Protect Stripe API keys
Keep secret and publishable keys separated and environment-matched.
Exact navigationAdmin Area → Setup → Settings → Payment Gateways → Stripe iDEAL V2
Before you begin
- Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
- Confirm module activation and the stated permission before attempting the action.
- Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.
What this guide covers
Keep secret and publishable keys separated and environment-matched. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.
Exact step-by-step process
- Restrict gateway settings.
- Never place the secret key in client-side code or public documentation.
- Rotate exposed keys in Stripe and recreate the webhook if necessary.
Fields, choices and supported possibilities
Secret settingEncrypted
Publishable settingClient-visible by design
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-security-troubleshooting/
Code-backed validations and workflow rules
- The supplied module implements or omits this behaviour exactly as described.
Expected result and verification
- Protect Stripe API keys completes through the supplied module flow.
- Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.
Security, privacy and operational checks
- Protect credentials and invoice/payment data.
- Verify Stripe state before any retry or manual finance correction.
