Paste Your MCP Config

🛡️

All validation runs 100% locally within your browser. Your JSON config and Stripe API keys are never sent to any remote server, never logged, never stored. You can disconnect from the internet after the page loads and it still works.

Supports Claude Desktop, Cursor, Windsurf, Codex, and Continue MCP config formats.

--

Checking...

Analyzing your configuration

    Ready for Production?

    Your config is validated. Now make sure your AI agent asks the right questions and never takes destructive actions.

    Get Stripe MCP Prompt Pack → $19

    Who This Tool Is For

    ✅ For

    • Developers setting up Stripe MCP server for Claude Desktop / Cursor / Windsurf
    • Who want to audit MCP JSON config for key-leak risks before applying
    • Teams reviewing MCP configs for security compliance
    • Anyone who wants to catch JSON syntax errors before loading config

    ❌ Not For

    • Users who haven't set up an MCP client yet
    • This tool cannot test actual network connectivity to Stripe API
    • Cannot verify that your restricted key actually has read-only permissions
    • Only static JSON text inspection — no real API calls are made

    Common MCP Config Pitfalls

    • Trailing commas inside JSON config — MCP clients will silently fail to load. For example: {"args": ["-y", "@stripe/mcp",]} (trailing comma after last item). Always validate JSON before saving.
    • Missing -y flag inside npx args — Without it, npx prompts interactively and the MCP server hangs forever.
    • Mix-up publishable key pk_ / restricted rk_ / full secret sk_ — pk_ keys cannot authenticate MCP servers; sk_ keys give full account access.
    • Windows file-path backslash escaping error — If your command uses a Windows path, double-escape backslashes or use forward slashes.
    • Using sk_live in development — Always test with rk_test_ first. Switch to live only after full testing.

    Frequently Asked Questions

    Does this tool send my API key to your server?

    No. All validation runs 100% locally within your browser using JavaScript. Your JSON config and Stripe API keys are never sent to any remote server, never logged, and never stored. You can verify this by opening DevTools Network tab — zero requests are made when you click Validate.

    What MCP clients are supported?

    This validator works with any MCP client that uses the standard mcpServers JSON config format, including Claude Desktop, Cursor, Windsurf, Codex, and Continue. The config format is standardized across all MCP-compatible clients.

    What is the risk of using sk_ secret key for Stripe MCP?

    A full secret key (sk_) gives the MCP server complete access to your Stripe account, including creating charges, issuing refunds, and transferring funds. If your AI agent is compromised or makes an error, it could cause real financial damage. Always use a restricted key (rk_) with read-only permissions for MCP.

    What is a Stripe restricted rk_ key?

    A restricted key (rk_) lets you limit what the API key can access. For MCP, create a restricted key with read-only permissions for Customers, Charges, Subscriptions, and Invoices. Explicitly DENY write permissions for Refunds, Transfers, and Payouts. Create one in Stripe Dashboard → Developers → API keys → Create restricted key.

    Can I use pk_ publishable key for MCP server?

    No. Publishable keys (pk_) are designed for client-side use only (e.g., Stripe.js in your frontend) and cannot authenticate MCP servers. They are not a security risk if leaked, but they will not work for MCP. Use a restricted key (rk_) instead.

    🔑 Why rk_ Keys Matter

    Stripe restricted keys (rk_) let you limit what the MCP server can access. Using a full secret key (sk_) gives your AI agent write access to charges, refunds, and transfers. Even with rk_ restricted key, remove Refunds / Transfers / Payouts write permissions.

    ⚠️ 4 Key Types Detected

    sk_ = Full secret (CRITICAL risk)
    rk_ = Restricted (verify read-only)
    pk_ = Publishable (wrong for MCP)
    agent_ = Agent Key (Stripe recommended)

    🛡️ Your Data Stays Local

    All validation happens in your browser using JavaScript. No server calls, no analytics on your config, no storage. You can verify by opening DevTools Network tab — zero requests are made when you click Validate.

    Important: This tool performs static JSON text inspection only. It cannot make network requests to Stripe or verify that your API key actually works or has the permissions you expect. Always test in Stripe test mode first. Not affiliated with Stripe Inc.