Skip to main content

Overview

OneCLI connects AI agents to Stripe with a restricted API key. Agents can look up customers, payments, and subscriptions, and take actions like refunds or invoices. The gateway injects the key into every request, so your agent never sees it. Connecting takes about a minute.

Connect Stripe

1

Create a restricted key in Stripe

In the Stripe Dashboard, open Developers > API keys and click Create restricted key. Name it OneCLI and grant only the permissions your agents need. Start with Read and add Write only where agents must act.Copy the key right away. Restricted keys start with rk_.
2

Paste it in OneCLI

In the OneCLI dashboard, open Connections > Stripe, paste the key into Restricted API key, and click Connect Stripe. Add a Label like production or sandbox to tell several Stripe accounts apart.
OneCLI connect window for Stripe, showing the setup guide link, the Restricted API key field, and the Connect Stripe button.

The Stripe connect window in OneCLI.

OneCLI checks the key when you connect. It rejects publishable keys (pk_), which can’t read account data.
Stripe recommends restricted keys (rk_) over secret keys (sk_) for AI agents. The key’s own permissions are the hard limit on what any agent can do.

What agents can do

Controlling access

Grant the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what’s blocked. Anything that moves money (Create refund, Create charge, Create payout, Cancel subscription) belongs behind approval. Organization rules add guardrails on top. A blocked request never reaches Stripe. To disconnect, remove the connection in Connections > Stripe, then roll or delete the key in Stripe under Developers > API keys.