Stripe Best Practices
kanchengw/cnllm
Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…
A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.
$ npx skills add fossasia/eventyay --skill stripe-apps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install fossasia/eventyay stripe-apps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/fossasia/eventyay.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/stripe-apps .claude/skills/stripe-apps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "stripe-apps" agent skill from https://github.com/fossasia/eventyay/tree/dev/.agents/skills/stripe-apps into .claude/skills/stripe-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-apps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/fossasia/eventyay/tree/dev/.agents/skills/stripe-appsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add fossasia/eventyay --skill stripe-apps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install fossasia/eventyay stripe-apps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fossasia/eventyay.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/stripe-apps .agents/skills/stripe-apps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "stripe-apps" agent skill from https://github.com/fossasia/eventyay/tree/dev/.agents/skills/stripe-apps into .agents/skills/stripe-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-apps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add fossasia/eventyay --skill stripe-apps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install fossasia/eventyay stripe-apps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fossasia/eventyay.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/stripe-apps .cursor/skills/stripe-apps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "stripe-apps" agent skill from https://github.com/fossasia/eventyay/tree/dev/.agents/skills/stripe-apps into .cursor/skills/stripe-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-apps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/fossasia/eventyay.git --path .agents/skills/stripe-apps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add fossasia/eventyay --skill stripe-apps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install fossasia/eventyay stripe-apps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fossasia/eventyay.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/stripe-apps .gemini/skills/stripe-apps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "stripe-apps" agent skill from https://github.com/fossasia/eventyay/tree/dev/.agents/skills/stripe-apps into .gemini/skills/stripe-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-apps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install fossasia/eventyay stripe-appsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add fossasia/eventyay --skill stripe-apps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/fossasia/eventyay.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/stripe-apps .github/skills/stripe-apps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "stripe-apps" agent skill from https://github.com/fossasia/eventyay/tree/dev/.agents/skills/stripe-apps into .github/skills/stripe-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-apps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add fossasia/eventyay --skill stripe-apps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install fossasia/eventyay stripe-apps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fossasia/eventyay.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/stripe-apps .opencode/skills/stripe-apps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "stripe-apps" agent skill from https://github.com/fossasia/eventyay/tree/dev/.agents/skills/stripe-apps into .opencode/skills/stripe-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-apps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
stripe-appsA skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.
Stripe Apps is an agent skill from fossasia/eventyay. Use when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g. "add a panel to the customer page", "customize my Stripe Dashboard", "react to Stripe events from my app", "connect my service to Stripe without sharing API keys"). Covers the full app development workflow (scaffold, preview, upload, versioning), UI extension architecture (sandboxed iframe, Stripe UI toolkit, viewports), extension types (UI extensions, backend-only, extension interfaces, embedded…
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `references/authentication.md`, `references/backend.md` and `references/canonical-docs.md`).
It sits in Backend & APIs, covering Webhooks. It works with Stripe and React. The repository describes itself as: Open Source Event Management, Ticketing and Checkins, Talks and Schedules, Video and Interpretations, Badges, Exhibitions and more https://eventyay.com. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b539d59. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
stripepnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.stripe.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Stripe Apps loads about 3.6k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 257 tokens; SKILL.md has 1,692 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from fossasia/eventyay at commit b539d59, republished under its Apache-2.0 licence (© fossasia). 1,692 words, ~3,586 tokens.
.claude/skills/stripe-apps/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.FIRST ACTION: Say “Loading Stripe Apps skill.” then Read references/discovery.md. This file has routing logic you need before asking the user questions.
You are a PROJECT BUILDER and INSTRUCTOR. Your primary output is working files on the user’s machine that they can run immediately. If you explain code without also writing it to disk using your Write tool, the user has nothing they can execute.
You are also a patient guide. Many users have never heard of Stripe Apps, viewports, or webhooks. When they say “I’m not sure” or “what does that mean?”, explain concepts in plain language with examples from their specific idea.
Your tool calls (Read, Write) are your real work. Your chat messages explain what you did and teach the user why.
Your training data for Stripe Apps SDK patterns may be outdated or incorrect. Before writing any code file, you MUST read the relevant canonical docs page using WebFetch. See references/canonical-docs.md for the full list of docs pages.
If you cannot access the docs, tell the user: “I need to check the current Stripe Apps documentation to write correct code. Can you provide the current patterns from [relevant docs URL], or shall I proceed with the scaffold and you can verify against the docs?”
| # | Rule | What failure looks like |
|---|---|---|
| 0 | BEFORE ANYTHING ELSE: (1) Say “Loading Stripe Apps skill.” (2) Call Read on references/discovery.md to load the routing table. You need this data before you can ask informed questions. | Responding to the user before calling Read on discovery.md |
| 1 | After reading discovery.md, your FIRST message to the user is ONLY the 4 discovery questions (see Step 1). No code, no plan, no summary. Even if the user’s request already mentions details — ask anyway. Users have unstated requirements that only emerge through questions. | Presenting a summary, plan, or any code before asking questions 1-4 and getting answers |
| 2 | You MUST use your Write tool to create or modify files on disk. The scaffold creates base files via CLI — after that, use Write to modify scaffolded files and create new ones. A response with code only in chat gives the user nothing runnable. | Producing code in chat without calling Write to save it to disk |
| 3 | Run stripe generate app <name> using your Bash tool to scaffold the project. Then use Write to modify scaffolded files and create additional files the app needs. | Writing stripe-app.yaml or package.json from scratch instead of modifying the scaffold output |
| 4 | Before writing code for any topic (backend, UI, webhooks, auth), read the relevant canonical docs page using WebFetch. See references/canonical-docs.md. The docs are the source of truth — not this skill file, not your training data. | Writing code from memory without checking the current docs |
| 5 | Tell user: stripe apps upload BEFORE testing fetchStripeSignature/Secret Store (the signing secret is generated during first upload). | Omitting upload-first requirement |
| 6 | File names: ui/src/views/App.tsx (V2 workspace layout), server.js (project root). Only create files that are needed for the app’s architecture (see Step 3). | Using wrong filenames or creating files the architecture doesn’t need |
| 7 | Every file you write to disk MUST be complete and runnable — not a skeleton or placeholder. The user should be able to run it immediately. Do not write partial files with TODOs. | Writing a file with TODO placeholders or incomplete implementations |
| 8 | When presenting the development workflow, include pnpm build and pnpm test as explicit steps for apps with a UI extension. Backend-only apps without TypeScript skip pnpm build. | Omitting build/test steps for UI apps, or requiring them for backend-only apps |
| 9 | If the user’s app requires custom objects or extension interfaces (private preview features), inform them the feature is in private preview and ask them to confirm they have access BEFORE proceeding. Do not silently proceed with a private preview feature. | Building with private preview features without confirming user has access |
| 10 | Before ending the conversation, if you ran any toolchain command this session, submit exactly one stripe feedback report — see references/feedback.md. Never block delivery on it. | Ending a build session in which commands were run without submitting one feedback report |
| BLOCKED (never use) | Use instead |
|---|---|
stripe apps create | stripe generate app <name> |
Raw HTML in UI extensions (<div>, <span>, <p>, <button>, <input>, <h1>-<h6>) | SDK components from @stripe/ui-extension-sdk/ui (Box, Inline, Button, TextField, etc.) |
| CSS frameworks in UI (Tailwind, MUI, Bootstrap, styled-components, CSS files) | Only @stripe/ui-extension-sdk/ui components — no custom styling |
React 18+ APIs in UI (useId, useDeferredValue, useTransition, concurrent features) | React 17 hooks only (Stripe Apps run React 17.0.2) |
window, document, localStorage, sessionStorage in UI | Not available in sandboxed iframe |
Read references/discovery.md using your file-reading tool.
You CANNOT determine the correct architecture without user input because:
Ask these questions in your FIRST message — nothing else:
Do NOT include a summary, plan, or architecture in this first message. ONLY the 4 questions above.
If the user doesn’t know an answer or asks for clarification:
Private preview check: After getting answers, before showing your summary, check whether their app implies needing:
If yes: tell the user that feature is in private preview, ask them to confirm access. See references/discovery.md for exact wording and alternatives.
Full-page apps require @stripe/ui-extension-sdk version 9.2.1 or later and the latest version of the Stripe Apps CLI plugin.
After the user answers, show a plain-language summary:
Wait for explicit confirmation before proceeding.
Run the scaffold command yourself using your Bash tool:
stripe generate app <name>This creates a V2 workspace: stripe-app.yaml, package.json, pnpm-workspace.yaml, ui/src/views/App.tsx.
After the scaffold completes, proceed directly to Step 3.
Before writing any code, read the relevant canonical docs pages (see references/canonical-docs.md) using WebFetch:
YOUR PRIMARY JOB: Create files on disk following the patterns from the docs.
Which files to create depends on discovery answers:
| Architecture | Files to write |
|---|---|
| Frontend-only (reads Stripe data, no external services) | Modify: stripe-app.yaml, ui/src/views/App.tsx |
| Backend-only (webhooks/events, no Dashboard UI) | Modify: stripe-app.yaml. Create: server.js |
| Full-stack (UI + backend) | Modify: stripe-app.yaml, ui/src/views/App.tsx. Create: server.js |
| Script extension | Generate the extension, then implement its source, configuration, and tests. |
For each file: call your Write tool FIRST, then explain what it does.
Key constraints for UI code:
@stripe/ui-extension-sdk/ui for componentsKey constraints for backend code (server.js):
Access-Control-Allow-Origin: *) only on endpoints called by the UI extension — webhook endpoints don’t need CORSfetchStripeSignature verification follows the pattern in https://docs.stripe.com/stripe-apps/build-backendevent_read permission must be declared in the manifest for webhook event accessKey constraints for stripe-app.yaml:
extensions; use extensions: [] when the app has no extension declarationsYour FINAL message MUST present the development workflow:
stripe generate app <name> → scaffoldpnpm install → dependenciespnpm build → compile TypeScript (UI and script extensions)pnpm test → run unit testsstripe apps start → local preview for Dashboard UI extensionsstripe apps upload → publish version (required before fetchStripeSignature or Secret Store)Important workflow facts:
stripe apps upload generates the signing secret needed for fetchStripeSignaturereferences/webhooks.mdBefore ending the conversation, confirm your files are on disk. Run ls on the files you wrote to verify they exist.
If any file is MISSING, call Write now to create it.
| Error | Cause | Fix |
|---|---|---|
Invalid manifest | Missing required fields or malformed YAML | Check indentation; ensure id:, version:, name: are present |
Build failed | UI component has type/import errors | Run pnpm build locally first |
Version already exists | Already uploaded this version number | Bump version in stripe-app.yaml |
Permission denied | CLI not logged in or wrong account | Run stripe login |
connect-src / CSP error | App calls undeclared URL | Add URL to content_security_policy.connect-src |
extensions field required | Missing extensions: [] | Add extensions: [] to stripe-app.yaml |
Component not found | Viewport references wrong component name | Match component: value to your default export |
| File | Read when |
|---|---|
| references/canonical-docs.md | ALWAYS — lists docs pages to WebFetch before writing code |
| references/discovery.md | ALWAYS FIRST — full discovery script with routing |
| references/backend.md | Before writing server.js |
| references/ui-extensions.md | Before writing React/UI code |
| references/workflow.md | Full development loop with all CLI commands |
| references/extension-types.md | After discovery — map answers to extension type |
| references/script-extensions.md | When authoring a script extension: generation, SDK contracts, runtime, configuration, and tests |
| references/webhooks.md | When app reacts to Stripe events |
| references/authentication.md | For auth type selection and patterns |
| references/onboarding-ux.md | For first-run experience |
| references/publishing.md | For marketplace publishing |
| references/feedback.md | After a build where you ran CLI/build commands — submit one feedback report |
© fossasia, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 12 other files (references) in .agents/skills/stripe-apps of fossasia/eventyay.
Open the folder on GitHubat commit b539d59
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in fossasia/eventyay, which our catalogue first saw on October 7, 2026.
Stripe Apps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Stripe Apps this skillfossasia/eventyay | 1.7k | 1 repos | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Stripe Best Practiceskanchengw/cnllm | 173 | 2 repos | ~925 | Automated safety check: Pass | Apache-2.0 | |
| Cashier Stripe Developmentluadotsh/lua | 343 | 1 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Stripe Integrationwshobson/agents | 40k | 10 repos | ~1k | Automated safety check: Pass | MIT | |
| Convex HTTP Actionswaynesutton/builder-skills | 406 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Integrating Stripe Webhookspr-pm/prpm | 122 | 1 repos | ~1.8k | Automated safety check: Pass | MIT |
kanchengw/cnllm
Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…
luadotsh/lua
Handles Laravel Cashier Stripe integration including subscriptions, webhooks, Stripe Checkout, invoices, charges, refunds, trials, coupons, metered billing, and payment failure handling.
wshobson/agents
Implement Stripe payment processing for robust, PCI-compliant payment flows including checkout, subscriptions, and webhooks.
waynesutton/builder-skills
Adds HTTP endpoints in convex/http.ts: webhook receivers with signature checks, REST style routes, CORS, auth headers, streaming responses, and file uploads over HTTP.
pr-pm/prpm
A skill your agent uses when implementing Stripe webhook endpoints and getting 'Raw body not available' or signature verification errors - provides raw body parsing solutions and subscription period…
manaflow-ai/cmux
Runbook for the cmux billing code: Stripe Checkout, customer portal, subscription changes, webhooks and how Pro plan entitlement is resolved from Stack metadata.
fossasia/eventyay
A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.
fossasia/eventyay
A skill your agent uses when the user asks about Stripe Connect configuration, charge patterns, Dashboard access, or how to get started with Connect, is building a marketplace, platform…
fossasia/eventyay
Steps for initiating the Django development server without Docker
fossasia/eventyay
Docker Compose, container services, deployment. An agent skill from fossasia/eventyay.
fossasia/eventyay
Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents)…
fossasia/eventyay
Repository layout and where to find code. An agent skill from fossasia/eventyay.
Categories
A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g. Stripe Apps is an agent skill from fossasia/eventyay.g.
Stripe Apps fits situations like: reviewing a Stripe App —; the user describes something that implies one (e.g; the user mentions Stripe Apps; @stripe/ui-extension-sdk.
Run `npx skills add fossasia/eventyay --skill stripe-apps -a claude-code`. Or copy the skill folder (.agents/skills/stripe-apps in fossasia/eventyay) into .claude/skills/stripe-apps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add fossasia/eventyay --skill stripe-apps -a codex`. Or copy the skill folder (.agents/skills/stripe-apps in fossasia/eventyay) into .agents/skills/stripe-apps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fossasia/eventyay --skill stripe-apps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stripe-apps, .gemini/skills/stripe-apps, .github/skills/stripe-apps and .opencode/skills/stripe-apps in your project.
Going by SKILL.md and its folder, Stripe Apps needs the command-line tools its instructions call (stripe and pnpm).
SKILL.md names 1 domain. As links in the text: docs.stripe.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Stripe Apps is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Stripe Apps: Stripe Best Practices (kanchengw/cnllm, 173 stars), Cashier Stripe Development (luadotsh/lua, 343 stars), Stripe Integration (wshobson/agents, 40k stars) and Convex HTTP Actions (waynesutton/builder-skills, 406 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
fossasia (a GitHub organization) maintains it in fossasia/eventyay, which has 1,702 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 9, 2026.
Source: fossasia/eventyay on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.