Security, limitations and troubleshooting

Validate Stripe webhook signatures

Accept only events signed with the stored endpoint secret.

Audience: CRM staffPermission: Administrator / finance / technical supportModule v1.0.0
Exact navigationTechnical endpoint → /ideal/webhook
Before you begin
  • Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
  • Confirm module activation and the stated permission before attempting the action.
  • Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.

What this guide covers

Accept only events signed with the stored endpoint secret. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.

Exact step-by-step process

  1. Keep the signing secret current.
  2. Send only Stripe-generated events to the endpoint.
  3. Verify invalid signatures return HTTP 400.

Fields, choices and supported possibilities

HeaderStripe-Signature
Secretideal_module_stripe_webhook_signing_secret
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-security-troubleshooting/

Code-backed validations and workflow rules

  • Webhook::constructEvent performs payload/signature validation.

Expected result and verification

  • Validate Stripe webhook signatures completes through the supplied module flow.
  • Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.

Security, privacy and operational checks

  • Protect credentials and invoice/payment data.
  • Verify Stripe state before any retry or manual finance correction.