Stripe webhook management

Protect the webhook signing secret

Treat the stored signing secret as a production credential.

Audience: CRM staffPermission: Administrator / settings accessModule v1.0.0
Exact navigationAdmin Area → Setup → Settings → Payment Gateways → Stripe iDEAL V2
Before you begin
  • Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
  • Confirm module activation and the stated permission before attempting the action.
  • Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.

What this guide covers

Treat the stored signing secret as a production credential. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.

Exact step-by-step process

  1. Restrict settings and server access.
  2. Recreate the webhook if the secret is exposed.
  3. Do not paste the secret into tickets or screenshots.

Fields, choices and supported possibilities

Stored optionideal_module_stripe_webhook_signing_secret
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-webhook-management/

Code-backed validations and workflow rules

  • Incoming events are accepted only after Stripe Webhook::constructEvent validates the signature against this secret.

Expected result and verification

  • Protect the webhook signing secret completes through the supplied module flow.
  • Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.

Security, privacy and operational checks

  • Use the correct Stripe test/live account and protect signing credentials.
  • Do not call webhook-management routes from an untrusted session.