{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "paypal-mcp-server",
    "name": "PayPal MCP server",
    "vendor": "PayPal",
    "vendorUrl": "https://www.paypal.com",
    "kind": "mcp",
    "category": "payment-platforms",
    "summary": "PayPal's official MCP server lets a merchant's AI client work with invoices, orders, refunds, disputes, subscriptions, catalogue products and transaction reports. It runs locally through `npx @paypal/mcp` or as a hosted server at mcp.paypal.com with a PayPal login.",
    "url": "https://www.anchorterminal.com/tools/paypal-mcp-server",
    "markdownUrl": "https://www.anchorterminal.com/tools/paypal-mcp-server.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paypal-mcp-server.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paypal-mcp-server.json",
    "repo": "https://github.com/paypal/paypal-mcp-server",
    "license": "Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement",
    "transports": [
      "stdio",
      "sse",
      "streamable-http"
    ],
    "remoteUrl": "https://mcp.paypal.com/mcp",
    "packages": [
      {
        "registry": "npm",
        "name": "@paypal/mcp"
      },
      {
        "registry": "npm",
        "name": "@paypal/agent-toolkit"
      },
      {
        "registry": "pypi",
        "name": "paypal-agent-toolkit"
      }
    ],
    "auth": "mixed",
    "authNotes": "The remote server takes OAuth. The MCP client sends the user to a PayPal login and consent page, using authorisation code with PKCE S256, refresh tokens and dynamic client registration. It also accepts a Bearer header built from a REST app's client ID and secret. The local server takes only a PayPal REST access token in `PAYPAL_ACCESS_TOKEN` or `--access-token`, which the README says lasts 32,400 seconds. A person creates the app in the PayPal Developer Dashboard, and live use needs a PayPal Business account. No scope list for the MCP server was found.",
    "pricing": "usage",
    "pricingNotes": "No charge for the MCP server or the toolkit was found. PayPal's US merchant fees apply to payments made through it, 3.49% plus $0.49 for PayPal Checkout and invoices, 2.99% plus $0.49 for standard card processing, plus 1.5% on international transactions, with no monthly fee on most products (fees page updated 1 October 2026, https://www.paypal.com/us/business/paypal-business-fees). The sandbox is free with a developer account and no card, so an agent can start without a contract.",
    "priceSummary": "3.49% fee",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the MCP quickstart, the agent tools reference, the developer llms.txt indexes or either repository (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 28,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 995,
      "pypiWeekly": 107,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.paypal.com/ai-tools/mcp-server",
    "llmsTxt": "https://developer.paypal.com/llms.txt",
    "registryName": "io.github.paypal/paypal-mcp-server",
    "capabilities": [
      "payments.checkout",
      "accounting.invoices",
      "commerce.orders",
      "commerce.products"
    ],
    "tags": [
      "official",
      "hosted",
      "local",
      "open-source",
      "mcp",
      "oauth",
      "sandbox",
      "llms-txt",
      "typescript",
      "python",
      "status-page",
      "bug-bounty"
    ],
    "lastRelease": "2026-09-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 56.3,
      "grade": "C",
      "agentReady": false,
      "rank": 571,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 66,
        "maintenance": 64,
        "payments": 40,
        "reliability": 52,
        "schema": 70,
        "security": 48,
        "transparency": 78
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 52,
          "points": 10.4,
          "reason": "Graded on the hosted lines, because the remote server at mcp.paypal.com is the surface the quickstart leads to. PayPal's status page at paypal-status.com covers its production products (20). The page is drawn by script, so we read its Atom feed, which on 8 October went back only to 15 August 2026. It shows two resolved degraded-performance events on PayPal payments, on 15 August (refunds, payments, authorisations, orders) and 22 September (Checkout), with no durations given, and no entry naming the MCP server (15 of 30). PayPal states that it doesn't publish rate limits (0). The rate-limiting guide tells callers to read `Retry-After` on 429 and lengthen delays, and the REST APIs take `PayPal-Request-Id`, but the MCP tools have no per-call idempotency argument (10 of 15). No SLA found, and the Developer Agreement gives no uptime guarantee for the sandbox (0). No beta label on the server, but the remote commerce tools are limited to gift cards behind a feature flag and the documented `/http` path returned 404 (7 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 70,
          "points": 11.38,
          "reason": "Each tool is registered with a zod shape that the MCP SDK turns into JSON Schema (25). developer.paypal.com/llms.txt indexes the docs by section, including the MCP and toolkit pages (10). Tool descriptions state the purpose and some say when to choose another tool, such as cancelling instead of deleting an active recurring series, while many are one line (13 of 20). Inputs carry 32 enums plus length and range limits, and list tools bound `page_size` at 100 (12 of 15). The quickstart gives one example prompt and no error reference for the tools was found (6 of 15). The toolkit changelog stops at 1.3.5 from April 2025 although 1.11.0 is current, the MCP repository has none, and in August 2026 the version went to 1.12.0 and back to 1.9.0 after failed builds (4 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 66,
          "points": 10.73,
          "reason": "`--tools=all` loads 28 tools (15), and `--tools=` takes a comma-separated subset, so a client can load only what a task needs (8 back, 23 of 25). List tools take `page`, `page_size`, `total_required` and status or date filters (16 of 20). Errors come back as `ok`, `status`, `code` and a message cut to 200 characters, which is usable but undocumented (10 of 20). Tools are registered with a name, description and schema only, so there is no `readOnlyHint` or `destructiveHint`, and `PayPal-Request-Id` is set only from toolkit context (4 of 20). The sandbox is the default, most tools need few fields, and the toolkit ships for TypeScript and Python (13 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 48,
          "points": 8.4,
          "reason": "The remote server publishes OAuth metadata with authorisation code, PKCE S256, refresh tokens, revocation and dynamic client registration, and no scope list. The local server takes a REST access token that carries the whole app's permissions for about nine hours (22 of 30). `--tools=` narrows the local tool set and the sandbox is the default, but no read-only mode and no confirmation step for refunds, captures or accepting a dispute claim was found (8 of 20). Tools return invoice notes, dispute text and product descriptions written by other people, and the only guidance found is to write clear system prompts and keep human oversight (4 of 15). No audit log or per-call view for MCP use was found in the reviewed pages, and we did not look inside the dashboard (0). security.txt names a HackerOne bug bounty and has no Expires field. We did not read PayPal's certification pages, and neither repository has a security policy file (14 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found in the MCP docs, the developer llms.txt indexes or either repository, and PayPal's Agentic Commerce Protocol and Universal Commerce Protocol pages concern checkout, not paying for calls (0). US fees are public without a login, 3.49% plus $0.49 for PayPal Checkout and 2.99% plus $0.49 for standard cards (20). The sandbox is free with a developer account, with no card and no monthly fee on most products (20). A person has to create the PayPal account and app, and log in for the remote server (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 64,
          "points": 5.6,
          "reason": "`@paypal/mcp` 1.8.1 was published on 28 October 2025, but it loads `@paypal/agent-toolkit` at `latest`, whose 1.11.0 came out on 1 September 2026, 37 days before this check (20 of 30). The toolkit had three npm releases in the last 90 days, 1.9.0 on 10 August, 1.10.0 on 20 August and 1.11.0 on 1 September (20). Pull requests were merged in August 2026. GitHub's API refused us, so the issue queue went unread (8 of 25). The server is in the official registry as `io.github.paypal/paypal-mcp-server`, a GitHub-verified namespace, with a 1.8.1 entry that lists the stdio package and not the remote server (13 of 15). Neither repository has test files, the toolkit's test script only prints an error, CI publishes without testing, and the server depends on the toolkit at `latest` (3 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 78,
          "points": 6.83,
          "note": "editorial 58, provenance 98",
          "reason": "The local server and toolkit are Apache-2.0 on GitHub, though the toolkit's npm metadata says ISC, and the hosted server is closed under the PayPal Developer Agreement (20 of 30). The Privacy Statement of 28 September 2026 gives retention as the relationship plus 10 years, says personal information may be used to train PayPal's AI models, and describes a third-party list updated quarterly with 30 days to object. No statement specific to MCP traffic was found (20 of 30). The Developer Agreement lets PayPal change or discontinue APIs on notice at any time, with 30 days' notice for substantial changes to the agreement, and no deprecation notice for the MCP server or toolkit was found (8 of 20). The toolkit changelog discloses User-Agent telemetry with no opt-out found, and the Privacy Statement's third-party list was not read for data locations (10 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`--tools=all` loads 28 tools (15), and `--tools=` takes a comma-separated subset, so a client can load only what a task needs (8 back, 23 of 25). List tools take `page`, `page_size`, `total_required` and status or date filters (16 of 20). Errors come back as `ok`, `status`, `code` and a message cut to 200 characters, which is usable but undocumented (10 of 20). Tools are registered with a name, description and schema only, so there is no `readOnlyHint` or `destructiveHint`, and `PayPal-Request-Id` is set only from toolkit context (4 of 20). The sandbox is the default, most tools need few fields, and the toolkit ships for TypeScript and Python (13 of 15).",
          "maintenance": "`@paypal/mcp` 1.8.1 was published on 28 October 2025, but it loads `@paypal/agent-toolkit` at `latest`, whose 1.11.0 came out on 1 September 2026, 37 days before this check (20 of 30). The toolkit had three npm releases in the last 90 days, 1.9.0 on 10 August, 1.10.0 on 20 August and 1.11.0 on 1 September (20). Pull requests were merged in August 2026. GitHub's API refused us, so the issue queue went unread (8 of 25). The server is in the official registry as `io.github.paypal/paypal-mcp-server`, a GitHub-verified namespace, with a 1.8.1 entry that lists the stdio package and not the remote server (13 of 15). Neither repository has test files, the toolkit's test script only prints an error, CI publishes without testing, and the server depends on the toolkit at `latest` (3 of 10).",
          "payments": "Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found in the MCP docs, the developer llms.txt indexes or either repository, and PayPal's Agentic Commerce Protocol and Universal Commerce Protocol pages concern checkout, not paying for calls (0). US fees are public without a login, 3.49% plus $0.49 for PayPal Checkout and 2.99% plus $0.49 for standard cards (20). The sandbox is free with a developer account, with no card and no monthly fee on most products (20). A person has to create the PayPal account and app, and log in for the remote server (0).",
          "reliability": "Graded on the hosted lines, because the remote server at mcp.paypal.com is the surface the quickstart leads to. PayPal's status page at paypal-status.com covers its production products (20). The page is drawn by script, so we read its Atom feed, which on 8 October went back only to 15 August 2026. It shows two resolved degraded-performance events on PayPal payments, on 15 August (refunds, payments, authorisations, orders) and 22 September (Checkout), with no durations given, and no entry naming the MCP server (15 of 30). PayPal states that it doesn't publish rate limits (0). The rate-limiting guide tells callers to read `Retry-After` on 429 and lengthen delays, and the REST APIs take `PayPal-Request-Id`, but the MCP tools have no per-call idempotency argument (10 of 15). No SLA found, and the Developer Agreement gives no uptime guarantee for the sandbox (0). No beta label on the server, but the remote commerce tools are limited to gift cards behind a feature flag and the documented `/http` path returned 404 (7 of 10).",
          "schema": "Each tool is registered with a zod shape that the MCP SDK turns into JSON Schema (25). developer.paypal.com/llms.txt indexes the docs by section, including the MCP and toolkit pages (10). Tool descriptions state the purpose and some say when to choose another tool, such as cancelling instead of deleting an active recurring series, while many are one line (13 of 20). Inputs carry 32 enums plus length and range limits, and list tools bound `page_size` at 100 (12 of 15). The quickstart gives one example prompt and no error reference for the tools was found (6 of 15). The toolkit changelog stops at 1.3.5 from April 2025 although 1.11.0 is current, the MCP repository has none, and in August 2026 the version went to 1.12.0 and back to 1.9.0 after failed builds (4 of 15).",
          "security": "The remote server publishes OAuth metadata with authorisation code, PKCE S256, refresh tokens, revocation and dynamic client registration, and no scope list. The local server takes a REST access token that carries the whole app's permissions for about nine hours (22 of 30). `--tools=` narrows the local tool set and the sandbox is the default, but no read-only mode and no confirmation step for refunds, captures or accepting a dispute claim was found (8 of 20). Tools return invoice notes, dispute text and product descriptions written by other people, and the only guidance found is to write clear system prompts and keep human oversight (4 of 15). No audit log or per-call view for MCP use was found in the reviewed pages, and we did not look inside the dashboard (0). security.txt names a HackerOne bug bounty and has no Expires field. We did not read PayPal's certification pages, and neither repository has a security policy file (14 of 20).",
          "transparency": "The local server and toolkit are Apache-2.0 on GitHub, though the toolkit's npm metadata says ISC, and the hosted server is closed under the PayPal Developer Agreement (20 of 30). The Privacy Statement of 28 September 2026 gives retention as the relationship plus 10 years, says personal information may be used to train PayPal's AI models, and describes a third-party list updated quarterly with 30 days to object. No statement specific to MCP traffic was found (20 of 30). The Developer Agreement lets PayPal change or discontinue APIs on notice at any time, with 30 days' notice for substantial changes to the agreement, and no deprecation notice for the MCP server or toolkit was found (8 of 20). The toolkit changelog discloses User-Agent telemetry with no opt-out found, and the Privacy Statement's third-party list was not read for data locations (10 of 20)."
        },
        "sources": [
          {
            "what": "MCP server quickstart",
            "url": "https://developer.paypal.com/ai-tools/mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "agent tools reference",
            "url": "https://developer.paypal.com/ai-tools/agent-tools",
            "seen": "2026-10-08"
          },
          {
            "what": "agent toolkit quickstart",
            "url": "https://developer.paypal.com/ai-tools/toolkit/",
            "seen": "2026-10-08"
          },
          {
            "what": "remote server OAuth metadata",
            "url": "https://mcp.paypal.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "remote server protected resource metadata",
            "url": "https://mcp.paypal.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server repository (clone)",
            "url": "https://github.com/paypal/paypal-mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "agent toolkit repository (clone)",
            "url": "https://github.com/paypal/agent-toolkit",
            "seen": "2026-10-08"
          },
          {
            "what": "npm, @paypal/mcp versions",
            "url": "https://registry.npmjs.org/@paypal/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "npm, @paypal/agent-toolkit versions",
            "url": "https://registry.npmjs.org/@paypal/agent-toolkit",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry entry",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=io.github.paypal",
            "seen": "2026-10-08"
          },
          {
            "what": "status page Atom feed",
            "url": "https://www.paypal-status.com/feed/atom",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limiting guide",
            "url": "https://developer.paypal.com/api/rate-limiting",
            "seen": "2026-10-08"
          },
          {
            "what": "idempotency guide",
            "url": "https://developer.paypal.com/reference/guidelines/idempotency",
            "seen": "2026-10-08"
          },
          {
            "what": "US merchant fees",
            "url": "https://www.paypal.com/us/business/paypal-business-fees",
            "seen": "2026-10-08"
          },
          {
            "what": "PayPal Developer Agreement",
            "url": "https://www.paypal.com/us/legalhub/paypal/xdeveloper-full",
            "seen": "2026-10-08"
          },
          {
            "what": "PayPal Privacy Statement",
            "url": "https://www.paypal.com/us/legalhub/paypal/privacy-full",
            "seen": "2026-10-08"
          },
          {
            "what": "PayPal User Agreement (US)",
            "url": "https://www.paypal.com/us/legalhub/paypal/useragreement-full",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.paypalobjects.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "developer docs llms.txt",
            "url": "https://developer.paypal.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for paypal.com",
            "url": "https://rdap.verisign.com/com/v1/domain/paypal.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the tool list, annotations and scopes the hosted server at mcp.paypal.com returns after login, because we did not authenticate",
          "unchecked: GitHub stars, open issues and security advisories for paypal/agent-toolkit and paypal/paypal-mcp-server, because the GitHub API refused our requests",
          "unchecked: status history before 15 August 2026 and incident durations, because the status page is drawn by script and its feed holds 13 entries",
          "unchecked: PayPal's certification pages (PCI DSS, SOC reports) and the third-party list linked from the Privacy Statement",
          "unchecked: API call logs in the PayPal Developer Dashboard, which need a login",
          "The lead gave a second remote transport without naming its path. The docs name `/http`, which returned 404, and `/mcp` is what answers",
          "The registry entry describes `PAYPAL_ENVIRONMENT` as 'SANDBOX' or 'LIVE', but the code treats every value other than `production` as sandbox",
          "Whether the remote commerce tools (`search_product`, `create_cart`, `checkout_cart`) are open to any account or only by feature flag"
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "8 October 2026. The MCP quickstart (last updated 30 June 2026) gives `https://mcp.paypal.com/http` and `https://mcp.sandbox.paypal.com/http` as the streamable HTTP endpoints. Both returned 404 to an initialise request on 8 October 2026, while `/mcp` on each host returned the OAuth challenge. A documented endpoint that doesn't answer, minus 2 (https://developer.paypal.com/ai-tools/mcp-server)."
      ],
      "verdict": "The hosted server uses OAuth with PKCE and dynamic client registration, and the local package defaults to the sandbox. No tool carries a read-only or destructive annotation, no confirmation step for refunds or captures was found, and the documented `/http` streamable HTTP path returned 404 on 8 October 2026 while `/mcp` answered.",
      "bestFor": "A merchant already on PayPal who wants an assistant to draft and send invoices, look up orders and transactions, and manage subscriptions and disputes.",
      "strengths": [
        "Hosted server at mcp.paypal.com publishes OAuth metadata with authorisation code, PKCE S256, refresh tokens, revocation and dynamic client registration",
        "The local package starts in the sandbox unless `PAYPAL_ENVIRONMENT` is `PRODUCTION`, and `--tools=` limits which tools load",
        "Every tool input is a typed schema with enums and range limits, built from zod definitions in the Apache-2.0 toolkit",
        "US fees are public without a login, and sandbox testing needs no card or monthly fee",
        "Listed in the official MCP registry as `io.github.paypal/paypal-mcp-server`, and the toolkit had three releases between 10 August and 1 September 2026"
      ],
      "weaknesses": [
        "The quickstart gives `/http` for streamable HTTP. On 8 October 2026 it returned 404 on both hosts, and `/mcp` returned the OAuth challenge",
        "Tools are registered without `readOnlyHint` or `destructiveHint`, and no approval step for `create_refund`, `pay_order` or `accept_dispute_claim` was found",
        "`@paypal/mcp` 1.8.1 dates from 28 October 2025 and selects 28 tool keys, while the toolkit it loads defines 48 tools",
        "PayPal states that it doesn't publish rate limits, and no SLA was found. The Developer Agreement gives no uptime guarantee for the sandbox",
        "Neither repository has tests in CI, and the toolkit changelog stops at 1.3.5 from April 2025 although 1.11.0 is current"
      ],
      "agentNotes": [
        "Connect a remote client to `https://mcp.paypal.com/mcp` or `/sse`. The documented `/http` path returned 404 on 8 October 2026",
        "Set `PAYPAL_ENVIRONMENT=PRODUCTION` for live calls. Any other value, including the registry's `LIVE`, runs against the sandbox",
        "Refresh `PAYPAL_ACCESS_TOKEN` before it expires. The README gives `expires_in` 32400 seconds, and the local server takes no client ID or secret",
        "Pass `--tools=` with only the keys the task needs, such as `invoices.list,orders.get`. `--tools=all` loads 28 keys including refunds and captures",
        "Ask the user before `create_refund`, `pay_order`, `cancel_subscription` or `accept_dispute_claim`. The server applies them without a confirmation step"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 56.3
        }
      ],
      "editorialScores": {
        "ergonomics": 66,
        "maintenance": 64,
        "payments": 40,
        "reliability": 52,
        "schema": 70,
        "security": 48,
        "transparency": 58
      },
      "provenanceScore": 98
    },
    "connect": {
      "install": "npx -y @paypal/mcp --tools=all",
      "config": {
        "mcpServers": {
          "paypal": {
            "args": [
              "-y",
              "@paypal/mcp",
              "--tools=all"
            ],
            "command": "npx",
            "env": {
              "PAYPAL_ACCESS_TOKEN": "YOUR_PAYPAL_ACCESS_TOKEN",
              "PAYPAL_ENVIRONMENT": "SANDBOX"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/payments.checkout",
      "tool": "https://letme.dev/paypal-mcp-server"
    },
    "notable": [
      "The quickstart, last updated 30 June 2026, describes a local server run with `npx -y @paypal/mcp --tools=all` and a remote server at https://mcp.paypal.com and https://mcp.sandbox.paypal.com over SSE and streamable HTTP (https://developer.paypal.com/ai-tools/mcp-server)",
      "On 8 October 2026 a POST to `/http` returned 404 on mcp.paypal.com and mcp.sandbox.paypal.com, while `/mcp` and `/sse` returned 401 with an OAuth `WWW-Authenticate` challenge (https://mcp.paypal.com/.well-known/oauth-protected-resource)",
      "The authorisation server metadata lists authorisation code and refresh token grants, PKCE S256, a registration endpoint and a revocation endpoint, with no `scopes_supported` (https://mcp.paypal.com/.well-known/oauth-authorization-server)",
      "The agent tools reference, last updated 28 May 2026, lists 30 merchant tools and three commerce tools (`search_product`, `create_cart`, `checkout_cart`) on the remote server behind the `x-feature-flags: commerce:true` header, for gift cards only (https://developer.paypal.com/ai-tools/agent-tools)",
      "The server code moved to paypal/paypal-mcp-server in October 2025. Its `ACCEPTED_TOOLS` list has 28 keys and it depends on `@paypal/agent-toolkit` at `latest`, which defines 48 tools in 1.11.0 (https://github.com/paypal/paypal-mcp-server)",
      "The PayPal Privacy Statement, last updated 28 September 2026, says PayPal may use personal information to train its AI models and keeps relationship data for the relationship plus 10 years (https://www.paypal.com/us/legalhub/paypal/privacy-full)"
    ],
    "area": "payments",
    "details": [
      {
        "label": "Surfaces",
        "value": "Local stdio server (`npx -y @paypal/mcp`, Node 18 or later) and a hosted server at https://mcp.paypal.com, with a sandbox twin at https://mcp.sandbox.paypal.com"
      },
      {
        "label": "Remote transports",
        "value": "`/sse` and `/mcp` answered with an OAuth challenge on 8 October 2026. The quickstart's `/http` path returned 404"
      },
      {
        "label": "Local tools",
        "value": "28 selectable keys across invoices (7), orders (3), disputes (3), shipment tracking (2), products (4), subscription plans (3), subscriptions (3), transactions (1) and refunds (2)"
      },
      {
        "label": "Toolkit",
        "value": "`@paypal/agent-toolkit` 1.11.0 (1 September 2026) defines 48 tools, including recurring invoice series, invoice search, auto reminders and merchant insights, for MCP, LangChain, OpenAI Agents SDK, Vercel AI SDK, Amazon Bedrock and CrewAI"
      },
      {
        "label": "Remote commerce tools",
        "value": "`search_product`, `create_cart` and `checkout_cart`, enabled with the `x-feature-flags: commerce:true` header and limited to gift cards per the tools reference"
      },
      {
        "label": "Credentials",
        "value": "OAuth login with PKCE and dynamic client registration on the remote server, or a Bearer header from client credentials. A REST access token for the local server"
      },
      {
        "label": "Environment",
        "value": "Sandbox by default. `PAYPAL_ENVIRONMENT=PRODUCTION` or `--paypal-environment=production` switches to live"
      },
      {
        "label": "Rate limits",
        "value": "Not published. PayPal says limits vary by API and environment. 429 responses can carry `Retry-After`, and the docs advise increasing delays between retries"
      },
      {
        "label": "Idempotency",
        "value": "The REST APIs accept `PayPal-Request-Id` on some endpoints. The toolkit sets it only from a `request_id` in its context, with no per-call argument on the tools"
      },
      {
        "label": "Errors",
        "value": "The toolkit returns `ok`, `status`, `code` and a message cut to 200 characters"
      },
      {
        "label": "Status",
        "value": "https://www.paypal-status.com with an Atom feed at `/feed/atom`. The feed on 8 October 2026 went back to 15 August 2026"
      },
      {
        "label": "Security programme",
        "value": "Bug bounty on HackerOne named in security.txt, which has no Expires field"
      }
    ],
    "unitPrices": [
      {
        "item": "PayPal Checkout, US domestic",
        "unit": "pct",
        "usd": 3.49,
        "note": "plus $0.49 per transaction"
      },
      {
        "item": "PayPal Checkout fixed fee, USD",
        "unit": "tx",
        "usd": 0.49
      },
      {
        "item": "Standard card processing, US domestic",
        "unit": "pct",
        "usd": 2.99,
        "note": "plus $0.49 per transaction"
      },
      {
        "item": "International commercial transaction surcharge",
        "unit": "pct",
        "usd": 1.5
      },
      {
        "item": "Standard dispute fee",
        "unit": "tx",
        "usd": 15
      }
    ],
    "provenance": {
      "legalEntity": "PayPal, Inc.",
      "domain": "paypal.com",
      "domainRegistered": "1999-07-15",
      "endpointOnVendorDomain": true,
      "terms": "https://www.paypal.com/us/legalhub/paypal/xdeveloper-full",
      "privacy": "https://www.paypal.com/us/legalhub/paypal/privacy-full",
      "statusPage": "https://www.paypal-status.com",
      "changelog": "https://github.com/paypal/agent-toolkit/blob/main/typescript/CHANGELOG.md",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The PayPal Developer Agreement, last updated 18 November 2024, governs the Developer's Tools and API calls and takes precedence over the User Agreement for them. US users contract with PayPal, Inc. and some other regions with PayPal Pte. Ltd.",
        "The US User Agreement (last updated 14 September 2026) and Privacy Statement (last updated 28 September 2026) name PayPal, Inc.",
        "www.paypal.com/.well-known/security.txt redirects to www.paypalobjects.com and names the HackerOne programme. It has no Expires field.",
        "The toolkit changelog on GitHub stops at 1.3.5 from 23 April 2025. Later releases are visible only as tags and npm versions.",
        "RDAP for paypal.com gives a registration date of 1999-07-15. The status page is on paypal-status.com, a separate domain."
      ],
      "score": 98,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "PayPal, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "paypal.com, registered 1999-07-15 (27 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "mcp.paypal.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "www.paypal-status.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.paypal.com/us/legalhub/paypal/xdeveloper-full",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2024-11-18",
          "words": 14297,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated on November 18, 2024",
              "says": "Last updated 2024-11-18"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "…waiving any other rights or remedies) to injunctive or equitable relief as may be deemed proper by a court of competent jurisdiction, without obligation to post any bond."
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN NO EVENT SHALL WE, THE OTHER COMPANIES IN OUR CORPORATE GROUP, PERSONS WHO ACT ON OUR BEHALF, AND/OR THE PERSONS WE ENTER INTO CONTRACTS WITH BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL OR EXEMPLARY DAMAGES ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT, OUR SERVICES, OUR WEBSITES, DEVELOPER…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If you revoke this license, this Agreement will immediately terminate."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "This fee may be added to your initial rate when you first sign up for the PayPal Services, or may be added at any time by PayPal with 30 days' prior written notice of the fee increase.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not agree to these terms and conditions, you may not access or use the Developer’s Tools."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "and (b) must be accepted “as is,” without any express or implied warranties or service levels, including without limitation, the warranties of merchantability, fitness for a particular purpose and non-infringement."
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "PayPal may also impose limits on certain features and services or restrict your access to parts of or all of the Developer’s Tools without notice or liability."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "In the event you have a dispute with PayPal, the relevant provisions (including arbitration requirements) of your PayPal User Agreement will govern the dispute."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "PayPal may use the developer's trade marks to publicise the developer's use of the Developer's Tools and its application.",
              "quote": "You grant PayPal a revocable, non-exclusive, non-transferable, worldwide, royalty-free license to use your Marks to publicize your use of the Developer’s Tools and your Application."
            },
            {
              "date": "2026-10-08",
              "text": "The developer is liable for all activity carried out with its App ID, API credentials or other PayPal account credentials.",
              "quote": "You are liable for all activities performed with your App ID, API Credentials or other PayPal Account credentials."
            },
            {
              "date": "2026-10-08",
              "text": "Listed categories of PayPal user information must be deleted within 48 hours of receipt.",
              "quote": "The following PayPal User Information must be deleted within 48 hours of receipt:"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.paypal.com/us/legalhub/paypal/privacy-full",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-28",
          "words": 19886,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated on September 28, 2026",
              "says": "Last updated 2026-09-28"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Categories of Personal Information collected from you, including from your interactions with us and use of the Services:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "…relationship between you and PayPal is stored for the duration of the relationship plus a period of 10 years or such period as mandated by any applicable local law once our relationship comes to an end, unless we need to keep it longer to the extent permitted by applicable law, such as:",
              "says": "Names a period of 10 years"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Third parties, including service providers, Partners and Merchants, payment partners, such as payment networks and processors, credit reporting agencies and public and private credit databases (\"CRAs\"), government entities, data brokers, and financial institutions."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We also use Personal Information to allow you to participate in certain features that may be of interest to you, such as syncing your contact list to your account, personalizing content and offers, targeted advertising, or connecting to a third-party platform."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Your right to know and request a copy of the Personal Information."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "In compliance with LGPD article 41, the identity and contact information of the Data Protection Officer (DPO) and of his deputy (Deputy DPO) are the following:",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "(ii) the recipient has signed appropriate contractual terms with us that incorporate the European Commission’s Standard Contractual Clauses or the UK Information Commissioner’s International Data Transfer Agreement or International Data Transfer Addendum (as applicable);",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "We may use Personal Information to train our artificial intelligence (AI) models that power our Services and help us deliver more secure, efficient, and personalized services.",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Agentic AI tools that PayPal makes available have access to the user's personal information, including purchase history and payment information.",
              "quote": "When you use these tools, they will have access to your Personal Information, including queries, preferences, interests, purchase history, and payment information."
            },
            {
              "date": "2026-10-08",
              "text": "PayPal may disclose customers' personal information to partners and merchants so that they and PayPal can personalise services and promotions.",
              "quote": "For our PayPal customers, we may also disclose your Personal Information to Partners and Merchants that you and we interact with to help ourselves and Partners and Merchants personalize services and offers so you can have a better and more relevant experience."
            },
            {
              "date": "2026-10-08",
              "text": "PayPal continues to share a person's information as described in its financial privacy notice after that person stops being a customer.",
              "quote": "When you are no longer our customer, we continue to share your information as described in this notice."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/paypal-mcp-server.json",
    "live": {
      "slug": "paypal-mcp-server",
      "probe": {
        "target": "https://mcp.paypal.com/mcp",
        "method": "mcp-initialize",
        "lastAt": "2026-10-09T10:42:52.197242752Z",
        "lastOk": true,
        "lastStatus": 401,
        "lastMs": 76,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 60,
        "p95ms24h": 157,
        "samples24h": 33,
        "samples30d": 33,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 33,
            "ok": 33
          }
        ]
      },
      "vendorStatus": {
        "page": "https://www.paypal-status.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:58:24.882591825Z"
      },
      "updatedAt": "2026-10-09T10:42:52.197242752Z"
    }
  }
}
