AgentsReady
Verified deep dive · Payments

Stripe

Run the agent liveReport a change
2 minTime to key
YesNo-human path
0Gates to a test key
10/10Onboarding score
Live keys only:Email verificationKYC / business checkMandatory 2FA

Fastest path to a key

  1. npm i -g @stripe/cli
  2. stripe sandbox create --from-git --non-interactive (solves a proof-of-work challenge, no account, test keys saved to CLI profile)
  3. use the sandbox sk_test key / stripe CLI commands immediately
  4. optional: within 7 days a human runs `stripe sandbox claim` (browser) to turn it into a real account; then `stripe login` (pairing code) for permanent keys
  5. KYC / business check
    live keys: activate account (business details, bank account, identity verification)
  6. Working API key

Biggest gap

Anonymous sandbox expires in 7 days and the MCP/CLI need an admin toggle on existing accounts; the 2026-10-31 key-policy change will break existing MCP configs using plain secret keys.

Worth copying

Anonymous, claimable sandbox (`stripe sandbox create`) gated by proof-of-work instead of signup/captcha - the agent builds first, the human claims later.

Sources (9) · checked 2026-10-11
80Readiness score / 100
L4 Agent-nativeBeats 95% of 1,846 companies
Access20/20
Context17/20
Interfaces24/32
Onboarding14/19
Trust5/9
llms.txt · root
MCP · https://mcp.stripe.com/

Biggest gains

  1. +8 Machine-readable API spec. Publish an OpenAPI spec at a stable URL like /openapi.json and link it from llms.txt.
  2. +5 Self-serve API keys. Show how to create a key on the first docs page. No sales call.
  3. +4 Agent manifests. Publish an MCP server card (/.well-known/mcp.json) or A2A agent card.
All 20 checks
  • PASSAgents get the real page, not a bot wall10
  • PASSrobots.txt lets user-triggered agents in6
  • PASSContent is server-rendered4
  • PASSllms.txt exists8
  • FAILllms-full.txt exists3
  • PASSDocs available as markdown6
  • PASSSitemap2
  • PASSStructured metadata1
  • PASSPublic developer docs4
  • FAILMachine-readable API spec8
  • PASSRemote MCP server for the product12
  • PASSDocs MCP or searchable docs4
  • PASSSDKs and a CLI4
  • PASSOAuth discovery metadata5
  • PASSAgents can self-register OAuth clients6
  • FAILSelf-serve API keys5
  • PASSFree tier or test mode3
  • FAILAgent manifests4
  • PASSsecurity.txt2
  • PASSPublic status page3

Your fix pack: 5 changes, up to +20 points

Each change is ready to paste, filled in for stripe.com, with a command to check it worked. Or hand the whole list to your coding agent.

An OpenAPI spec is the contract agents and SDK generators build against. Without it they guess from prose.

Where: https://stripe.com/openapi.json, linked from llms.txt and the API reference
// Serve the spec your API framework already generates (FastAPI: /openapi.json is built in).
// Next.js: app/openapi.json/route.ts
import spec from "@/openapi/openapi.json";
export const GET = () => Response.json(spec, { headers: { "Access-Control-Allow-Origin": "*" } });

// Every operation needs: operationId, summary, description, request/response examples,
// and the auth scheme (components.securitySchemes) so agents know how to send the key.
Check it worked:curl -s https://stripe.com/openapi.json | head -c 200

Add the badge to your README

AgentsReady badge for stripe.com
[![AgentsReady](https://agentsready.dev/badge/stripe.com)](https://agentsready.dev/c/stripe.com)