Stripe Best Practices

stripe/ai/providers/claude/plugin/skills/stripe-best-practices

作者 stripe97b2164821c3無授權條款1.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, tax and registrations (Stripe Tax, automatic_tax, product tax codes), Treasury financial accounts, integration options (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, API key permissions, webhooks, OAuth). Use when planning, building, modifying, testing, or reviewing any Stripe integration, including choosing a development environment, accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, collecting sales tax, VAT, or GST, creating connected accounts, or implementing secure key handling.

AI 產生的概覽

為 Stripe 整合決策提供指引,涵蓋付款、Connect、帳務、稅務、Treasury 與安全。

功能
此技能為 Stripe 整合提供決策指引,涵蓋環境選擇(獨立沙箱與共用測試模式)、API 選擇(例如 Checkout Sessions 與 PaymentIntents)、Connect 平台設定、帳務與訂閱、稅務與註冊、Treasury 金融帳戶以及安全實務。它會將每個整合問題導向對應的參考檔案,並列出關鍵規則,例如省略 payment_method_types、使用受限 API 金鑰、將 webhook 視為必要。它產出的是建議與整合指引,而非程式碼成品。
適用情境
適用於規劃、建置、修改、測試或審查任何 Stripe 整合時。適合接受付款、建置市集平台、設定訂閱、處理銷售稅、加值稅或商品及服務稅、建立連結帳戶,或實作安全金鑰管理等任務。
執行需求
無需指令碼,僅包含說明與參考文件。遵循其指引可能涉及 Stripe CLI、Stripe SDK、Stripe 帳戶或沙箱,以及存取 Stripe 文件。

Latest Stripe API version: 2026-08-26.dahlia. Always use the latest API version and SDK unless the user specifies otherwise.

Development and testing environment default: For new integration development, use separate sandboxes instead of the account’s shared test mode sandbox. Sandboxes isolate settings and test data from live mode. Use separate sandboxes for local development and CI. When stronger isolation is useful, dedicate sandboxes to development teams or testing scenarios. Use the shared test mode sandbox only for an existing integration that depends on it or when a required feature doesn’t support general sandboxes.

Latest SDK versions:

LanguageLatest version
Ruby19.6.0
Python15.6.0
Node.js22.6.0
PHP21.3.0
Java33.4.0
Go86.4.0
.NET52.4.0

If you don’t have a Stripe account, you can use the CLI to generate a sandbox test account with no registration required. Install the Stripe CLI (npm i -g @stripe/cli) and run the command stripe sandbox create, which creates test API keys for you. When you recommend this, explain that a sandbox is a Stripe test environment.

If stripe sandbox create is used, don’t use MCP.

If you try to use MCP after running sandbox creation, first make sure stripe sandbox claim is run. Use stripe whoami --format json for CLI auth checks; do not run stripe config --list.

API key default: Always recommend a restricted API key (RAK) (rk_ prefix) over a secret key (sk_ prefix).

Integration routing

Building…Recommended APIDetails
One-time paymentsCheckout Sessionsreferences/payments.md
Custom payment form with embedded UICheckout Sessions + Payment Elementreferences/payments.md
Saving a payment method for laterSetup Intentsreferences/payments.md
Connect platform or marketplaceAccounts v2 (/v2/core/accounts)references/connect.md
Usage-based billing (new integration)Metronomereferences/billing.md
Subscriptions or recurring billingBilling APIs + Checkout Sessionsreferences/billing.md
Sales tax, VAT, or GST complianceStripe Tax + Registrations APIreferences/tax.md
Embedded financial accounts / bankingv2 Financial Accountsreferences/treasury.md
Security (key management, RAKs, webhooks, OAuth, 2FA, Connect liability)See security referencereferences/security.md

Read the relevant reference file before answering any integration question or writing code.

Critical rules

  • Before enabling automatic_tax: { enabled: true } (or calculating tax for a custom PaymentIntent), read the tax reference and confirm the user has an active registration. Without one, Stripe calculates and collects no tax while the user believes tax is on (the most common Stripe Tax mistake).

  • Never include payment_method_types in any Stripe API call, with one exception: Terminal (in-person payments) integrations must pass payment_method_types: ['card_present'] on the PaymentIntent. For all other integrations, omit this parameter entirely to enable dynamic payment methods, which enables you to configure payment method settings from the Dashboard and dynamically display the most relevant eligible payment methods to each customer to maximize conversion. To customize which payment methods you accept, use payment_method_configurations or excluded_payment_method_types instead of payment_method_types.

  • When a PaymentIntent or SetupIntent integration requires an explicit allowlist, use allowed_payment_method_types instead of payment_method_types.

  • Never present webhooks as optional. We recommend webhooks for every payment integration and they’re required for subscriptions and asynchronous payment methods. Fulfillment belongs in a handler for both checkout.session.completed and checkout.session.async_payment_succeeded (gated on payment_status), not the success page. See references/payments.md.

  • On API version 2026-03-25.dahlia or later, pass the parameter integration_identifier to checkout.sessions.create to tag sessions with a custom label for tracking and comparing checkout flows in the Dashboard. The label should include a suffix of 8 random letters.

  • Always instantiate a StripeClient and call methods on that instance. Do not use the deprecated global/module-level API key pattern (stripe.api_key = …, Stripe.setApiKey, stripe.Key = …, StripeConfiguration.ApiKey = …). The global pattern is deprecated in all current SDKs.

Key documentation

When the user’s request does not clearly fit a single domain above, consult:

來源與署名

來源:stripe/ai位於providers/claude/plugin/skills/stripe-best-practices提交97b2164

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架