Payments

Payment checks: Stripe, webhooks, subscriptions

Make sure nobody can pay the wrong price or get the product for free.

A checkout that works in a demo can still be cheated. The browser sends the price, the webhook accepts a fake "paid" message, or a cancelled subscription keeps its access forever.

The payment agents follow the money from the buy button to the moment access is granted. They check where the price comes from, how the webhook proves who is calling, and what happens on a refund. Stripe, Dodo Payments, Lemon Squeezy, Polar and Paddle are covered.

62
Checks
4
Agents
6
Commands

Some of what it looks for

  • DODO-01criticalThe webhook handler does not verify the signature
  • DODO-02criticalAccess is granted on the return page, not after a verified payment event
  • PAY-01criticalThe price or amount charged comes from the browser
  • PAY-02criticalThe product is unlocked on the "success" page instead of after Stripe confirms payment
  • SUB-01criticalPaid features are locked only in the interface, and the server serves them to anyone
  • LSP-01criticalThe webhook handler does not verify the signature
  • LSP-02criticalAccess is granted on the redirect page, not after a verified event
  • HOOK-01criticalThe handler does not verify the webhook signature

These are 8 of the 62 checks in this area, worst first.

The agents that do the work

  • payments-checker

    Reviews checkout, subscriptions, pricing and refunds to find ways customers could pay the wrong amount, get the product without paying, or keep access after a refund.

  • webhook-checker

    Reviews payment webhook handlers for missing signature verification, duplicate processing, unhandled events and silent failures that lose paid orders.

  • billing-sync-checker

    Finds places where the app's record of who has paid drifts from the payment provider over time: out-of-order webhook events, renewals that cannot be matched to a user, subscription statuses handled wrong, double billing, cancellations that cut access too early, no resync after a missed webhook and currency conversion mistakes.

  • payment-reliability-checker

    Finds payment code that fails silently or twice under real conditions: charges and refunds that can be sent twice, provider list calls that read only the first page, unpinned API versions, no record of payment events, swallowed payment errors and card declines users cannot recover from.

The commands you type

  • /launch-payments

    All payment checks, plus production checks that `/launch-check` does not run (see below). `/launch-payments basic` skips them

  • /check-stripe

    Checkout, subscriptions and refunds (Stripe, Dodo Payments, Lemon Squeezy, Polar, Paddle)

  • /check-webhooks

    Signature verification, duplicates, missing events

  • /check-pricing

    Does the pricing page match what is charged and delivered?

  • /check-billing-sync

    Events applied out of order, renewals matched to nobody, trial and past-due users handled wrong, double billing, access cut too early on cancel, no resync after a missed webhook

  • /check-payment-reliability

    Charges sent twice, provider lists read one page only, unpinned API version, no payment event log, swallowed payment errors

/launch-check

Find the problems before your users do.

Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.

41 agents · 440 checks · read-only audit · one-time payment