Passa al contenuto principale

Webhooks

Server-to-server callbacks from Stripe and ACube. Never called by a client: each request is authenticated by the sender signature, not by a token.

๐Ÿ“„๏ธStripe: checkout session completed or expired

Called by Stripe, never by a client: the request is accepted only with a valid Stripe-Signature for one of the endpoint secrets (STRIPE_CHECKOUT_WEBHOOK_SECRET, STRIPE_CHECKOUT_WEBHOOK_SECRET_CONNECT). checkout.session.completed confirms the order (lessons paid, family document issued, notifications, referral credit); checkout.session.expired releases it (lessons deleted, slots restored, promotion usage and family credit given back). Both are idempotent, and the cron lessons/check-expired-lessons applies the same outcomes to the sessions whose event never arrived.