stripe.access.grant_on_payment ​
Verify a Stripe payment webhook and grant the paying end-user an access group
Verify a Stripe webhook and move the paying end-user into an access group.
The payment-to-entitlement chain, as one governed run: verify the signature, read the session back from Stripe rather than trusting the event body, and assign the access group that the app's capabilities are gated on.
Point a hook redirect at this workflow (dispatch_workflow_type) and a Stripe payment grants access with no application backend in the path. The end-user is identified by the client_reference_id set at checkout — pass the end_user_uuid there and no email matching is needed.
Cancellation events (customer.subscription.deleted, invoice.payment_failed) move the end-user to revoke_group_slug when one is configured, so losing access is the same governed path as gaining it.
Requires identity.end-user.assign-group from the app-identity library to be registered on the same engine host.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-stripe |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | — |
cloud_connection_uuid | uuid | Yes | — | Org-scoped Stripe connection (customer's own account) |
payload | string | Yes | — | Raw webhook request body, exactly as received |
signature | string | Yes | — | Stripe-Signature header value |
webhook_secret | string | No | — | Endpoint secret; defaults to the one on the connection |
identity_app_uuid | uuid | Yes | — | Identity app whose end-users are being entitled |
grant_group_slug | string | Yes | — | Access group to assign when payment succeeds |
revoke_group_slug | string | No | — | Access group to assign on cancellation or failed payment |
actor | string | No | — | Actor recorded on the group assignment |
force | boolean | No | — | Passed through to identity.end-user.assign-group |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | — |
cloud_connection_uuid | uuid | Yes | — | — |
identity_app_uuid | uuid | No | — | — |
granted | boolean | No | — | — |
end_user_uuid | string | No | — | — |
group_slug | string | No | — | — |
previous_group | string | No | — | — |
event_type | string | No | — | — |
payment_status | string | No | — | — |
skipped_reason | string | No | — | — |
verify_event | json | No | — | — |
read_session | json | No | — | — |
assign_group | json | No | — | — |
grant_group_slug | string | No | — | — |
revoke_group_slug | string | No | — | — |
payload | string | No | — | — |
signature | string | No | — | — |
webhook_secret | string | No | — | — |
actor | string | No | — | — |
force | boolean | No | — | — |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | json | No | — | — |
failed_layer | integer | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | verify | stripe.webhooks.receive | — |
| 2 | resolve | stripe.checkout.get_session | — |
| 3 | grant | identity.end-user.assign-group | — |
Execution Flow ​
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
stripe.webhooks.receive | verify_event |
stripe.checkout.get_session | read_session |
identity.end-user.assign-group | assign_group |
API Usage ​
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "stripe.access.grant_on_payment",
"initial_data": {
"organization_uuid": "value",
"cloud_connection_uuid": "value",
"payload": "value",
"signature": "value"
}
}