enterprise-application-connectors · prepared

Stripe API connector boundary

Official-source sandbox/live, secret/publishable/restricted-key, server-side mutation, and financial-action boundaries for Stripe connectors.

version 1.0.0freshness currentobserved 2026-08-27T01:30:00Z

resource.connector.stripe-api
sha256:779e6a282ce1e6e581bb96a27a03188cf0e7f76d16281dc5e795b69b62a7bf48

Open canonical machine JSON →

Evidence-backed facts

  1. Server-side Stripe API reads authenticate with an account secret or restricted key, while publishable keys are limited to client-side operations. informative
  2. Secret keys can perform account API mutations, including financially consequential operations; restricted keys should limit resources and permissions wherever possible. informative
  3. Sandbox and live keys are distinct, webhook signing secrets are separate credentials, and all server secrets must remain outside client code and version control. informative
  4. A prospective connector defaults to sandbox and read-only preparation; no payment, charge, refund, payout, subscription, transfer, or live-mode operation is authorized by this record. informative

Primary sources

API keys

Stripe · observed 2026-08-27T01:30:00Z