Skip to content
Proud to collaborate with Microsoft for Startups

stripe.access.grant_on_payment ​

Verify a Stripe payment webhook and grant the paying end-user an access group

Verify a Stripe webhook and move the paying end-user into an access group.

The payment-to-entitlement chain, as one governed run: verify the signature, read the session back from Stripe rather than trusting the event body, and assign the access group that the app's capabilities are gated on.

Point a hook redirect at this workflow (dispatch_workflow_type) and a Stripe payment grants access with no application backend in the path. The end-user is identified by the client_reference_id set at checkout — pass the end_user_uuid there and no email matching is needed.

Cancellation events (customer.subscription.deleted, invoice.payment_failed) move the end-user to revoke_group_slug when one is configured, so losing access is the same governed path as gaining it.

Requires identity.end-user.assign-group from the app-identity library to be registered on the same engine host.

Overview ​

PropertyValue
Workflow typeDag
LibraryApp-stripe
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes——
cloud_connection_uuiduuidYes—Org-scoped Stripe connection (customer's own account)
payloadstringYes—Raw webhook request body, exactly as received
signaturestringYes—Stripe-Signature header value
webhook_secretstringNo—Endpoint secret; defaults to the one on the connection
identity_app_uuiduuidYes—Identity app whose end-users are being entitled
grant_group_slugstringYes—Access group to assign when payment succeeds
revoke_group_slugstringNo—Access group to assign on cancellation or failed payment
actorstringNo—Actor recorded on the group assignment
forcebooleanNo—Passed through to identity.end-user.assign-group

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes——
cloud_connection_uuiduuidYes——
identity_app_uuiduuidNo——
grantedbooleanNo——
end_user_uuidstringNo——
group_slugstringNo——
previous_groupstringNo——
event_typestringNo——
payment_statusstringNo——
skipped_reasonstringNo——
verify_eventjsonNo——
read_sessionjsonNo——
assign_groupjsonNo——
grant_group_slugstringNo——
revoke_group_slugstringNo——
payloadstringNo——
signaturestringNo——
webhook_secretstringNo——
actorstringNo——
forcebooleanNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepjsonNo——
failed_layerintegerNo——
errorstringNo——
error_typestringNo——

DAG Layers ​

#LayerStepsCompensation
1verifystripe.webhooks.receive—
2resolvestripe.checkout.get_session—
3grantidentity.end-user.assign-group—

Execution Flow ​

Sub-workflows ​

Sub-workflowStep name
stripe.webhooks.receiveverify_event
stripe.checkout.get_sessionread_session
identity.end-user.assign-groupassign_group

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "stripe.access.grant_on_payment",
  "initial_data": {
    "organization_uuid": "value",
    "cloud_connection_uuid": "value",
    "payload": "value",
    "signature": "value"
  }
}