Get a key, link your Stripe account, make a link, hand it to your operator.
# 1. key (no card required) curl -X POST https://agent-checkout.mrdavesemailaddress.workers.dev/v1/keys \ -H "Content-Type: application/json" \ -d '{"email":"you@example.com","agent_name":"my-agent"}' # → {"api_key": "ack_live_...", "connect_url": "https://connect.stripe.com/..."} # 2. open connect_url in a browser, finish Stripe onboarding (~3 min) # 3. link curl -X POST https://agent-checkout.mrdavesemailaddress.workers.dev/v1/checkout-links \ -H "Authorization: Bearer YOUR_KEY" \ -d '{"amount_cents":900,"product_name":"Widget"}' # 4. hand payment_url to your operator. they click, they pay, you get paid.
Every API key operates in one mode. Pick the one that fits.
| Mode | Money flow | Our fee | Best for |
|---|---|---|---|
| Connect (default) | Settles directly to your Stripe account | Free: 0% · Starter: 0.9% · Pro: 0.5% | Most sellers — 3-minute onboarding, no key management |
| Bring your own key | Directly on your Stripe account | 0% — nothing from us | Privacy-focused sellers, enterprises |
| First-party | Settles to Orbital Desk LLC | N/A | Our own products only — not available to the public |
You are the merchant of record in Connect and BYOK modes. We never hold your funds.
GET /v1/connect/start — auth required. Returns {connect_url}. Open it, complete Stripe's Express onboarding, and you're live. Your key activates automatically.
If you disconnect your Stripe account later, link creation pauses until you reconnect. We'll tell you — the API returns 403 with instructions.
POST /v1/byok — auth required. Body: {"stripe_key": "rk_live_..."} (restricted or secret key).
We validate the key with Stripe, then store it encrypted (AES-GCM). We never display or return it. Links are created directly on your account — zero platform fee.
Bearer token. Put your API key in the Authorization header on every request except POST /v1/keys.
Authorization: Bearer ack_live_...
Keys are shown once at creation and stored as hashes. If you lose it, make a new one.
POST /v1/keys — no auth. No card required.
{
"email": "you@example.com", // required, valid email
"agent_name": "my-agent" // required, 2-80 chars
}
Returns 201 with api_key, key_prefix, and tier ("free"). You must be 18 or older.
POST /v1/checkout-links — auth required.
{
"amount_cents": 900, // required, integer, 50–500000 ($0.50–$5,000)
"currency": "usd", // optional, 3-letter code, default usd
"product_name": "Widget", // required, 2–100 chars, shown to payer
"description": "A fine widget" // optional, max 500 chars
}
Returns 201:
{
"payment_url": "https://buy.stripe.com/...",
"link_id": "plink_...",
"amount_cents": 900,
"currency": "usd",
"product_name": "Widget"
}
GET /v1/links/:link_id — auth required. Tells you whether the operator paid.
{
"link_id": "plink_...",
"paid": true,
"paid_at": 1728394800,
...
}
GET /v1/stats — auth required. Your tier, daily limit, links used today, links created in the last 30 days.
| Tier | Price | Links / day | Extras |
|---|---|---|---|
| Free | $0 | 100 | All endpoints, MCP server |
| Starter | $9/mo | 1,000 | Link analytics, email support |
| Pro | $29/mo | 10,000 | Everything in Starter, priority support |
Exceeding the daily limit returns 429. Paid tiers activate automatically after checkout — your key's tier upgrades within minutes.
All errors look like {"error": "message"}.
| Code | Meaning |
|---|---|
| 400 | Bad input — the message says what's wrong |
| 401 | Missing, invalid, or revoked API key |
| 404 | Link not found (or not yours) |
| 429 | Daily link limit reached for your tier |
| 502 | Payment provider error — retry |
A dependency-free Python MCP server (stdlib only) with two tools: create_checkout_link and check_link_status. Point your MCP client at it — no server needed on our side.
Download: ask in the llms.txt. Configure with your API key as an environment variable.