
Stripe Best Practices
Financeby stripe
3/3 audits passMIT
Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents), Connect platform setup…
Stripe Best Practices, published by stripe in its ai repository under MIT, guides an agent through Stripe integration decisions. It routes each use case to a recommended API: Checkout Sessions for one-time payments, Setup Intents for saving payment methods, Accounts v2 for Connect platforms, Billing APIs for subscriptions, Stripe Tax and the Registrations API for sales tax and VAT, and v2 Financial Accounts for embedded banking. It tells the agent to read the matching reference file (payments, billing, connect, tax, treasury, security) before answering or writing code.
Its critical rules include preferring restricted API keys over secret keys, never passing payment_method_types except for Terminal, never presenting webhooks as optional, confirming an active tax registration before enabling automatic_tax, instantiating a StripeClient instead of the global API-key pattern, and using separate sandboxes for new development. It is aimed at developers planning, building or reviewing a Stripe integration and is mainly for coding agents like Claude Code; it does not move money or change your account by itself.
BusinessMCP can import it as a playbook, useful alongside a connected Stripe MCP server when the analyst reviews billing questions.
What you can do with it
- Choose between Checkout Sessions, Payment Element and Setup Intents
- Review a Stripe integration for webhook and API-key mistakes
- Plan a Connect marketplace on Accounts v2
- Check tax registration before enabling automatic_tax
Run it on your business data
Imported into BusinessMCP, Stripe Best Practices becomes a playbook your AI business analyst applies to your Stripe revenue and connected databases.
Use Stripe Best Practices in BusinessMCPInstall it in a coding agent
One command adds Stripe Best Practices to your project.
npx skills add https://github.com/stripe/ai --skill stripe-best-practicesHow we vetted it
- Source
- stripe/ai at af7c088
- Licence
- MIT
- Security audits (skills.sh)
- Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
- Bundled scripts
- None, instructions only
Checked 2026-09-25 against its skills.sh listing. How we vet skills
Related skills
All skillsClaude API
Reference for the Claude API / Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model migration. TRIGGER — read BEFORE opening the target file;
Secrets Management
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
Security and Hardening
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe…
Frequently asked questions
How do I install Stripe Best Practices?
Run `npx skills add stripe/ai --skill stripe-best-practices` to add it to a Claude Code or other skills-compatible agent. You can also import it from the BusinessMCP dashboard, where it becomes a playbook in your workspace.
What API key does it recommend?
A restricted API key with the rk_ prefix rather than a secret key with the sk_ prefix, as a default.
Does it treat webhooks as optional?
No. One of its critical rules is never to present webhooks as optional; they are recommended for every payment integration and required for subscriptions and asynchronous payment methods.
Run Stripe Best Practices against your whole business
Free plan, no credit card.
Use Stripe Best Practices in BusinessMCP