Stripe: checkout session completed or expired
POST/api/payment/webhook/checkout
Called by Stripe, never by a client: the request is accepted only with a valid Stripe-Signature for one of the endpoint secrets (STRIPE_CHECKOUT_WEBHOOK_SECRET, STRIPE_CHECKOUT_WEBHOOK_SECRET_CONNECT). checkout.session.completed confirms the order (lessons paid, family document issued, notifications, referral credit); checkout.session.expired releases it (lessons deleted, slots restored, promotion usage and family credit given back). Both are idempotent, and the cron lessons/check-expired-lessons applies the same outcomes to the sessions whose event never arrived.
Request
Responses
- 200
- 400
- 403
- 500
Event handled, or already handled
Invalid payload, or unknown provider or order
Invalid signature
The outcome could not be applied: Stripe retries the event