# PayPal MCP server > PayPal's official MCP server lets a merchant's AI client work with invoices, orders, refunds, disputes, subscriptions, catalogue products and transaction reports. It runs locally through npx @paypal/mcp or as a hosted server at mcp.paypal.com with a PayPal login. - Canonical: https://www.anchorterminal.com/tools/paypal-mcp-server - Markdown: https://www.anchorterminal.com/tools/paypal-mcp-server.md (~7,800 tokens) - Slim: https://www.anchorterminal.com/tools/paypal-mcp-server.min.md (~1,830 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/paypal-mcp-server.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade C · 56.3/100 · rank #571 of 842 · #6 in Payment & monetisation platforms · not agent-ready · confidence medium** ## Assessment The hosted server uses OAuth with PKCE and dynamic client registration, and the local package defaults to the sandbox. No tool carries a read-only or destructive annotation, no confirmation step for refunds or captures was found, and the documented `/http` streamable HTTP path returned 404 on 8 October 2026 while `/mcp` answered. ## Facts | Field | Value | | --- | --- | | Vendor | PayPal (https://www.paypal.com) | | Kind | MCP server | | Category | Payment & monetisation platforms (https://www.anchorterminal.com/categories/payment-platforms) | | Transport | stdio, SSE (legacy), Streamable HTTP | | Endpoint | `https://mcp.paypal.com/mcp` | | Auth | OAuth or key · The remote server takes OAuth. The MCP client sends the user to a PayPal login and consent page, using authorisation code with PKCE S256, refresh tokens and dynamic client registration. It also accepts a Bearer header built from a REST app's client ID and secret. The local server takes only a PayPal REST access token in `PAYPAL_ACCESS_TOKEN` or `--access-token`, which the README says lasts 32,400 seconds. A person creates the app in the PayPal Developer Dashboard, and live use needs a PayPal Business account. No scope list for the MCP server was found. | | Pricing | Pay per use (3.49% fee) · No charge for the MCP server or the toolkit was found. PayPal's US merchant fees apply to payments made through it, 3.49% plus $0.49 for PayPal Checkout and invoices, 2.99% plus $0.49 for standard card processing, plus 1.5% on international transactions, with no monthly fee on most products (fees page updated 1 October 2026, https://www.paypal.com/us/business/paypal-business-fees). The sandbox is free with a developer account and no card, so an agent can start without a contract. | | x402 | No · No x402, MPP or L402 in the MCP quickstart, the agent tools reference, the developer llms.txt indexes or either repository (checked 2026-10-08). | | Licence | Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement | | Tools exposed | 28 | | Packages | npm: `@paypal/mcp`; npm: `@paypal/agent-toolkit`; pypi: `paypal-agent-toolkit` | | MCP registry name | `io.github.paypal/paypal-mcp-server` | | Source | https://github.com/paypal/paypal-mcp-server | | Docs | https://developer.paypal.com/ai-tools/mcp-server | | llms.txt | https://developer.paypal.com/llms.txt | | Last release | 2026-09-01 | | npm downloads / week | 995 | | PyPI downloads / week | 107 | | Surfaces | Local stdio server (`npx -y @paypal/mcp`, Node 18 or later) and a hosted server at https://mcp.paypal.com, with a sandbox twin at https://mcp.sandbox.paypal.com | | Remote transports | `/sse` and `/mcp` answered with an OAuth challenge on 8 October 2026. The quickstart's `/http` path returned 404 | | Local tools | 28 selectable keys across invoices (7), orders (3), disputes (3), shipment tracking (2), products (4), subscription plans (3), subscriptions (3), transactions (1) and refunds (2) | | Toolkit | `@paypal/agent-toolkit` 1.11.0 (1 September 2026) defines 48 tools, including recurring invoice series, invoice search, auto reminders and merchant insights, for MCP, LangChain, OpenAI Agents SDK, Vercel AI SDK, Amazon Bedrock and CrewAI | | Remote commerce tools | `search_product`, `create_cart` and `checkout_cart`, enabled with the `x-feature-flags: commerce:true` header and limited to gift cards per the tools reference | | Credentials | OAuth login with PKCE and dynamic client registration on the remote server, or a Bearer header from client credentials. A REST access token for the local server | | Environment | Sandbox by default. `PAYPAL_ENVIRONMENT=PRODUCTION` or `--paypal-environment=production` switches to live | | Rate limits | Not published. PayPal says limits vary by API and environment. 429 responses can carry `Retry-After`, and the docs advise increasing delays between retries | | Idempotency | The REST APIs accept `PayPal-Request-Id` on some endpoints. The toolkit sets it only from a `request_id` in its context, with no per-call argument on the tools | | Errors | The toolkit returns `ok`, `status`, `code` and a message cut to 200 characters | | Status | https://www.paypal-status.com with an Atom feed at `/feed/atom`. The feed on 8 October 2026 went back to 15 August 2026 | | Security programme | Bug bounty on HackerOne named in security.txt, which has no Expires field | | Capabilities | payments.checkout, accounting.invoices, commerce.orders, commerce.products | | Tags | official, hosted, local, open-source, mcp, oauth, sandbox, llms-txt, typescript, python, status-page, bug-bounty | | JSON | https://www.anchorterminal.com/api/v1/tools/paypal-mcp-server.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 52 | 10.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 70 | 11.4 | | Agent ergonomics | 13% | 16.2 | 66 | 10.7 | | Security & auth | 14% | 17.5 | 48 | 8.4 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 64 | 5.6 | | Transparency & trust (editorial 58, provenance 98) | 7% | 8.8 | 78 | 6.8 | | Negative events | up to −15 | up to −15 | 8 October 2026. The MCP quickstart (last updated 30 June 2026) gives `https://mcp.paypal.com/http` and `https://mcp.sandbox.paypal.com/http` as the streamable HTTP endpoints. Both returned 404 to an initialise request on 8 October 2026, while `/mcp` on each host returned the OAuth challenge. A documented endpoint that doesn't answer, minus 2 (https://developer.paypal.com/ai-tools/mcp-server). | -2 | | **Total** | | | | **56.3 → C** | ### Why each score - Reliability 52: Graded on the hosted lines, because the remote server at mcp.paypal.com is the surface the quickstart leads to. PayPal's status page at paypal-status.com covers its production products (20). The page is drawn by script, so we read its Atom feed, which on 8 October went back only to 15 August 2026. It shows two resolved degraded-performance events on PayPal payments, on 15 August (refunds, payments, authorisations, orders) and 22 September (Checkout), with no durations given, and no entry naming the MCP server (15 of 30). PayPal states that it doesn't publish rate limits (0). The rate-limiting guide tells callers to read `Retry-After` on 429 and lengthen delays, and the REST APIs take `PayPal-Request-Id`, but the MCP tools have no per-call idempotency argument (10 of 15). No SLA found, and the Developer Agreement gives no uptime guarantee for the sandbox (0). No beta label on the server, but the remote commerce tools are limited to gift cards behind a feature flag and the documented `/http` path returned 404 (7 of 10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 70: Each tool is registered with a zod shape that the MCP SDK turns into JSON Schema (25). developer.paypal.com/llms.txt indexes the docs by section, including the MCP and toolkit pages (10). Tool descriptions state the purpose and some say when to choose another tool, such as cancelling instead of deleting an active recurring series, while many are one line (13 of 20). Inputs carry 32 enums plus length and range limits, and list tools bound `page_size` at 100 (12 of 15). The quickstart gives one example prompt and no error reference for the tools was found (6 of 15). The toolkit changelog stops at 1.3.5 from April 2025 although 1.11.0 is current, the MCP repository has none, and in August 2026 the version went to 1.12.0 and back to 1.9.0 after failed builds (4 of 15). - Agent ergonomics 66: `--tools=all` loads 28 tools (15), and `--tools=` takes a comma-separated subset, so a client can load only what a task needs (8 back, 23 of 25). List tools take `page`, `page_size`, `total_required` and status or date filters (16 of 20). Errors come back as `ok`, `status`, `code` and a message cut to 200 characters, which is usable but undocumented (10 of 20). Tools are registered with a name, description and schema only, so there is no `readOnlyHint` or `destructiveHint`, and `PayPal-Request-Id` is set only from toolkit context (4 of 20). The sandbox is the default, most tools need few fields, and the toolkit ships for TypeScript and Python (13 of 15). - Security & auth 48: The remote server publishes OAuth metadata with authorisation code, PKCE S256, refresh tokens, revocation and dynamic client registration, and no scope list. The local server takes a REST access token that carries the whole app's permissions for about nine hours (22 of 30). `--tools=` narrows the local tool set and the sandbox is the default, but no read-only mode and no confirmation step for refunds, captures or accepting a dispute claim was found (8 of 20). Tools return invoice notes, dispute text and product descriptions written by other people, and the only guidance found is to write clear system prompts and keep human oversight (4 of 15). No audit log or per-call view for MCP use was found in the reviewed pages, and we did not look inside the dashboard (0). security.txt names a HackerOne bug bounty and has no Expires field. We did not read PayPal's certification pages, and neither repository has a security policy file (14 of 20). - Payments & pricing 40: Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found in the MCP docs, the developer llms.txt indexes or either repository, and PayPal's Agentic Commerce Protocol and Universal Commerce Protocol pages concern checkout, not paying for calls (0). US fees are public without a login, 3.49% plus $0.49 for PayPal Checkout and 2.99% plus $0.49 for standard cards (20). The sandbox is free with a developer account, with no card and no monthly fee on most products (20). A person has to create the PayPal account and app, and log in for the remote server (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 64: `@paypal/mcp` 1.8.1 was published on 28 October 2025, but it loads `@paypal/agent-toolkit` at `latest`, whose 1.11.0 came out on 1 September 2026, 37 days before this check (20 of 30). The toolkit had three npm releases in the last 90 days, 1.9.0 on 10 August, 1.10.0 on 20 August and 1.11.0 on 1 September (20). Pull requests were merged in August 2026. GitHub's API refused us, so the issue queue went unread (8 of 25). The server is in the official registry as `io.github.paypal/paypal-mcp-server`, a GitHub-verified namespace, with a 1.8.1 entry that lists the stdio package and not the remote server (13 of 15). Neither repository has test files, the toolkit's test script only prints an error, CI publishes without testing, and the server depends on the toolkit at `latest` (3 of 10). - Transparency & trust 78: The local server and toolkit are Apache-2.0 on GitHub, though the toolkit's npm metadata says ISC, and the hosted server is closed under the PayPal Developer Agreement (20 of 30). The Privacy Statement of 28 September 2026 gives retention as the relationship plus 10 years, says personal information may be used to train PayPal's AI models, and describes a third-party list updated quarterly with 30 days to object. No statement specific to MCP traffic was found (20 of 30). The Developer Agreement lets PayPal change or discontinue APIs on notice at any time, with 30 days' notice for substantial changes to the agreement, and no deprecation notice for the MCP server or toolkit was found (8 of 20). The toolkit changelog discloses User-Agent telemetry with no opt-out found, and the Privacy Statement's third-party list was not read for data locations (10 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/paypal-mcp-server.md (JSON https://www.anchorterminal.com/fixes/paypal-mcp-server.json) ### What we couldn't check - unchecked: the tool list, annotations and scopes the hosted server at mcp.paypal.com returns after login, because we did not authenticate - unchecked: GitHub stars, open issues and security advisories for paypal/agent-toolkit and paypal/paypal-mcp-server, because the GitHub API refused our requests - unchecked: status history before 15 August 2026 and incident durations, because the status page is drawn by script and its feed holds 13 entries - unchecked: PayPal's certification pages (PCI DSS, SOC reports) and the third-party list linked from the Privacy Statement - unchecked: API call logs in the PayPal Developer Dashboard, which need a login - The lead gave a second remote transport without naming its path. The docs name `/http`, which returned 404, and `/mcp` is what answers - The registry entry describes `PAYPAL_ENVIRONMENT` as 'SANDBOX' or 'LIVE', but the code treats every value other than `production` as sandbox - Whether the remote commerce tools (`search_product`, `create_cart`, `checkout_cart`) are open to any account or only by feature flag ### Sources - MCP server quickstart: (seen 2026-10-08) - agent tools reference: (seen 2026-10-08) - agent toolkit quickstart: (seen 2026-10-08) - remote server OAuth metadata: (seen 2026-10-08) - remote server protected resource metadata: (seen 2026-10-08) - MCP server repository (clone): (seen 2026-10-08) - agent toolkit repository (clone): (seen 2026-10-08) - npm, @paypal/mcp versions: (seen 2026-10-08) - npm, @paypal/agent-toolkit versions: (seen 2026-10-08) - official MCP registry entry: (seen 2026-10-08) - status page Atom feed: (seen 2026-10-08) - rate limiting guide: (seen 2026-10-08) - idempotency guide: (seen 2026-10-08) - US merchant fees: (seen 2026-10-08) - PayPal Developer Agreement: (seen 2026-10-08) - PayPal Privacy Statement: (seen 2026-10-08) - PayPal User Agreement (US): (seen 2026-10-08) - security.txt: (seen 2026-10-08) - developer docs llms.txt: (seen 2026-10-08) - RDAP for paypal.com: (seen 2026-10-08) ## Who's behind it (provenance 98/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | PayPal, Inc. | 20/20 | | Domain age | paypal.com, registered 1999-07-15 (27 years) | 15/15 | | Endpoint on the vendor's domain | mcp.paypal.com | 15/15 | | Terms of service | read, states 7 of the 7 things a reader expects | 10/10 | | Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 | | Status page | www.paypal-status.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The PayPal Developer Agreement, last updated 18 November 2024, governs the Developer's Tools and API calls and takes precedence over the User Agreement for them. US users contract with PayPal, Inc. and some other regions with PayPal Pte. Ltd. The US User Agreement (last updated 14 September 2026) and Privacy Statement (last updated 28 September 2026) name PayPal, Inc. www.paypal.com/.well-known/security.txt redirects to www.paypalobjects.com and names the HackerOne programme. It has no Expires field. The toolkit changelog on GitHub stops at 1.3.5 from 23 April 2025. Later releases are visible only as tags and npm versions. RDAP for paypal.com gives a registration date of 1999-07-15. The status page is on paypal-status.com, a separate domain. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.paypal.com/us/legalhub/paypal/xdeveloper-full), read 2026-10-08, dated 2024-11-18, states 7 of the 7 things a reader expects. - To know. Says access can be ended without notice or for any reason. "PayPal may also impose limits on certain features and services or restrict your access to parts of or all of the Developer’s Tools without notice or liability." - To know. Requires arbitration or waives class actions. "In the event you have a dispute with PayPal, the relevant provisions (including arbitration requirements) of your PayPal User Agreement will govern the dispute." - Gives the date it was last updated. Last updated 2024-11-18. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Says how changes to the terms are announced. Gives 30 days of notice before a change. - Also in the text (2026-10-08). PayPal may use the developer's trade marks to publicise the developer's use of the Developer's Tools and its application. "You grant PayPal a revocable, non-exclusive, non-transferable, worldwide, royalty-free license to use your Marks to publicize your use of the Developer’s Tools and your Application." - Also in the text (2026-10-08). The developer is liable for all activity carried out with its App ID, API credentials or other PayPal account credentials. "You are liable for all activities performed with your App ID, API Credentials or other PayPal Account credentials." - Also in the text (2026-10-08). Listed categories of PayPal user information must be deleted within 48 hours of receipt. "The following PayPal User Information must be deleted within 48 hours of receipt:" **Privacy policy** (https://www.paypal.com/us/legalhub/paypal/privacy-full), read 2026-10-08, dated 2026-09-28, states 8 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "We may use Personal Information to train our artificial intelligence (AI) models that power our Services and help us deliver more secure, efficient, and personalized services." - Gives the date it was last updated. Last updated 2026-09-28. - Says how long data is kept. Names a period of 10 years. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). Agentic AI tools that PayPal makes available have access to the user's personal information, including purchase history and payment information. "When you use these tools, they will have access to your Personal Information, including queries, preferences, interests, purchase history, and payment information." - Also in the text (2026-10-08). PayPal may disclose customers' personal information to partners and merchants so that they and PayPal can personalise services and promotions. "For our PayPal customers, we may also disclose your Personal Information to Partners and Merchants that you and we interact with to help ourselves and Partners and Merchants personalize services and offers so you can have a better and more relevant experience." - Also in the text (2026-10-08). PayPal continues to share a person's information as described in its financial privacy notice after that person stops being a customer. "When you are no longer our customer, we continue to share your information as described in this notice." ## Live (updated 2026-10-09 11:46 UTC) - Right now: up, HTTP 401, 45 ms, checked 2026-10-09 11:46 UTC (mcp-initialize on `https://mcp.paypal.com/mcp`, asks for auth) - Uptime 24h 100.0% (44 probes) · 30 days 100.0% (44 probes) · p50 59 ms · p95 138 ms - Vendor status page: unknown, no machine-readable status found - Always current: https://www.anchorterminal.com/api/v1/live/paypal-mcp-server.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | PayPal Checkout, US domestic | 3.49% | percentage fee | plus $0.49 per transaction | | PayPal Checkout fixed fee, USD | $0.49 | per transaction | | | Standard card processing, US domestic | 2.99% | percentage fee | plus $0.49 per transaction | | International commercial transaction surcharge | 1.5% | percentage fee | | | Standard dispute fee | $15 | per transaction | | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Hosted server at mcp.paypal.com publishes OAuth metadata with authorisation code, PKCE S256, refresh tokens, revocation and dynamic client registration - The local package starts in the sandbox unless `PAYPAL_ENVIRONMENT` is `PRODUCTION`, and `--tools=` limits which tools load - Every tool input is a typed schema with enums and range limits, built from zod definitions in the Apache-2.0 toolkit - US fees are public without a login, and sandbox testing needs no card or monthly fee - Listed in the official MCP registry as `io.github.paypal/paypal-mcp-server`, and the toolkit had three releases between 10 August and 1 September 2026 ## Weaknesses - The quickstart gives `/http` for streamable HTTP. On 8 October 2026 it returned 404 on both hosts, and `/mcp` returned the OAuth challenge - Tools are registered without `readOnlyHint` or `destructiveHint`, and no approval step for `create_refund`, `pay_order` or `accept_dispute_claim` was found - `@paypal/mcp` 1.8.1 dates from 28 October 2025 and selects 28 tool keys, while the toolkit it loads defines 48 tools - PayPal states that it doesn't publish rate limits, and no SLA was found. The Developer Agreement gives no uptime guarantee for the sandbox - Neither repository has tests in CI, and the toolkit changelog stops at 1.3.5 from April 2025 although 1.11.0 is current ## Before you call it (notes for agents) 1. Connect a remote client to `https://mcp.paypal.com/mcp` or `/sse`. The documented `/http` path returned 404 on 8 October 2026 2. Set `PAYPAL_ENVIRONMENT=PRODUCTION` for live calls. Any other value, including the registry's `LIVE`, runs against the sandbox 3. Refresh `PAYPAL_ACCESS_TOKEN` before it expires. The README gives `expires_in` 32400 seconds, and the local server takes no client ID or secret 4. Pass `--tools=` with only the keys the task needs, such as `invoices.list,orders.get`. `--tools=all` loads 28 keys including refunds and captures 5. Ask the user before `create_refund`, `pay_order`, `cancel_subscription` or `accept_dispute_claim`. The server applies them without a confirmation step ## Connect Install: ```bash npx -y @paypal/mcp --tools=all ``` MCP client configuration: ```json { "mcpServers": { "paypal": { "args": [ "-y", "@paypal/mcp", "--tools=all" ], "command": "npx", "env": { "PAYPAL_ACCESS_TOKEN": "YOUR_PAYPAL_ACCESS_TOKEN", "PAYPAL_ENVIRONMENT": "SANDBOX" } } } } ``` Through letme (picks today, calling later): https://letme.dev/paypal-mcp-server. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Square | B | 69.2 | 186 | commerce.products, commerce.orders, payments.checkout | no | https://www.anchorterminal.com/tools/square.md | | Shopify API + MCP | BB | 75 | 57 | commerce.products, commerce.orders | no | https://www.anchorterminal.com/tools/shopify.md | | WooCommerce API + MCP | BB | 72.9 | 94 | commerce.products, commerce.orders | no | https://www.anchorterminal.com/tools/woocommerce.md | | Shopware | BB | 71.4 | 124 | commerce.products, commerce.orders | no | https://www.anchorterminal.com/tools/shopware.md | | commercetools | BB | 71.3 | 128 | commerce.products, commerce.orders | no | https://www.anchorterminal.com/tools/commercetools.md | | Vendure | BB | 70.9 | 135 | commerce.products, commerce.orders | no | https://www.anchorterminal.com/tools/vendure.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The quickstart, last updated 30 June 2026, describes a local server run with `npx -y @paypal/mcp --tools=all` and a remote server at https://mcp.paypal.com and https://mcp.sandbox.paypal.com over SSE and streamable HTTP (source: ) - On 8 October 2026 a POST to `/http` returned 404 on mcp.paypal.com and mcp.sandbox.paypal.com, while `/mcp` and `/sse` returned 401 with an OAuth `WWW-Authenticate` challenge (source: ) - The authorisation server metadata lists authorisation code and refresh token grants, PKCE S256, a registration endpoint and a revocation endpoint, with no `scopes_supported` (source: ) - The agent tools reference, last updated 28 May 2026, lists 30 merchant tools and three commerce tools (`search_product`, `create_cart`, `checkout_cart`) on the remote server behind the `x-feature-flags: commerce:true` header, for gift cards only (source: ) - The server code moved to paypal/paypal-mcp-server in October 2025. Its `ACCEPTED_TOOLS` list has 28 keys and it depends on `@paypal/agent-toolkit` at `latest`, which defines 48 tools in 1.11.0 (source: ) - The PayPal Privacy Statement, last updated 28 September 2026, says PayPal may use personal information to train its AI models and keeps relationship data for the relationship plus 10 years (source: ) ## Compare - [Adyen MCP server vs PayPal MCP server](https://www.anchorterminal.com/compare/adyen-mcp-server-vs-paypal-mcp-server.md): C 60.3 vs C 56.3 - [Crossmint API + Docs MCP vs PayPal MCP server](https://www.anchorterminal.com/compare/crossmint-vs-paypal-mcp-server.md): B 67.1 vs C 56.3 - [Nevermined API + MCP vs PayPal MCP server](https://www.anchorterminal.com/compare/nevermined-vs-paypal-mcp-server.md): BB 70.8 vs C 56.3 - [PayPal MCP server vs Skyfire API + MCP](https://www.anchorterminal.com/compare/paypal-mcp-server-vs-skyfire.md): C 56.3 vs E 40.3 - [PayPal MCP server vs Stripe API + MCP](https://www.anchorterminal.com/compare/paypal-mcp-server-vs-stripe-mcp.md): C 56.3 vs A 82.4 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on paypal.com or one of its subdomains, or the README of github.com/paypal/paypal-mcp-server. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "paypal-mcp-server", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html PayPal MCP server on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![PayPal MCP server on Anchor Terminal](https://www.anchorterminal.com/badges/paypal-mcp-server.svg)](https://www.anchorterminal.com/tools/paypal-mcp-server) ``` Plain link: ```html PayPal MCP server on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say PayPal MCP server is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/paypal-mcp-server-dark.png - Light: https://www.anchorterminal.com/assets/share/paypal-mcp-server-light.png