Stripe MCP Integration
Govern AI agents that call Stripe through the Stripe MCP server. Detection covers PCI, financial, and PII categories; policy adds graduated transactional limits, refund caps, and approval-required actions for any payment- or billing-modifying tool.
How Stripe MCP is different from vanilla MCP
Vanilla MCP servers are configured with adapterType: "mcp". Stripe's MCP server uses a slightly different invocation shape — particularly around tool argument structure and authentication — so Rivaro ships a dedicated mcp-stripe adapter that handles those differences transparently.
From the customer's perspective, the configuration model is identical to vanilla MCP: you register a gateway, optionally register specific tools, and distribute the detection key to your agents. The adapter type is the only thing that changes.
Registering the gateway
POST /api/admin/mcp/configurations
{
"name": "Stripe Payments",
"role": "gateway",
"adapterType": "mcp-stripe",
"transport": "stdio",
"stdio": {
"command": "npx",
"args": ["-y", "@stripe/mcp", "--tools=all"],
"env": { "STRIPE_SECRET_KEY": "sk_live_..." }
},
"enabledDetectors": ["PII", "PCI", "FINANCIAL", "AGENT_TOOL_USE"]
}
The STRIPE_SECRET_KEY is held only inside the spawned Stripe MCP process — Rivaro doesn't store it long-term beyond the gateway configuration. Use Stripe restricted keys (rather than the unrestricted secret key) for least-privilege.
Alternatively, supply the key as part of the gateway's configuration.stripeApiKey field; the adapter falls back to that if STRIPE_SECRET_KEY is not in the env.
HTTP transport (alternative)
If your environment can't run stdio processes (sealed Docker, Lambda), Stripe also publishes an HTTP-mode MCP server image. Configure with transport: "http" and upstreamEndpoint: "https://your-stripe-mcp.internal/mcp".
Common Stripe tools and their detection sensitivity
| Tool | Suggested detectors | Recommended policy |
|---|---|---|
create_refund | PII, FINANCIAL | Risk-adaptive with graduated amount thresholds |
create_payment_intent | PCI, PII, FINANCIAL | Step-up over a threshold |
update_customer | PII | Log; redact non-explicit PII |
list_charges | PII, FINANCIAL | Allow; log |
cancel_subscription | FINANCIAL | Step-up |
create_payout | FINANCIAL | Risk-adaptive with strict graduated thresholds |
delete_* | FINANCIAL | Step-up always |
Register the high-sensitivity tools individually so you can pin distinct detector sets and policy rules to each.
Recommended risk-adaptive rule for refunds
POST /api/policy/organizations/rules
{
"detectionType": "AGENT_TOOL_FINANCIAL_PAYOUT",
"lifecycle": "EGRESS",
"action": "RISK_ADAPTIVE",
"evaluationStrategy": "MOST_RESTRICTIVE",
"evaluationRules": [
{
"name": "graduated_refund_amount",
"mode": "graduated",
"metric": "transaction_amount",
"ranges": [
{ "gte": 0, "lt": 100, "action": "ALLOW" },
{ "gte": 100, "lt": 1000, "action": "LOG" },
{ "gte": 1000, "lt": 10000, "action": "STEP_UP" },
{ "gte": 10000, "action": "BLOCK" }
]
}
]
}
This is the rule the FINANCIAL template ships by default — you can either use the template or write the rule directly.
Agent configuration
Your agent's MCP client points at:
https://api.rivaro.ai/api/v1/mcp/invoke/Stripe%20Payments
with X-Detection-Key set to the detection key returned at gateway creation. Rivaro routes through the mcp-stripe adapter, which handles the Stripe-specific request shape on the way to the upstream Stripe MCP process.
Detection key rotation
POST /api/admin/mcp/configurations/{configId}/regenerate-key
For Stripe specifically, you may also want to rotate the underlying STRIPE_SECRET_KEY simultaneously. Rotate the Stripe key in Stripe's dashboard, then update the gateway configuration with the new key. Old detection keys and old Stripe keys both stop working immediately.
Next steps
- MCP (Model Context Protocol) — Core MCP configuration model
- Policy Templates — The FINANCIAL template ships rules tuned for Stripe-like workloads
- Authority Envelopes — Lock down a Stripe-connected agent to specific actions
- Enforcement & Policies — How risk-adaptive evaluation runs for financial actions