Payment Testing
petrkindlmann/qa-skills
Test payment and checkout flows end to end against PSP sandboxes — Stripe first, with the general pattern for Adyen/Braintree/PayPal.
Guide for testing Polar payment integrations using the sandbox environment.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add chmonitor/chmonitor --skill polar-testing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install chmonitor/chmonitor polar-testing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/polar-testing .claude/skills/polar-testing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "polar-testing" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/polar-testing into .claude/skills/polar-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polar-testing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/polar-testingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add chmonitor/chmonitor --skill polar-testing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install chmonitor/chmonitor polar-testing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/polar-testing .agents/skills/polar-testing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "polar-testing" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/polar-testing into .agents/skills/polar-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polar-testing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add chmonitor/chmonitor --skill polar-testing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install chmonitor/chmonitor polar-testing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/polar-testing .cursor/skills/polar-testing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "polar-testing" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/polar-testing into .cursor/skills/polar-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polar-testing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/chmonitor/chmonitor.git --path .agents/skills/polar-testing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add chmonitor/chmonitor --skill polar-testing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install chmonitor/chmonitor polar-testing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/polar-testing .gemini/skills/polar-testing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "polar-testing" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/polar-testing into .gemini/skills/polar-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polar-testing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install chmonitor/chmonitor polar-testingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add chmonitor/chmonitor --skill polar-testing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/polar-testing .github/skills/polar-testing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "polar-testing" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/polar-testing into .github/skills/polar-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polar-testing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add chmonitor/chmonitor --skill polar-testing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install chmonitor/chmonitor polar-testing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/polar-testing .opencode/skills/polar-testing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "polar-testing" agent skill from https://github.com/chmonitor/chmonitor/tree/main/.agents/skills/polar-testing into .opencode/skills/polar-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "polar-testing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
polar-testingGuide for testing Polar payment integrations using the sandbox environment.
Polar Testing is an agent skill from chmonitor/chmonitor. Guide for testing Polar payment integrations using the sandbox environment. Use this skill when: (1) Setting up the Polar sandbox for development; (2) Testing checkout flows without real payments; (3) Using Stripe test cards with Polar; (4) Writing integration tests for payment flows; (5) Testing webhooks locally with ngrok; (6) Mocking Polar in unit tests; (7) Setting up CI/CD pipelines with Polar sandbox; (8) Debugging payment issues in sandbox.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Data & Analytics, covering DataFrames, Webhooks and Unit testing. It works with Stripe. The repository describes itself as: Open-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations. The licence is GPL-3.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit fc39ef0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmngrokFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
sandbox.polar.shabc123.ngrok.ioAlso links to:
sandbox-api.polar.shFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
POLAR_ACCESS_TOKENPOLAR_WEBHOOK_SECRETPOLAR_SANDBOX_TOKENPOLAR_SANDBOX_WEBHOOK_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Polar Testing loads about 2.8k tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 469 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
py the ngrok URL (e.g., `https://abc123.ngrok.io`) and configure it in Polar:2. Add endpoint: `https://abc123.ngrok.io/api/webhooks/polar`# .env.localAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from chmonitor/chmonitor at commit fc39ef0, republished under its GPL-3.0 licence (© chmonitor). 469 words, ~2,751 tokens.
.claude/skills/polar-testing/SKILL.md (or your agent's skills folder).Test Polar integrations safely using the sandbox environment - a fully isolated server where you can experiment without affecting production data or processing real payments.
The sandbox is completely isolated from production. You need separate:
// TypeScript
import { Polar } from "@polar-sh/sdk";
const polar = new Polar({
accessToken: process.env.POLAR_ACCESS_TOKEN,
server: "sandbox", // Switch to "production" for live
});# Python
from polar_sdk import Polar
polar = Polar(
access_token=os.environ["POLAR_ACCESS_TOKEN"],
server="sandbox",
)// Go
s := polargo.New(
polargo.WithServer("sandbox"),
polargo.WithSecurity(os.Getenv("POLAR_ACCESS_TOKEN")),
)Polar uses Stripe for payment processing. Use these test card numbers:
| Card Number | Brand | CVC | Expiry |
|---|---|---|---|
| 4242 4242 4242 4242 | Visa | Any 3 digits | Any future date |
| 5555 5555 5555 4444 | Mastercard | Any 3 digits | Any future date |
| 3782 822463 10005 | Amex | Any 4 digits | Any future date |
| 6011 1111 1111 1117 | Discover | Any 3 digits | Any future date |
| Card Number | Decline Reason |
|---|---|
| 4000 0000 0000 0002 | Generic decline |
| 4000 0000 0000 9995 | Insufficient funds |
| 4000 0000 0000 9987 | Lost card |
| 4000 0000 0000 9979 | Stolen card |
| 4000 0000 0000 0069 | Expired card |
| 4000 0000 0000 0127 | Incorrect CVC |
| Card Number | Behavior |
|---|---|
| 4000 0027 6000 3184 | Requires 3DS authentication |
| 4000 0000 0000 3220 | Requires 3DS authentication |
# Start your app
npm run dev
# In another terminal, start ngrok
ngrok http 3000Copy the ngrok URL (e.g., https://abc123.ngrok.io) and configure it in Polar:
https://abc123.ngrok.io/api/webhooks/polar# .env.local
POLAR_ACCESS_TOKEN=pat_sandbox_xxx
POLAR_WEBHOOK_SECRET=whsec_sandbox_xxx
POLAR_SERVER=sandboximport { describe, it, expect, beforeAll } from "vitest";
import { Polar } from "@polar-sh/sdk";
describe("Polar Checkout", () => {
const polar = new Polar({
accessToken: process.env.POLAR_SANDBOX_TOKEN!,
server: "sandbox",
});
let testProductId: string;
beforeAll(async () => {
// Create test product
const product = await polar.products.create({
name: "Test Product",
organizationId: process.env.POLAR_ORG_ID!,
prices: [{
type: "one_time",
amountType: "fixed",
priceAmount: 1000,
priceCurrency: "usd",
}],
});
testProductId = product.id;
});
it("should create checkout session", async () => {
const checkout = await polar.checkouts.create({
products: [testProductId],
successUrl: "http://localhost:3000/success",
customerEmail: "test@example.com",
});
expect(checkout.status).toBe("open");
expect(checkout.url).toBeDefined();
expect(checkout.url).toContain("sandbox");
});
it("should retrieve checkout", async () => {
const checkout = await polar.checkouts.create({
products: [testProductId],
successUrl: "http://localhost:3000/success",
});
const retrieved = await polar.checkouts.get({ id: checkout.id });
expect(retrieved.id).toBe(checkout.id);
});
});import { describe, it, expect } from "vitest";
import { createHmac } from "crypto";
describe("Webhook Handler", () => {
const webhookSecret = "whsec_test_secret";
function signPayload(payload: string, timestamp: number): string {
const signedPayload = `${timestamp}.${payload}`;
return createHmac("sha256", webhookSecret)
.update(signedPayload)
.digest("hex");
}
it("should verify valid webhook signature", async () => {
const payload = JSON.stringify({
type: "order.paid",
data: { id: "order_123" },
});
const timestamp = Math.floor(Date.now() / 1000);
const signature = signPayload(payload, timestamp);
const response = await fetch("/api/webhooks/polar", {
method: "POST",
headers: {
"Content-Type": "application/json",
"webhook-id": "evt_123",
"webhook-timestamp": timestamp.toString(),
"webhook-signature": `v1,${signature}`,
},
body: payload,
});
expect(response.status).toBe(200);
});
it("should reject invalid signature", async () => {
const response = await fetch("/api/webhooks/polar", {
method: "POST",
headers: {
"Content-Type": "application/json",
"webhook-id": "evt_123",
"webhook-timestamp": "1234567890",
"webhook-signature": "v1,invalid",
},
body: JSON.stringify({ type: "order.paid" }),
});
expect(response.status).toBe(400);
});
});describe("License Keys", () => {
it("should validate license key", async () => {
// First create a customer with a license key benefit
// Then validate the key
const result = await polar.licenseKeys.validate({
key: "TEST-XXXX-XXXX-XXXX",
organizationId: process.env.POLAR_ORG_ID!,
});
expect(result.valid).toBe(true);
expect(result.customer).toBeDefined();
});
it("should reject invalid license key", async () => {
const result = await polar.licenseKeys.validate({
key: "INVALID-KEY",
organizationId: process.env.POLAR_ORG_ID!,
});
expect(result.valid).toBe(false);
});
});import { vi } from "vitest";
// Mock the entire SDK
vi.mock("@polar-sh/sdk", () => ({
Polar: vi.fn().mockImplementation(() => ({
checkouts: {
create: vi.fn().mockResolvedValue({
id: "checkout_mock",
url: "https://sandbox.polar.sh/checkout/mock",
status: "open",
}),
get: vi.fn().mockResolvedValue({
id: "checkout_mock",
status: "succeeded",
}),
},
customers: {
getState: vi.fn().mockResolvedValue({
activeSubscriptions: [
{ id: "sub_mock", status: "active", productId: "prod_mock" },
],
grantedBenefits: [],
}),
},
subscriptions: {
list: vi.fn().mockResolvedValue([]),
cancel: vi.fn().mockResolvedValue({}),
},
})),
}));export const mockWebhookPayloads = {
orderPaid: {
type: "order.paid",
data: {
id: "order_123",
status: "paid",
customer_id: "cust_123",
product_id: "prod_123",
total_amount: 2900,
currency: "usd",
},
},
subscriptionCreated: {
type: "subscription.created",
data: {
id: "sub_123",
status: "active",
customer_id: "cust_123",
product_id: "prod_123",
current_period_end: "2025-02-15T00:00:00Z",
},
},
subscriptionCanceled: {
type: "subscription.canceled",
data: {
id: "sub_123",
status: "active",
cancel_at_period_end: true,
ends_at: "2025-02-15T00:00:00Z",
},
},
benefitGrantCreated: {
type: "benefit_grant.created",
data: {
id: "grant_123",
customer_id: "cust_123",
benefit_id: "benefit_123",
is_granted: true,
properties: {
license_key: "TEST-XXXX-XXXX-XXXX",
},
},
},
};name: Test Polar Integration
on: [push, pull_request]
jobs:
test:
runs-on: ubuntu-latest
env:
POLAR_ACCESS_TOKEN: ${{ secrets.POLAR_SANDBOX_TOKEN }}
POLAR_WEBHOOK_SECRET: ${{ secrets.POLAR_SANDBOX_WEBHOOK_SECRET }}
POLAR_ORG_ID: ${{ secrets.POLAR_SANDBOX_ORG_ID }}
POLAR_SERVER: sandbox
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: "npm"
- run: npm ci
- name: Run unit tests
run: npm run test:unit
- name: Run integration tests
run: npm run test:integrationCreate sandbox credentials specifically for CI:
Webhook signature mismatch
Checkout not completing
API returns 401
const polar = new Polar({
accessToken: process.env.POLAR_ACCESS_TOKEN,
server: "sandbox",
// Enable debug mode if available
});
// Log all requests
polar.checkouts.create({...}).then(console.log).catch(console.error);Before going to production:
© chmonitor, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/polar-testing of chmonitor/chmonitor.
Open the folder on GitHubat commit fc39ef0
Polar Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Polar Testing this skillchmonitor/chmonitor | 299 | — | ~2.8k | Automated safety check: Warn | GPL-3.0 | |
| Payment Testingpetrkindlmann/qa-skills | 165 | — | ~4.9k | Automated safety check: Pass | MIT | |
| Emulate Seedyonatangross/orchestkit | 289 | — | ~4.5k | Automated safety check: Pass | MIT | |
| Stripe Best Practicesfossasia/eventyay | 1.7k | 1 repos | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| cmux Billing Runbookmanaflow-ai/cmux | 28k | — | ~2.8k | Automated safety check: Pass | Custom licence | |
| Verifier Webpolarsource/polar | 10k | — | ~3k | Automated safety check: Notes | MIT |
petrkindlmann/qa-skills
Test payment and checkout flows end to end against PSP sandboxes — Stripe first, with the general pattern for Adyen/Braintree/PayPal.
yonatangross/orchestkit
Generate emulate seed configs for stateful API emulation. An agent skill from yonatangross/orchestkit.
fossasia/eventyay
Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents)…
manaflow-ai/cmux
Runbook for the cmux billing code: Stripe Checkout, customer portal, subscription changes, webhooks and how Pro plan entitlement is resolved from Stack metadata.
polarsource/polar
Evidence-capture protocol for verifying web/dashboard/backoffice/checkout changes in the Polar local stack by driving the real UI with Playwright.
bybren-llc/safe-agentic-workflow
Stripe payment integration patterns for checkout flows, webhooks, and subscriptions.
chmonitor/chmonitor
Non-animation creative direction for HyperFrames videos. An agent skill from chmonitor/chmonitor.
chmonitor/chmonitor
Audio and media assets for HyperFrames compositions, produced by one shared audio engine (scripts/audio.mjs) — multi-provider TTS (HeyGen / ElevenLabs / Kokoro local), background music + sound…
chmonitor/chmonitor
Port an existing Remotion (React) composition to HyperFrames HTML.
chmonitor/chmonitor
A skill your agent uses when the user has a music track (an audio file, or a video to pull audio from) and wants a beat-synced HyperFrames video, calm to hard-hitting.
chmonitor/chmonitor
All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus…
chmonitor/chmonitor
turn arbitrary text — an article, notes, a topic, a brief — into a faceless explainer video, up to ~3 min (sweet spot 30-90s), where every visual is invented (typography, abstract graphics…
Works with
Guide for testing Polar payment integrations using the sandbox environment. Polar Testing is an agent skill from chmonitor/chmonitor. Guide for testing Polar payment integrations using the sandbox environment.
Polar Testing fits situations like: setting up the Polar sandbox for development; testing checkout flows without real payments; using Stripe test cards with Polar; writing integration tests for payment flows.
Run `npx skills add chmonitor/chmonitor --skill polar-testing -a claude-code`. Or copy the skill folder (.agents/skills/polar-testing in chmonitor/chmonitor) into .claude/skills/polar-testing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add chmonitor/chmonitor --skill polar-testing -a codex`. Or copy the skill folder (.agents/skills/polar-testing in chmonitor/chmonitor) into .agents/skills/polar-testing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chmonitor/chmonitor --skill polar-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/polar-testing, .gemini/skills/polar-testing, .github/skills/polar-testing and .opencode/skills/polar-testing in your project.
Going by SKILL.md and its folder, Polar Testing needs the command-line tools its instructions call (npm and ngrok) and credentials named POLAR_ACCESS_TOKEN, POLAR_WEBHOOK_SECRET, POLAR_SANDBOX_TOKEN and POLAR_SANDBOX_WEBHOOK_SECRET. Our summary lists: Python 3; A credential in POLAR_ACCESS_TOKEN; A credential in POLAR_WEBHOOK_SECRET.
SKILL.md names 3 domains. In commands or code: sandbox.polar.sh and abc123.ngrok.io; the agent is likely to contact these when it follows the instructions. As links in the text: sandbox-api.polar.sh. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 2 warning(s): mentions a paste, webhook or tunnelling service often used to send data out. Read the flagged lines before installing; the check is not a guarantee either way.
Polar Testing is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Polar Testing: Payment Testing (petrkindlmann/qa-skills, 165 stars), Emulate Seed (yonatangross/orchestkit, 289 stars), Stripe Best Practices (fossasia/eventyay, 1.7k stars) and cmux Billing Runbook (manaflow-ai/cmux, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
chmonitor (a GitHub organization) maintains it in chmonitor/chmonitor, which has 299 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 5, 2026.
Source: chmonitor/chmonitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.