mcpbeat

Stripe Best Practices

stripe/ai-stripe-best-practices

>- Guides Stripe integration decisions across API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, tax and registrations (Stripe Tax, automatic_tax, product tax codes), Treasury financial accounts, integration options (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration, including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, collecting sales tax, VAT, or GST, creating connected accounts, or implementing secure key handling.

This is a copy. The original lives at stripe/stripe-best-practices.

13k tokens
context cost
the whole folder, loaded on every use
7
files
instructions only
0
copies elsewhere
how many repositories repackaged it
1717
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/stripe/ai --skill stripe-best-practices

What comes with it

47 065 bytes besides the instruction
references/billing.md
references/connect.md
references/payments.md
references/security.md
references/tax.md
references/treasury.md

The instruction itself

3 sections, as written by the author

Latest Stripe API version: 2026-07-29.dahlia. Always use the latest API version and SDK unless the user specifies otherwise.

Latest SDK versions:

| Language | Latest version |

| --- | --- |

| Ruby | 19.4.0 |

| Python | 15.4.0 |

| Node.js | 22.4.0 |

| PHP | 21.1.0 |

| Java | 33.2.0 |

| Go | 86.2.0 |

| .NET | 52.2.0 |

If you don’t have a Stripe account, you can call a CLI command to generate working API keys with no registration required. You can install the Stripe CLI (npm i -g @stripe/cli) and run the command stripe sandbox create to get started.

If stripe sandbox create is used, don’t use MCP.

If you try to use MCP after running sandbox creation, first make sure stripe sandbox claim is run. Use stripe whoami --format json for CLI auth checks; do not run stripe config --list.

API key default: Always recommend a restricted API key (RAK) (rk_ prefix) over a secret key (sk_ prefix).

Integration routing

| Building… | Recommended API | Details |

| --- | --- | --- |

| One-time payments | Checkout Sessions | <references/payments.md> |

| Custom payment form with embedded UI | Checkout Sessions + Payment Element | <references/payments.md> |

| Saving a payment method for later | Setup Intents | <references/payments.md> |

| Connect platform or marketplace | Accounts v2 (/v2/core/accounts) | <references/connect.md> |

| Usage-based billing (new integration) | Metronome | <references/billing.md> |

| Subscriptions or recurring billing | Billing APIs + Checkout Sessions | <references/billing.md> |

| Sales tax, VAT, or GST compliance | Stripe Tax + Registrations API | <references/tax.md> |

| Embedded financial accounts / banking | v2 Financial Accounts | <references/treasury.md> |

| Security (key management, RAKs, webhooks, OAuth, 2FA, Connect liability) | See security reference | <references/security.md> |

Read the relevant reference file before answering any integration question or writing code.

Critical rules

  • *Before enabling automatic_tax: { enabled: true }* (or calculating tax for a custom PaymentIntent), read the tax reference and confirm the user has an active registration. Without one, Stripe calculates and collects no tax while the user believes tax is on (the most common Stripe Tax mistake).
  • On API version 2026-03-25.dahlia or later, pass the parameter integration_identifier to checkout.sessions.create to tag sessions with a custom label for tracking and comparing checkout flows in the Dashboard. The label should include a suffix of 8 random letters.

Key documentation

When the user’s request does not clearly fit a single domain above, consult:

How to use it

Copy the folder

Take stripe/ai-stripe-best-practices from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.

Install what it needs

The instructions reference npm. Without those the skill loads but fails at the first command.