Registry teardown
How does an error from the Stripe MCP server reach a human?
From the public pages, it does not travel. When a call to the Stripe MCP server fails, the person sees an error in their AI client, and the docs then point them to Contact Support, a Discord server or an email address. They leave the chat and explain the failure again. Three support tools mounted inside the server would carry the failed call, the account and the client to Stripe's team with the ticket, so nobody describes it twice. This is a reading of public material, not a claim about what Stripe runs inside.
What we checked
- Where it is listed
- The official MCP registry lists com.stripe/mcp, version 0.2.4, with the remote https://mcp.stripe.com (streamable HTTP) and the repository github.com/stripe/agent-toolkit.
- What a failed sign-in looks like
- A request with no credentials gets HTTP 401 with a WWW-Authenticate challenge that points to the OAuth metadata, and a JSON body with a message, an error_code (missing_api_key) and a link to the docs. We sent one initialize request to check this on 2026-10-08. We did not test a signed-in session.
- What the docs say about authentication
- Two methods: OAuth, or an agent API key. From October 31, 2026 the server no longer accepts full-access secret keys or restricted keys without the Agent tag, and such requests get a 401 with an OAuth discovery challenge.
- Where the docs send a person
- The docs page ends with a Contact Support link, a Discord server for talking to Stripe developers, and an email address, [email protected], for feedback and tool requests. Tool calls can be viewed in Workbench. OAuth sessions can be listed and revoked in the Dashboard.
- How the open-source toolkit treats errors
- In the toolkit's TypeScript MCP code, a failed tool call is re-thrown so the MCP protocol reports it as an error, as a code comment there explains. That is the client-facing failure, not a path to a person.
The one request we sent
This is the answer to an initialize call with no credentials. It is a good error: it has a code, a message and a link. It is also the moment a person is stuck inside a chat window, with a link to read.
POST https://mcp.stripe.com (initialize, no credentials)
HTTP/2 401
www-authenticate: Bearer resource_metadata="https://mcp.stripe.com/.well-known/oauth-protected-resource"
request-id: req_...
{
"error": "Unauthorized. See https://docs.stripe.com/mcp for usage instructions.",
"error_code": "missing_api_key",
"error_description": "No valid API key provided."
}What three tools would change
- support_ask answers known questions from rules in code, such as "my agent key stopped working" on the days around the October 31 key change, and lists the account's recent errors. No model call. An unknown question is never invented.
- support_open_ticket opens a ticket from the chat with the customer's name and email, and a context block the server attaches: the account, the client user agent, the tool catalogue version and the last calls with their errors.
- support_ticket_status reads the ticket and the team's public replies back into the same conversation. Internal notes stay out.
A vendor mounts them in a few lines. The example below uses a made-up vendor, not Stripe.
// Example only: how a vendor mounts the three tools in its own MCP server.
import { withSupport } from "@canhelpto/mcp-support";
withSupport(server, {
apiKey: process.env.CANHELPTO_API_KEY,
product: "Example Payments", // an example vendor, not a real one
user: (ctx) => ({ name: ctx.account.name, email: ctx.account.email }),
rules: [
{ match: /agent key|401/i, answer: "Create an agent API key in the Dashboard, or reconnect with OAuth." },
],
});What this does not fix
A good support desk does not make the 401 go away. It makes the next step short: ask, open a ticket with the context attached, and read the answer in the same place. Large vendors already have desks. The gap is the front door in the agent channel.
Questions
- Is Stripe a canhelpto customer?
- No. We chose it because it is a large, public server in the official registry whose docs we could read. Nothing here comes from Stripe or from inside their company.
- Does Stripe lack support?
- No. Stripe has a support organisation, docs and a developer community. The question here is narrower: when a tool call fails inside Claude or Cursor, does the failure travel with the person to a human? From the public pages, the person leaves the chat and describes it again.
- Is this a claim about Stripe's internal tooling?
- No. We only describe what is public: the registry entry, the docs page, the open-source toolkit and one unauthenticated request.
First make your errors useful: handle MCP tool errors so the user gets help. The calls are in the docs for agents. Plans are on the pricing page.