Agent skill

Integrating Stripe Webhooks

by pr-pm in pr-pm/prpm

A skill your agent uses when implementing Stripe webhook endpoints and getting 'Raw body not available' or signature verification errors - provides raw body parsing solutions and subscription period…

MITAuto-check passedBackend & APIs

Install Integrating Stripe Webhooks

skills CLI
$ npx skills add pr-pm/prpm --skill integrating-stripe-webhooks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pr-pm/prpm integrating-stripe-webhooks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pr-pm/prpm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/integrating-stripe-webhooks .claude/skills/integrating-stripe-webhooks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
integrating-stripe-webhooks
GitHub stars
122
Used in
1 other repo
Token cost
~1.8k tokens
SKILL.md length
461 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when implementing Stripe webhook endpoints and getting 'Raw body not available' or signature verification errors - provides raw body parsing solutions and subscription period…

  • Works in 3 steps: Subscription Period Fields Missing → Route Not Found (404) → URL Encoding in Checkout URLs
  • Implementing Stripe webhook endpoints and getting Raw body not available
  • SKILL.md covers Overview, When to Use, Quick Reference and Critical: Raw Body Parsing, plus 5 more sections
  • Calls stripe and brew; needs STRIPE_WEBHOOK_SECRET

What it does

Integrating Stripe Webhooks is an agent skill from pr-pm/prpm. Use when implementing Stripe webhook endpoints and getting 'Raw body not available' or signature verification errors - provides raw body parsing solutions and subscription period field fixes across frameworks

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks. It works with Stripe. The repository describes itself as: The universal registry for AI coding tools. The licence is MIT.

When your agent uses it

  • Implementing Stripe webhook endpoints and getting Raw body not available
  • Signature verification errors - provides raw body parsing solutions and subscription period field fixes across frameworks

Example prompts

  • “Raw body not available”
  • “/integrating-stripe-webhooks”

Requirements

  • Python 3
  • Node.js
  • A credential in STRIPE_WEBHOOK_SECRET

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Subscription Period Fields Missing
  2. Route Not Found (404)
  3. URL Encoding in Checkout URLs

What it can do on your machine

Read from SKILL.md and the folder at commit 5f993e6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • stripe
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • stripe.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STRIPE_WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Integrating Stripe Webhooks loads about 1.8k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 461 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pr-pm/prpm at commit 5f993e6, republished under its MIT licence (© pr-pm). 461 words, ~1,820 tokens.

Download SKILL.mdSave it as .claude/skills/integrating-stripe-webhooks/SKILL.md (or your agent's skills folder).
name
integrating-stripe-webhooks
description
Use when implementing Stripe webhook endpoints and getting 'Raw body not available' or signature verification errors - provides raw body parsing solutions and subscription period field fixes across frameworks

Integrating Stripe Webhooks

Overview

Stripe webhooks require raw request bodies for signature verification. Most web frameworks parse JSON automatically, breaking verification. This skill provides framework-specific solutions for the raw body problem and documents common TypeScript type mismatches.

When to Use

Use this skill when:

  • Getting "Raw body not available" errors from Stripe webhooks
  • Webhook signature verification fails with 400 errors
  • Implementing new Stripe webhook endpoints
  • Getting TypeError: Cannot read property 'current_period_start' from subscription events
  • Webhooks return 404 (route registration issues)

Don't use for:

  • General Stripe API integration (not webhooks)
  • Frontend Stripe Elements implementation
  • Stripe checkout session creation (use Stripe docs)

Quick Reference

ProblemSolution
Raw body not availableConfigure custom body parser (see framework examples)
Signature verification failsUse raw body bytes/buffer, not parsed JSON
404 on webhook endpointRegister webhook route inside API prefix
current_period_start undefinedAccess from subscription.items.data[0] not root
URI validation errorsURL-encode dynamic parameters with encodeURIComponent()

Critical: Raw Body Parsing

THE PROBLEM: Stripe's constructEvent() requires the exact bytes received to verify the signature. JSON parsing modifies the body, breaking verification.

THE SOLUTION: Access raw body before any parsing middleware.

Framework Examples

Node.js - Fastify (most common for new projects):

typescript
// In main server file, BEFORE registering routes
server.addContentTypeParser('application/json',
  { parseAs: 'buffer' },
  async (req: any, body: Buffer) => {
    req.rawBody = body;  // Store for webhooks
    return JSON.parse(body.toString('utf8'));  // Parse for other routes
  }
);

// In webhook handler
const rawBody = (request as any).rawBody;
const event = stripe.webhooks.constructEvent(
  rawBody, signature, webhookSecret
);

Node.js - Express:

javascript
// Define webhook route BEFORE express.json() middleware
app.post('/webhooks/stripe',
  express.raw({ type: 'application/json' }),
  (req, res) => {
    const event = stripe.webhooks.constructEvent(
      req.body,  // Already raw Buffer
      req.headers['stripe-signature'],
      webhookSecret
    );
  }
);

app.use(express.json());  // After webhook route

Python - FastAPI:

python
@app.post('/webhooks/stripe')
async def stripe_webhook(request: Request):
    payload = await request.body()  # Use .body() not .json()
    signature = request.headers.get('stripe-signature')

    event = stripe.Webhook.construct_event(
        payload, signature, webhook_secret
    )

General Pattern: Get raw bytes/buffer → verify signature → use parsed event from Stripe.

Common Mistakes

1. Subscription Period Fields Missing

Error: TypeError: Cannot read property 'current_period_start' of undefined

Cause: Stripe returns period dates in subscription.items.data[0], not at subscription root. TypeScript types don't include these fields on SubscriptionItem.

Fix:

typescript
// ❌ WRONG - fields don't exist here
new Date(subscription.current_period_start * 1000)

// ✅ CORRECT - get from first subscription item
const firstItem = subscription.items.data[0] as any;
const periodStart = firstItem?.current_period_start || subscription.billing_cycle_anchor;
const periodEnd = firstItem?.current_period_end || subscription.billing_cycle_anchor;

await updateOrg({
  start_date: new Date(periodStart * 1000),
  end_date: new Date(periodEnd * 1000),
});
2. Route Not Found (404)

Cause: Webhook routes registered outside API prefix.

typescript
// ❌ WRONG - creates /webhooks/stripe instead of /api/v1/webhooks/stripe
export async function registerRoutes(server) {
  server.register(async (api) => {
    await api.register(subscriptionRoutes, { prefix: '/subscriptions' });
  }, { prefix: '/api/v1' });

  await server.register(webhookRoutes, { prefix: '/webhooks' });  // Outside!
}

// ✅ CORRECT - inside API prefix
export async function registerRoutes(server) {
  server.register(async (api) => {
    await api.register(subscriptionRoutes, { prefix: '/subscriptions' });
    await api.register(webhookRoutes, { prefix: '/webhooks' });  // Inside
  }, { prefix: '/api/v1' });
}
3. URL Encoding in Checkout URLs

Error: "body/successUrl must match format 'uri'"

Cause: Organization names or parameters with spaces not URL-encoded.

typescript
// ❌ WRONG - "Broke Org" creates invalid URL
const successUrl = `${origin}/orgs?name=${orgName}&subscription=success`;

// ✅ CORRECT - encode dynamic parameters
const successUrl = `${origin}/orgs?name=${encodeURIComponent(orgName)}&subscription=success`;
Show full SKILL.md (185 more words)Show less

Implementation Checklist

Server Setup:

  • Configure raw body parser BEFORE routes
  • Register webhook routes inside API prefix (if using one)
  • Set STRIPE_WEBHOOK_SECRET environment variable
  • Verify webhook secret is configured before processing

Webhook Handler:

  • Validate stripe-signature header exists
  • Access raw body (not parsed JSON)
  • Use stripe.webhooks.constructEvent() for verification
  • Handle SignatureVerificationError separately
  • Return 200 for received events (even if processing fails)
  • Log all events with ID and type

Subscription Events:

  • Get period dates from subscription.items.data[0]
  • Cast to any to access TypeScript-missing fields
  • Fallback to billing_cycle_anchor if items missing
  • Store org_id in subscription metadata
  • Update verification status based on subscription status

Frontend:

  • URL-encode all dynamic parameters
  • URL-encode organization names in success/cancel URLs
  • Handle checkout errors gracefully
  • Poll for verification after checkout success

Testing Locally

bash
# Install Stripe CLI
brew install stripe/stripe-cli/stripe

# Forward webhooks to local server
stripe listen --forward-to localhost:3000/api/v1/webhooks/stripe

# Trigger test events
stripe trigger customer.subscription.created
stripe trigger customer.subscription.updated
stripe trigger invoice.paid

Real-World Impact

Before applying these patterns:

  • Webhooks fail with 400 "Invalid signature"
  • Subscription updates crash with undefined property errors
  • Hours debugging TypeScript type mismatches
  • Checkout fails with URL validation errors

After applying:

  • Webhooks verify successfully
  • Subscription data extracts correctly
  • Type-safe with explicit casting
  • Checkout URLs work with any organization name

References

© pr-pm, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/integrating-stripe-webhooks of pr-pm/prpm.

Open the folder on GitHubat commit 5f993e6

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in pr-pm/prpm, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Integrating Stripe Webhooks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Integrating Stripe Webhooks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Integrating Stripe Webhooks this skillpr-pm/prpm1221 repos~1.8kAutomated safety check: PassMIT
Stripe Appsfossasia/eventyay1.7k1 repos~3.6kAutomated safety check: PassApache-2.0
Stripe Best Practiceskanchengw/cnllm1752 repos~925Automated safety check: PassApache-2.0
Cashier Stripe Developmentluadotsh/lua3431 repos~1.2kAutomated safety check: PassMIT
Stripe Best Practicesfossasia/eventyay1.7k1 repos~1.7kAutomated safety check: PassApache-2.0
Stripe Integrationwshobson/agents40k10 repos~1kAutomated safety check: PassMIT

Similar skills

  • Stripe Apps

    fossasia/eventyay

    A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.

    1.7k GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    175 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed
  • Handles Laravel Cashier Stripe integration including subscriptions, webhooks, Stripe Checkout, invoices, charges, refunds, trials, coupons, metered billing, and payment failure handling.

    343 GitHub starsUsed in 1 repo~1.2k tokens
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    fossasia/eventyay

    Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents)…

    1.7k GitHub starsUsed in 1 repo~1.7k tokens
    Backend & APIsAuto-check passed
  • Stripe Integration

    wshobson/agents

    Implement Stripe payment processing for robust, PCI-compliant payment flows including checkout, subscriptions, and webhooks.

    40k GitHub starsUsed in 10 repos~1k tokens
    Backend & APIsAuto-check passed
  • Convex HTTP Actions

    waynesutton/builder-skills

    Adds HTTP endpoints in convex/http.ts: webhook receivers with signature checks, REST style routes, CORS, auth headers, streaming responses, and file uploads over HTTP.

    406 GitHub stars~2.6k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed

More from pr-pm/prpm

All 35 skills in this repo
  • Reference for writing Claude Code agent files: location, frontmatter fields, validation limits, tool and model choices, and the required content format.

    122 GitHub starsUsed in 2 repos~4k tokens
    Auto-check passed
  • Covers how to build, configure and publish Claude Code hooks: event types, exit codes, JSON I/O, and PRPM packaging.

    122 GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check: notes
  • Shows how to write .claude/rules/ files correctly: paths frontmatter instead of globs, quoted glob patterns, global rules and conversion of Cursor rules.

    122 GitHub starsUsed in 2 repos~551 tokens
    Auto-check passed
  • Reference for writing portable Agent Skills packages, covering SKILL.md frontmatter limits, name rules, directory layout and where Codex CLI, GitHub Copilot and Amp look for skills.

    122 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Guides writing an agents.md project-context file: plain markdown with no frontmatter, focused on what an AI coding assistant cannot already know.

    122 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • A skill your agent uses when creating Continue rules - provides required name field, alwaysApply semantics, glob/regex patterns, and markdown format with optional frontmatter

    122 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Integrating Stripe Webhooks

What does Integrating Stripe Webhooks do?

A skill your agent uses when implementing Stripe webhook endpoints and getting 'Raw body not available' or signature verification errors - provides raw body parsing solutions and subscription period…. Integrating Stripe Webhooks is an agent skill from pr-pm/prpm.

When should I use Integrating Stripe Webhooks?

Integrating Stripe Webhooks fits situations like: implementing Stripe webhook endpoints and getting Raw body not available; signature verification errors - provides raw body parsing solutions and subscription period field fixes across frameworks.

How do I install Integrating Stripe Webhooks in Claude Code?

Run `npx skills add pr-pm/prpm --skill integrating-stripe-webhooks -a claude-code`. Or copy the skill folder (.claude/skills/integrating-stripe-webhooks in pr-pm/prpm) into .claude/skills/integrating-stripe-webhooks in your project. Claude Code loads it when a task matches its description.

How do I install Integrating Stripe Webhooks in Codex?

Run `npx skills add pr-pm/prpm --skill integrating-stripe-webhooks -a codex`. Or copy the skill folder (.claude/skills/integrating-stripe-webhooks in pr-pm/prpm) into .agents/skills/integrating-stripe-webhooks in your project. Codex loads it when a task matches its description.

Can I use Integrating Stripe Webhooks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pr-pm/prpm --skill integrating-stripe-webhooks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/integrating-stripe-webhooks, .gemini/skills/integrating-stripe-webhooks, .github/skills/integrating-stripe-webhooks and .opencode/skills/integrating-stripe-webhooks in your project.

What does Integrating Stripe Webhooks need to run?

Going by SKILL.md and its folder, Integrating Stripe Webhooks needs the command-line tools its instructions call (stripe and brew) and credentials named STRIPE_WEBHOOK_SECRET. Our summary lists: Python 3; Node.js; A credential in STRIPE_WEBHOOK_SECRET.

Does Integrating Stripe Webhooks access the network?

SKILL.md names 1 domain. As links in the text: stripe.com. This is read from the text; nothing was executed.

Is Integrating Stripe Webhooks safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Integrating Stripe Webhooks use?

Integrating Stripe Webhooks is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Integrating Stripe Webhooks use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Integrating Stripe Webhooks?

Skills that share tags, products or a category with Integrating Stripe Webhooks: Stripe Apps (fossasia/eventyay, 1.7k stars), Stripe Best Practices (kanchengw/cnllm, 175 stars), Cashier Stripe Development (luadotsh/lua, 343 stars) and Stripe Best Practices (fossasia/eventyay, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Integrating Stripe Webhooks?

pr-pm (a GitHub organization) maintains it in pr-pm/prpm, which has 122 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 6, 2026.

Source: pr-pm/prpm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.