JustHandled Labs
// payments

Stripe Webhook & Checkout Doctor

Audit Stripe Checkout, Billing Portal, and webhook code for the mistakes that make payments work locally and fail in production, with exact evidence and verification steps for each review target.

What it does

The documented scope covers Next.js, Express, FastAPI, and generic serverless projects using Node.js, TypeScript, JavaScript, or Python.

What you give it

Point the skill at the relevant route handlers, Checkout or Billing Portal setup, package.json, safe configuration examples such as .env.example, and the Stripe CLI or server logs you want reviewed. Do not paste live secret values into the conversation or commit them to the repository.

Declared file scopes include its own package, Next.js files, .env.example, package.json, and matching .js, .ts, .tsx, and .py files.

What comes back

The skill combines a local heuristic scan with a structured review checklist. Findings are ranked by severity and tied to evidence from the inspected code or supplied logs, with remediation snippets and a concrete verification step. The scanner can print Markdown or JSON.

Representative finding: a production webhook route verifies with a local whsec_ value. The report identifies the environment reference, explains that signing secrets are endpoint-specific, and asks you to verify the live endpoint's secret without exposing it.

Permissions and safety boundary

Known limitations

The scanner is heuristic: it prioritizes code and configuration for review but cannot prove that an integration is correct. A clean result does not verify the live endpoint URL, selected events, signing secret, delivery responses, production variables, database effects, or customer access state.

The bundled clean fixture intentionally surfaces a review item because the scanner flags constructs for human review rather than treating every match as an outright error. When Python or matching project files are unavailable, the workflow falls back to its manual checklist.

Use the production webhook checklist to collect live delivery and replay evidence the local scan cannot see.

Questions

What Stripe integration errors can it identify?

It creates a review queue for signature verification, raw-body parsing, idempotency, test and live configuration, Checkout URLs, Billing Portal redirects, and subscription lifecycle behavior.

Which frameworks and languages does it support?

The documented scope covers Next.js, Express, FastAPI, and generic serverless projects using Node.js, TypeScript, JavaScript, or Python.

Does it need access to my Stripe Dashboard?

No. It reviews matching local files and supplied logs. Live endpoint configuration, delivery, account mode, and Dashboard state still require manual verification.

What files can it read?

The declared scope includes its package, Next.js files, .env.example, package.json, and matching JavaScript, TypeScript, TSX, and Python files.

What does the report contain?

Evidence-backed findings with severity, review evidence, remediation snippets, and verification steps, available as Markdown or JSON from the scanner.

Does a clean result prove the integration is correct?

No. The scan is heuristic and cannot verify the live Stripe account, endpoint delivery, production secrets, or business effects. Use live delivery and replay evidence before approval.

Add Stripe Webhook & Checkout Doctor to your toolkit.

Current price and purchase option are shown on Agensi. The workflow starts read-only and works with agents that load SKILL.md packages.

Get Stripe Webhook & Checkout Doctor on Agensi