SkillAgentSearch skills...

stripe-best-practices

Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, tax and registrations (S…

Install / Use

npx skills add stripe/ai --skill stripe-best-practices

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

81/100

Category

Security

Supported Platforms

Universal

Our assessment of stripe-best-practices

stripe-best-practices scores 81/100 on our quality scale, 681st of 889 Security skills we index.

Its SKILL.md is 6.6 KB long, split into 3 sections and no code examples: a thorough specification that gives an agent plenty to work with.

With 1,830 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
29/30
Structure
8/20
Description
15/15
Adoption
14/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 6 days ago, so stripe-best-practices is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

stripe-best-practices compared with similar skills

All 4 of these similar skills score higher than stripe-best-practices; compare them before choosing.

SkillScoreStarsUpdatedFormat
stripe-best-practices (this skill)by stripe811.8k6d agoSKILL.md
Agent-Reachby Panniantong10086.2k14d agoCLAUDE.md
headroomby headroomlabs-ai10074.1ktodayCLAUDE.md
Scraplingby D4Vinci10084.6ktodayMCP Server
crawl4aiby unclecode10084.5k4d agoMCP Server

Frequently asked questions

How do I install stripe-best-practices?
Run npx skills add stripe/ai --skill stripe-best-practices. The install tabs above show the steps for each supported agent.
Which AI agents does stripe-best-practices work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is stripe-best-practices safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is stripe-best-practices still maintained?
The repository was last updated 6 days ago, so stripe-best-practices is actively maintained.

name: stripe-best-practices description: >- Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, tax and registrations (Stripe Tax, automatic_tax, product tax codes), Treasury financial accounts, integration options (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, API key permissions, webhooks, OAuth). Use when planning, building, modifying, testing, or reviewing any Stripe integration, including choosing a development environment, accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, collecting sales tax, VAT, or GST, creating connected accounts, or implementing secure key handling.


Latest Stripe API version: 2026-08-26.dahlia. Always use the latest API version and SDK unless the user specifies otherwise.

Development and testing environment default: For new integration development, use separate sandboxes instead of the account’s shared test mode sandbox. Sandboxes isolate settings and test data from live mode. Use separate sandboxes for local development and CI. When stronger isolation is useful, dedicate sandboxes to development teams or testing scenarios. Use the shared test mode sandbox only for an existing integration that depends on it or when a required feature doesn’t support general sandboxes.

Latest SDK versions:

| Language | Latest version | | --- | --- | | Ruby | 19.6.0 | | Python | 15.6.0 | | Node.js | 22.6.0 | | PHP | 21.3.0 | | Java | 33.4.0 | | Go | 86.4.0 | | .NET | 52.4.0 |

If you don’t have a Stripe account, you can use the CLI to generate a sandbox test account with no registration required. Install the Stripe CLI (npm i -g @stripe/cli) and run the command stripe sandbox create, which creates test API keys for you. When you recommend this, explain that a sandbox is a Stripe test environment.

If stripe sandbox create is used, don’t use MCP.

If you try to use MCP after running sandbox creation, first make sure stripe sandbox claim is run. Use stripe whoami --format json for CLI auth checks; do not run stripe config --list.

API key default: Always recommend a restricted API key (RAK) (rk_ prefix) over a secret key (sk_ prefix).

Integration routing

| Building… | Recommended API | Details | | --- | --- | --- | | One-time payments | Checkout Sessions | references/payments.md | | Custom payment form with embedded UI | Checkout Sessions + Payment Element | references/payments.md | | Saving a payment method for later | Setup Intents | references/payments.md | | Connect platform or marketplace | Accounts v2 (/v2/core/accounts) | references/connect.md | | Usage-based billing (new integration) | Metronome | references/billing.md | | Subscriptions or recurring billing | Billing APIs + Checkout Sessions | references/billing.md | | Sales tax, VAT, or GST compliance | Stripe Tax + Registrations API | references/tax.md | | Embedded financial accounts / banking | v2 Financial Accounts | references/treasury.md | | Security (key management, RAKs, webhooks, OAuth, 2FA, Connect liability) | See security reference | references/security.md |

Read the relevant reference file before answering any integration question or writing code.

Critical rules

  • Before enabling automatic_tax: { enabled: true } (or calculating tax for a custom PaymentIntent), read the tax reference and confirm the user has an active registration. Without one, Stripe calculates and collects no tax while the user believes tax is on (the most common Stripe Tax mistake).

  • Never include payment_method_types in any Stripe API call, with one exception: Terminal (in-person payments) integrations must pass payment_method_types: ['card_present'] on the PaymentIntent. For all other integrations, omit this parameter entirely to enable dynamic payment methods, which enables you to configure payment method settings from the Dashboard and dynamically display the most relevant eligible payment methods to each customer to maximize conversion. To customize which payment methods you accept, use payment_method_configurations or excluded_payment_method_types instead of payment_method_types.

  • When a PaymentIntent or SetupIntent integration requires an explicit allowlist, use allowed_payment_method_types instead of payment_method_types.

  • Never present webhooks as optional. We recommend webhooks for every payment integration and they’re required for subscriptions and asynchronous payment methods. Fulfillment belongs in a handler for both checkout.session.completed and checkout.session.async_payment_succeeded (gated on payment_status), not the success page. See references/payments.md.

  • On API version 2026-03-25.dahlia or later, pass the parameter integration_identifier to checkout.sessions.create to tag sessions with a custom label for tracking and comparing checkout flows in the Dashboard. The label should include a suffix of 8 random letters.

  • Always instantiate a StripeClient and call methods on that instance. Do not use the deprecated global/module-level API key pattern (stripe.api_key = …, Stripe.setApiKey, stripe.Key = …, StripeConfiguration.ApiKey = …). The global pattern is deprecated in all current SDKs.

Key documentation

When the user’s request does not clearly fit a single domain above, consult:

Related Skills

View on GitHub
GitHub Stars1.8k
CategorySecurity
Updated6d ago
Forks348

Languages

TypeScript

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions