Security, limitations and troubleshooting

Protect Stripe API keys

Keep secret and publishable keys separated and environment-matched. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: CRM staffPermission: Administrator / finance / technical supportModule v1.0.0
Jump to steps
Where to goAdmin Area → Setup → Settings → Payment Gateways → Stripe iDEAL V2
Before you start
  • Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
  • Verify module activation and the stated permission before attempting the action.
  • Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.

What you’ll accomplish

Keep secret and publishable keys separated and environment-matched. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.

Follow these steps

  1. Restrict gateway settings.
  2. Never place the secret key in client-side code or public documentation.
  3. Rotate exposed keys in Stripe and recreate the webhook if necessary.

Fields and options to review

Secret settingEncrypted
Publishable settingClient-visible by design
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-security-troubleshooting/

Rules the system enforces

  • The supplied module implements or omits this behaviour exactly as described.

How to confirm it worked

  • Protect Stripe API keys completes through the supplied module flow.
  • Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.

Security, privacy and operational checks

  • Protect credentials and invoice/payment data.
  • Verify Stripe state before any retry or manual finance correction.