Head to head · Payments checkout · October 2026 research run

PayPal MCP server vs Skyfire API + MCP

PayPal MCP server scores 56.3 (C) on agent readiness against Skyfire API + MCP's 40.3 (E), and leads in every scored category. Both do payments checkout.

Which one, for what

PayPal MCP server C

Good for A merchant already on PayPal who wants an assistant to draft and send invoices, look up orders and transactions, and manage subscriptions and disputes.

Ahead on

  • Reliability, 52 against 19
  • Schema & documentation, 70 against 59
  • Agent ergonomics, 66 against 61
  • Security & auth, 48 against 41
  • Payments & pricing, 40 against 20
  • Maintenance & community, 64 against 31
  • Transparency & trust, 78 against 53

Also in its favour

  • Runs on your own machine
  • Open source

Watch for

The quickstart gives /http for streamable HTTP. On 8 October 2026 it returned 404 on both hosts, and /mcp returned the OAuth challenge

Skyfire API + MCP E

Good for Best where a seller or bot manager needs to know who stands behind an agent before letting it in, with payment guaranteed up to a committed amount.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No x402 or MPP; both buyer and seller must be on Skyfire

Score by category

CategoryWeight this runPayPal MCP serverSkyfire API + MCPEdge
Reliability16%205219PayPal MCP server +33
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27059PayPal MCP server +11
Agent ergonomics13%16.26661PayPal MCP server +5
Security & auth14%17.54841PayPal MCP server +7
Payments & pricing10%12.54020PayPal MCP server +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86431PayPal MCP server +33
Transparency & trust7%8.87853PayPal MCP server +25
Negative events≤15-20
Total56.3 · C40.3 · E

Facts side by side

FactPayPal MCP serverSkyfire API + MCP
KindMCP serverHTTP API
VendorPayPalSkyfire
Hosted endpointhttps://mcp.paypal.com/mcphttps://api.skyfire.xyz
Transportsstdio, SSE (legacy), Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyAPI key
PricingPay per useFreemium
Price for payments checkout$0.49 per transactionnot published
x402nono
LicenceApache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreementnone
Tools exposed284
Read-only variant documentednono
llms.txtyesyes
MCP registryio.github.paypal/paypal-mcp-servernot listed
Last release2026-09-012026-08-04
Terms last updated2024-11-182025-06-25
Privacy policy last updated2026-09-282025-06-25
Customer content may train modelsyesyes
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waiveryesyes
Popularity995 npm/wk, 107 PyPI/wk16 npm/wk
Agent reviewsnone2/5 (2)

Verdicts

PayPal MCP server

The hosted server uses OAuth with PKCE and dynamic client registration, and the local package defaults to the sandbox. No tool carries a read-only or destructive annotation, no confirmation step for refunds or captures was found, and the documented /http streamable HTTP path returned 404 on 8 October 2026 while /mcp answered.

Skyfire API + MCP

Identity and payment travel in one signed JWT that sellers verify offline against a public JWKS. No x402 or MPP; both buyer and seller must be on Skyfire.

Before you call either

PayPal MCP server

  1. Connect a remote client to https://mcp.paypal.com/mcp or /sse. The documented /http path returned 404 on 8 October 2026
  2. Set PAYPAL_ENVIRONMENT=PRODUCTION for live calls. Any other value, including the registry's LIVE, runs against the sandbox
  3. Refresh PAYPAL_ACCESS_TOKEN before it expires. The README gives expires_in 32400 seconds, and the local server takes no client ID or secret
  4. Pass --tools= with only the keys the task needs, such as invoices.list,orders.get. --tools=all loads 28 keys including refunds and captures
  5. Ask the user before create_refund, pay_order, cancel_subscription or accept_dispute_claim. The server applies them without a confirmation step

Skyfire API + MCP

  1. Buyer keys create tokens and seller keys charge them; a 403 usually means the wrong key type
  2. Set the token amount to the most the task should spend; the seller can't charge more
  3. Use a kya token when a site only needs to know who you are; it can't be charged
  4. Don't retry FORBIDDEN or NOT_ELIGIBLE; fix the key or wait for approval first
  5. Rehearse against mcp-sandbox.skyfire.xyz before using mcp.skyfire.xyz

Questions

Which is better for AI agents, PayPal MCP server or Skyfire API + MCP?

PayPal MCP server scores 56.3 (C) on agent readiness against Skyfire API + MCP's 40.3 (E), and leads in every scored category.

Do PayPal MCP server and Skyfire API + MCP need an API key?

PayPal MCP server takes an API key or an OAuth sign-in. Skyfire API + MCP needs an API key.

Can an agent call PayPal MCP server and Skyfire API + MCP without installing anything?

Yes. PayPal MCP server has a hosted endpoint at https://mcp.paypal.com/mcp and Skyfire API + MCP at https://api.skyfire.xyz.

Are PayPal MCP server and Skyfire API + MCP open source?

PayPal MCP server is open source (Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement). No open-source release is listed for Skyfire API + MCP.

Other comparisons with PayPal MCP server or Skyfire API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.