lovable.project.wire-payments ​
Create the payment webhook that grants a Lovable app's end-users access
Create the webhook endpoint that turns a payment into app access.
Returns a public URL to paste into the payment provider's webhook settings. From then on a completed payment reaches the engine, is signature-verified, and moves the paying end-user into an access group — with no endpoint, no server, and no provider secret in the Lovable-generated code.
The provider's API key stays in the Orkestia connection vault; the app only ever holds the public PKCE client key.
Today only stripe is wired. AbacatePay reaches the same outcome through abacatepay.webhook.receive, but its grant composition is not written yet, so it is deliberately not offered here rather than silently creating a redirect that grants nothing.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-lovable |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
actor | string | No | — | Member or agent wiring payments. |
organization_uuid | uuid | Yes | — | Organization that owns the app and the connection. |
identity_app_uuid | uuid | Yes | — | Identity app whose end-users are entitled by payment. |
provider | string | No | — | Payment provider; 'stripe' (default) is the only one wired. |
define_group_slug | string | No | — | Access group to create for paying users, e.g. pro. |
define_group_name | string | No | — | Display name for that group. |
redirect_name | string | No | — | Name for the webhook redirect. |
redirect_description | string | No | — | Description for the webhook redirect. |
extra_configuration | json | No | — | Extra hook redirect configuration keys. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | — |
webhook_url | string | No | — | — |
redirect_uuid | string | No | — | — |
signed_uuid | string | No | — | — |
grant_workflow_type | string | No | — | — |
group_created | boolean | No | — | — |
next_step | string | No | — | — |
define_group | json | No | — | — |
create_redirect | json | No | — | — |
actor | string | No | — | — |
identity_app_uuid | uuid | No | — | — |
provider | string | No | — | — |
define_group_slug | string | No | — | — |
define_group_name | string | No | — | — |
redirect_name | string | No | — | — |
redirect_description | string | No | — | — |
extra_configuration | json | No | — | — |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | json | No | — | — |
failed_layer | integer | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | group | identity.end-user.group.define | — |
| 2 | webhook | hook.create-redirect | — |
Execution Flow ​
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
identity.end-user.group.define | define_group |
hook.create-redirect | create_redirect |
API Usage ​
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "lovable.project.wire-payments",
"initial_data": {
"organization_uuid": "value",
"identity_app_uuid": "value"
}
}