Payments
Payment checks: Stripe, webhooks, subscriptions
Make sure nobody can pay the wrong price or get the product for free.
A checkout that works in a demo can still be cheated. The browser sends the price, the webhook accepts a fake "paid" message, or a cancelled subscription keeps its access forever.
The payment agents follow the money from the buy button to the moment access is granted. They check where the price comes from, how the webhook proves who is calling, and what happens on a refund. Stripe, Dodo Payments, Lemon Squeezy, Polar and Paddle are covered.
- 62
- Checks
- 4
- Agents
- 6
- Commands
Some of what it looks for
DODO-01criticalThe webhook handler does not verify the signatureDODO-02criticalAccess is granted on the return page, not after a verified payment eventPAY-01criticalThe price or amount charged comes from the browserPAY-02criticalThe product is unlocked on the "success" page instead of after Stripe confirms paymentSUB-01criticalPaid features are locked only in the interface, and the server serves them to anyoneLSP-01criticalThe webhook handler does not verify the signatureLSP-02criticalAccess is granted on the redirect page, not after a verified eventHOOK-01criticalThe handler does not verify the webhook signature
These are 8 of the 62 checks in this area, worst first.
The agents that do the work
payments-checkerReviews checkout, subscriptions, pricing and refunds to find ways customers could pay the wrong amount, get the product without paying, or keep access after a refund.
webhook-checkerReviews payment webhook handlers for missing signature verification, duplicate processing, unhandled events and silent failures that lose paid orders.
billing-sync-checkerFinds places where the app's record of who has paid drifts from the payment provider over time: out-of-order webhook events, renewals that cannot be matched to a user, subscription statuses handled wrong, double billing, cancellations that cut access too early, no resync after a missed webhook and currency conversion mistakes.
payment-reliability-checkerFinds payment code that fails silently or twice under real conditions: charges and refunds that can be sent twice, provider list calls that read only the first page, unpinned API versions, no record of payment events, swallowed payment errors and card declines users cannot recover from.
The commands you type
/launch-paymentsAll payment checks, plus production checks that `/launch-check` does not run (see below). `/launch-payments basic` skips them
/check-stripeCheckout, subscriptions and refunds (Stripe, Dodo Payments, Lemon Squeezy, Polar, Paddle)
/check-webhooksSignature verification, duplicates, missing events
/check-pricingDoes the pricing page match what is charged and delivered?
/check-billing-syncEvents applied out of order, renewals matched to nobody, trial and past-due users handled wrong, double billing, access cut too early on cancel, no resync after a missed webhook
/check-payment-reliabilityCharges sent twice, provider lists read one page only, unpinned API version, no payment event log, swallowed payment errors
/launch-check
Find the problems before your users do.
Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.
41 agents · 440 checks · read-only audit · one-time payment