{ }
Resource profile / Stripe Integration Planning & Best Practices
About this skill

Workflow & requirements

Latest Stripe API version: 2026-09-30.endive. Always use the latest API version and SDK unless the user specifies otherwise.

Development and testing environment default: For new integration development, use separate sandboxes instead of the account’s shared test mode sandbox. Sandboxes isolate settings and test data from live mode. Use separate sandboxes for local development and CI. When stronger isolation is useful, dedicate sandboxes to development teams or testing scenarios. Use the shared test mode sandbox only for an existing integration that depends on it or when a required feature doesn’t support general sandboxes.

Latest SDK versions:

Language Latest version
Ruby 19.6.0
Python 15.6.0
Node.js 22.6.0
PHP 21.3.0
Java 33.4.0
Go 86.4.0
.NET 52.4.0

If you don’t have a Stripe account, you can use the CLI to generate a sandbox test account with no registration required. Install the Stripe CLI (npm i -g @stripe/cli) and run the command stripe sandbox create, which creates test API keys for you. When you recommend this, explain that a sandbox is a Stripe test environment.

If stripe sandbox create is used, don’t use MCP.

If you try to use MCP after running sandbox creation, first make sure stripe sandbox claim is run. Use stripe whoami --format json for CLI auth checks; do not run stripe config --list.

API key default: Always recommend a restricted API key (RAK) (rk_ prefix) over a secret key (sk_ prefix).

Integration routing

Building… Recommended API Details
One-time payments Checkout Sessions references/payments.md
Custom payment form with embedded UI Checkout Sessions + Payment Element references/payments.md
Saving a payment method for later Setup Intents references/payments.md
Connect platform or marketplace Accounts v2 (/v2/core/accounts) references/connect.md
Usage-based billing (new integration) Metronome references/billing.md
Subscriptions or recurring billing Billing APIs + Checkout Sessions references/billing.md
Sales tax, VAT, or GST compliance Stripe Tax + Registrations API references/tax.md
Embedded financial accounts / banking v2 Financial Accounts references/treasury.md
Security (key management, RAKs, webhooks, OAuth, 2FA, Connect liability) See security reference references/security.md

Read the relevant reference file before answering any integration question or writing code.

Critical rules

  • Before enabling automatic_tax: { enabled: true } (or calculating tax for a custom PaymentIntent), read the tax reference and confirm the user has an active registration. Without one, Stripe calculates and collects no tax while the user believes tax is on (the most common Stripe Tax mistake).

  • Never include payment_method_types in any Stripe API call, with one exception: Terminal (in-person payments) integrations must pass payment_method_types: ['card_present'] on the PaymentIntent. For all other integrations, omit this parameter entirely to enable dynamic payment methods, which enables you to configure payment method settings from the Dashboard and dynamically display the most relevant eligible payment methods to each customer to maximize conversion. To customize which payment methods you accept, use payment_method_configurations or excluded_payment_method_types instead of payment_method_types.

  • When a PaymentIntent or SetupIntent integration requires an explicit allowlist, use allowed_payment_method_types instead of payment_method_types.

  • Never present webhooks as optional. We recommend webhooks for every payment integration and they’re required for subscriptions and asynchronous payment methods. Fulfillment belongs in a handler for both checkout.session.completed and checkout.session.async_payment_succeeded (gated on payment_status), not the success page. See references/payments.md.

  • On API version 2026-03-25.dahlia or later, pass the parameter integration_identifier to checkout.sessions.create to tag sessions with a custom label for tracking and comparing checkout flows in the Dashboard. The label should include a suffix of 8 random letters.

  • Always instantiate a StripeClient and call methods on that instance. Do not use the deprecated global/module-level API key pattern (stripe.api_key = …, Stripe.setApiKey, stripe.Key = …, StripeConfiguration.ApiKey = …). The global pattern is deprecated in all current SDKs.

Key documentation

When the user’s request does not clearly fit a single domain above, consult:

PACKAGE TRANSPARENCY

Inspect before installing

Source: Stripe · MIT · SHA-256 shown alongside the download.

11 files29128 ZIP bytes0 script/code files

License file included. A license and checksum are not a security certification. Review package instructions and scripts before running them.

View files and uncompressed sizes
Machine-readable installation guide →
CATALOG REVIEW NOTES

Know what you need before installing

Source and packaging checks recorded on 2026-10-03. These notes are not safety certification or measured task performance.

Requirements

A relevant Stripe project and current official documentation; account access, SDKs or CLI tools are separate requirements for actual integration work. Use isolated sandbox credentials for tests.

Costs, access & practical limits

API and SDK versions in this snapshot may become stale. Check current docs and project compatibility before upgrades. Financial products, tax registrations, regional availability, provider fees and legal obligations require separate verification. This catalog does not collect payments, create accounts or handle credentials.

View the recorded checks
  • Pinned upstream source and Git blob hashes verified
  • Applicable original license and notices preserved
  • Archive paths and metadata validated
  • Local Markdown and named reference files checked

Upstream commit: 27db051dba7cee2e13d2dbf6d65939cf412f5b3c

Runtime status: not tested by this catalog. Configure your client and test the skill in your own environment.

SCENARIOS

Inputs, criteria and recorded outcomes

Records are supplied by the site administrator and bound to a specific package. They are not third-party safety certification. This page does not execute skills.

No published scenario records yet. Resource availability and download counts do not imply measured task performance.

Community reviews

★ New

Be the first to share your experience.

Sign in to leave a review →

More to explore

View all ↗