Protect the webhook signing secret
Treat the stored signing secret as a production credential. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.
Where to goAdmin Area → Setup → Settings → Payment Gateways → Stripe iDEAL V2
Before you start
- Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
- Verify module activation and the stated permission before attempting the action.
- Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.
What you’ll accomplish
Treat the stored signing secret as a production credential. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.
Follow these steps
- Restrict settings and server access.
- Recreate the webhook if the secret is exposed.
- Do not paste the secret into tickets or screenshots.
Fields and options to review
Stored optionideal_module_stripe_webhook_signing_secret
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-webhook-management/
Rules the system enforces
- Incoming events are accepted only after Stripe Webhook::constructEvent validates the signature against this secret.
How to confirm it worked
- Protect the webhook signing secret completes through the supplied module flow.
- Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.
Security, privacy and operational checks
- Use the correct Stripe test/live account and protect signing credentials.
- Do not call webhook-management routes from an untrusted session.
Continue with related guidance
Was this guide useful?Your response is stored only in this browser.
