Skip to content
MCPCompare

Vendor-published

PayPal MCP server

PayPal MCP server provides access to PayPal services and operations for AI assistants

PayPal (`com.paypal.mcp/mcp`, v1.0.0) is published by the vendor. It exposes a hosted endpoint over streamable-http and sse, and no self-hostable package. It requires authentication and publishes 3 scopes — but they do not separate reading from writing, so read-only access cannot be granted. 4 of 4 enterprise control criteria are undocumented. Last checked 2026-09-19.
Add to comparison

Identity and maintenance

Publisher and version information
Registry namecom.paypal.mcp/mcp
Publisher domainpaypal.com
Maintainer typeVendor-published

namespace com.paypal.mcp -> paypal.com; host mcp.paypal.com is within paypal.com

Latest version seen1.0.0
Last checked
Last changed

Separate from “last checked”: we check far more often than anything changes.

Enterprise evaluation

Every row below exists whether or not we found an answer. Expand any row to see the exact source and the date. Unknown means undocumented, never unsupported.

Enterprise evaluation criteria for PayPal
Access and authentication
Authentication required

Whether the hosted endpoint accepted a connection with no credentials when we checked.

Yes
We checked checked
POST initialize without credentials -> HTTP 401
Unauthenticated connection attempthttps://mcp.paypal.com/mcp
OAuth 2.1 authorization

Whether the server publishes OAuth discovery metadata a client can follow automatically.

Yes
We checked checked
https://mcp.paypal.com/.well-known/oauth-protected-resource/mcp -> 200
OAuth discovery metadatahttps://mcp.paypal.com/mcp
Dynamic client registration

Without it, an IdP administrator must register a client by hand before anyone can connect.

Yes
We checked checked
"registration_endpoint": "https://mcp.paypal.com/register"
Authorization server metadatahttps://mcp.paypal.com/mcp
Documented scopes
Yes
openid, email, profile
We checked checked
"scopes_supported": ["openid","email","profile"]
Protected Resource Metadatahttps://mcp.paypal.com/mcp
Read and write are separate scopes

A single opaque scope means read-only access cannot be granted: approving access approves everything.

No
We checked checked
scopes_supported is ["openid","email","profile"] -- no separate read-only scope is offered
Protected Resource Metadatahttps://mcp.paypal.com/mcp
Deployment and transport
Streamable HTTP transport
Yes
Registry checked
"type": "streamable-http", "url": "https://mcp.paypal.com/mcp"
SSE transport
Yes
Registry checked
"type": "sse", "url": "https://mcp.paypal.com/sse"
Vendor-hosted endpoint

Data leaves your network. Where it goes is a question for the vendor's documentation.

Yes
Registry checked
Self-hostable package

A published npm, PyPI, container or bundle artifact you can run inside your own perimeter.

No
Registry checked
Supply chain
Public source repository
No
Registry checked
no repository declared in the registry record
Open-source license
Not checked
Repository actively maintained
Not checked
Package deprecated
Not checked
Secret inputs marked as secret

Credential-shaped inputs the publisher did not flag as secret may be logged by a client.

Yes
Registry checked
2 credential input(s), all marked isSecret
Documented controls
Audit logging documented
Not documented
Access controls documented
Not documented
Data residency documented
Not documented
Data retention documented
Not documented

What remains unknown

7 of 18 criteria are undocumented. These are the questions to put to the vendor — not conclusions about the product.

Turn these into a vendor questionnaire

How we checked

One unauthenticated initialize request, plus the two OAuth discovery documents. Nothing was installed or executed. The exact request headers are below so you can reproduce the result — endpoint behaviour can depend on them.

POST https://mcp.paypal.com/mcp
user-agent: mcpcompare.ai/1.0 (+https://mcpcompare.ai/methodology/probe; probe@mcpcompare.ai)
content-type: application/json
accept: application/json, text/event-stream
mcp-protocol-version: 2025-06-18

-> HTTP 401  (auth-required)
   checked 2026-09-19T17:17:16.381Z

Questions people ask

Does the PayPal MCP server require authentication?
Yes. When we connected to https://mcp.paypal.com/mcp without credentials on 2026-09-19, it returned HTTP 401.
Can I grant read-only access to the PayPal MCP server?
No. It publishes ["openid","email","profile"], which does not separate reading from writing, so granting access grants both.
Can the PayPal MCP server be self-hosted?
Not from the registry record. No installable package is declared, so the vendor-hosted endpoint is the only documented option.