All skills
stripe avatar

/stripe-best-practices

@38d8933 official
by stripestripe/ai1.9k stars
349

Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, tax and registrations (Stripe Tax, automatic_tax, product tax codes), Treasury financial accounts, integration options (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, API key permissions, webhooks, OAuth). Use when planning, building, modifying, testing, or reviewing any Stripe integration, including choosing a development environment, accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, collecting sales tax, VAT, or GST, creating connected accounts, or implementing secure key handling.

Use this Skill: https://skilld.dev/gh/stripe/ai/stripe-best-practices

This session only. Nothing lands on disk.

referencestreasury.md

≈199 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Treasury / Financial Accounts

Table of contents

  • v2 Financial Accounts API
  • Legacy v1 Treasury

v2 Financial Accounts API

For embedded financial accounts (bank accounts, account and routing numbers, money movement), use the v2 Financial Accounts API (POST /v2/core/vault/financial_accounts). This is required for new integrations.

For Treasury for platforms concepts and guides, see the Treasury for platforms overview.

Legacy v1 Treasury

Don’t use the v1 Treasury Financial Accounts API (POST /v1/treasury/financial_accounts) for new integrations. Existing v1 integrations continue to work.

Source: SKILL.md on GitHub

No alerts12d5 checks · Risk SAFE
  • Gen Agent Trust Hub12d

    This skill provides architectural guidance and security best practices for Stripe integrations. It includes recommendations for using the Stripe CLI to manage test environments and emphasizes the use of Restricted API Keys. While the listed SDK versions appear to be synthetic or future-dated, the security patterns and tool recommendations align with safe, standard development practices.

  • Socket12d

    No alerts

  • Snyk12d

    Risk: LOW · No issues

  • Runlayer6mo

    1/1 file flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 38d8933. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 2 weeks ago
  • Security
  • stripe
  • payments
  • billing
  • connect
  • webhooks
  • api-design
  • subscriptions
  • marketplace

README badge

README badge for stripe/ai/stripe-best-practices

Guides decisions on Stripe API selection, Connect platform setup, billing and subscriptions, Treasury financial accounts, and security best practices including restricted keys and webhooks. Use when building or reviewing any Stripe integration — payments, marketplaces, subscriptions, or connected accounts.

Generated from the current SKILL.md.

Should I use Checkout Sessions or PaymentIntents?
Use Checkout Sessions for one-time payments and custom forms with Payment Element. PaymentIntents are lower-level and require more manual implementation; use them only when Checkout Sessions cannot meet your requirements.
What API version should I target?
Always use the latest Stripe API version (2026-05-27.dahlia) unless the user explicitly requests otherwise.
Should I use restricted API keys or secret keys?
Always use restricted API keys (rk_ prefix) over secret keys (sk_ prefix) to limit scope and improve security.
Does this skill cover Connect marketplaces and platform setup?
Yes. It includes guidance on Accounts v2, controller properties, and platform liability. Consult the Connect reference before building marketplace features.
What should I do before writing payment or billing code?
Install the Stripe MCP server and call the stripe_implementation_planner tool with your business description to get a tailored integration guide. If MCP is unavailable, use the integration routing table in the skill.

Generated from the current SKILL.md. These answers refresh after source changes.