{
  "data": {
    "a": {
      "slug": "paypal-mcp-server",
      "name": "PayPal MCP server",
      "vendor": "PayPal",
      "vendorUrl": "https://www.paypal.com",
      "kind": "mcp",
      "category": "payment-platforms",
      "summary": "PayPal's official MCP server lets a merchant's AI client work with invoices, orders, refunds, disputes, subscriptions, catalogue products and transaction reports. It runs locally through `npx @paypal/mcp` or as a hosted server at mcp.paypal.com with a PayPal login.",
      "url": "https://www.anchorterminal.com/tools/paypal-mcp-server",
      "markdownUrl": "https://www.anchorterminal.com/tools/paypal-mcp-server.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paypal-mcp-server.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paypal-mcp-server.json",
      "repo": "https://github.com/paypal/paypal-mcp-server",
      "license": "Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement",
      "transports": [
        "stdio",
        "sse",
        "streamable-http"
      ],
      "remoteUrl": "https://mcp.paypal.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@paypal/mcp"
        },
        {
          "registry": "npm",
          "name": "@paypal/agent-toolkit"
        },
        {
          "registry": "pypi",
          "name": "paypal-agent-toolkit"
        }
      ],
      "auth": "mixed",
      "authNotes": "The remote server takes OAuth. The MCP client sends the user to a PayPal login and consent page, using authorisation code with PKCE S256, refresh tokens and dynamic client registration. It also accepts a Bearer header built from a REST app's client ID and secret. The local server takes only a PayPal REST access token in `PAYPAL_ACCESS_TOKEN` or `--access-token`, which the README says lasts 32,400 seconds. A person creates the app in the PayPal Developer Dashboard, and live use needs a PayPal Business account. No scope list for the MCP server was found.",
      "pricing": "usage",
      "pricingNotes": "No charge for the MCP server or the toolkit was found. PayPal's US merchant fees apply to payments made through it, 3.49% plus $0.49 for PayPal Checkout and invoices, 2.99% plus $0.49 for standard card processing, plus 1.5% on international transactions, with no monthly fee on most products (fees page updated 1 October 2026, https://www.paypal.com/us/business/paypal-business-fees). The sandbox is free with a developer account and no card, so an agent can start without a contract.",
      "priceSummary": "3.49% fee",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the MCP quickstart, the agent tools reference, the developer llms.txt indexes or either repository (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 28,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 995,
        "pypiWeekly": 107,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.paypal.com/ai-tools/mcp-server",
      "llmsTxt": "https://developer.paypal.com/llms.txt",
      "registryName": "io.github.paypal/paypal-mcp-server",
      "capabilities": [
        "payments.checkout",
        "accounting.invoices",
        "commerce.orders",
        "commerce.products"
      ],
      "tags": [
        "official",
        "hosted",
        "local",
        "open-source",
        "mcp",
        "oauth",
        "sandbox",
        "llms-txt",
        "typescript",
        "python",
        "status-page",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.3,
        "grade": "C",
        "agentReady": false,
        "rank": 571,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 64,
          "payments": 40,
          "reliability": 52,
          "schema": 70,
          "security": 48,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "8 October 2026. The MCP quickstart (last updated 30 June 2026) gives `https://mcp.paypal.com/http` and `https://mcp.sandbox.paypal.com/http` as the streamable HTTP endpoints. Both returned 404 to an initialise request on 8 October 2026, while `/mcp` on each host returned the OAuth challenge. A documented endpoint that doesn't answer, minus 2 (https://developer.paypal.com/ai-tools/mcp-server)."
        ],
        "verdict": "The hosted server uses OAuth with PKCE and dynamic client registration, and the local package defaults to the sandbox. No tool carries a read-only or destructive annotation, no confirmation step for refunds or captures was found, and the documented `/http` streamable HTTP path returned 404 on 8 October 2026 while `/mcp` answered.",
        "bestFor": "A merchant already on PayPal who wants an assistant to draft and send invoices, look up orders and transactions, and manage subscriptions and disputes.",
        "strengths": [
          "Hosted server at mcp.paypal.com publishes OAuth metadata with authorisation code, PKCE S256, refresh tokens, revocation and dynamic client registration",
          "The local package starts in the sandbox unless `PAYPAL_ENVIRONMENT` is `PRODUCTION`, and `--tools=` limits which tools load",
          "Every tool input is a typed schema with enums and range limits, built from zod definitions in the Apache-2.0 toolkit",
          "US fees are public without a login, and sandbox testing needs no card or monthly fee",
          "Listed in the official MCP registry as `io.github.paypal/paypal-mcp-server`, and the toolkit had three releases between 10 August and 1 September 2026"
        ],
        "weaknesses": [
          "The quickstart gives `/http` for streamable HTTP. On 8 October 2026 it returned 404 on both hosts, and `/mcp` returned the OAuth challenge",
          "Tools are registered without `readOnlyHint` or `destructiveHint`, and no approval step for `create_refund`, `pay_order` or `accept_dispute_claim` was found",
          "`@paypal/mcp` 1.8.1 dates from 28 October 2025 and selects 28 tool keys, while the toolkit it loads defines 48 tools",
          "PayPal states that it doesn't publish rate limits, and no SLA was found. The Developer Agreement gives no uptime guarantee for the sandbox",
          "Neither repository has tests in CI, and the toolkit changelog stops at 1.3.5 from April 2025 although 1.11.0 is current"
        ],
        "agentNotes": [
          "Connect a remote client to `https://mcp.paypal.com/mcp` or `/sse`. The documented `/http` path returned 404 on 8 October 2026",
          "Set `PAYPAL_ENVIRONMENT=PRODUCTION` for live calls. Any other value, including the registry's `LIVE`, runs against the sandbox",
          "Refresh `PAYPAL_ACCESS_TOKEN` before it expires. The README gives `expires_in` 32400 seconds, and the local server takes no client ID or secret",
          "Pass `--tools=` with only the keys the task needs, such as `invoices.list,orders.get`. `--tools=all` loads 28 keys including refunds and captures",
          "Ask the user before `create_refund`, `pay_order`, `cancel_subscription` or `accept_dispute_claim`. The server applies them without a confirmation step"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.3
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 64,
          "payments": 40,
          "reliability": 52,
          "schema": 70,
          "security": 48,
          "transparency": 58
        },
        "provenanceScore": 98
      },
      "connect": {
        "install": "npx -y @paypal/mcp --tools=all",
        "config": {
          "mcpServers": {
            "paypal": {
              "args": [
                "-y",
                "@paypal/mcp",
                "--tools=all"
              ],
              "command": "npx",
              "env": {
                "PAYPAL_ACCESS_TOKEN": "YOUR_PAYPAL_ACCESS_TOKEN",
                "PAYPAL_ENVIRONMENT": "SANDBOX"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/payments.checkout",
        "tool": "https://letme.dev/paypal-mcp-server"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "PayPal Checkout, US domestic",
          "unit": "pct",
          "usd": 3.49,
          "note": "plus $0.49 per transaction"
        },
        {
          "item": "PayPal Checkout fixed fee, USD",
          "unit": "tx",
          "usd": 0.49
        },
        {
          "item": "Standard card processing, US domestic",
          "unit": "pct",
          "usd": 2.99,
          "note": "plus $0.49 per transaction"
        },
        {
          "item": "International commercial transaction surcharge",
          "unit": "pct",
          "usd": 1.5
        },
        {
          "item": "Standard dispute fee",
          "unit": "tx",
          "usd": 15
        }
      ],
      "provenance": {
        "legalEntity": "PayPal, Inc.",
        "domain": "paypal.com",
        "domainRegistered": "1999-07-15",
        "endpointOnVendorDomain": true,
        "terms": "https://www.paypal.com/us/legalhub/paypal/xdeveloper-full",
        "privacy": "https://www.paypal.com/us/legalhub/paypal/privacy-full",
        "statusPage": "https://www.paypal-status.com",
        "changelog": "https://github.com/paypal/agent-toolkit/blob/main/typescript/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The PayPal Developer Agreement, last updated 18 November 2024, governs the Developer's Tools and API calls and takes precedence over the User Agreement for them. US users contract with PayPal, Inc. and some other regions with PayPal Pte. Ltd.",
          "The US User Agreement (last updated 14 September 2026) and Privacy Statement (last updated 28 September 2026) name PayPal, Inc.",
          "www.paypal.com/.well-known/security.txt redirects to www.paypalobjects.com and names the HackerOne programme. It has no Expires field.",
          "The toolkit changelog on GitHub stops at 1.3.5 from 23 April 2025. Later releases are visible only as tags and npm versions.",
          "RDAP for paypal.com gives a registration date of 1999-07-15. The status page is on paypal-status.com, a separate domain."
        ],
        "score": 98
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/paypal-mcp-server.json",
      "live": {
        "slug": "paypal-mcp-server",
        "probe": {
          "target": "https://mcp.paypal.com/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-09T11:46:36.683353195Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 45,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 59,
          "p95ms24h": 138,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.paypal-status.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:24.882591825Z"
        },
        "updatedAt": "2026-10-09T11:46:36.683353195Z"
      }
    },
    "answer": "PayPal MCP server scores 56.3 (C) on agent readiness against Skyfire API + MCP's 40.3 (E), and leads in every scored category.",
    "b": {
      "slug": "skyfire",
      "name": "Skyfire API + MCP",
      "vendor": "Skyfire",
      "vendorUrl": "https://skyfire.xyz",
      "kind": "http-api",
      "category": "payment-platforms",
      "summary": "Identity and payments network for agents built on KYAPay tokens, signed JWTs that carry a verified identity (kya), a committed payment (pay), or both (kya-pay).",
      "url": "https://www.anchorterminal.com/tools/skyfire",
      "markdownUrl": "https://www.anchorterminal.com/tools/skyfire.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/skyfire.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/skyfire.json",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.skyfire.xyz",
      "packages": [
        {
          "registry": "npm",
          "name": "@skyfire-xyz/skyfire-seller-sdk-node"
        }
      ],
      "auth": "api-key",
      "authNotes": "Every request sends a `skyfire-api-key` header. Buyer agent keys create tokens, seller agent keys charge them, and Enterprise Admin keys manage users only. The MCP server takes the same header. Sellers verify tokens against the JWKS at app.skyfire.xyz.",
      "pricing": "freemium",
      "pricingNotes": "No published price list. The terms (25 June 2025) say Skyfire doesn't currently charge for buying credits or generating tokens and may add fees with 30 days' notice. Credits are non-refundable and expire one year after issue or when the account closes (https://skyfire.xyz/terms-of-service/).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "Skyfire uses its own KYAPay token format in a header rather than x402 challenges; no x402 support is documented (https://docs.skyfire.xyz/docs/kyapay-tokens).",
        "endpoints": []
      },
      "toolCount": 4,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 16,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.skyfire.xyz",
      "llmsTxt": "https://docs.skyfire.xyz/llms.txt",
      "capabilities": [
        "payments.stablecoin",
        "payments.card",
        "payments.checkout"
      ],
      "tags": [
        "hosted",
        "mcp",
        "llms-txt",
        "stablecoin",
        "wallet",
        "closed-source"
      ],
      "lastRelease": "2026-08-04",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 40.3,
        "grade": "E",
        "agentReady": false,
        "rank": 806,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 31,
          "payments": 20,
          "reliability": 19,
          "schema": 59,
          "security": 41,
          "transparency": 53
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Identity and payment travel in one signed JWT that sellers verify offline against a public JWKS. No x402 or MPP; both buyer and seller must be on Skyfire.",
        "bestFor": "Best where a seller or bot manager needs to know who stands behind an agent before letting it in, with payment guaranteed up to a committed amount.",
        "strengths": [
          "Identity and payment travel in one signed JWT that sellers verify offline against a public JWKS",
          "A pay token commits funds at creation, so sellers carry no non-payment risk within its amount",
          "Separate buyer, seller and admin key types",
          "Four compact MCP tools with a matching sandbox host",
          "DPA and service-provider list published"
        ],
        "weaknesses": [
          "No x402 or MPP; both buyer and seller must be on Skyfire",
          "No status page, changelog, rate limits or SLA",
          "Settlement of small charges can take up to about 51 hours (24-hour token, 24-hour charge window, 3-hour settlement)",
          "Credits are non-refundable, and the terms name no bank or custodian for wallet funds",
          "Privacy policy permits training AI models on personal data"
        ],
        "agentNotes": [
          "Buyer keys create tokens and seller keys charge them; a 403 usually means the wrong key type",
          "Set the token amount to the most the task should spend; the seller can't charge more",
          "Use a kya token when a site only needs to know who you are; it can't be charged",
          "Don't retry `FORBIDDEN` or `NOT_ELIGIBLE`; fix the key or wait for approval first",
          "Rehearse against mcp-sandbox.skyfire.xyz before using mcp.skyfire.xyz"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 40.3
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 31,
          "payments": 20,
          "reliability": 19,
          "schema": 59,
          "security": 41,
          "transparency": 50
        },
        "provenanceScore": 56
      },
      "connect": {
        "http": "curl -X POST https://api.skyfire.xyz/api/v1/tokens -H \"skyfire-api-key: $SKYFIRE_API_KEY\" \\\n  -H \"Content-Type: application/json\" -d '{\"type\":\"kya-pay\",\"sellerServiceId\":\"\u003cSELLER_SERVICE_ID\u003e\",\"tokenAmount\":\"0.01\"}'",
        "claudeCode": "claude mcp add --transport http skyfire https://mcp.skyfire.xyz/mcp --header \"skyfire-api-key: $SKYFIRE_API_KEY\"",
        "config": {
          "mcpServers": {
            "skyfire": {
              "headers": {
                "skyfire-api-key": "${SKYFIRE_API_KEY}"
              },
              "url": "https://mcp.skyfire.xyz/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/payments.stablecoin",
        "tool": "https://letme.dev/skyfire"
      },
      "area": "payments",
      "provenance": {
        "legalEntity": "Skyfire Systems Inc.",
        "domain": "skyfire.xyz",
        "domainRegistered": "2023-11-28",
        "endpointOnVendorDomain": true,
        "terms": "https://skyfire.xyz/terms-of-service/",
        "privacy": "https://skyfire.xyz/privacy-policy/",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/skyfire.json",
      "live": {
        "slug": "skyfire",
        "probe": {
          "target": "https://api.skyfire.xyz",
          "method": "get",
          "lastAt": "2026-10-09T11:46:40.737927363Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 480,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 99.96,
          "p50ms24h": 503,
          "p95ms24h": 579,
          "samples24h": 259,
          "samples30d": 2311,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 271
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@skyfire-xyz/skyfire-seller-sdk-node",
            "version": "0.0.7",
            "seenAt": "2026-10-08T16:29:37.322920713Z"
          }
        ],
        "npmWeekly": 5,
        "securityTxt": {
          "url": "https://skyfire.xyz/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:09.855335127Z"
        },
        "llmsTxt": {
          "url": "https://docs.skyfire.xyz/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:52.358280511Z"
        },
        "domain": {
          "domain": "skyfire.xyz",
          "registered": "2023-11-28",
          "source": "https://rdap.centralnic.com/xyz/domain/skyfire.xyz",
          "checkedAt": "2026-10-04T13:09:03.55575612Z"
        },
        "pages": [
          {
            "url": "https://skyfire.xyz/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:22.109668681Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c1150a5691ff"
          },
          {
            "url": "https://skyfire.xyz/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:24.386298589Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "144fa8551297"
          }
        ],
        "updatedAt": "2026-10-09T11:46:40.737927363Z"
      }
    },
    "facts": [
      {
        "a": "MCP server",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "PayPal",
        "b": "Skyfire",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.paypal.com/mcp",
        "b": "https://api.skyfire.xyz",
        "name": "Hosted endpoint"
      },
      {
        "a": "stdio, SSE (legacy), Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "$0.49 per transaction",
        "b": "not published",
        "name": "Price for payments checkout"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement",
        "b": "none",
        "name": "Licence"
      },
      {
        "a": "28",
        "b": "4",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "io.github.paypal/paypal-mcp-server",
        "b": "not listed",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-01",
        "b": "2026-08-04",
        "name": "Last release"
      },
      {
        "a": "2024-11-18",
        "b": "2025-06-25",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-28",
        "b": "2025-06-25",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "995 npm/wk, 107 PyPI/wk",
        "b": "16 npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "PayPal MCP server scores 56.3 (C) on agent readiness against Skyfire API + MCP's 40.3 (E), and leads in every scored category.",
        "question": "Which is better for AI agents, PayPal MCP server or Skyfire API + MCP?"
      },
      {
        "answer": "PayPal MCP server takes an API key or an OAuth sign-in. Skyfire API + MCP needs an API key.",
        "question": "Do PayPal MCP server and Skyfire API + MCP need an API key?"
      },
      {
        "answer": "Yes. PayPal MCP server has a hosted endpoint at https://mcp.paypal.com/mcp and Skyfire API + MCP at https://api.skyfire.xyz.",
        "question": "Can an agent call PayPal MCP server and Skyfire API + MCP without installing anything?"
      },
      {
        "answer": "PayPal MCP server is open source (Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement). No open-source release is listed for Skyfire API + MCP.",
        "question": "Are PayPal MCP server and Skyfire API + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 52 against 19",
          "Schema \u0026 documentation, 70 against 59",
          "Agent ergonomics, 66 against 61",
          "Security \u0026 auth, 48 against 41",
          "Payments \u0026 pricing, 40 against 20",
          "Maintenance \u0026 community, 64 against 31",
          "Transparency \u0026 trust, 78 against 53"
        ],
        "also": [
          "Runs on your own machine",
          "Open source"
        ],
        "goodFor": "A merchant already on PayPal who wants an assistant to draft and send invoices, look up orders and transactions, and manage subscriptions and disputes.",
        "slug": "paypal-mcp-server",
        "watchFor": "The quickstart gives `/http` for streamable HTTP. On 8 October 2026 it returned 404 on both hosts, and `/mcp` returned the OAuth challenge"
      },
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "Best where a seller or bot manager needs to know who stands behind an agent before letting it in, with payment guaranteed up to a committed amount.",
        "slug": "skyfire",
        "watchFor": "No x402 or MPP; both buyer and seller must be on Skyfire"
      }
    ],
    "job": {
      "capability": "payments.checkout",
      "name": "Payments checkout"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/adyen-mcp-server-vs-paypal-mcp-server.json",
        "title": "Adyen MCP server vs PayPal MCP server",
        "url": "https://www.anchorterminal.com/compare/adyen-mcp-server-vs-paypal-mcp-server"
      },
      {
        "json": "https://www.anchorterminal.com/compare/adyen-mcp-server-vs-skyfire.json",
        "title": "Adyen MCP server vs Skyfire API + MCP",
        "url": "https://www.anchorterminal.com/compare/adyen-mcp-server-vs-skyfire"
      },
      {
        "json": "https://www.anchorterminal.com/compare/crossmint-vs-paypal-mcp-server.json",
        "title": "Crossmint API + Docs MCP vs PayPal MCP server",
        "url": "https://www.anchorterminal.com/compare/crossmint-vs-paypal-mcp-server"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nevermined-vs-paypal-mcp-server.json",
        "title": "Nevermined API + MCP vs PayPal MCP server",
        "url": "https://www.anchorterminal.com/compare/nevermined-vs-paypal-mcp-server"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paypal-mcp-server-vs-stripe-mcp.json",
        "title": "PayPal MCP server vs Stripe API + MCP",
        "url": "https://www.anchorterminal.com/compare/paypal-mcp-server-vs-stripe-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/crossmint-vs-skyfire.json",
        "title": "Crossmint API + Docs MCP vs Skyfire API + MCP",
        "url": "https://www.anchorterminal.com/compare/crossmint-vs-skyfire"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payman-vs-skyfire.json",
        "title": "Payman Genie MCP vs Skyfire API + MCP",
        "url": "https://www.anchorterminal.com/compare/payman-vs-skyfire"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nevermined-vs-skyfire.json",
        "title": "Nevermined API + MCP vs Skyfire API + MCP",
        "url": "https://www.anchorterminal.com/compare/nevermined-vs-skyfire"
      },
      {
        "json": "https://www.anchorterminal.com/compare/skyfire-vs-stripe-mcp.json",
        "title": "Skyfire API + MCP vs Stripe API + MCP",
        "url": "https://www.anchorterminal.com/compare/skyfire-vs-stripe-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/skyfire-vs-tempo.json",
        "title": "Skyfire API + MCP vs Tempo",
        "url": "https://www.anchorterminal.com/compare/skyfire-vs-tempo"
      }
    ],
    "scores": [
      {
        "by": 33,
        "edge": "paypal-mcp-server",
        "key": "reliability",
        "name": "Reliability",
        "paypal-mcp-server": 52,
        "skyfire": 19,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 11,
        "edge": "paypal-mcp-server",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "paypal-mcp-server": 70,
        "skyfire": 59,
        "weight": 13
      },
      {
        "by": 5,
        "edge": "paypal-mcp-server",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "paypal-mcp-server": 66,
        "skyfire": 61,
        "weight": 13
      },
      {
        "by": 7,
        "edge": "paypal-mcp-server",
        "key": "security",
        "name": "Security \u0026 auth",
        "paypal-mcp-server": 48,
        "skyfire": 41,
        "weight": 14
      },
      {
        "by": 20,
        "edge": "paypal-mcp-server",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "paypal-mcp-server": 40,
        "skyfire": 20,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 33,
        "edge": "paypal-mcp-server",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "paypal-mcp-server": 64,
        "skyfire": 31,
        "weight": 7
      },
      {
        "by": 25,
        "edge": "paypal-mcp-server",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "paypal-mcp-server": 78,
        "skyfire": 53,
        "weight": 7
      }
    ],
    "summary": "PayPal MCP server scores 56.3 (C) on agent readiness against Skyfire API + MCP's 40.3 (E), and leads in every scored category. Both do payments checkout.",
    "verdicts": {
      "paypal-mcp-server": "The hosted server uses OAuth with PKCE and dynamic client registration, and the local package defaults to the sandbox. No tool carries a read-only or destructive annotation, no confirmation step for refunds or captures was found, and the documented `/http` streamable HTTP path returned 404 on 8 October 2026 while `/mcp` answered.",
      "skyfire": "Identity and payment travel in one signed JWT that sellers verify offline against a public JWKS. No x402 or MPP; both buyer and seller must be on Skyfire."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/paypal-mcp-server-vs-skyfire",
    "json": "https://www.anchorterminal.com/compare/paypal-mcp-server-vs-skyfire.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/paypal-mcp-server-vs-skyfire.md",
    "slim": "https://www.anchorterminal.com/compare/paypal-mcp-server-vs-skyfire.min.md"
  },
  "markdown": "PayPal MCP server scores 56.3 (C) on agent readiness against Skyfire API + MCP's 40.3 (E), and leads in every scored category. Both do payments checkout.\n\n- PayPal MCP server: grade C, 56.3/100, rank #571 of 842. Markdown https://www.anchorterminal.com/tools/paypal-mcp-server.md · JSON https://www.anchorterminal.com/api/v1/tools/paypal-mcp-server.json\n- Skyfire API + MCP: grade E, 40.3/100, rank #806 of 842. Markdown https://www.anchorterminal.com/tools/skyfire.md · JSON https://www.anchorterminal.com/api/v1/tools/skyfire.json\n\n## Which one, for what\n\n### PayPal MCP server (C)\n\nGood for: A merchant already on PayPal who wants an assistant to draft and send invoices, look up orders and transactions, and manage subscriptions and disputes.\n\nAhead on:\n- Reliability, 52 against 19\n- Schema \u0026 documentation, 70 against 59\n- Agent ergonomics, 66 against 61\n- Security \u0026 auth, 48 against 41\n- Payments \u0026 pricing, 40 against 20\n- Maintenance \u0026 community, 64 against 31\n- Transparency \u0026 trust, 78 against 53\n\nAlso in its favour:\n- Runs on your own machine\n- Open source\n\nWatch for: The quickstart gives `/http` for streamable HTTP. On 8 October 2026 it returned 404 on both hosts, and `/mcp` returned the OAuth challenge\n\n### Skyfire API + MCP (E)\n\nGood for: Best where a seller or bot manager needs to know who stands behind an agent before letting it in, with payment guaranteed up to a committed amount.\n\nWatch for: No x402 or MPP; both buyer and seller must be on Skyfire\n\n\n## Score by category\n\n| Category | Weight | PayPal MCP server | Skyfire API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 52 | 19 | PayPal MCP server +33 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 59 | PayPal MCP server +11 |\n| Agent ergonomics | 13% (16.2 this run) | 66 | 61 | PayPal MCP server +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 48 | 41 | PayPal MCP server +7 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 20 | PayPal MCP server +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 64 | 31 | PayPal MCP server +33 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 78 | 53 | PayPal MCP server +25 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **56.3 · C** | **40.3 · E** | |\n\n## Facts side by side\n\n| Fact | PayPal MCP server | Skyfire API + MCP |\n| --- | --- | --- |\n| Kind | MCP server | HTTP API |\n| Vendor | PayPal | Skyfire |\n| Hosted endpoint | `https://mcp.paypal.com/mcp` | `https://api.skyfire.xyz` |\n| Transports | stdio, SSE (legacy), Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | API key |\n| Pricing | Pay per use | Freemium |\n| Price for payments checkout | $0.49 per transaction | not published |\n| x402 | no | no |\n| Licence | Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement | none |\n| Tools exposed | 28 | 4 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | `io.github.paypal/paypal-mcp-server` | not listed |\n| Last release | 2026-09-01 | 2026-08-04 |\n| Terms last updated | 2024-11-18 | 2025-06-25 |\n| Privacy policy last updated | 2026-09-28 | 2025-06-25 |\n| Customer content may train models | yes | yes |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 995 npm/wk, 107 PyPI/wk | 16 npm/wk |\n| Agent reviews | none | 2/5 (2) |\n\n## Verdicts\n\n**PayPal MCP server.** The hosted server uses OAuth with PKCE and dynamic client registration, and the local package defaults to the sandbox. No tool carries a read-only or destructive annotation, no confirmation step for refunds or captures was found, and the documented `/http` streamable HTTP path returned 404 on 8 October 2026 while `/mcp` answered.\n\n**Skyfire API + MCP.** Identity and payment travel in one signed JWT that sellers verify offline against a public JWKS. No x402 or MPP; both buyer and seller must be on Skyfire.\n\n## Before you call either\n\n### PayPal MCP server\n\n1. Connect a remote client to `https://mcp.paypal.com/mcp` or `/sse`. The documented `/http` path returned 404 on 8 October 2026\n2. Set `PAYPAL_ENVIRONMENT=PRODUCTION` for live calls. Any other value, including the registry's `LIVE`, runs against the sandbox\n3. Refresh `PAYPAL_ACCESS_TOKEN` before it expires. The README gives `expires_in` 32400 seconds, and the local server takes no client ID or secret\n4. Pass `--tools=` with only the keys the task needs, such as `invoices.list,orders.get`. `--tools=all` loads 28 keys including refunds and captures\n5. Ask the user before `create_refund`, `pay_order`, `cancel_subscription` or `accept_dispute_claim`. The server applies them without a confirmation step\n\n### Skyfire API + MCP\n\n1. Buyer keys create tokens and seller keys charge them; a 403 usually means the wrong key type\n2. Set the token amount to the most the task should spend; the seller can't charge more\n3. Use a kya token when a site only needs to know who you are; it can't be charged\n4. Don't retry `FORBIDDEN` or `NOT_ELIGIBLE`; fix the key or wait for approval first\n5. Rehearse against mcp-sandbox.skyfire.xyz before using mcp.skyfire.xyz\n\n## Questions\n\n### Which is better for AI agents, PayPal MCP server or Skyfire API + MCP?\n\nPayPal MCP server scores 56.3 (C) on agent readiness against Skyfire API + MCP's 40.3 (E), and leads in every scored category.\n\n### Do PayPal MCP server and Skyfire API + MCP need an API key?\n\nPayPal MCP server takes an API key or an OAuth sign-in. Skyfire API + MCP needs an API key.\n\n### Can an agent call PayPal MCP server and Skyfire API + MCP without installing anything?\n\nYes. PayPal MCP server has a hosted endpoint at https://mcp.paypal.com/mcp and Skyfire API + MCP at https://api.skyfire.xyz.\n\n### Are PayPal MCP server and Skyfire API + MCP open source?\n\nPayPal MCP server is open source (Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement). No open-source release is listed for Skyfire API + MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/paypal-mcp-server-vs-skyfire.json, and with the fewest tokens: https://www.anchorterminal.com/compare/paypal-mcp-server-vs-skyfire.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"paypal-mcp-server\", \"b\": \"skyfire\"}`. From a terminal: `anchor compare paypal-mcp-server skyfire`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/paypal-mcp-server.json and https://www.anchorterminal.com/api/v1/tools/skyfire.json\n\n## Other comparisons with PayPal MCP server or Skyfire API + MCP\n\n- [Adyen MCP server vs PayPal MCP server](https://www.anchorterminal.com/compare/adyen-mcp-server-vs-paypal-mcp-server.md)\n- [Adyen MCP server vs Skyfire API + MCP](https://www.anchorterminal.com/compare/adyen-mcp-server-vs-skyfire.md)\n- [Crossmint API + Docs MCP vs PayPal MCP server](https://www.anchorterminal.com/compare/crossmint-vs-paypal-mcp-server.md)\n- [Nevermined API + MCP vs PayPal MCP server](https://www.anchorterminal.com/compare/nevermined-vs-paypal-mcp-server.md)\n- [PayPal MCP server vs Stripe API + MCP](https://www.anchorterminal.com/compare/paypal-mcp-server-vs-stripe-mcp.md)\n- [Crossmint API + Docs MCP vs Skyfire API + MCP](https://www.anchorterminal.com/compare/crossmint-vs-skyfire.md)\n- [Payman Genie MCP vs Skyfire API + MCP](https://www.anchorterminal.com/compare/payman-vs-skyfire.md)\n- [Nevermined API + MCP vs Skyfire API + MCP](https://www.anchorterminal.com/compare/nevermined-vs-skyfire.md)\n- [Skyfire API + MCP vs Stripe API + MCP](https://www.anchorterminal.com/compare/skyfire-vs-stripe-mcp.md)\n- [Skyfire API + MCP vs Tempo](https://www.anchorterminal.com/compare/skyfire-vs-tempo.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "PayPal MCP server vs Skyfire API + MCP",
        "url": ""
      }
    ],
    "description": "PayPal MCP server scores 56.3 (C) on agent readiness against Skyfire API + MCP's 40.3 (E), and leads in every scored category. Both do payments checkout. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "PayPal MCP server C 56.3",
      "Skyfire API + MCP E 40.3",
      "scores"
    ],
    "h1": "PayPal MCP server vs Skyfire API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-paypal-mcp-server-vs-skyfire.png",
    "path": "/compare/paypal-mcp-server-vs-skyfire",
    "published": "2026-10-01",
    "section": "tools",
    "title": "PayPal MCP server vs Skyfire API + MCP for AI agents, C 56.3 vs E 40.3",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/paypal-mcp-server-vs-skyfire"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 730
  },
  "version": 1
}
