Stripe MCP Agent Keys: What Changes on October 31, 2026 and How to Migrate
Beginning October 31, 2026, Stripe's MCP server will stop accepting full-access secret keys (sk_...) and restricted API keys that aren't tagged as Agent keys. If your AI agent currently authenticates to https://mcp.stripe.com with one of those key types, requests will start failing with a 401 response. To keep working, you need to either reconnect the client with OAuth or replace the key with a newly created Agent key before the deadline.
Stripe's own documentation states it plainly:
"Beginning October 31, 2026, Stripe MCP no longer accepts full-access secret keys or restricted API keys without the Agent tag. Before then, replace these keys with newly created Agent Keys or reconnect with OAuth. Requests using an unsupported key receive a
401response with an OAuth discovery challenge." — docs.stripe.com/mcp, accessed 2026-09-28
Who is affected
You're affected if your Stripe MCP integration currently authenticates with:
- A full-access secret key (
sk_live_...orsk_test_...) passed as a bearer token, or - A restricted API key (
rk_...) that was not created with the "Authorizing agent access to your account" designation (i.e., not tagged as an Agent key)
You're not affected if your client already connects via OAuth, or if you've already generated an Agent key and set it as the bearer token.
Per Stripe: "You can identify agent API keys in the Dashboard by the Agent badge." (docs.stripe.com/mcp, accessed 2026-09-28)
How to migrate
Stripe's guidance splits by client type:
"Use OAuth for interactive MCP clients. OAuth lets you authorize and revoke a client without sharing an API key. For autonomous clients that can't use OAuth, create an [agent API key] with only the permissions the client needs. ... Pass the agent API key as the bearer token in the
Authorizationheader of your request. Test the new configuration in a sandbox, then expire the old key." — docs.stripe.com/mcp, accessed 2026-09-28
Concretely:
1. Decide OAuth vs. Agent key. Interactive clients (Cursor, Claude Desktop, ChatGPT) use OAuth. Autonomous clients with no human to click through a consent flow use an Agent key.
2. For interactive clients, connect via OAuth. For Claude Code, Stripe's docs show:
claude mcp add --transport http stripe https://mcp.stripe.com/
followed by:
claude /mcp
to authenticate with OAuth. (docs.stripe.com/mcp, accessed 2026-09-28)
3. For autonomous clients, create an Agent key and reference it via environment variable. Stripe's docs give this example for Claude Code, using an agent API key instead of OAuth:
{
"mcpServers": {
"stripe": {
"type": "http",
"url": "https://mcp.stripe.com",
"headers": {
"Authorization": "Bearer ${AGENT_API_KEY}"
}
}
}
}
Stripe's note on this snippet: "${AGENT_API_KEY} is a placeholder; replace AGENT_API_KEY with the actual name of your environment variable, and set that environment variable in your shell before running Claude Code." (docs.stripe.com/mcp, accessed 2026-09-28)
To create the key itself, Stripe's API keys documentation explains the tagging step: "When you create a restricted API key, you can tag it as belonging to an autonomous agent... To tag a key as an agent key, select Authorizing agent access to your account when Stripe prompts you for the key's intended use during creation." (docs.stripe.com/keys, accessed 2026-09-28)
4. Test in a sandbox first, using a sandbox Agent key (prefixed rk_test_), before switching production traffic.
5. Expire the old key from the API keys Dashboard page once the new connection is confirmed working.
What happens if you don't migrate
After October 31, 2026, any MCP request still using a full-access secret key or a non-Agent restricted key will fail. Per Stripe: "Requests using an unsupported key receive a 401 response with an OAuth discovery challenge." (docs.stripe.com/mcp, accessed 2026-09-28) In practice, this means your agent's Stripe tool calls stop working until you reconnect with OAuth or swap in an Agent key — there's no grace period described on Stripe's docs page beyond the October 31, 2026 date itself.
Scoping what an agent can do with money
Migrating your key is also a natural checkpoint to review how much autonomy your agent has over your Stripe account. Stripe ships several built-in controls:
- Agent key permissions are scoped like any restricted key. "Agent-tagged keys work the same as other restricted API keys for authentication and permissions." (docs.stripe.com/keys, accessed 2026-09-28) Grant only the resources and actions the agent's job requires.
- Approval rules apply automatically to agent-tagged keys. "The difference is in governance: agent-tagged keys are automatically subject to approval rules, which require a designated reviewer to approve sensitive actions before they take effect. Stripe provides a set of default rules when you create your first agent-tagged key. These rules cover high-risk actions such as payouts, refunds, and account configuration changes." (docs.stripe.com/keys, accessed 2026-09-28)
- Human confirmation gates sensitive write actions in MCP specifically. "To prevent agents from making mistakes, Stripe requires human confirmation before it takes certain
stripe_api_writeactions, such as refunds and outbound payments. To confirm an action, click the URL provided by your agent and review the details of the request." (docs.stripe.com/mcp, accessed 2026-09-28) - Confirmations expire after 24 hours. "When you click Approve, Stripe provides the agent with an approval token, but you need to tell the agent to retry the operation, which doesn't require human confirmation. If you don't approve the action within 24 hours, it expires." (docs.stripe.com/mcp, accessed 2026-09-28)
- Admins can disable MCP access at the team level. "If you're an administrator, you can enable or disable MCP access for your entire team in the Dashboard. Configure access separately for live mode and sandbox environments." (docs.stripe.com/mcp, accessed 2026-09-28)
- Sessions are revocable individually. OAuth sessions appear under "OAuth sessions" in user settings, and admins can "revoke one session" or "revoke all" for a team member. (docs.stripe.com/mcp, accessed 2026-09-28)
- Stripe flags the prompt-injection risk directly: "Enable human confirmation of tools and exercise caution when using the Stripe MCP with other servers to avoid prompt injection attacks." (docs.stripe.com/mcp, accessed 2026-09-28)
General practices, regardless of which payment MCP server you use:
- Least-privilege keys — grant only the specific resources the agent's job needs, not blanket read/write access.
- Keep human confirmation on, especially for anything that moves money, even if your client lets you disable it.
- Don't mix an untrusted MCP server into the same session as your payment MCP server — a compromised tool can prompt-inject the agent holding your Stripe credentials.
- Disable client-side "auto-approve" for write tools tied to payments, refunds, or payouts.
- Monitor tool-call logs (Stripe exposes these in Workbench) periodically, not just when something breaks.
- Treat per-agent budgets and approval thresholds as an ongoing pattern — revisit them as you add agents or connect more MCP servers.
For a broader look at how different payment MCP servers approach these controls, see our neutral comparison: Payment MCP servers compared (2026). For terminology and patterns around limiting agent spend generally, see our glossary entry: AI agent spending controls.
FAQ
Does the October 31, 2026 deadline affect OAuth connections? No. It only affects full-access secret keys and restricted keys without the Agent tag — Stripe's docs scope the change to those key types specifically (docs.stripe.com/mcp, accessed 2026-09-28).
What error will I see if I don't migrate in time?
A 401 response with an OAuth discovery challenge: "Requests using an unsupported key receive a 401 response with an OAuth discovery challenge." (docs.stripe.com/mcp, accessed 2026-09-28)
Is an Agent key a new key type, or a tagged restricted key? A tagged restricted key, not a separate format: "Agent-tagged keys work the same as other restricted API keys for authentication and permissions." (docs.stripe.com/keys, accessed 2026-09-28)
Does an Agent key add protection beyond normal restricted-key permissions? Yes — approval rules apply automatically: "agent-tagged keys are automatically subject to approval rules, which require a designated reviewer to approve sensitive actions before they take effect." (docs.stripe.com/keys, accessed 2026-09-28)
Can I turn off Stripe MCP access entirely for my team while I migrate? Yes, if you're an administrator: "you can enable or disable MCP access for your entire team in the Dashboard. Configure access separately for live mode and sandbox environments." (docs.stripe.com/mcp, accessed 2026-09-28)
Sources
All quotes verified by direct access on 2026-09-28.
-
Stripe, "Model Context Protocol (MCP)" — https://docs.stripe.com/mcp - "Beginning October 31, 2026, Stripe MCP no longer accepts full-access secret keys or restricted API keys without the Agent tag. Before then, replace these keys with newly created Agent Keys or reconnect with OAuth. Requests using an unsupported key receive a
401response with an OAuth discovery challenge." - "Use OAuth for interactive MCP clients. OAuth lets you authorize and revoke a client without sharing an API key. For autonomous clients that can't use OAuth, create an agent API key with only the permissions the client needs... Pass the agent API key as the bearer token in the Authorization header of your request. Test the new configuration in a sandbox, then expire the old key." - "You can identify agent API keys in the Dashboard by the Agent badge." - "To prevent agents from making mistakes, Stripe requires human confirmation before it takes certain stripe_api_write actions, such as refunds and outbound payments. To confirm an action, click the URL provided by your agent and review the details of the request." - "When you click Approve, Stripe provides the agent with an approval token, but you need to tell the agent to retry the operation, which doesn't require human confirmation. If you don't approve the action within 24 hours, it expires." - "Enable human confirmation of tools and exercise caution when using the Stripe MCP with other servers to avoid prompt injection attacks." - "If you're an administrator, you can enable or disable MCP access for your entire team in the Dashboard. Configure access separately for live mode and sandbox environments." - "Your authorized MCP clients appear under OAuth sessions in your user settings... To revoke a session: 1. Find the client... 2. Click the overflow menu (⋯). 3. Select Revoke access." -
Stripe, "API keys" — https://docs.stripe.com/keys - "When you create a restricted API key, you can tag it as belonging to an autonomous agent, an AI system that operates independently to complete tasks such as processing refunds or managing subscriptions. To tag a key as an agent key, select Authorizing agent access to your account when Stripe prompts you for the key's intended use during creation." - "Agent-tagged keys work the same as other restricted API keys for authentication and permissions." - "The difference is in governance: agent-tagged keys are automatically subject to approval rules, which require a designated reviewer to approve sensitive actions before they take effect. Stripe provides a set of default rules when you create your first agent-tagged key. These rules cover high-risk actions such as payouts, refunds, and account configuration changes." - "This is the recommended way to give autonomous agents access to your Stripe account. The approval rules act as a safeguard against agent mistakes, unexpected behavior, and hallucinations—giving you visibility and control without blocking agents from doing their jobs."






