Skip to content
Proud to collaborate with Microsoft for Startups

stripe.webhooks.receive ​

Verify a Stripe webhook, parse the event, and route by event type

Webhook ingress: verify the signature, parse the event, and normalise the fields a downstream grant/fulfilment step needs.

Point a hook redirect at this workflow (dispatch_workflow_type) and Stripe events reach the engine without the app owning an endpoint. The signature is verified against the webhook_secret stored on the connection, so an unsigned or replayed body fails closed before anything acts on it.

This workflow classifies and normalises; it does not itself mutate access. route_workflow_type names the workflow a composition should run next — see stripe.access.grant_on_payment for the payment-to-entitlement chain.

Acts on the CUSTOMER'S OWN Stripe account, authenticated via the org-scoped Stripe connection selected by cloud_connection_uuid.

Inputs:

  • cloud_connection_uuid: Org-scoped Stripe connection (customer's own account).
  • payload: Raw request body, exactly as received.
  • signature: Stripe-Signature header value.
  • webhook_secret: Endpoint secret (whsec_...); defaults to the secret on the connection (optional).
  • webhook_secret_key: Named key in the connection secrets (optional). A missing named key fails closed (WEBHOOK_SECRET_NOT_FOUND).

Outputs (terminal state_data):

  • event_id: str
  • event_type: str
  • livemode: bool
  • route_workflow_type: str — workflow a composition should run next, or None
  • object_id: str — id of the event's primary object
  • client_reference_id: str — identity carried from checkout, when present
  • customer_id: str
  • subscription_id: str
  • payment_status: str
  • event_metadata: json

Connection required: cloud_connection_uuid — the organization's own Stripe account credentials; there is no platform-key fallback.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-stripe
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
cloud_connection_uuiduuidYes—Org-scoped Stripe connection (customer's own account)
payloadstringYes—Raw request body, exactly as received
signaturestringYes—Stripe-Signature header value
webhook_secretstringNo—Endpoint secret (whsec_...); defaults to the secret on the connection
webhook_secret_keystringNo—Named connection secret key; missing key fails closed

Output Schema ​

FieldTypeRequiredDefaultDescription
event_idstringNo——
event_typestringNo——
livemodebooleanNo——
route_workflow_typestringNo——
object_idstringNo——
client_reference_idstringNo——
customer_idstringNo——
subscription_idstringNo——
payment_statusstringNo——
event_metadatajsonNo——
cloud_connection_uuiduuidNo——
payloadstringNo——
signaturestringNo——
webhook_secretstringNo——
webhook_secret_keystringNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
errorstringNo——
error_typestringNo——
failed_layerintegerNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "stripe.webhooks.receive",
  "initial_data": {
    "cloud_connection_uuid": "value",
    "payload": "value",
    "signature": "value"
  }
}