पाठ 22 / 25
Security and PCI Scope
Keep card data away from your servers.
Why Stripe.js and Elements matter
Any business that accepts cards must comply with the PCI DSS standard. If raw card numbers touch your servers, your compliance burden is large. With Checkout, Elements or the Payment Element, card details are entered in fields hosted by Stripe (inside iframes) and sent directly to Stripe, so your servers only see tokens and IDs. That typically lets you qualify for the simplest self-assessment, SAQ A; Stripe documents which integration maps to which questionnaire, so check the docs. Always load Stripe.js from https://js.stripe.com rather than bundling or self-hosting it, serve every page over HTTPS, keep secret keys on the server and protect your webhook endpoint with signature checks.
Secure, tested and ready for live money
Before going live, reduce PCI scope, switch keys and webhooks to live mode, configure fraud and tax, and test every path.
Loading Stripe.js correctly
In the browser or a bundled app.
// Option 1: script tag in your HTML
// <script src="https://js.stripe.com/v3/"></script>
// const stripe = Stripe('pk_live_...');
// Option 2: the official loader package, which injects the script from js.stripe.com
import { loadStripe } from '@stripe/stripe-js';
const stripe = await loadStripe('pk_live_...');
// Never do this: posting raw card fields to your own API
// fetch('/api/charge', { body: JSON.stringify({ cardNumber, cvc }) })
A bank's night safe
Elements is like a night-safe slot in the bank wall: customers drop valuables directly into the bank's vault, and your shop never holds the cash.
त्वरित जाँच: Why does using the Payment Element reduce your PCI scope?
- It disables 3D Secure
- It encrypts data with your secret key
- It stores card numbers in your database securely
- Card details go directly to Stripe and never touch your servers
Answer
Card details go directly to Stripe and never touch your servers — Your servers only handle tokens and object IDs.