Agent skill

Dodo Best Practices

by hashgraph-online in hashgraph-online/awesome-codex-plugins

Starting point for any Dodo Payments integration, covering Merchant of Record basics, SDK installation and client setup, test and live environments, API keys, and the canonical checkout-to-webhook…

Apache-2.0Auto-check passedBackend & APIs

Install Dodo Best Practices

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill dodo-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins dodo-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dodopayments/dodo-agent-plugin/skills/dodo-best-practices .claude/skills/dodo-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dodo-best-practices
GitHub stars
1.3k
Token cost
~3.6k tokens
SKILL.md length
945 words
Files
1
Skills in repo
716
Repo updated
First seen
Licence
Apache-2.0

At a glance

Starting point for any Dodo Payments integration, covering Merchant of Record basics, SDK installation and client setup, test and live environments, API keys, and the canonical checkout-to-webhook…

  • Works in 8 steps: Granting access on return_url redirect → Hand-rolling webhook verification → Re-serializing the request body → …
  • Starting a new integration
  • SKILL.md covers When to use this skill, What is Dodo Payments, Environment Setup and SDK Installation &…, plus 4 more sections
  • Calls npm, pip and go; reaches live.dodopayments.com and test.dodopayments.com; needs DODO_PAYMENTS_API_KEY and DODO_PAYMENTS_WEBHOOK_KEY

What it does

Dodo Best Practices is an agent skill from hashgraph-online/awesome-codex-plugins. Starting point for any Dodo Payments integration, covering Merchant of Record basics, SDK installation and client setup, test and live environments, API keys, and the canonical checkout-to-webhook flow. Use when starting a new integration, initializing the dodopayments client, choosing an architecture, or unsure which Dodo Payments skill applies.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks and Payments and billing. It works with Next.js and Nuxt. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Starting a new integration
  • Initializing the dodopayments client
  • Choosing an architecture
  • Unsure which Dodo Payments skill applies

Example prompts

  • “/dodo-best-practices”

Requirements

  • Python 3
  • Node.js
  • A credential in DODO_PAYMENTS_API_KEY
  • A credential in DODO_PAYMENTS_WEBHOOK_KEY

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Granting access on return_url redirect
  2. Hand-rolling webhook verification
  3. Re-serializing the request body
  4. Using deprecated APIs
  5. Forgetting to set environment: 'test_mode'
  6. Storing API keys in code
  7. Ignoring the webhook-timestamp header
  8. Using unsafeUnwrap() in production

What it can do on your machine

Read from SKILL.md and the folder at commit 3e1456a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pip
    • go
    • composer
    • gem

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • live.dodopayments.com
    • test.dodopayments.com

    Also links to:

    • docs.dodopayments.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DODO_PAYMENTS_API_KEY
    • DODO_PAYMENTS_WEBHOOK_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dodo Best Practices loads about 3.6k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 945 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 3e1456a, republished under its Apache-2.0 licence (© hashgraph-online). 945 words, ~3,607 tokens.

Download SKILL.mdSave it as .claude/skills/dodo-best-practices/SKILL.md (or your agent's skills folder).
name
dodo-best-practices
description
Starting point for any Dodo Payments integration, covering Merchant of Record basics, SDK installation and client setup, test and live environments, API keys, and the canonical checkout-to-webhook flow. Use when starting a new integration, initializing the dodopayments client, choosing an architecture, or unsure which Dodo Payments skill applies.

Dodo Payments Integration Guide

This skill covers the foundational concepts and setup for Dodo Payments. Use it when starting a new integration, setting up the SDK, or understanding the core payment flow.

When to use this skill

  • You're building a new payment integration and need to understand Dodo's architecture
  • You need to install and initialize the SDK in your language
  • You want to understand the canonical payment flow and webhook verification
  • You're choosing between framework adapters or payment methods
  • You need to know what Dodo handles versus what you must build

What is Dodo Payments

Dodo Payments is a Merchant of Record (MoR). That means Dodo is the legal seller on every transaction, handles sales tax registration and calculation across all jurisdictions, remits taxes to authorities, and manages card-network disputes and chargebacks. As a developer, you don't build a sales-tax engine or dispute-handling system. You create checkout sessions, listen to webhooks, and grant access when payment succeeds.


Environment Setup

Base URLs

Only two real base URLs exist:

  • Live: https://live.dodopayments.com
  • Test: https://test.dodopayments.com

Never use api.dodopayments.com — it has no DNS record and cannot be reached.

API Keys

Keys have two formats:

  • Test: dodo_test_...
  • Live: dodo_live_...
Environment Variables
bash
DODO_PAYMENTS_API_KEY       # Bearer token for API requests
DODO_PAYMENTS_WEBHOOK_KEY   # Secret for webhook signature verification
Default Environment

The environment parameter defaults to live_mode if omitted. Always pass test_mode explicitly during development.


SDK Installation & Initialization

TypeScript/Node.js
bash
npm install dodopayments
typescript
import DodoPayments from 'dodopayments';

const client = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,
  environment: 'test_mode', // defaults to 'live_mode'
});

Constructor options:

OptionTypeDefaultNotes
bearerTokenstringenv DODO_PAYMENTS_API_KEYRequired for API calls
environment'test_mode' | 'live_mode''live_mode'Explicit in dev
webhookKeystringenv DODO_PAYMENTS_WEBHOOK_KEYFor webhooks.unwrap()
baseURLstring—Override; mutually exclusive with environment
Python
bash
pip install dodopayments
python
import os
from dodopayments import DodoPayments

client = DodoPayments(
    bearer_token=os.environ.get("DODO_PAYMENTS_API_KEY"),
    environment="test_mode",  # defaults to "live_mode"
)
Go
bash
go get -u github.com/dodopayments/dodopayments-go@v1.110.0
go
import (
    "os"

    "github.com/dodopayments/dodopayments-go"
    "github.com/dodopayments/dodopayments-go/option"
)

client := dodopayments.NewClient(
    option.WithBearerToken(os.Getenv("DODO_PAYMENTS_API_KEY")),
    option.WithEnvironmentTestMode(), // defaults to live
)
PHP
bash
composer require "dodopayments/client:6.19.0"
php
use Dodopayments\Client;

$apiKey = getenv('DODO_PAYMENTS_API_KEY');
if ($apiKey === false || $apiKey === '') {
    throw new RuntimeException('DODO_PAYMENTS_API_KEY is not set');
}

$client = new Client(
    bearerToken: $apiKey,
    environment: 'test_mode',
);
Ruby
bash
gem "dodopayments", "~> 2.22.0"
ruby
dodo_payments = Dodopayments::Client.new(
    bearer_token: ENV["DODO_PAYMENTS_API_KEY"],
    environment: "test_mode"
)
Java
xml
<dependency>
    <groupId>com.dodopayments.api</groupId>
    <artifactId>dodo-payments-java</artifactId>
    <version>1.110.0</version>
</dependency>
java
// fromEnv() reads DODO_PAYMENTS_API_KEY, DODO_PAYMENTS_WEBHOOK_KEY, DODO_PAYMENTS_BASE_URL.
// Without testMode() (or a test DODO_PAYMENTS_BASE_URL) the client targets live mode.
DodoPaymentsClient client = DodoPaymentsOkHttpClient.builder()
    .fromEnv()
    .testMode()
    .build();
Kotlin
xml
<dependency>
    <groupId>com.dodopayments.api</groupId>
    <artifactId>dodo-payments-kotlin</artifactId>
    <version>1.110.0</version>
</dependency>
kotlin
// Without testMode() (or a test DODO_PAYMENTS_BASE_URL) the client targets live mode.
val client: DodoPaymentsClient = DodoPaymentsOkHttpClient.builder()
    .fromEnv()
    .testMode()
    .build()

Framework Adapters

Dodo publishes framework-specific packages under @dodopayments/*. Use the one matching your stack:

FrameworkPackageUse if
Next.js@dodopayments/nextjsBuilding with Next.js App Router
Nuxt@dodopayments/nuxtBuilding with Nuxt 3+
Express@dodopayments/expressUsing Express.js
Fastify@dodopayments/fastifyUsing Fastify
Hono@dodopayments/honoUsing Hono (Edge/Node)
Astro@dodopayments/astroUsing Astro endpoints
SvelteKit@dodopayments/sveltekitUsing SvelteKit server routes
Remix@dodopayments/remixUsing Remix loaders/actions
TanStack Start@dodopayments/tanstackUsing TanStack Start
Better Auth@dodopayments/better-authIntegrating with Better Auth
Convex@dodopayments/convexUsing Convex backend
Bun@dodopayments/bunUsing Bun.serve()

Each adapter provides checkout, customer portal, and webhook handlers tailored to the framework's conventions.


Core Concepts

Products

Items you sell. Create in the dashboard or via API. Types:

  • One-time: Single purchase
  • Subscription: Recurring billing
  • Usage-based: Metered consumption
Customers

Represent buyers. Can have multiple payment methods, subscriptions, and credit balances. Create explicitly or implicitly during checkout.

Checkout Sessions

The primary payment collection method. Create a session server-side, redirect the customer to the hosted checkout URL, and listen for webhooks to confirm payment.

See the checkout-integration skill for detailed checkout configuration and the subscription-integration skill for recurring lifecycle management.

Subscriptions

Recurring charges on a schedule. Managed through checkout sessions or the subscriptions API. See the subscription-integration skill for lifecycle, trials, plan changes, and on-demand charging.

Webhooks

Real-time event notifications. Dodo sends events like payment.succeeded, subscription.active, refund.succeeded, and credit.deducted. Webhook signature verification is covered in the webhook-integration skill.

Credit Entitlements

Virtual balances (API calls, tokens, compute hours) attached to products. Configured per product with rollover, overage, and expiration rules. See the credit-based-billing skill.


The Canonical Payment Flow

  1. Create checkout session on your server with product ID and customer email.
  2. Redirect customer to the checkout_url returned.
  3. Customer pays on the hosted checkout.
  4. Dodo sends webhook (e.g., payment.succeeded) to your endpoint.
  5. Verify the webhook signature using client.webhooks.unwrap().
  6. Grant access only after webhook verification succeeds.

Never grant access based on the browser return_url redirect alone. The webhook is the authoritative confirmation.

typescript
import express from 'express';

const app = express();

// 1. Create session
const session = await client.checkoutSessions.create({
  product_cart: [{ product_id: 'pdt_example', quantity: 1 }],
  customer: { email: 'customer@example.com' },
  return_url: 'https://yoursite.com/success',
});

// 2. Redirect to session.checkout_url

// 3. Listen for webhook with the exact raw request bytes
app.post('/webhook', express.raw({ type: 'application/json' }), async (req, res) => {
  try {
    // 4. Verify signature
    const webhookId = req.headers['webhook-id'] as string;
    const event = client.webhooks.unwrap(req.body.toString(), {
      headers: {
        'webhook-id': webhookId,
        'webhook-signature': req.headers['webhook-signature'] as string,
        'webhook-timestamp': req.headers['webhook-timestamp'] as string,
      },
    });

    // 5. Suppress duplicates with an atomic unique insert and run side effects
    // in the same database transaction.
    const handled = await processWebhookOnce(webhookId, async () => {
      if (event.type === 'payment.succeeded') {
        // ONE-TIME purchases only. Subscription access starts on subscription.active.
        const payment = event.data;
        await grantOneTimeAccess(payment.customer.customer_id);
      }

      if (event.type === 'subscription.active') {
        await grantSubscriptionAccess(event.data);
      }
    });

    res.json({ received: true, duplicate: !handled });
  } catch (error) {
    res.status(401).json({ error: 'Invalid signature' });
  }
});

Show full SKILL.md (367 more words)Show less

API Foundations

Authentication

All requests use Bearer token authentication:

http
Authorization: Bearer dodo_live_...
Pagination

List endpoints are page-numbered. They accept page_size and page_number, and the response exposes the rows on items:

typescript
const payments = await client.payments.list({
  page_size: 50,
  page_number: 0,
});

for (const payment of payments.items) {
  console.log(payment.payment_id);
}

The SDK can also walk every page for you:

typescript
for await (const payment of client.payments.list()) {
  console.log(payment.payment_id);
}
Rate Limits

Dodo enforces rate limits. The SDK automatically retries 429 responses as described below.

SDK Error Classes

The SDK throws typed errors. Catch and inspect:

typescript
try {
  await client.checkoutSessions.create({...});
} catch (error) {
  if (error instanceof DodoPayments.APIError) {
    console.error(error.status, error.message);
  }
}
Retries

The SDK retries twice by default with a short exponential backoff on connection errors and 408, 409, 429, and 5xx responses. Do not add an unconditional custom retry loop.

Override the default for all requests when constructing the client:

typescript
const clientWithoutRetries = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,
  environment: 'test_mode',
  maxRetries: 0,
});

Or override it for one request:

typescript
await client.checkoutSessions.create(
  {
    product_cart: [{ product_id: 'pdt_example', quantity: 1 }],
    customer: { email: 'customer@example.com' },
  },
  { maxRetries: 0 },
);

Webhook Verification

Webhook signature verification is mandatory. Never trust the payload without verification.

Dodo implements the Standard Webhooks spec. The signed message is webhook-id.webhook-timestamp.raw_body (period-joined), HMAC-SHA256, base64-encoded.

Use the SDK helper:

typescript
const event = client.webhooks.unwrap(req.body.toString(), {
  headers: {
    'webhook-id': req.headers['webhook-id'] as string,
    'webhook-signature': req.headers['webhook-signature'] as string,
    'webhook-timestamp': req.headers['webhook-timestamp'] as string,
  },
});

The unwrap() method verifies the signature and parses the payload. If verification fails, it throws an error.

For detailed webhook setup, event types, and testing, see the webhook-integration skill.


Common Mistakes

1. Granting access on return_url redirect

The browser redirect is not proof of payment. Always wait for the webhook.

typescript
// WRONG
app.get('/success', (req, res) => {
  grantAccess(req.query.customer_id); // No verification!
});

// CORRECT
app.post('/webhook', async (req, res) => {
  const event = client.webhooks.unwrap(...);
  if (event.type === 'payment.succeeded') {
    grantAccess(event.data.customer.customer_id);
  }
});
2. Hand-rolling webhook verification

Don't implement HMAC verification yourself. Use client.webhooks.unwrap().

The old approach of signing just the payload is wrong because Standard Webhooks signs webhook-id.webhook-timestamp.raw_body. Hand-rolled HMAC will never match.

3. Re-serializing the request body

Webhook verification requires the exact raw body. If you parse JSON and re-stringify it, the signature breaks.

typescript
// WRONG
const body = JSON.parse(req.body);
const event = client.webhooks.unwrap(JSON.stringify(body), {...});

// CORRECT
const event = client.webhooks.unwrap(req.body.toString(), {...});
4. Using deprecated APIs

Don't use client.payments.create() or client.subscriptions.create() for new integrations. Both are deprecated. Use client.checkoutSessions.create().

5. Forgetting to set environment: 'test_mode'

The default is live_mode. Always pass test_mode explicitly during development to avoid charging real cards.

6. Storing API keys in code

Never hardcode keys. Always use environment variables.

7. Ignoring the webhook-timestamp header

The timestamp prevents replay attacks. client.webhooks.unwrap() validates it automatically, but if you hand-roll verification, check that the timestamp is recent (within a few minutes).

8. Using unsafeUnwrap() in production

unsafeUnwrap() skips signature verification. Use it only for unsigned test payloads from dodo wh trigger. Never use it for production webhooks.


Resources

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/dodopayments/dodo-agent-plugin/skills/dodo-best-practices of hashgraph-online/awesome-codex-plugins.

Open the folder on GitHubat commit 3e1456a

Compare with similar skills

Dodo Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dodo Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dodo Best Practices this skillhashgraph-online/awesome-codex-plugins1.3k—~3.6kAutomated safety check: PassApache-2.0
Clerkgeekskai/blog1033 repos~1.5kAutomated safety check: PassMIT
Sanity Best Practicessanity-io/agent-toolkit188—~1.4kAutomated safety check: PassMIT
Stripe Integration Expertalirezarezvani/claude-skills28k1 repos~3.7kAutomated safety check: PassMIT
Stripe Integration Expertborghei/Claude-Skills891—~1.6kAutomated safety check: PassMIT
Yalidine Delivery Integrationbighadj22/codflow354—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Clerk

    geekskai/blog

    Clerk authentication router. An agent skill from geekskai/blog.

    103 GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Sanity Best Practices

    sanity-io/agent-toolkit

    Official

    Sanity development best practices for schema design, GROQ queries, TypeGen, Visual Editing, images, Portable Text, Studio structure, localization, migrations, Sanity Functions, webhooks, Blueprints…

    188 GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Stripe Integration Expert

    alirezarezvani/claude-skills

    Production-grade Stripe integrations: subscriptions with trials and proration, one-time payments, usage-based billing, checkout sessions, idempotent webhook handlers, customer portal, and invoicing.

    28k GitHub starsUsed in 1 repo~3.7k tokens
    Backend & APIsAuto-check passed
  • Stripe Integration Expert

    borghei/Claude-Skills

    Implement Stripe integrations for SaaS billing: subscriptions, checkout, proration, usage- based billing, idempotent webhooks, customer portal, dunning, and SCA.

    891 GitHub stars~1.6k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Wires an app to the Yalidine (Guepex) Algerian courier API: parcels, zone lookups, delivery fees and verified delivery-status webhooks.

    354 GitHub stars~2.5k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    fossasia/eventyay

    Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents)…

    1.7k GitHub starsUsed in 1 repo~1.7k tokens
    Backend & APIsAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 716 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Dodo Best Practices

What does Dodo Best Practices do?

Starting point for any Dodo Payments integration, covering Merchant of Record basics, SDK installation and client setup, test and live environments, API keys, and the canonical checkout-to-webhook…. Dodo Best Practices is an agent skill from hashgraph-online/awesome-codex-plugins. Starting point for any Dodo Payments integration, covering Merchant of Record basics, SDK installation and client setup, test and live environments, API keys, and the canonical checkout-to-webhook flow.

When should I use Dodo Best Practices?

Dodo Best Practices fits situations like: starting a new integration; initializing the dodopayments client; choosing an architecture; unsure which Dodo Payments skill applies.

How do I install Dodo Best Practices in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill dodo-best-practices -a claude-code`. Or copy the skill folder (plugins/dodopayments/dodo-agent-plugin/skills/dodo-best-practices in hashgraph-online/awesome-codex-plugins) into .claude/skills/dodo-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Dodo Best Practices in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill dodo-best-practices -a codex`. Or copy the skill folder (plugins/dodopayments/dodo-agent-plugin/skills/dodo-best-practices in hashgraph-online/awesome-codex-plugins) into .agents/skills/dodo-best-practices in your project. Codex loads it when a task matches its description.

Can I use Dodo Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill dodo-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dodo-best-practices, .gemini/skills/dodo-best-practices, .github/skills/dodo-best-practices and .opencode/skills/dodo-best-practices in your project.

What does Dodo Best Practices need to run?

Going by SKILL.md and its folder, Dodo Best Practices needs the command-line tools its instructions call (npm, pip, go, composer and gem) and credentials named DODO_PAYMENTS_API_KEY and DODO_PAYMENTS_WEBHOOK_KEY. Our summary lists: Python 3; Node.js; A credential in DODO_PAYMENTS_API_KEY; A credential in DODO_PAYMENTS_WEBHOOK_KEY.

Does Dodo Best Practices access the network?

SKILL.md names 4 domains. In commands or code: live.dodopayments.com and test.dodopayments.com; the agent is likely to contact these when it follows the instructions. As links in the text: docs.dodopayments.com and github.com. This is read from the text; nothing was executed.

Is Dodo Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dodo Best Practices use?

Dodo Best Practices is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dodo Best Practices use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dodo Best Practices?

Skills that share tags, products or a category with Dodo Best Practices: Clerk (geekskai/blog, 103 stars), Sanity Best Practices (sanity-io/agent-toolkit, 188 stars), Stripe Integration Expert (alirezarezvani/claude-skills, 28k stars) and Stripe Integration Expert (borghei/Claude-Skills, 891 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dodo Best Practices?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,267 GitHub stars. The repository holds 716 skills in this directory. The repository was last updated on October 10, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.