Understand the webhook CSRF exclusion
Limit the CSRF exclusion to the inbound Stripe endpoint. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.
Where to goTechnical configuration → ideal/webhook
Before you start
- Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
- Verify module activation and the stated permission before attempting the action.
- Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.
What you’ll accomplish
Limit the CSRF exclusion to the inbound Stripe endpoint. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.
Follow these steps
- Keep the exclusion unchanged and narrow.
- Do not add broad payment-controller exclusions.
Fields and options to review
Excluded URIideal/webhook
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-security-troubleshooting/
Rules the system enforces
- The module config excludes only ideal/webhook.
How to confirm it worked
- Understand the webhook CSRF exclusion completes through the supplied module flow.
- Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.
Security, privacy and operational checks
- Protect credentials and invoice/payment data.
- Verify Stripe state before any retry or manual finance correction.
Continue with related guidance
Was this guide useful?Your response is stored only in this browser.
