Recommended action
For bearer-token connections, create a least-privilege Agent Key, test it in a sandbox, then expire the old key. Interactive clients can reconnect with OAuth. Keep human confirmation enabled.
Compatibility change · action required
Starting October 31, 2026, Stripe MCP will reject full-access secret keys and restricted keys without the Agent tag with HTTP 401. OAuth remains available. Observed October 2, 2026 and published after review on October 2, 2026.
Operator action
This is a compatibility action, not a security, availability, or provider-performance guarantee.
For bearer-token connections, create a least-privilege Agent Key, test it in a sandbox, then expire the old key. Interactive clients can reconnect with OAuth. Keep human confirmation enabled.
chg_0c2a31dbe8f14a019452c709a762bd30The effective date does not predate ResolveMesh observation.
Effective date: October 31, 2026.
1 reviewed fact delta
Values are projected from the approved typed ledger; the page does not fetch or reinterpret the source at request time.
| Field | Before | After |
|---|---|---|
| caveats | Stripe administrators must enable MCP access separately for sandbox and live environments., Stripe strongly recommends restricted API keys for bearer-token sessions and human confirmation before tools run., Connected-account access requires a Stripe-Account header and is not available through OAuth. | Stripe administrators must enable MCP access separately for sandbox and live environments., From October 31, 2026, Stripe MCP rejects full-access secret keys and restricted keys without the Agent tag; migrate to Agent Keys or OAuth. Keep human confirmation enabled., Connected-account access requires a Stripe-Account header and is not available through OAuth. |
Affected surfaces
A client-wide or tool-wide event matches all catalog records in the unspecified dimension. No published match is not proof that an integration is unaffected.
Stripe's hosted MCP server for authenticated Stripe API reads and writes.
Founder-reviewed alerts
A request records interest only. It creates no account, monitoring promise, alert-delivery commitment, or charge.
Official evidence
The source owner can revise documentation after this observation. Verify the current page before a production change.
Official documentation used to approve this compatibility fact delta.
Read the primary sourceThe same event is available without page markup at the stable change-ID endpoint.
GET /v1/compatibility-changes/chg_0c2a31dbe8f14a019452c709a762bd30