# PayPal MCP server (slim) > PayPal's official MCP server lets a merchant's AI client work with invoices, orders, refunds, disputes, subscriptions, catalogue products and transaction reports. It runs locally through npx @paypal/mcp or as a hosted server at mcp.paypal.com with a PayPal login. - Full: https://www.anchorterminal.com/tools/paypal-mcp-server.md (~7,800 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/paypal-mcp-server.json · canonical https://www.anchorterminal.com/tools/paypal-mcp-server - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 56.3/100 · rank #571 of 842 · #6 in Payment & monetisation platforms · not agent-ready · confidence medium** Assessment: The hosted server uses OAuth with PKCE and dynamic client registration, and the local package defaults to the sandbox. No tool carries a read-only or destructive annotation, no confirmation step for refunds or captures was found, and the documented `/http` streamable HTTP path returned 404 on 8 October 2026 while `/mcp` answered. ## Facts - Kind: MCP server · vendor: PayPal · category: Payment & monetisation platforms · legal entity: PayPal, Inc. · provenance 98/100 - Endpoint: `https://mcp.paypal.com/mcp` (stdio, SSE (legacy), Streamable HTTP) - Auth: OAuth or key · pricing: Pay per use · x402: no · licence: Apache-2.0 for the local server and the agent toolkit. The hosted server is a closed service under the PayPal Developer Agreement - Probe metrics: not measured yet (probes haven't run) - Surfaces: Local stdio server (`npx -y @paypal/mcp`, Node 18 or later) and a hosted server at https://mcp.paypal.com, with a sandbox twin at https://mcp.sandbox.paypal.com - Remote transports: `/sse` and `/mcp` answered with an OAuth challenge on 8 October 2026. The quickstart's `/http` path returned 404 - Local tools: 28 selectable keys across invoices (7), orders (3), disputes (3), shipment tracking (2), products (4), subscription plans (3), subscriptions (3), transactions (1) and refunds (2) - Toolkit: `@paypal/agent-toolkit` 1.11.0 (1 September 2026) defines 48 tools, including recurring invoice series, invoice search, auto reminders and merchant insights, for MCP, LangChain, OpenAI Agents SDK, Vercel AI SDK, Amazon Bedrock and CrewAI - Remote commerce tools: `search_product`, `create_cart` and `checkout_cart`, enabled with the `x-feature-flags: commerce:true` header and limited to gift cards per the tools reference - Credentials: OAuth login with PKCE and dynamic client registration on the remote server, or a Bearer header from client credentials. A REST access token for the local server - Environment: Sandbox by default. `PAYPAL_ENVIRONMENT=PRODUCTION` or `--paypal-environment=production` switches to live - Rate limits: Not published. PayPal says limits vary by API and environment. 429 responses can carry `Retry-After`, and the docs advise increasing delays between retries - Idempotency: The REST APIs accept `PayPal-Request-Id` on some endpoints. The toolkit sets it only from a `request_id` in its context, with no per-call argument on the tools - Errors: The toolkit returns `ok`, `status`, `code` and a message cut to 200 characters - Status: https://www.paypal-status.com with an Atom feed at `/feed/atom`. The feed on 8 October 2026 went back to 15 August 2026 - Security programme: Bug bounty on HackerOne named in security.txt, which has no Expires field - Prices: PayPal Checkout, US domestic 3.49% percentage fee; PayPal Checkout fixed fee, USD $0.49 per transaction; Standard card processing, US domestic 2.99% percentage fee; International commercial transaction surcharge 1.5% percentage fee; Standard dispute fee $15 per transaction - Scores: Reliability 52, Performance pending, Schema & documentation 70, Agent ergonomics 66, Security & auth 48, Payments & pricing 40, Task success pending, Maintenance & community 64, Transparency & trust 78 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Graded on the hosted lines, because the remote server at mcp.paypal.com is the surface the quickstart leads to. · Schema & documentation, Each tool is registered with a zod shape that the MCP SDK turns into JSON Schema (25). · Agent ergonomics, `--tools=all` loads 28 tools (15), and `--tools=` takes a comma-separated subset, so a client can load only what a task needs (8 back, 23 of… · Security & auth, The remote server publishes OAuth metadata with authorisation code, PKCE S256, refresh tokens, revocation and dynamic client registration, a… · Payments & pricing, Payment platforms take the highest step that applies on the 40-point protocol line. · Maintenance & community, `@paypal/mcp` 1.8.1 was published on 28 October 2025, but it loads `@paypal/agent-toolkit` at `latest`, whose 1.11.0 came out on 1 September… · Transparency & trust, The local server and toolkit are Apache-2.0 on GitHub, though the toolkit's npm metadata says ISC, and the hosted server is closed under the… - Sources: 20, open questions: 8, both in the full twin - Capabilities: payments.checkout, accounting.invoices, commerce.orders, commerce.products - JSON: https://www.anchorterminal.com/api/v1/tools/paypal-mcp-server.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/paypal-mcp-server.svg` or a link to https://www.anchorterminal.com/tools/paypal-mcp-server from a page on paypal.com or one of its subdomains, or the README of github.com/paypal/paypal-mcp-server, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Connect a remote client to `https://mcp.paypal.com/mcp` or `/sse`. The documented `/http` path returned 404 on 8 October 2026 2. Set `PAYPAL_ENVIRONMENT=PRODUCTION` for live calls. Any other value, including the registry's `LIVE`, runs against the sandbox 3. Refresh `PAYPAL_ACCESS_TOKEN` before it expires. The README gives `expires_in` 32400 seconds, and the local server takes no client ID or secret 4. Pass `--tools=` with only the keys the task needs, such as `invoices.list,orders.get`. `--tools=all` loads 28 keys including refunds and captures 5. Ask the user before `create_refund`, `pay_order`, `cancel_subscription` or `accept_dispute_claim`. The server applies them without a confirmation step ## Connect ```bash npx -y @paypal/mcp --tools=all ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/paypal-mcp-server ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Square | B | 69.2 | commerce.products, commerce.orders, payments.checkout | https://www.anchorterminal.com/tools/square.min.md | | Shopify API + MCP | BB | 75 | commerce.products, commerce.orders | https://www.anchorterminal.com/tools/shopify.min.md | | WooCommerce API + MCP | BB | 72.9 | commerce.products, commerce.orders | https://www.anchorterminal.com/tools/woocommerce.min.md | | Shopware | BB | 71.4 | commerce.products, commerce.orders | https://www.anchorterminal.com/tools/shopware.min.md | | commercetools | BB | 71.3 | commerce.products, commerce.orders | https://www.anchorterminal.com/tools/commercetools.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)