# Accounts, Modes and API Keys — Stripe Payments

Source: https://www.skillbyai.com/en/stripe-payments/f-account

> Test mode, live mode and the keys that go with them.

## Test versus live, publishable versus secret

Every Stripe account has a **test mode** and a **live mode**, each with its own data and its own keys; objects created in one are invisible in the other. **Publishable keys** (`pk_test_...`, `pk_live_...`) identify your account to Stripe.js in the browser and can only do limited things such as tokenising payment details. **Secret keys** (`sk_test_...`, `sk_live_...`) can do anything on your account and must only live on your server, in environment variables or a secrets manager. **Restricted keys** (`rk_...`) are secret keys limited to specific resources and permissions, which suits a reporting job or a third-party tool. Stripe also pins your account to an **API version**; the library can request a specific version, so check the docs for your version before upgrading.

## Where each key belongs

Server and client configuration (placeholder keys only).

```bash
# .env on the server (never commit this file)
STRIPE_SECRET_KEY=sk_test_...
STRIPE_WEBHOOK_SECRET=whsec_...

# public config that can ship to the browser
STRIPE_PUBLISHABLE_KEY=pk_test_...

# a restricted key for a read-only reporting job
STRIPE_REPORTING_KEY=rk_test_...

```

## Roll a leaked key immediately

If a secret key ever lands in a repository, log or chat, roll it from the Dashboard API keys page and update your servers. Prefer restricted keys for anything that does not need full access.

**Quiz:** Which key is safe to include in browser JavaScript?

- [x] The publishable key (pk_test_... or pk_live_...)
- [ ] The secret key (sk_live_...)
- [ ] A restricted key with write access
- [ ] The webhook signing secret (whsec_...)

*Answer:* The publishable key (pk_test_... or pk_live_...). Publishable keys are designed to be public; everything else stays on the server.
