Protect Stripe API keys
Keep secret and publishable keys separated and environment-matched. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.
Where to goAdmin Area → Setup → Settings → Payment Gateways → Stripe iDEAL V2
Before you start
- Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
- Verify module activation and the stated permission before attempting the action.
- Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.
What you’ll accomplish
Keep secret and publishable keys separated and environment-matched. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.
Follow these steps
- Restrict gateway settings.
- Never place the secret key in client-side code or public documentation.
- Rotate exposed keys in Stripe and recreate the webhook if necessary.
Fields and options to review
Secret settingEncrypted
Publishable settingClient-visible by design
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-security-troubleshooting/
Rules the system enforces
- The supplied module implements or omits this behaviour exactly as described.
How to confirm it worked
- Protect Stripe API keys completes through the supplied module flow.
- Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.
Security, privacy and operational checks
- Protect credentials and invoice/payment data.
- Verify Stripe state before any retry or manual finance correction.
Continue with related guidance
Was this guide useful?Your response is stored only in this browser.
