Stripe Clinic — payment integration review
Paste your Stripe integration code and get a senior payments engineer's review: a go-live posture, the inventory of every payment call, webhook event, route and client construction, prioritized findings across security, correctness, idempotency, webhooks, lifecycle and maintainability — each with the problem, what it costs and a corrected fragment in your SDK's language — quick wins, focus areas and a go-live checklist. A free client-side prescan flags hardcoded keys, webhooks accepted without signature verification, body parsers that destroy the signature, money-moving calls with no idempotency key, decimal amounts, client-supplied prices, raw card data, missing 3D Secure handling and unhandled subscription events before you spend anything, and masks every key-shaped literal before showing it back. Derived from the @wshobson/stripe-integration skill (MIT). Not affiliated with or endorsed by Stripe, Inc.
Details
gpt-terra Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.