Skip to content
Last updated

PayPal integration

PayPal is an online payments platform for accepting payments, billing, and payouts.

It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through PayPal's own hosted MCP server. Each user authorizes with their own PayPal account, and agents reach only the resources covered by the permissions granted at authorization.
  • In-house — Agen.co wraps the PayPal REST API directly through its own integration layer, using a REST API app you register once in the PayPal Developer Dashboard.

Pick Official if invoicing, orders and payments, disputes, and transaction search cover what your agents need. Fall back to In-house if your agents must also manage subscriptions, payouts, shipment tracking, or the product catalog — the Official server's granted permissions don't cover those.


Connect via the official MCP server

Prerequisites

  • A PayPal account with access to the resources you want to connect. No app needs to be registered with PayPal — the MCP server registers Agen.co as a client automatically, so there is no Client ID or Client Secret to copy.

Connect PayPal in Agen.co

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.

  2. In the Select connector drawer, search for PayPal and select it. The Add PayPal panel opens with Official selected at the top.

  3. Fill in the field:

    FieldRequiredDescription
    Instance SlugYesPrefixes each imported tool as slug__tool, so several instances of the connector can coexist. Prefilled with paypal. Use lowercase kebab-case. You can change it later from the connector's settings.
  4. Click Connect. PayPal opens in a new tab, and the panel shows Waiting for authorization — complete it in the opened tab…

  5. Sign in to PayPal if prompted, then approve the requested access on PayPal's consent screen.

  6. Back in Agen.co, the panel switches to Select the tools to import from PayPal. Every tool is toggled on; turn off any you don't want to import, then click Add.

The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved, even though the PayPal tab reported success.

Authorize each user

Adding the connector doesn't authorize anyone's tool calls yet. The first time each user's agent calls a PayPal tool, the call returns an authorization link instead of a result. The user opens the link and signs in — authorization happens on live paypal.com, with no sandbox option — and approves access on a consent screen that names the app pp-mcp-server. After that, the user's tool calls run with their own PayPal account, within the permissions granted.

Once connected, PayPal appears under My connectors with tools covering:

AreaWhat it covers
InvoicesCreating, listing, and sending invoices, one at a time or in bulk
Payment linksCreating shareable payment links, listing them, and checking their status
DisputesListing disputes
ReportingListing transactions for a date range of up to 31 days

create_invoice, send_invoice, and create_payment_link open an interactive form for the user to fill in, rather than taking the details as tool arguments.

The Official server's granted permissions don't cover subscriptions, payouts, shipment tracking, or the product catalog. Use the In-house tab for those.

Enabling the PayPal connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect to PayPal

PayPal is an online payments platform for accepting payments, billing, and payouts. Integrating PayPal with Frontegg lets your application create and capture orders, attach shipment tracking, refund captures, manage invoices and chase unpaid ones, run subscriptions with their plans and products, send payouts, handle disputes, and search transactions on behalf of your users — all through Frontegg's integration layer (PayPal REST API). PayPal authenticates with OAuth 2.0 client credentials.

Prerequisites

PayPal uses the OAuth 2.0 client credentials grant — an app-to-app flow with no browser step or redirect URL. You create a REST API app in the PayPal Developer Dashboard, which issues a Client ID and Secret, and the integration exchanges them for a short-lived access token on each request.

Step 1: Open Apps & Credentials

Sign in to the PayPal Developer Dashboard and open Apps & Credentials. Use the Sandbox / Live toggle to choose the environment — sandbox and live apps have separate credentials. Your account starts with a Default Application, or click Create App to add one.

PayPal Apps & Credentials page with the Sandbox/Live toggle and REST API apps

Step 2: Copy the Client ID and Secret

Open your app. Copy the Client ID and reveal and copy the Secret.

Keep your Secret safe

The Secret grants access to your account through the API. Treat it like a password and never expose it in client-side code or commit it to version control. You can add or delete secrets on the app page.

PayPal app page showing the Client ID and Secret key

Step 3: Enable the features you need

Scroll to Features on the app page and enable the capabilities the integration should use — for example Invoicing, Subscriptions, Payouts, Customer disputes, and Transaction search. PayPal grants only the matching scopes to tokens issued for the app, and drops the rest from the token without failing the request. A missing feature therefore does not stop the integration from connecting — it surfaces later, as a NOT_AUTHORIZED error on the affected operation. If a tool fails that way, check this section first.

PayPal app Features section with payment capabilities and add-on services

Configure the Frontegg portal

Once you have your credentials, configure the integration in the Frontegg portal:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → PayPal.
  2. Enter the Client ID and Client Secret.
  3. Enable Use sandbox environment only if you entered sandbox credentials. Leave it off for live credentials.
  4. Click Save.

The integration requests the following scopes, granted through the app's Features. All scopes except openid share the prefix https://uri.paypal.com, abbreviated as ... below.

ScopeDescription
.../services/payments/realtimepaymentCreate and manage orders
.../services/payments/paymentAttach and correct shipment tracking on orders
.../services/payments/payment/authcaptureAuthorize, capture, and reauthorize payments
.../services/payments/refundRefund captured payments
.../services/invoicingCreate, send, and manage invoices
.../services/subscriptionsManage subscriptions, plans, and products
.../payments/payoutsSend payouts
.../services/disputes/read-sellerRead disputes
.../services/disputes/update-sellerRespond to disputes
.../services/reporting/search/readSearch transactions and read account balances
openidRead the connected account's profile

Keep your credentials secure

Never share or commit your Secret to version control.

Additional resources