Skip to content

Stripe webhook

A message Stripe sends to your server when something happens in your account, like a payment succeeding or a subscription being cancelled.

The page a customer lands on after checkout is not proof they paid. They can close the tab early or type that URL in themselves. Subscriptions also change with nobody on your site at all, like a renewal at 3am or a card that expires.

Webhooks are how your app finds out. Stripe posts the event to an endpoint, and your code checks it's genuine before updating anything.

On Base44 that endpoint is a backend function, since each one gets its own URL. Keep the signing secret in secrets and verify the signature on every request. Otherwise anyone can post a fake "payment succeeded".

Base44 workflows can react to app payments now, but the docs say subscription renewals may not trigger one yet. So for subscriptions, the webhook is still your source of truth.

Expect the same event to arrive twice, and test the sad paths, like a failed card.

I've got Stripe payments and subscriptions in production on client apps.