MoltenRock Connect · the Human Queue for Stripe · live
Your agent handles Stripe. You approve every change.
Your AI agent reads over a hundred kinds of Stripe data and proposes the work: refunds, dispute evidence, invoices, subscription changes. Each proposal waits in your Human Queue until you approve it with Touch ID. Then MoltenRock Connect sends it. The agent never holds a write key.
Free download · approving needs MoltenRock Pro · works with Claude Code, Claude Desktop, Cursor, Codex and OpenClaw
- Why
- Charged twice for order #4411, three minutes apart.
- It read
- Two charges on the same card; one delivery.
- Prompted by
- “I think I paid twice, can you check?”
Waiting for you · expires in 72 h if nobody decides
Illustration, example data.
How it works
Your agent does the work. You make the call.
The same four steps for every change, whether it’s a 5.00 refund or a stack of dispute evidence.
- 01It readsCharges, disputes, invoices, subscriptions, customers and more, through Connect. Names and addresses arrive as tokens.
- 02It proposesOne line saying what, why, and what it read, with the customer’s message quoted when that’s what prompted it.
- 03You decideThe card appears in Connect’s Human Queue. Approve with Touch ID, or deny with a note so the agent can amend.
- 04Connect sends itWith the key it holds. The result is logged on your Mac and your agent sees it. Undecided proposals expire after 72 hours.
What your agent can propose
Thirty-four kinds of Stripe change, one queue.
Grouped the way you think about them. The key you give Connect decides which of these are available.
- RefundsFull or partial, up to 1,000.00 per refund in two-decimal currencies, checked against the charge before anything is sent.
- DisputesSave or submit evidence (receipts, shipping, policies, what the customer did), or accept a dispute.
- Fraud reviewsApprove a review, or report a charge as fraudulent.
- CustomersCreate or update a customer, add a note or a tax ID, credit their balance.
- SubscriptionsCancel at period end or undo it, pause or resume payments, change quantity, extend a trial, apply a coupon.
- InvoicesCreate, add an item, finalize, send, void, mark uncollectible or paid outside Stripe.
- Credit notesCreate a credit note, or void one.
- Payment linksCreate a payment link, or deactivate one.
- PaymentsCapture an authorised payment, or cancel it.
- Coupons & promotion codesCreate a coupon or a promotion code; deactivate a promotion code.
Why a queue
Not another key in your agent’s config.
Handing an agent a Stripe key lets it do whatever the key allows, instantly. The Human Queue puts you between the agent and the change.
- The key stays with ConnectIn your Mac’s Keychain, or in MoltenRock’s Secure-Enclave vault. Your agent never receives it.
- Every change waitsNot only the big ones. A refund, a coupon, a billing email: each is a card you approve.
- Customer data stays tokenisedYour agent works with ⟨cust_7F3A⟩, not a name. Real values are resolved only when you approve.
- The record stays on your MacEvery proposal, decision and result, logged locally. No MoltenRock server in the path.
Stripe itself lets you require a reviewer for sensitive actions on agent-tagged keys; the Human Queue works with any key you choose and covers every change your agent proposes. Cloudflare is the next platform coming to the Human Queue. See Cloudflare →
Set up
From download to your first approval.
- 01Install ConnectDownload MoltenRock Connect, move it to Applications and open it.
- 02Add StripePaste a secret or restricted key. Test Connection needs Read on Charges and Refunds. Live or test mode shows on the card.
- 03Add your agentClaude Code, Claude Desktop and Cursor over MCP (Settings → Agent Setup), or a short note for Codex, OpenClaw and others.
- 04Ask for something real“Refund the duplicate charge from this morning.” The proposal appears in your Human Queue.
Questions
Before you connect Stripe
Can my agent change anything in Stripe on its own?
No. It can read, and it can propose. Nothing changes in Stripe until you approve the proposal with Touch ID in MoltenRock Connect; Connect then sends it with the key it holds. The agent never receives a write key.
Doesn’t Stripe have approvals for agents already?
Stripe lets you require a reviewer’s approval for sensitive actions on agent-tagged keys, and that’s a good thing. The Human Queue works with any secret or restricted key you choose, keeps that key away from your agent, waits on every change your agent proposes (not only the sensitive ones), keeps customer names tokenised until you approve, and keeps the record on your Mac.
Which Stripe key should I use?
A secret key (sk_…) or a restricted key (rk_…). You decide what it allows: anything it can’t do is simply unavailable, and if a proposal needs a permission the key doesn’t have, its card names it in Stripe’s words. Test Connection reads your charges, so the key needs at least Read on Charges and Refunds.
Can I try it in test mode first?
Yes. Add a test-mode key; every Stripe card in Connect shows whether it is live or test.
What happens if I don’t answer a proposal?
Nothing is sent. A proposal nobody decides on expires after 72 hours. If you deny one, you can add a note; the agent can amend its proposal and send a new one.
Does my customer data leave my Mac?
Connect talks to Stripe directly from your Mac and your agent talks to Connect on your Mac; there is no MoltenRock server in between. Customer names and addresses reach the agent as tokens and are resolved only when you approve.
What does it cost?
MoltenRock Connect is free to download and covers a couple of platforms for free. Approving Human Queue proposals needs MoltenRock Pro ($9.99/month or $99.99/year), which also unlocks every Connect platform.
Let your agent do the Stripe work. Keep the last word.
Free to download. Approving needs MoltenRock Pro, from $9.99/month.
Who it’s for
MoltenRock for your kind of work
- Online storesShopify, WooCommerce and Stripe: agents answer order questions and propose refunds you approve.See how
- DevelopersAPI keys out of .env and config files; Claude Code, Cursor, Codex, OpenClaw and Hermes, scoped.See how
- Solo founders & startupsNo IT team needed: one vault on your Mac, every agent scoped, nothing changes without you.See how
- Law, accounting & agenciesClient email and keys stay on your Macs; agents read and draft, and never send on their own.See how
- Teams & enterpriseRolling MoltenRock out across a team, and the team Human Queue on our roadmap. Talk to us.See how