[Feat] Add Stripe built-in integration - #2995
Open
roomote-roomote[bot] wants to merge 4 commits into
Open
roomote-roomote[bot] wants to merge 4 commits into
roomote-roomote[bot] wants to merge 4 commits into
Conversation
Contributor
This was referenced Sep 19, 2026
daniel-lxs
marked this pull request as ready for review
September 19, 2026 20:33
daniel-lxs
requested review from
brunobergher,
daniel-lxs and
mrubens
as code owners
September 19, 2026 20:33
daniel-lxs
approved these changes
Sep 19, 2026
daniel-lxs
approved these changes
Sep 19, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
MCP_INTEGRATIONSregistry as a deployment-scoped hosted MCP connection backed by an encrypted restricted API key.CredentialIntegrations.tsxflow used by admin-configured providers. This adds no new list, section, or special UI.rk_keys while preserving blank edits that retain an existing stored key; unrestrictedsk_*and public keys are rejected before persistence.stripe_api_writeas disabled, and preserved admin Manage tools control for opt-in writes.Why this change was made
Stripe's official hosted MCP server supports restricted API keys for persistent application access. The deployment-key model matches the researched shared-account scope while preventing accidental storage of unrestricted secret keys.
Impact
Operators can configure Stripe in the same built-in list as existing integrations. Keys are encrypted at rest, unrestricted secret keys are rejected, agent traffic receives only the Roomote proxy URL, and the general write tool starts disabled. Schema and Settings regressions passed alongside the existing proxy/persistence tests, full
check-types,lint:fast, andgit diff --check. Live Stripe authentication, sandbox reads, and credential-backed tool discovery were not performed.Related PRs