Integration guides
Stripe automation: keep payment credentials off the website
Plan payment-event workflows around secret management, test data and duplicate-safe downstream actions.
By AutomateHQ · Updated · 2 min read
Before you start
Keep Stripe secret keys server-side, use restricted access where appropriate and test away from live payments. A browser should never receive a secret key for a back-office automation.
- 01Define the task
- 02Connect safely
- 03Test exceptions
- 04Assign an owner
Separate test credentials from live access
Stripe distinguishes publishable and secret keys, with separate testing and live contexts. Publishable does not mean every key is safe to put in a website. Confirm the key type and its permissions before connecting a workflow.
Decide whether the task only needs to read payment state or can change financial records. Granting refund or payment-related write access needs a clear business reason and appropriate controls.
Connect a payment event to fulfilment
A confirmed payment event might update an order status and create a fulfilment task. Link each downstream action to the source event or payment so retries do not create duplicate work.
Keep the finance system authoritative. A notification in Slack or a row in a spreadsheet is not itself confirmation that a payment succeeded.
Test retries without repeating financial actions
Use test data and check successful payment, failed payment, duplicate notification and a delayed event. Verify incoming events using the provider's supported verification process.
Test an interrupted run after one downstream step has completed. The recovery path should finish only the missing work, not repeat a charge, refund or fulfilment action.
Reconcile unfinished updates with the payment record
A failed fulfilment update does not necessarily mean the payment failed. Check the payment record before deciding which downstream action to retry.
Keep an exception list for confirmed payments whose order updates are incomplete. Give finance and operations access to the records they need to resolve each case.