Configure payments and email
Stripe (test mode first)
- Ask the owner for their Stripe test secret key (
sk_test_…, at dashboard.stripe.com/test/apikeys). Prefer that they paste it into.env.sellbasethemselves (STRIPE_SECRET_KEY=) instead of the chat, then read it from there. - Webhooks:
- Deployed (public https Supabase URL): call
integration_connectwithoutwebhook_secret. Sellbase creates the Stripe webhook endpoint and stores its secret. - Local: run
stripe listen --forward-to <SUPABASE_URL>/functions/v1/sellbase-webhooks/stripeand keep it running. Pass thewhsec_…it prints aswebhook_secret.
- Deployed (public https Supabase URL): call
integration_connectwithprovider: "stripe". Follownext_stepsin the response.- Run
test_purchase. Then checkstore_status:paymentswarns "test mode" until you go live, which is expected.
Going live (real money)
Only when the owner explicitly says the store is ready to sell. Full guide: docs/guides/stripe-live.md.
- The Stripe account must be activated (business details and bank account).
store_statusfailspaymentswhile live charges are disabled. - The owner connects the live key themselves in the admin (Settings → Payments), so it goes straight to Supabase Vault. Never ask for it in chat or put it in a file. Use a restricted
rk_live_…key if they prefer, with write access to Checkout Sessions, Payment Intents, Refunds and Webhook Endpoints. - After they connect it, check
store_status:paymentsshows the live account, and deployed projects get the Stripe webhook automatically. (integration_connectwithconfirm: truealso accepts live keys, but prefer the admin.) payments_live_checkwithconfirm: true: give the owner the URL. They pay the minimum (10 MXN or 0.50 USD) with a real card, and it is refunded automatically.store_statusthen shows "Live payment check" ok. Stripe keeps its small fee.test_purchasenever runs with live keys; it tells you to use the live check.
Never echo keys back. Never switch back to test keys on a live store without asking: pending checkouts would fail.
Resend (email)
Without Resend, order emails are only printed to the function logs. Ask for an API key (re_…, resend.com/api-keys), call integration_connect with provider: "resend", then integration_test. Until a domain is verified in Resend, emails only reach the account owner's address.
Raw Markdown for agents: skills/configure-payments/SKILL.md · Edit on GitHub