पाठ 25 / 25

A Stripe Integration Checklist

Review before taking real payments.

Questions to ask

Are prices calculated on the server and amounts sent as integers in the smallest unit? Is fulfilment driven by verified webhooks with duplicate events handled? Do POST requests that create money movement use idempotency keys? Are card errors shown to customers while API errors are retried or alerted? Are SCA, delayed payment methods and off-session failures handled? Do subscriptions sync status from webhooks and handle past_due? Are refunds and disputes monitored? Is card data kept off your servers with Stripe.js loaded from js.stripe.com? Are live keys and live webhook secrets in a secrets manager?

The checklist

Use it in code review and launch readiness.

# [ ] amounts computed server-side, integers in minor units, explicit currency
# [ ] metadata links Stripe objects to your order and user IDs
# [ ] webhooks: raw body, signature verified, 2xx fast, duplicates ignored
# [ ] fulfilment from checkout.session.completed / payment_intent.succeeded
# [ ] idempotency keys on create and refund calls; maxNetworkRetries set
# [ ] card errors -> customer message; transient errors -> backoff; bugs -> alert
# [ ] requires_action, processing and authentication_required paths handled
# [ ] subscription status synced; past_due and trial_will_end handled
# [ ] refunds, disputes and payouts monitored and reconciled
# [ ] Stripe.js from js.stripe.com; HTTPS everywhere; no card data on servers
# [ ] live keys and whsec_ secrets in a secrets manager; restricted keys where possible
# [ ] Radar rules, statement descriptor and tax settings reviewed

Watch the first live payments closely

Make a small real purchase and refund it, confirm the webhook fired and the order was fulfilled, and monitor errors and declines during the first days after launch.

त्वरित जाँच: Which item belongs on a Stripe production checklist?

  • Amounts are calculated in the browser
  • Secret keys are embedded in the mobile app
  • Webhook signatures are verified and duplicate events are ignored
  • Fulfilment happens on the success page only
Answer

Webhook signatures are verified and duplicate events are ignored — Verified, idempotent webhooks are the backbone of a reliable integration.