Evidence-backed facts
- Server-side Stripe API reads authenticate with an account secret or restricted key, while publishable keys are limited to client-side operations. informative
- Secret keys can perform account API mutations, including financially consequential operations; restricted keys should limit resources and permissions wherever possible. informative
- Sandbox and live keys are distinct, webhook signing secrets are separate credentials, and all server secrets must remain outside client code and version control. informative
- A prospective connector defaults to sandbox and read-only preparation; no payment, charge, refund, payout, subscription, transfer, or live-mode operation is authorized by this record. informative