Agent skill

Stripe Link CLI

by hewi333 in hewi333/Mom-n-Pop-Skills

Agent-initiated spend via Stripe Link — requests purchases, issues virtual cards, owner approves in the Link mobile/web app.

MITAuto-check passed

Install Stripe Link CLI

skills CLI
$ npx skills add hewi333/Mom-n-Pop-Skills --skill stripe-link-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hewi333/Mom-n-Pop-Skills stripe-link-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hewi333/Mom-n-Pop-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/stripe-link-cli .claude/skills/stripe-link-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stripe-link-cli
GitHub stars
122
Token cost
~2.8k tokens
SKILL.md length
1,304 words
Files
2 (incl. references)
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Agent-initiated spend via Stripe Link — requests purchases, issues virtual cards, owner approves in the Link mobile/web app.

  • Works in 7 steps: Check / establish auth → Evaluate the merchant before creating a… → List payment methods + shipping → …
  • SKILL.md covers When to Use, Prerequisites, Install and How to Run, plus 5 more sections
  • Calls npm, node and npx

What it does

Stripe Link CLI is an agent skill from hewi333/Mom-n-Pop-Skills. Agent-initiated spend via Stripe Link — requests purchases, issues virtual cards, owner approves in the Link mobile/web app. Hermes cannot self-approve. The 'spend' rail to complement stripe-payments.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/error-fixes.md`).

It works with Stripe. The repository describes itself as: Collection of skills for small businesses using AI Agents. The licence is MIT.

Example prompts

  • “/stripe-link-cli”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Check / establish auth
  2. Evaluate the merchant before creating a spend request
  3. List payment methods + shipping
  4. Create the spend request
  5. Retrieve the credential — SECURELY
  6. Use the credential
  7. Clean up

What it can do on your machine

Read from SKILL.md and the folder at commit 70a2273. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • node
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Stripe Link CLI loads about 2.8k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 54 tokens; SKILL.md has 1,304 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hewi333/Mom-n-Pop-Skills at commit 70a2273, republished under its MIT licence (© hewi333). 1,304 words, ~2,789 tokens.

Download SKILL.mdSave it as .claude/skills/stripe-link-cli/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
stripe-link-cli
description
Agent-initiated spend via Stripe Link — requests purchases, issues virtual cards, owner approves in the Link mobile/web app. Hermes cannot self-approve. The 'spend' rail to complement stripe-payments.
version
1.0.0
author
Hermes Agent
license
MIT
platforms
linux, macos

Wraps @stripe/link-cli so Hermes can complete purchases on the user's behalf using one-time-use virtual cards or Shared Payment Tokens (SPT). Every spend is gated by an in-app approval in the Link mobile/web app — Hermes cannot self-approve.

US-only at the moment (Link account requirement). Windows is not supported by the upstream CLI — this skill is gated [linux, macos].

When to Use

Trigger phrases:

  • "buy X", "pay for X", "make a purchase", "complete checkout"
  • "get me a card", "I need a payment method"
  • "log in to Link", "connect my Link wallet"
  • HTTP 402 response from a merchant API with www-authenticate: ... method="stripe"

If the user wants a paid API call (HTTP 402, no checkout form), the card path is wrong — use SPT via this same skill, or hand off to the mpp-agent skill.

Prerequisites

  • Node.js 20+ available on PATH (node --version)
  • US-based (Link account requirement)

The Link account, payment method, and spend-approval app do NOT need to be set up before Hermes attempts to pay — the CLI walks the user through them on first run:

  • A Link account at https://app.link.com — created/linked during first link-cli auth
  • At least one payment method — added during first run at https://app.link.com/wallet
  • The Link mobile/web app — opened to approve the first spend request when it's made

No env vars required — auth state is stored locally by the CLI under its own config directory.

Install

Install once, globally:

npm install -g @stripe/link-cli

Or invoke ad-hoc via npx @stripe/link-cli. The skill below uses the installed link-cli form.

How to Run

All commands run through the terminal tool. The CLI auto-detects non-TTY callers and emits compact toon output by default — fine for the model. Pass --format json if a step needs structured fields.

Discover commands: link-cli --llms-full. Get a command's schema before invoking: link-cli <command> --schema.

Procedure

1. Check / establish auth
link-cli auth status

If not authenticated, log in with a clear client name (this label shows in the user's Link app):

link-cli auth login --client-name "Hermes" --interval 5 --timeout 300

The --interval/--timeout form polls inline so the agent doesn't need to manage a _next step. Print the verification URL + phrase to the user and wait for the CLI to return.

Background-polling pattern (when not using inline flags): If you run auth login without --interval/--timeout (or with pty=true), it returns immediately with a verification_url, phrase, and a _next.command like auth status --interval 5 --max-attempts 60. Start that poll as a background terminal process with notify_on_complete=true so you get notified when the user approves:

link-cli auth status --interval 5 --max-attempts 60
# → run with: background=true, notify_on_complete=true, timeout=330

Print the verification URL and phrase to the user immediately — don't wait for them to ask. The background poll will notify you when auth succeeds.

Do not proceed past this step until auth status confirms login.

2. Evaluate the merchant before creating a spend request

Decide the credential type:

Merchant surface--credential-type
Standard web checkout form / Stripe Elementscard (default)
Returns HTTP 402 with method="stripe" in www-authenticateshared_payment_token
Returns HTTP 402 without method="stripe"unsupported — stop

For 402 responses, do NOT decode the challenge manually. Pass the raw header:

link-cli mpp decode --challenge '<full WWW-Authenticate header>'

This validates the challenge and extracts the network ID + decoded request body.

3. List payment methods + shipping
link-cli payment-methods list
link-cli shipping-address list

Use the first entry unless the user specifies otherwise. The id from payment-methods list is the --payment-method-id in the next step.

4. Create the spend request

Confirm the final total with the user before issuing this command. Amounts are in cents.

link-cli spend-request create \
  --payment-method-id <pm_id> \
  --merchant-name "<name>" \
  --merchant-url "<url>" \
  --context "<what is being purchased and why — MUST be ≥100 characters or the CLI returns VALIDATION_ERROR too_small>" \
  --amount <cents> \
  --line-item "name:<item>,unit_amount:<cents>,quantity:1" \
  --total "type:total,display_text:Total,amount:<cents>" \
  --request-approval

For MPP merchants add --credential-type shared_payment_token.

--request-approval sends the approval push notification to the user's Link app and returns immediately with status: "pending_approval". It does NOT poll — the response includes a _next.command (spend-request retrieve <id> --interval 2 --max-attempts 300) that you must run separately to poll for approval.

Best pattern: After create --request-approval returns, immediately start a background retrieve call that combines polling + card retrieval in one shot (see Section 5). This eliminates the gap between approval and retrieval that causes card expiry.

5. Retrieve the credential — SECURELY

Do not print card details to stdout. Use --output-file so the PAN never enters the agent's transcript or logs.

All five options are required by the schema even though they appear to have defaults — omitting any of --timeout, --interval, --max-attempts, --force, or --include can cause a terminated error. Always pass all five explicitly:

Combined poll + retrieve (preferred): Combines approval polling and card retrieval in one background call. Run this immediately after create --request-approval returns — it polls until the user approves, then retrieves the card in the same process, eliminating the approval-to-retrieval gap:

link-cli spend-request retrieve <lsrq_id> \
  --include card \
  --output-file /tmp/link-card.json \
  --timeout 600 \
  --interval 2 \
  --max-attempts 0 \
  --force \
  --format json
# → run with: background=true, notify_on_complete=true, timeout=660

Post-approval retrieve (only when poll already confirmed approval): If you already polled separately (e.g. via a background process) and confirmed status: "approved", retrieve the card with zero interval:

link-cli spend-request retrieve <lsrq_id> \
  --include card \
  --output-file /tmp/link-card.json \
  --timeout 30 \
  --interval 0 \
  --max-attempts 0 \
  --force \
  --format json

The file is written with 0600 perms; stdout shows only redacted fields (brand, last4, expiry) plus a card_output_file path.

Show full SKILL.md (543 more words)Show less
6. Use the credential
  • For web checkout: hand the file path to the user, OR pass it to a browser-driving tool that fills the form directly from disk. Never read_file or cat the card file into the agent's reasoning context.

  • For MPP merchants:

    link-cli mpp pay <merchant-url> \
      --spend-request-id <lsrq_id> \
      --method POST \
      --data '<json body>'
7. Clean up

Delete the card file as soon as the purchase is done:

rm -f /tmp/link-card.json

Optional: run as an MCP server instead

@stripe/link-cli --mcp exposes the same commands as MCP tools over stdio. To register it with Hermes' native MCP:

hermes mcp add stripe-link --command "npx" --args "@stripe/link-cli --mcp"

Then hermes mcp list should show stripe-link. The same approval rules apply — MCP doesn't bypass the Link app approval step.

Pitfalls

  • US-only. Outside the US, auth login will fail. Tell the user, don't keep retrying.
  • --context must be ≥100 characters. The CLI returns VALIDATION_ERROR / too_small if shorter. Write a detailed context string (what, why, who) — not a one-liner.
  • --request-approval does NOT poll. It returns immediately with pending_approval and a _next.command. You must separately poll via retrieve --interval 2 --max-attempts 300 (background, notify_on_complete). The previous skill text that said it "polls until they approve or deny" was wrong.
  • One-time cards expire ~90 seconds after approval. The window between the user approving in the Link app and you retrieving the card is very short. If the card expires, you must recreate the entire spend request and get a new approval. To avoid this: (a) use the combined poll+retrieve pattern in Section 5 so there's no gap, or (b) if you polled separately, retrieve the card immediately after seeing status: "approved" — do not do any other work in between.
  • retrieve requires explicit options or it errors with terminated. Even though the schema shows defaults, omitting --timeout, --interval, --max-attempts, --force, or --include can fail. Always pass all five. See Section 5 for exact flags.
  • Token refresh failures during retrieval. If retrieve fails with Token refresh failed (400), you need to re-auth (auth login --interval 5 --timeout 300) and retry. But the card may expire during re-auth — which means recreating the spend request. This is why the combined poll+retrieve pattern is strongly preferred: it retrieves the card as part of the same process that detects approval, so no token refresh gap exists.
  • Card PAN must never enter agent context. Use --output-file every time. If you've already retrieved without it, immediately link-cli auth logout is not enough — the card is one-time-use but rotate hygiene matters.
  • --request-approval blocks until the user acts. If the user is asleep, the CLI will hit its timeout. Set expectations.
  • Multi-step _next commands. Some commands return _next.command that must be executed to continue. When in doubt, prefer the inline-polling flags (--interval/--timeout).
  • Output format defaults to toon in non-TTY mode. Fine for prose, but if a downstream step needs to parse a specific field, pass --format json.
  • Don't default to card. The merchant-evaluation step (Section 2) exists because picking the wrong credential type fails the purchase silently or leaks more data than needed.
  • spend-request list only shows active requests by default. Use --include-history to see expired/denied/terminal-state requests. Useful for debugging.

Verification

link-cli --version && link-cli auth status

Exit code 0 means installed and logged in.

Reference

  • references/error-fixes.md — Session-verified error→fix log with exact commands: context ≥100 chars, terminated error, token refresh failure, card expiry, and the full correct end-to-end sequence.

© hewi333, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/stripe-link-cli of hewi333/Mom-n-Pop-Skills.

  • SKILL.md
  • references/error-fixes.md

Open the folder on GitHubat commit 70a2273

Compare with similar skills

Stripe Link CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Stripe Link CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Stripe Link CLI this skillhewi333/Mom-n-Pop-Skills122—~2.8kAutomated safety check: PassMIT
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Minimax PDFpoco-ai/poco-claw1.4k6 repos~2.1kAutomated safety check: PassMIT
Get API Docs with chubandrewyng/context-hub14k1 repos~775Automated safety check: PassMIT
Stripe Projectsfossasia/eventyay1.7k5 repos~2kAutomated safety check: NotesApache-2.0
Effect Client WrapperUsefulSoftwareCo/executor4.1k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Minimax PDF

    poco-ai/poco-claw

    A skill your agent uses when visual quality and design identity matter for a PDF.

    1.4k GitHub starsUsed in 6 repos~2.1k tokens
    Documents & OfficeAuto-check passed
  • Get API Docs with chub

    andrewyng/context-hub

    Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.

    14k GitHub starsUsed in 1 repo~775 tokens
    DevelopmentAuto-check passed
  • Stripe Projects

    fossasia/eventyay

    A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.

    1.7k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check: notes
  • Effect Client Wrapper

    UsefulSoftwareCo/executor

    Pattern for wrapping third-party SDK clients (Stripe, Resend, AWS, etc.) with Effect.

    4.1k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Stripe Apps

    fossasia/eventyay

    A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.

    1.7k GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed

More from hewi333/Mom-n-Pop-Skills

All 13 skills in this repo
  • Construction Business Agent

    hewi333/Mom-n-Pop-Skills

    Runs a construction company's back office by bridging Gmail, Drive and JobTread: routing email attachments to the PM system, checking project status and sending daily Telegram briefings.

    122 GitHub stars~2.3k tokensUpdated 27 days ago
    Auto-check: notes
  • Lead-to-Payment Sales Flow

    hewi333/Mom-n-Pop-Skills

    Runs a small service business lead from intake through estimate, owner approval over Telegram, Stripe payment link and customer email draft to payment tracking.

    122 GitHub stars~2.8k tokensUpdated 27 days ago
    Auto-check: notes
  • QuickBooks Online Integration

    hewi333/Mom-n-Pop-Skills

    Connects a small business to QuickBooks Online for customers, estimates, invoices and payments, using Intuit OAuth 2.0 with token refresh and sandbox or production setups.

    122 GitHub stars~1.9k tokensUpdated 27 days ago
    Auto-check passed
  • Hermes Production Gateway Operations

    hewi333/Mom-n-Pop-Skills

    Procedures for changing the model, restarting and quietly tuning a live Hermes gateway that serves end-users on messaging platforms such as Telegram.

    122 GitHub stars~2k tokensUpdated 27 days ago
    Auto-check: warnings
  • CRM Lite

    hewi333/Mom-n-Pop-Skills

    A skill your agent uses when tracking customer interactions, managing leads, or building a lightweight CRM for small businesses without dedicated CRM software.

    122 GitHub stars~1.5k tokensUpdated 27 days ago
    Auto-check passed
  • Estimator Engine

    hewi333/Mom-n-Pop-Skills

    A skill your agent uses when calculating service estimates for jobs.

    122 GitHub stars~3.1k tokensUpdated 27 days ago
    Auto-check passed

Works with

Questions about Stripe Link CLI

What does Stripe Link CLI do?

Agent-initiated spend via Stripe Link — requests purchases, issues virtual cards, owner approves in the Link mobile/web app. Stripe Link CLI is an agent skill from hewi333/Mom-n-Pop-Skills. Agent-initiated spend via Stripe Link — requests purchases, issues virtual cards, owner approves in the Link mobile/web app.

How do I install Stripe Link CLI in Claude Code?

Run `npx skills add hewi333/Mom-n-Pop-Skills --skill stripe-link-cli -a claude-code`. Or copy the skill folder (skills/stripe-link-cli in hewi333/Mom-n-Pop-Skills) into .claude/skills/stripe-link-cli in your project. Claude Code loads it when a task matches its description.

How do I install Stripe Link CLI in Codex?

Run `npx skills add hewi333/Mom-n-Pop-Skills --skill stripe-link-cli -a codex`. Or copy the skill folder (skills/stripe-link-cli in hewi333/Mom-n-Pop-Skills) into .agents/skills/stripe-link-cli in your project. Codex loads it when a task matches its description.

Can I use Stripe Link CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hewi333/Mom-n-Pop-Skills --skill stripe-link-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stripe-link-cli, .gemini/skills/stripe-link-cli, .github/skills/stripe-link-cli and .opencode/skills/stripe-link-cli in your project.

What does Stripe Link CLI need to run?

Going by SKILL.md and its folder, Stripe Link CLI needs the command-line tools its instructions call (npm, node and npx). Our summary lists: Node.js.

Does Stripe Link CLI access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Stripe Link CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Stripe Link CLI use?

Stripe Link CLI is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Stripe Link CLI use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Stripe Link CLI?

Skills that share tags, products or a category with Stripe Link CLI: Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars), Minimax PDF (poco-ai/poco-claw, 1.4k stars), Get API Docs with chub (andrewyng/context-hub, 14k stars) and Stripe Projects (fossasia/eventyay, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Stripe Link CLI?

hewi333 (a GitHub user) maintains it in hewi333/Mom-n-Pop-Skills, which has 122 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on September 11, 2026.

Source: hewi333/Mom-n-Pop-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.