Dome Systems

Stripe MCP server and Dome

Let agents read live Stripe data. Keep their writes in a sandbox.

Connect Stripe's MCP server to Dome twice: once with a live agent key, once with a sandbox key. Rules decide each call on its connection and its tool. A write aimed at live mode is refused at the Gateway.

FinanceAgentsDomeStripeCallersFinanceAgentsbilling-supportAgentsrevenue-reporterAgentsinvoice-assistantGatewaysfinance-gatewayStripeLive modeStripeSandboxModel poolAny providerRulesGuardsAuditsaudit-trail
billing-support→stripe-live/stripe_api_read· as a.nakamuraAllowed

How Dome helps

Dome provides a tool gateway and authorization for Stripe

Live mode is read-only

Writes on the live connection are refused by a rule. Reads go through.

Writes land in a sandbox

Agents create invoices and refunds against sandbox data. Nothing they write reaches a real customer.

Keys stay in Dome

Dome stores each Stripe agent key and injects it on the outbound call. Agents never hold one.

Get started

Stripe behind the Gateway in three steps

Add one connection per Stripe environment, sync the catalog, and apply the rule. Agents reach both through the Gateway's single MCP endpoint.

  1. 01

    Add live and sandbox connections

    Stripe fixes the mode by the key, so each environment gets its own connection. Use an agent API key with only the permissions the agents need.

    $ dome tools add --name stripe-live \
    --url https://mcp.stripe.com \
    --auth-method api-key --credential-type shared \
    --authorization "Bearer $STRIPE_LIVE_AGENT_KEY" \
    --gateway finance-gateway
     
    $ dome tools add --name stripe-sandbox \
    --url https://mcp.stripe.com \
    --auth-method api-key --credential-type shared \
    --authorization "Bearer $STRIPE_SANDBOX_AGENT_KEY" \
    --gateway finance-gateway
  2. 02

    Sync the catalog

    Dome calls Stripe's tools/list with the stored key. A key Stripe rejects fails here, before any agent traffic.

    $ dome tools catalog sync stripe-live
  3. 03

    Apply the rule

    Scope it to one agent while you try it. Simulate before you deploy.

    $ dome rules apply stripe-live-read-only.cedar \
    --agent invoice-assistant --name stripe-live-read-only

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Stripe itself, see Stripe's documentation.

Rules

Read live, write in the sandbox

The permit opens both Stripe connections to the agent. The forbid refuses stripe_api_write on the live connection, the tool behind every POST, PATCH, PUT, and DELETE.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "stripe-live" ||
resource.connection_name == "stripe-sandbox"
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "stripe-live" &&
resource.tool_name == "stripe_api_write"
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Connection

agent invoice-assistant · acting as a.nakamura
stripe-sandbox/stripe_api_write(Create an invoice)
  1. Agentinvoice-assistant is registered and active
  2. Callera.nakamura verified through Okta
  3. RuleSandbox writes are allowed
DecisionAllowed

Example agents

Three agents on Stripe

From our template library. Each one reads broadly and writes narrowly.

billing-support

Answer billing questions

Looks up the customer, their charges, and their invoices, and drafts a reply. Refunds stay with a person.

  • stripe-live/stripe_api_read
  • stripe-live/stripe_api_search
  • stripe-live/search_stripe_documentation

revenue-reporter

Report on revenue

Pulls subscription and billing metrics and writes the weekly revenue summary.

  • stripe-live/stripe_analytics
  • stripe-live/stripe_api_read
  • stripe-live/get_stripe_account_info

invoice-assistant

Draft invoices

Reads the live customer record and builds the invoice in the sandbox for a person to check.

  • stripe-live/stripe_api_read
  • stripe-sandbox/stripe_api_details
  • stripe-sandbox/stripe_api_write

Agent workflow

Bringing it together

Connecting Stripe to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

MCP server

Stripe

This page

FAQ

Common questions

Does Dome work with Stripe's remote MCP server?

Yes. Add https://mcp.stripe.com by URL with a Stripe agent API key, and Dome injects the key on every call.

How do I stop an AI agent from making live Stripe writes?

Connect live mode and a sandbox as two connections. A rule refuses stripe_api_write on the live one.

Why two connections and not one?

Stripe fixes live or sandbox mode by the key, not per call. A connection per key gives rules a mode to decide on.

Can an agent still read live Stripe data?

Yes. stripe_api_read and the other read tools stay allowed on the live connection.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.