THRONE
See report Verify server

registry / record

@stripe/mcp

npm / sealed 2026-06-16 / No. fcfbb02e

Does @stripe/mcp MCP work in Claude Code and Cursor? Throne executed @stripe/mcp mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: needs your API key. Is @stripe/mcp mcp safe? Static security scan: 2 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry @stripe/mcp sealed
This server runs. It just needs your API keythe server installs and starts, then exits asking for an API key,  🚨 Error initializing Stripe MCP server:  Stripe API key not provided. Please either pass it as an argument --api-key=$KEY or set the STRIPE_SECRET_KEY environment variable. /home/worker/.npm/_npx/bce731a0395adf49/node_modules/@stripe/mcp/dist/cli.js:34 throw new Error('Stripe API key not provided. Please either pass it as an argument --api-key=$KEY or se [...] loader:1505:32) at Function._load (node:internal/modules/cjs/loader:1309:12) at wrapModuleLoad (node:internal/modules/cjs/loader:254:19) at Function.executeUserEntryPoint [as runMain] (node:internal/modules/run_main:171:5) at node:internal/main/run_main_module:36:49 Node.js v22.22.3
receiptsealed evidence
scan id
fcfbb02e9c604b6a93d47595a08ff513
target
@stripe/mcp
sealed at
2026-06-16 18:24:52Z
evidence hash
sha256:297480215262b5be029f53fe3640dfaf9d66a6bf3a712370ff69208fba2c7d6d
01connectFAIL0ms

server never launched: server process exited with code 1 before the MCP handshake, stderr:  🚨 Error initializing Stripe MCP server:  Stripe API key not provided. Please either pass it as an argument --api-key=$KEY or set the STRIPE_SECRET_KEY environment variable. /home/worker/.npm/_npx/bce731a0395adf49/node_modules/@stripe/mcp/dist/cli.js:34 throw new Error('Stripe API key not provided. Please either pass it as an argument --api-key=$KEY or se [...] loader:1505:32) at Function._load (node:internal/modules/cjs/loader:1309:12) at wrapModuleLoad (node:internal/modules/cjs/loader:254:19) at Function.executeUserEntryPoint [as runMain] (node:internal/modules/run_main:171:5) at node:internal/main/run_main_module:36:49 Node.js v22.22.3

02discoverSKIPPED0ms

not run, server never launched

03validate_schemasSKIPPED0ms

not run, server never launched

04smoke_test_toolsSKIPPED0ms

not run, server never launched

05error_handlingSKIPPED0ms

not run, server never launched

06streamingSKIPPED0ms

not run, server never launched

07resource_lifecycleSKIPPED0ms

not run, server never launched

08concurrent_callsSKIPPED0ms

not run, server never launched

09reconnectSKIPPED0ms

not run, server never launched

01connectFAIL0ms

server never launched: server process exited with code 1 before the MCP handshake, stderr:  🚨 Error initializing Stripe MCP server:  Stripe API key not provided. Please either pass it as an argument --api-key=$KEY or set the STRIPE_SECRET_KEY environment variable. /home/worker/.npm/_npx/bce731a0395adf49/node_modules/@stripe/mcp/dist/cli.js:34 throw new Error('Stripe API key not provided. Please either pass it as an argument --api-key=$KEY or se [...] loader:1505:32) at Function._load (node:internal/modules/cjs/loader:1309:12) at wrapModuleLoad (node:internal/modules/cjs/loader:254:19) at Function.executeUserEntryPoint [as runMain] (node:internal/modules/run_main:171:5) at node:internal/main/run_main_module:36:49 Node.js v22.22.3

02discoverSKIPPED0ms

not run, server never launched

03validate_schemasSKIPPED0ms

not run, server never launched

04smoke_test_toolsSKIPPED0ms

not run, server never launched

05error_handlingSKIPPED0ms

not run, server never launched

06streamingSKIPPED0ms

not run, server never launched

07resource_lifecycleSKIPPED0ms

not run, server never launched

08concurrent_callsSKIPPED0ms

not run, server never launched

09reconnectSKIPPED0ms

not run, server never launched

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 2 finding(s) / review recommended
LOWTHR-NET-05 / Hardcoded outbound endpoints

3 non-local endpoint host(s) referenced in code, verify each is expected for this server's purpose: dashboard.stripe.com (package/dist/cli.js:18), docs.stripe.com (package/dist/cli.js:45), mcp.stripe.com (package/dist/index.js:11)

package/dist/cli.js:18
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

package/dist/test/index.test.js:12
VERDICT: NEEDS YOUR API KEYSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility not assessable: needs credentials: the server installs and starts, then exits asking for an API key,  🚨 Error initializing Stripe MCP server:  Stripe API key not provided. Please either pass it as an argument --api-key=$KEY or set the STRIPE_SECRET_KEY environment variable. /home/worker/.npm/_npx/bce731a0395adf49/node_modules/@stripe/mcp/dist/cli.js:34 throw new Error('Stripe API key not provided. Please either pass it as an argument --api-key=$KEY or se [...] loader:1505:32) at Function._load (node:internal/modules/cjs/loader:1309:12) at wrapModuleLoad (node:internal/modules/cjs/loader:254:19) at Function.executeUserEntryPoint [as runMain] (node:internal/modules/run_main:171:5) at node:internal/main/run_main_module:36:49 Node.js v22.22.3 / security: review, 2 finding(s), 0 highsealed by THRONE / No. fcfbb02e / 2026-06-16
scopeattestation tuple
target
@stripe/mcp npm
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
18 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-06-16 18:24:52Z
evidence hash
sha256:297480215262b5be029f53fe3640dfaf9d66a6bf3a712370ff69208fba2c7d6d
valid until
2026-09-14
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.