> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Stripe Integration: Payments, Customers & Subscriptions for Agents

> Agents can read balances, customers, charges, and subscriptions in Stripe, and create refunds or invoices. Connect in a minute with a restricted API key.

## Overview

OneCLI connects AI agents to [Stripe](https://stripe.com) with a restricted API key. Agents can look up customers, payments, and subscriptions, and take actions like refunds or invoices. The gateway injects the key into every request, so your agent never sees it.

Connecting takes about a minute.

<a id="self-hosted" style={{ scrollMarginTop: "8rem" }} />

## Connect Stripe

<Steps>
  <Step title="Create a restricted key in Stripe">
    In the Stripe Dashboard, open [Developers > API keys](https://dashboard.stripe.com/apikeys) and click **Create restricted key**. Name it `OneCLI` and grant only the permissions your agents need. Start with **Read** and add **Write** only where agents must act.

    Copy the key right away. Restricted keys start with `rk_`.
  </Step>

  <Step title="Paste it in OneCLI">
    In the OneCLI dashboard, open **Connections** > **Stripe**, paste the key into **Restricted API key**, and click **Connect Stripe**. Add a **Label** like `production` or `sandbox` to tell several Stripe accounts apart.

    <Frame caption="The Stripe connect window in OneCLI.">
      <img src="https://mintcdn.com/chartdbinc/yFw2bbdvTPdZgMOT/images/integrations/stripe/onecli-connect-stripe.png?fit=max&auto=format&n=yFw2bbdvTPdZgMOT&q=85&s=6dee084479c6609f0d42868cddf97b25" alt="OneCLI connect window for Stripe, showing the setup guide link, the Restricted API key field, and the Connect Stripe button." width="1056" height="1328" data-path="images/integrations/stripe/onecli-connect-stripe.png" />
    </Frame>

    OneCLI checks the key when you connect. It rejects publishable keys (`pk_`), which can't read account data.
  </Step>
</Steps>

<Note>
  Stripe recommends restricted keys (`rk_`) over secret keys (`sk_`) for AI agents. The key's own permissions are the hard limit on what any agent can do.
</Note>

## What agents can do

| Area | What agents can do |
| - | - |
| **Account** | Read the account, balance, and balance transactions |
| **Customers** | List, read, create, update, and delete customers |
| **Payments** | List charges and payment intents, create or cancel payment intents, create charges and refunds |
| **Billing** | List, create, update, and cancel subscriptions. Create and finalize invoices |
| **Catalog** | List and create products and prices |
| **Operations** | List disputes, payouts, and events. Create payouts |

## Controlling access

[Grant](/docs/guides/agent-access) the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what's blocked. Anything that moves money (**Create refund**, **Create charge**, **Create payout**, **Cancel subscription**) belongs behind approval. Organization [rules](/docs/guides/rules) add guardrails on top. A blocked request never reaches Stripe.

To disconnect, remove the connection in **Connections** > **Stripe**, then roll or delete the key in Stripe under **Developers** > **API keys**.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.