Claude security directory
Stripe
Published by Stripe
High risk
The Stripe Model Context Protocol server defines a set of tools that AI agents can use to interact with the Stripe API and search its knowledge base (including documentation and support articles).
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Can spend money on your behalf: This connector can complete purchases, bookings, or payments. A misused or hijacked prompt could result in real financial charges before you confirm.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.
Available capabilities
This add-on exposes 23 tools or capabilities.
- search_documentation
- get_stripe_account_info
- create_customer
- list_customers
- create_product
- list_products
- create_price
- list_prices
- create_payment_link
- create_invoice
- list_invoices
- create_invoice_item
- finalize_invoice
- retrieve_balance
- create_refund
- list_payment_intents
- list_subscriptions
- update_subscription
- cancel_subscription
- list_coupons
- create_coupon
- list_disputes
- update_dispute
The interactive security report will load automatically.