This skill is a comprehensive documentation and guidance tool for Stripe integrations, focusing on official best practices, secure API usage, and migration from deprecated features. It promotes industry-standard security measures such as the principle of least privilege through restricted API keys and proper secret management. No security issues were detected.
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Claude CodeNot declared
CursorNot declared
CodexNot declared
GitHub CopilotNot declared
WindsurfNot declared
Gemini CLINot declared
ClineNot declared
OpenCodeNot declared
Repository health
Stars1.8K
LicenseLICENSE
Default branchmain
Open issues25
Status
Active
Package contents
Files included with this skill beyond the listing page.
skill mdSKILL.md5,385 B
docsSUMMARY.md767 B
History
First seen on skills.sh
First recorded snapshot · 83,124 installs
SKILL.md
Latest Stripe API version: 2026-08-26.dahlia. Always use the latest API version and SDK unless the user specifies otherwise.
Latest SDK versions:
Language
Latest version
Ruby
19.6.0
Python
15.6.0
Node.js
22.6.0
PHP
21.3.0
Java
33.4.0
Go
86.4.0
.NET
52.4.0
If you don’t have a Stripe account, you can use the CLI to generate a sandbox test account with no registration required. Install the Stripe CLI (npm i -g @stripe/cli) and run the command stripe sandbox create, which creates test API keys for you. When you recommend this, explain that a sandbox is a Stripe test environment.
If stripe sandbox create is used, don’t use MCP.
If you try to use MCP after running sandbox creation, first make sure stripe sandbox claim is run. Use stripe whoami --format json for CLI auth checks; do not run stripe config --list.
API key default: Always recommend a restricted API key (RAK) (rk prefix) over a secret key (sk prefix).
Read the relevant reference file before answering any integration question or writing code.
Critical rules
Before enabling automatic_tax: { enabled: true } (or calculating tax for a custom PaymentIntent), read the [tax reference](references/tax.md) and confirm the user has an active registration. Without one, Stripe calculates and collects no tax while the user believes tax is on (the most common Stripe Tax mistake).
Never include paymentmethodtypes in any Stripe API call, with one exception: Terminal (in-person payments) integrations must pass paymentmethodtypes: ['cardpresent'] on the PaymentIntent. For all other integrations, omit this parameter entirely to enable dynamic payment methods, which enables you to configure payment method settings from the Dashboard and dynamically display the most relevant eligible payment methods to each customer to maximize conversion. To customize which payment methods you accept, use paymentmethodconfigurations or excludedpaymentmethodtypes instead of paymentmethodtypes.
Never present webhooks as optional. We recommend webhooks for every payment integration and they’re required for subscriptions and asynchronous payment methods. Fulfillment belongs in a handler for both checkout.session.completed and checkout.session.asyncpaymentsucceeded (gated on payment_status), not the success page. See <references/payments.md>.
On API version 2026-03-25.dahlia or later, pass the parameter integration_identifier to checkout.sessions.create to tag sessions with a custom label for tracking and comparing checkout flows in the Dashboard. The label should include a suffix of 8 random letters.
Always instantiate a StripeClient and call methods on that instance. Do not use the deprecated global/module-level API key pattern (stripe.api_key = …, Stripe.setApiKey, stripe.Key = …, StripeConfiguration.ApiKey = …). The global pattern is deprecated in all current SDKs.
Key documentation
When the user’s request does not clearly fit a single domain above, consult: