Skip to main content

At a glance

  • Availability: Experimental (how to enable).
  • Authentication: OAuth 2.0.
  • Connection: A user authorizes the connection in the provider’s consent screen.
  • Scopes: MERCHANT_PROFILE_READ, PAYMENTS_READ, ORDERS_READ, CUSTOMERS_READ, ITEMS_READ.
  • Provider documentation: Authentication reference.

Credentials

Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.

Setup

  1. Create a Square application: Go to the Developer Console at https://developer.squareup.com/apps and create an application. Use the Production tab for live data; the Sandbox tab (connect.squareupsandbox.com) provides a test seller account.
  2. Configure the redirect URL: In the app’s OAuth settings, set the Production Redirect URL to your deployment’s /api/auth/square/callback URL.
  3. Copy credentials: Copy the Application ID and OAuth Application Secret from the OAuth page into SQUARE_CLIENT_ID and SQUARE_CLIENT_SECRET in your .env.
  4. Connect and verify: Complete the OAuth consent flow, then run List Locations to confirm access.

Provider notes

  • This connector uses the confidential code flow; Square’s token endpoint takes client_id and client_secret in the JSON request body
  • Every request sends a Square-Version header (tools default to 2026-05-20); update the default to adopt newer API versions
  • Refresh tokens from the code flow do not expire, but sellers can revoke access at any time
Provider API reference.

Tools

Verify the connection

Call a read tool such as square__list_payments with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.