Agent skill

Stripe App Setup

by vellum-ai in vellum-ai/vellum-assistant

Create and configure a Stripe restricted API key so the assistant can manage payments, subscriptions, and customers under its own scoped identity

MITAuto-check passed

Install Stripe App Setup

skills CLI
$ npx skills add vellum-ai/vellum-assistant --skill stripe-app-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vellum-ai/vellum-assistant stripe-app-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vellum-ai/vellum-assistant.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/stripe-app-setup .claude/skills/stripe-app-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stripe-app-setup
GitHub stars
1.4k
Token cost
~1.8k tokens
SKILL.md length
777 words
Files
4 (incl. scripts, assets)
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Create and configure a Stripe restricted API key so the assistant can manage payments, subscriptions, and customers under its own scoped identity

  • Works in 5 steps: Check Existing Configuration → Create the Restricted API Key → Collect the API Key → …
  • SKILL.md covers Overview, Prerequisites, Setup Flow and API Usage, plus 3 more sections
  • Runs TypeScript scripts from its folder; calls curl and bun; reaches api.stripe.com

What it does

Stripe App Setup is an agent skill from vellum-ai/vellum-assistant. Create and configure a Stripe restricted API key so the assistant can manage payments, subscriptions, and customers under its own scoped identity

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and assets (for example `scripts/check-config.ts` and `scripts/store-key.ts`). Compatibility notes: Designed for Vellum personal assistants

It works with Stripe. The repository describes itself as: An AI Assistant that’s easy to setup, does your work 24/7, knows your preferences and gets better over time. The licence is MIT.

Example prompts

  • “/stripe-app-setup”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Designed for Vellum personal assistants

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Check Existing Configuration
  2. Create the Restricted API Key
  3. Collect the API Key
  4. Verify
  5. Report Success

What it can do on your machine

Read from SKILL.md and the folder at commit 33cc983. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.stripe.com

    Also links to:

    • dashboard.stripe.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Vellum personal assistants

    From compatibility in the SKILL.md frontmatter.

Context cost

Stripe App Setup loads about 1.8k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 777 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from vellum-ai/vellum-assistant at commit 33cc983, republished under its MIT licence (© vellum-ai). 777 words, ~1,777 tokens.

Download SKILL.mdSave it as .claude/skills/stripe-app-setup/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
stripe-app-setup
description
Create and configure a Stripe restricted API key so the assistant can manage payments, subscriptions, and customers under its own scoped identity
compatibility
Designed for Vellum personal assistants
metadata.icon
assets/icon.svg
metadata.emoji
💳

Overview

Set up a Stripe restricted API key so the assistant can interact with a Stripe account — querying customers, managing subscriptions, processing refunds, reading invoices, and monitoring payments as a scoped entity.

Restricted API keys (RAKs) limit access to only the specific Stripe resources the assistant needs, reducing the blast radius if a key is ever compromised. RAKs are drop-in replacements for secret keys — they work identically with every Stripe API.

Total manual effort: ~2 interactions — create the restricted key in the Dashboard and hand it over via secure prompt.

Prerequisites

  • User must have admin or developer access to the Stripe account
  • User must be logged into the Stripe Dashboard in their browser

Setup Flow

Step 0: Check Existing Configuration

Before starting, check whether Stripe is already configured by running the check script:

bash
bun skills/stripe-app-setup/scripts/check-config.ts

The script outputs JSON: { "configured": boolean, "details": string }.

  • If configured is true — Stripe is already set up. Offer to verify the connection or reconfigure.
  • If configured is false — continue to Step 1.
Step 1: Create the Restricted API Key

Direct the user to create a new restricted key:

Open https://dashboard.stripe.com/apikeys and click + Create restricted key.

When Stripe asks "How will you use this API key?", select Providing this key to another website and enter the assistant's name.

Guide them through the permissions. A good default for managing payments, customers, and subscriptions:

ResourceAccess Level
CustomersRead & Write
ChargesRead & Write
InvoicesRead & Write
Payment IntentsRead & Write
SubscriptionsRead & Write
ProductsRead
PricesRead
BalanceRead
DisputesRead
PayoutsRead

Adjust permissions up or down based on the user's needs. The principle of least privilege applies — only request what the assistant will actually use. For read-only monitoring, set everything to Read.

Click Create key when done.

Important: The restricted key is revealed only once after creation. The user must copy it immediately.

Step 2: Collect the API Key

After the user copies their restricted key, run the store script to securely collect and store it:

bash
bun skills/stripe-app-setup/scripts/store-key.ts

The script opens a secure credential prompt in the user's app, stores the key in the encrypted vault with the correct injection templates for api.stripe.com, and exits. If it exits 0, the key is stored. Exit code 130 means the user cancelled the prompt — nothing was stored; that's a valid choice, not an error, so ask whether they'd like to try again rather than treating it as a failure. Any other non-zero exit is a real failure.

Step 3: Verify

After storing the key, verify the connection:

bash
curl -s https://api.stripe.com/v1/balance

Run with network_mode: "proxied" and the stripe credential. A successful response returns the account's balance object with available and pending arrays.

If the response returns a 401, the key is invalid or revoked. If 403, the key doesn't have the required permissions for the endpoint.

Show full SKILL.md (317 more words)Show less
Step 4: Report Success

Summarize with the completed checklist:

"Setup complete! ✅ Restricted API key configured ✅ Connection verified — balance accessible

Key type: Restricted API key (rk_...) Permissions: {list the configured permission levels} Key management: https://dashboard.stripe.com/apikeys"

API Usage

After setup, use bash with curl to call the Stripe API. The credential proxy injects the Authorization: Bearer header automatically when using network_mode: "proxied" with the stripe credential.

Common API Calls

List customers:

bash
curl -s https://api.stripe.com/v1/customers?limit=10

Create a customer:

bash
curl -s https://api.stripe.com/v1/customers \
  -d "email=customer@example.com" \
  -d "name=Jane Doe"

List recent payments:

bash
curl -s https://api.stripe.com/v1/payment_intents?limit=10

List subscriptions:

bash
curl -s https://api.stripe.com/v1/subscriptions?limit=10

Retrieve an invoice:

bash
curl -s https://api.stripe.com/v1/invoices/{invoice_id}

Issue a refund:

bash
curl -s https://api.stripe.com/v1/refunds \
  -d "payment_intent={pi_id}"

All calls use network_mode: "proxied" with the stripe credential.

Pagination

Stripe uses cursor-based pagination. Use starting_after with the last object's ID to page forward:

bash
curl -s "https://api.stripe.com/v1/customers?limit=100&starting_after=cus_lastId"
Sandbox vs Live

Stripe has separate sandbox and live modes with separate API keys. Keys starting with rk_test_ are sandbox keys; rk_live_ are live keys. The assistant uses whichever key the user provides.

Credential Reference

All credentials are stored under service: stripe:

FieldDescriptionWhen Set
api_keyRestricted API key (rk_live_ or rk_test_)Step 2

Troubleshooting

401 Unauthorized

The API key is invalid or has been revoked. Create a new restricted key in the Dashboard and re-run Step 2.

403 Forbidden / "Insufficient permissions"

The restricted key doesn't have the required permission for the API endpoint being called. Edit the key's permissions in the Dashboard at https://dashboard.stripe.com/apikeys (click the overflow menu → Edit key).

"No such customer" / "No such subscription"

Sandbox and live mode are separate environments. A sandbox key can't access live mode objects and vice versa. Confirm the key mode matches the data being queried.

Important Notes

  • Restricted API keys do not expire automatically. They remain valid until revoked in the Dashboard.
  • Live mode restricted keys can only be revealed once — the user must copy immediately after creation.
  • Always confirm with the user before performing write operations (creating charges, issuing refunds, modifying subscriptions).
  • Stripe rate limits API calls — standard limit is 100 read operations/second and 100 write operations/second per key.

© vellum-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, assets) in skills/stripe-app-setup of vellum-ai/vellum-assistant.

  • SKILL.md
  • assets/icon.svg
  • scripts/check-config.ts
  • scripts/store-key.ts

Open the folder on GitHubat commit 33cc983

Compare with similar skills

Stripe App Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Stripe App Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Stripe App Setup this skillvellum-ai/vellum-assistant1.4k—~1.8kAutomated safety check: PassMIT
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Minimax PDFpoco-ai/poco-claw1.4k6 repos~2.1kAutomated safety check: PassMIT
Get API Docs with chubandrewyng/context-hub14k1 repos~775Automated safety check: PassMIT
Stripe Projectsfossasia/eventyay1.7k5 repos~2kAutomated safety check: NotesApache-2.0
Effect Client WrapperUsefulSoftwareCo/executor4.1k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Minimax PDF

    poco-ai/poco-claw

    A skill your agent uses when visual quality and design identity matter for a PDF.

    1.4k GitHub starsUsed in 6 repos~2.1k tokens
    Documents & OfficeAuto-check passed
  • Get API Docs with chub

    andrewyng/context-hub

    Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.

    14k GitHub starsUsed in 1 repo~775 tokens
    DevelopmentAuto-check passed
  • Stripe Projects

    fossasia/eventyay

    A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.

    1.7k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check: notes
  • Effect Client Wrapper

    UsefulSoftwareCo/executor

    Pattern for wrapping third-party SDK clients (Stripe, Resend, AWS, etc.) with Effect.

    4.1k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Stripe Apps

    fossasia/eventyay

    A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.

    1.7k GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed

More from vellum-ai/vellum-assistant

All 108 skills in this repo
  • Vellum GitHub App Setup

    vellum-ai/vellum-assistant

    Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity.

    1.4k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Discord App Setup

    vellum-ai/vellum-assistant

    Connect a Discord bot to the assistant via the Discord Gateway with guided application creation and intent configuration

    1.4k GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Sentry App Setup

    vellum-ai/vellum-assistant

    Create and configure a Sentry internal integration so the assistant can manage issues, alerts, and releases under its own identity

    1.4k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Memory Corpus Ingest

    vellum-ai/vellum-assistant

    Ingest a large dataset into memory as a skimmed map. An agent skill from vellum-ai/vellum-assistant.

    1.4k GitHub stars~3k tokensUpdated yesterday
    Auto-check: notes
  • Plugin Builder

    vellum-ai/vellum-assistant

    A skill your agent uses when the user wants to build, scaffold, ship, or edit a Vellum plugin that bundles multiple surfaces (hooks, tools, skills, and more) into one installable package.

    1.4k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Slack App Setup

    vellum-ai/vellum-assistant

    Connect a Slack app to the Vellum Assistant via Socket Mode.

    1.4k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check: warnings

Works with

Questions about Stripe App Setup

What does Stripe App Setup do?

Create and configure a Stripe restricted API key so the assistant can manage payments, subscriptions, and customers under its own scoped identity. Stripe App Setup is an agent skill from vellum-ai/vellum-assistant.

How do I install Stripe App Setup in Claude Code?

Run `npx skills add vellum-ai/vellum-assistant --skill stripe-app-setup -a claude-code`. Or copy the skill folder (skills/stripe-app-setup in vellum-ai/vellum-assistant) into .claude/skills/stripe-app-setup in your project. Claude Code loads it when a task matches its description.

How do I install Stripe App Setup in Codex?

Run `npx skills add vellum-ai/vellum-assistant --skill stripe-app-setup -a codex`. Or copy the skill folder (skills/stripe-app-setup in vellum-ai/vellum-assistant) into .agents/skills/stripe-app-setup in your project. Codex loads it when a task matches its description.

Can I use Stripe App Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vellum-ai/vellum-assistant --skill stripe-app-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stripe-app-setup, .gemini/skills/stripe-app-setup, .github/skills/stripe-app-setup and .opencode/skills/stripe-app-setup in your project.

What does Stripe App Setup need to run?

Going by SKILL.md and its folder, Stripe App Setup needs TypeScript for the scripts in its folder and the command-line tools its instructions call (curl and bun). Our summary lists: Node.js. Compatibility (from SKILL.md): Designed for Vellum personal assistants.

Does Stripe App Setup access the network?

SKILL.md names 2 domains. In commands or code: api.stripe.com; the agent is likely to contact it when it follows the instructions. As links in the text: dashboard.stripe.com. This is read from the text; nothing was executed.

Is Stripe App Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Stripe App Setup use?

Stripe App Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Stripe App Setup use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Stripe App Setup?

Skills that share tags, products or a category with Stripe App Setup: Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars), Minimax PDF (poco-ai/poco-claw, 1.4k stars), Get API Docs with chub (andrewyng/context-hub, 14k stars) and Stripe Projects (fossasia/eventyay, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Stripe App Setup?

vellum-ai (a GitHub organization) maintains it in vellum-ai/vellum-assistant, which has 1,408 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 9, 2026.

Source: vellum-ai/vellum-assistant on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.