Shop

Checkout with Stripe

Customers pay on Stripe's secure checkout page. Your site never handles card details, and orders are marked paid when Stripe confirms.

How checkout works

1

Cart

The customer adds products and opens the cart.

2

Checkout page

They review the order summary and fill in billing and shipping details, when you have those turned on.

3

Stripe

They are sent to Stripe's hosted checkout to pay by card.

4

Back to your site

Stripe returns them to an order status page on your site.

The payment itself happens on Stripe, so card numbers never pass through your site.

Connect your Stripe account

Stripe is connected through environment variables on your project's backend. You manage these in the XFORG dashboard, in your project's environment variables.

1

Add your secret key

Copy the secret key from your Stripe dashboard and save it as STRIPE_SECRET_KEY on the backend.

2

Create a webhook in Stripe

Point it at your project's backend address followed by /system/functionality/stripeWebhook, and choose the events listed below.

3

Add the signing secret

Copy the webhook's signing secret and save it as STRIPE_WEBHOOK_SECRET on the backend.

4

Apply

Apply the variable changes in the dashboard.

Shop orders

checkout.session.completed, payment_intent.succeeded, payment_intent.payment_failed

Subscriptions

invoice.paid, invoice.payment_succeeded, invoice.payment_failed, customer.subscription.created, customer.subscription.updated, customer.subscription.deleted

Switch Stripe on

Go to Shop, then Shop Configuration, open Checkout Providers, turn on Stripe and click Save Checkout Providers Settings.

The Mercado Pago and PayPal switches appear on the same tab, but only Stripe processes payments today. A customer who picks another provider cannot finish paying, so leave those off.

What happens after payment

Stripe tells your site about each payment through the webhook you set up.

When Stripe confirms the payment, the order's Payment Status becomes paid, its status becomes Processing and Paid At is recorded.

If the payment fails, the order is marked Failed.

Administrators chosen in Notify Admins get an email about the paid order.

Tags chosen under Tags on Order Paid in User Tracking are given to the customer.

Built-in safety checks

Totals are always worked out again on the server before the customer is sent to Stripe. Checkout stops if a price changed after it went into the cart, if a product is no longer published and active, or if the cart asks for more units than a tracked product has.

Shop checkout always uses your live Stripe key. The per-person Stripe test mode applies to subscriptions only.