For AI agents and LLMs: a structured documentation index is available at /llms.txt. Every page has a Markdown sibling โ€” append .md to any URL.

Skip to content
Paddle Docs home

Build with Codex

Set up Codex for the best possible Paddle workflow by installing the Paddle plugin, connecting the Paddle MCP server, and adding an AGENTS.md file.

AI summary

Set up the Paddle plugin in Codex, configure sandbox and live API keys, and add Paddle conventions to your AGENTS.md file to enable AI-assisted integration development.

  • โ€ข Install the Paddle plugin via codex plugin marketplace add PaddleHQ/paddle-agent-skills and set both PADDLE_SANDBOX_API_KEY and PADDLE_LIVE_API_KEY environment variables to connect MCP servers for sandbox and live environments
  • โ€ข Define Paddle integration conventions in your project's AGENTS.md file to instruct Codex which SDK to use, how to handle webhook verification, and when to use sandbox vs. live โ€” this ensures consistent and safe code generation
  • โ€ข Always review Codex tool calls before execution, especially destructive operations, and explicitly mention the MCP server you want to use in your prompts (e.g., 'Use the paddle-docs MCP server to look up...')

Codex is OpenAI's AI coding agent. It runs as a CLI, an IDE extension, and on the web.

This guide runs through setting up Codex for the best possible experience when building with Paddle.

Before you begin

You'll need:

  • A Paddle account that you want to connect to โ€” sandbox, live, or both.
  • If connecting to a sandbox account, a sandbox API key with any permissions you plan to use.
  • Codex installed.
  • A project, with a Paddle SDK installed.

Install the Paddle plugin

The Paddle plugin bundles Paddle agent skills with the docs MCP server and Paddle MCP servers.

From your terminal, run:

Shell
codex plugin marketplace add PaddleHQ/paddle-agent-skills

Then open Codex and install the paddle plugin from the plugin directory.

To refresh later, run codex plugin marketplace upgrade paddle-agent-skills.

Connect the Paddle MCP servers

The plugin wires up two Paddle MCP servers so the agent can work in both sandbox and live environments. This is useful for porting data from one to the other.

MCP serverURLAuthentication
paddle-sandboxhttps://sandbox-mcp.paddle.com/mcpAPI key
paddle-livehttps://mcp.paddle.com/mcpOAuth or API key

paddle-sandbox reads a sandbox API key from an environment variable. Create a key at Paddle > Developer tools > Authentication, then export it in your shell profile (~/.zshrc, ~/.bashrc, or equivalent):

Shell
export PADDLE_SANDBOX_API_KEY= # Your sandbox API key

Restart Codex and your terminal after setting the variable so the MCP server picks it up.

paddle-live uses OAuth, so there's no API key to set. Authorize it in your browser:

Shell
codex mcp login paddle-live
Check MCP permissions carefully

A live connection made with OAuth has the same read access as your Paddle user role. You can change this under Paddle > Connectors > MCP. Access to sandbox is determined by its API key permissions, so scope the key to only what the agent needs.

Add Paddle conventions to your AGENTS.md

Codex reads project conventions from AGENTS.md at the project root. A focused Paddle section tells it which SDK to use, how to handle environments, and how to verify webhooks.

Create an AGENTS.md file at the project root, or add this to your existing AGENTS.md file.

AGENTS.md
## Paddle integration
When writing or modifying code that integrates with Paddle:
- Always check current Paddle documentation via the `paddle-docs` MCP server before suggesting code. The Paddle API and SDKs evolve frequently โ€” do not rely on training data alone.
- Use the official Paddle SDK for the language in use:
- Node.js โ†’ `@paddle/paddle-node-sdk`
- Python โ†’ `paddle-python-sdk` (imports as `paddle_billing`)
- Go โ†’ `github.com/PaddleHQ/paddle-go-sdk/v5`
- PHP โ†’ `paddlehq/paddle-php-sdk`
- All development uses the sandbox environment. Sandbox API keys contain `_sdbx`; sandbox client-side tokens are prefixed with `test_`.
- Always verify webhook signatures before acting on the payload:
- Node: `paddle.webhooks.unmarshal()`
- Python: `Verifier().verify(request, secret)`
- Go: `paddle.NewWebhookVerifier()` with `Middleware`
- PHP: `(new Verifier())->verify($request, $secret)`
- For destructive account changes (updating prices, archiving products, canceling subscriptions), ask for explicit confirmation before calling the `paddle-sandbox` or `paddle-live` MCP server.
- Use `paddle-sandbox` by default. Only call `paddle-live` when the prompt explicitly mentions live, production, or real customer data.
- API keys and webhook secrets live in environment variables โ€” never inline credentials into code.

Adjust the SDK list to match the languages your project uses. Codex will read this every time you start a session.

Prompt your first integration

With the plugin installed, the Paddle MCP server connected, and your AGENTS.md file in place, ask Codex to scaffold a Paddle integration.

markdown
Add a Paddle Checkout integration to this Next.js app. Use the paddle-docs MCP server to look up the current Paddle.js syntax. Then use the paddle-sandbox MCP server to create three products in my sandbox account โ€” Starter ($10/mo), Pro ($30/mo), Enterprise ($300/mo) โ€” and generate a /pricing page that opens checkout for each tier. Wire up a /api/webhooks route that verifies the signature and logs transaction.completed events.

Codex plans first, then uses the docs MCP for current syntax, the Paddle MCP to create the products in sandbox, and writes code that matches your AGENTS.md conventions.

Best practices

  • Mention Paddle and the relevant MCP server explicitly.
    "Use the paddle-docs MCP server to look up X" beats hoping the agent calls it on its own.
  • Be specific in prompts.
    Concrete pricing, event names, and entity IDs work better than vague descriptions.
  • Review changes before applying.
    Codex shows pending tool calls before executing. Review every tool call, especially anything destructive.
  • Never commit API keys.
    Keep API keys in environment variables.
  • Create your own skills.
    When you find yourself repeating the same instructions over and over, package them as a skill. Run the $plugin-creator skill in Codex to walk through it.

Was this page helpful?