Stripe MCP server and Dome
Let agents read live Stripe data. Keep their writes in a sandbox.
Connect Stripe's MCP server to Dome twice: once with a live agent key, once with a sandbox key. Rules decide each call on its connection and its tool. A write aimed at live mode is refused at the Gateway.
How Dome helps
Dome provides a tool gateway and authorization for Stripe
Live mode is read-only
Writes on the live connection are refused by a rule. Reads go through.
Writes land in a sandbox
Agents create invoices and refunds against sandbox data. Nothing they write reaches a real customer.
Keys stay in Dome
Dome stores each Stripe agent key and injects it on the outbound call. Agents never hold one.
Get started
Stripe behind the Gateway in three steps
Add one connection per Stripe environment, sync the catalog, and apply the rule. Agents reach both through the Gateway's single MCP endpoint.
01
Add live and sandbox connections
Stripe fixes the mode by the key, so each environment gets its own connection. Use an agent API key with only the permissions the agents need.
$ dome tools add --name stripe-live \--url https://mcp.stripe.com \--auth-method api-key --credential-type shared \--authorization "Bearer $STRIPE_LIVE_AGENT_KEY" \--gateway finance-gateway$ dome tools add --name stripe-sandbox \--url https://mcp.stripe.com \--auth-method api-key --credential-type shared \--authorization "Bearer $STRIPE_SANDBOX_AGENT_KEY" \--gateway finance-gateway02
Sync the catalog
Dome calls Stripe's tools/list with the stored key. A key Stripe rejects fails here, before any agent traffic.
$ dome tools catalog sync stripe-live03
Apply the rule
Scope it to one agent while you try it. Simulate before you deploy.
$ dome rules apply stripe-live-read-only.cedar \--agent invoice-assistant --name stripe-live-read-only
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Stripe itself, see Stripe's documentation.
Rules
Read live, write in the sandbox
The permit opens both Stripe connections to the agent. The forbid refuses stripe_api_write on the live connection, the tool behind every POST, PATCH, PUT, and DELETE.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "stripe-live" || resource.connection_name == "stripe-sandbox"}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "stripe-live" && resource.tool_name == "stripe_api_write"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Connection
- Agentinvoice-assistant is registered and active
- Callera.nakamura verified through Okta
- RuleSandbox writes are allowed
Example agents
Three agents on Stripe
From our template library. Each one reads broadly and writes narrowly.
billing-support
Answer billing questions
Looks up the customer, their charges, and their invoices, and drafts a reply. Refunds stay with a person.
- stripe-live/stripe_api_read
- stripe-live/stripe_api_search
- stripe-live/search_stripe_documentation
revenue-reporter
Report on revenue
Pulls subscription and billing metrics and writes the weekly revenue summary.
- stripe-live/stripe_analytics
- stripe-live/stripe_api_read
- stripe-live/get_stripe_account_info
invoice-assistant
Draft invoices
Reads the live customer record and builds the invoice in the sandbox for a person to check.
- stripe-live/stripe_api_read
- stripe-sandbox/stripe_api_details
- stripe-sandbox/stripe_api_write
Agent workflow
Bringing it together
Connecting Stripe to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
MCP server
Stripe
This page
Models
FAQ
Common questions
Does Dome work with Stripe's remote MCP server?
Yes. Add https://mcp.stripe.com by URL with a Stripe agent API key, and Dome injects the key on every call.
How do I stop an AI agent from making live Stripe writes?
Connect live mode and a sandbox as two connections. A rule refuses stripe_api_write on the live one.
Why two connections and not one?
Stripe fixes live or sandbox mode by the key, not per call. A connection per key gives rules a mode to decide on.
Can an agent still read live Stripe data?
Yes. stripe_api_read and the other read tools stay allowed on the live connection.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP servers for AI agents: per-argument rules on every call
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
See them all