox.
- **Hosted endpoint:** https://mcp.squareup.com/mcp
- **Official source:** [Square MCP documentation](https://developer.squareup.com/docs/mcp)

## Connecting to Square

### Environment variables

- `ACCESS_TOKEN` (required) — Square access token (local server).
- `SANDBOX` — Set to true to use the sandbox environment.
- `PRODUCTION` — Set to true to use production.
- `DISALLOW_WRITES` — Set to true to restrict the server to read-only requests.
- `SQUARE_VERSION` — Pin the Square API version, e.g. 2025-04-16.

### Client configuration

**Local, sandbox, read-only**

The safest way to start. Square recommends testing prompts in a sandbox before production.

```
{
  "mcpServers": {
    "square": {
      "command": "npx",
      "args": ["square-mcp-server", "start"],
      "env": {
        "ACCESS_TOKEN": "<SQUARE_SANDBOX_TOKEN>",
        "SANDBOX": "true",
        "DISALLOW_WRITES": "true"
      }
    }
  }
}
```

## Frequently asked questions

### Why does the Square MCP server have only three tools?

It reaches the whole Square API through get_service_info, get_type_info and make_api_request. The model discovers the method, checks its parameters, then calls it, instead of choosing among hundreds of tools.

### Can I test against the sandbox?

Yes, with the local server: set SANDBOX=true and use a sandbox access token. The hosted server works on production only.

### How do I make it read-only?

Run the local server with DISALLOW_WRITES=true. It then refuses write, update and delete requests.

### Is it production-ready?

Square labels it beta and keeps an allowlist of MCP clients for the hosted server. Test prompts in a sandbox before you point an agent at live data.

### How does it compare with the Stripe MCP server?

Stripe exposes a tool per operation. Square exposes three generic tools over its whole API, which covers more but asks more of the model. Square is the natural fit for in-person and point-of-sale businesses.

---

_Test this server across 40+ models on MCP Playground: https://mcpplaygroundonline.com/mcp-servers/square — free, no install._
