Connect Stripe in Extension Settings → Pay hub → Stripe to accept supported card payments through Cedros Pay. The complete setup includes matching API keys, the webhook endpoint shown by Cedros, a purchasable product or plan, and a successful buyer test.
If you are new to the payment tools, start with Getting started with payments in Cedros. This guide covers the current Pay interface; older installations can show different fields.
Before you begin
You need Cedros Pay installed and active, permission to manage its settings, and access to the Stripe account you intend to use. Your site administrator must also have enabled the hosting services Pay needs to store credentials and contact Stripe.
Use a separate test site and a Stripe sandbox while preparing an integration. Do not replace working live credentials with test credentials on a storefront that is already taking customer payments.
Check the selected Stripe account and environment before copying anything. A sandbox and live mode have separate keys and resources. A test product or price is not automatically available in live mode. Stripe explains these boundaries in its API key documentation.
The current Cedros form expects a Publishable key and a Secret key. Stripe's restricted and organization keys are different key types; do not assume they are interchangeable with the secret key this form validates. If your organization requires a restricted-key integration, confirm support and required permissions with your administrator first.
Enter matching keys in Cedros
- Open Extension Settings → Pay hub → Stripe.
- If Stripe is off, turn on its switch to reveal the setup fields. This enables a payment method; do it on the intended test site while preparing the connection.
- Select Test mode for setup and testing, or Live mode only for an intentional production configuration.
- Use Find your API keys to open Stripe's key page. Confirm the account and environment, then copy its publishable key into Publishable key.
- Enter the matching secret key into Secret key. Keep it in this designated field, not in page content, chat, or a support screenshot.
- Wait for autosave to finish. Resolve any displayed save error, reopen the Stripe tab, and confirm the saved state.
Test keys use pk_test_ and sk_test_; live keys use pk_live_ and sk_live_. The mode selector does not replace your credentials. Changing only the selector is not a completed environment switch.
The form warns when a visible key's test/live prefix contradicts the selected mode. Correct that mismatch before proceeding. A saved secret is masked, so an absence of visible warnings does not establish which hidden key is stored.
After saving, the secret input can appear empty with a Saved indicator and a prompt to enter a new value to replace it. That means a secret is already stored. You do not need to re-enter it every time you open the page, and clearing the displayed replacement text is not a reliable way to remove an existing secret.
Register the generated webhook endpoint
Stripe must send payment events back to Cedros so payment, order, subscription, and access records can follow the provider's result. Configure the webhook in the same Stripe account and environment as the saved keys.
- In the Cedros Stripe tab, find Webhook endpoint and use Copy for the complete URL.
- In Stripe, open Workbench → Webhooks and choose Create an event destination.
- Choose Your account as the event source. Use snapshot events for the event types listed by Cedros, rather than a connected-account or organization event feed.
- Select the events shown beneath the Cedros endpoint. Copy events helps you transfer the list; review the current list on your site rather than selecting only payment-success events.
- Choose Webhook endpoint as the destination, paste the complete copied URL, and finish creating the destination in Stripe.
- Reopen the destination and confirm its URL, account/environment, and event selection. Keep it enabled for the subsequent checkout test.
The URL contains a private token. Preserve the entire query string when copying it, and treat the full URL like a password. Do not shorten it, reconstruct it from a domain name, or share it in a public issue.
The current Cedros Stripe tab generates this URL for you and does not ask you to paste a Stripe webhook signing secret. Do not paste a whsec_ value into Secret key. If an older installation presents a signing-secret field, check its version-specific instructions before changing the connection.
Stripe's interface can evolve. Its webhook setup guide describes the current destination controls. If Stripe asks for an event API version, use one confirmed compatible with your installed Pay release; ask for help if that compatibility is unclear rather than assuming every version works.
Check the saved configuration
Use Check setup in the Stripe tab after the required fields are saved. Read errors and warnings and fix the named fields before continuing.
The setup check validates the configuration. It does not make a real Stripe payment, verify that every key permission is sufficient, or prove that webhook events have reached Cedros. A Saved indicator likewise confirms persistence, not a successful connection to Stripe.
Return to Pay hub → Overview. Confirm payment-method readiness and an active product with a checkout price. If Activate checkout is offered, follow that confirmation only when you intend to enable checkout for this site. See the payments introduction for activation and regional availability.
A Checkout is enabled label is not a declaration that your Stripe account is live or that a buyer has paid successfully.
Test payment, delivery, and buyer access
Test through the actual Cedros buyer page, using the matching Stripe sandbox/test environment. Use Stripe's published testing values, including supported failure cases. Do not use test card numbers in live mode or real payment details to simulate tests. See Stripe's testing guide.
- Open the public product, subscription, or paid-content page as the intended buyer. Check the item, price, currency, and offered Stripe payment option.
- Complete a successful test checkout. Confirm the provider result and the buyer's return to the site.
- In Stripe's webhook destination, inspect Event deliveries for the relevant checkout or payment event. Investigate failed deliveries instead of relying solely on the return page.
- In Monetization → Transactions, verify the payment and applicable order or subscription state. Match the test's amount, currency, and reference.
- Return as that buyer and verify the promised order or paid access. Then test checkout cancellation and a supported failed payment; neither should be mistaken for a completed purchase.
A successful webhook delivery shows that the endpoint accepted that event. Confirm the resulting Cedros records too; acceptance alone does not establish that every downstream action has finished.
Test each distinct flow you plan to offer. A one-time product test does not cover subscription renewal, a paid appointment, gated media, or a mobile return path. For appointments, also verify the confirmed booking described in Creating a booking type.
If Stripe shows a successful payment but Cedros is still pending, preserve the existing purchase and investigate confirmation delivery. Do not ask the buyer to pay again as a way to repair the missing status.
Move deliberately from testing to live payments
Prepare the production connection after the test flow works and the Stripe account is ready to accept real payments.
- Open the intended production site's Stripe tab and the correct live Stripe account.
- Select Live mode and replace both API keys with the matching live pair. Wait for autosave and resolve warnings.
- Configure the production site's complete webhook URL in Stripe's live environment with the event list shown by Cedros.
- Confirm that the products, prices, and recurring plans used by this site are valid for that environment, including any required catalog synchronization.
- Review the public checkout and launch readiness. Monitor the first legitimate customer payment, its event delivery, and the resulting Cedros record and access.
Keep simulated success and decline tests in the test environment. Do not repeatedly switch a live site between Stripe accounts or modes to troubleshoot one buyer's purchase. Existing payment references and event delivery belong to the account and environment that created them.
Configure optional return behavior separately
Under Advanced, Mobile app redirect schemes lets you list custom schemes used by your app to return from checkout, one per line. Add only schemes your application actually uses, and test the return on the target device. Ordinary HTTPS return links do not need a custom scheme entry.
The current Stripe tab is not a general tax-configuration page. Enabling Stripe does not configure tax or shipping rules. Review the corresponding commerce workflows and the final buyer total separately.
Stripe web checkout also does not configure Apple App Store or Google Play purchase verification; those settings belong under App stores.
Replace keys or regenerate the URL carefully
To replace a saved secret key, enter the new value in Secret key, allow it to save, and verify the intended account/environment and affected payment flows. Coordinate the Stripe-side key rotation with the Cedros change so checkout and event retrieval are not left using an expired credential. Follow Stripe's API key guidance for its rotation controls.
Regenerate URL rotates the private token used by the Cedros webhook endpoint. It immediately stops the old URL working. After regeneration, copy the new complete URL into the affected Stripe destination and verify delivery again. Regenerating is not a harmless refresh button and does not repair an incorrect API key or a missing product.
A site-domain change also warrants checking the displayed endpoint and the destination saved in Stripe. Update only the destination that belongs to the intended site and environment.
Troubleshoot the specific failure
- Stripe settings are missing or will not save: check Pay activation, admin permissions, and the reported hosting or configuration error. Keep the existing working settings until the error is understood.
- A mode warning appears: compare the selected mode with both keys from the intended Stripe account. A masked secret cannot be verified by its empty-looking input alone.
- Stripe is absent at checkout: check the saved enabled state, product or plan, checkout activation, and country rules under Availability.
- Checkout cannot create a payment: inspect the exact error and Stripe request logs. Check the account/environment, valid credentials, product pricing, and the site's ability to reach Stripe.
- Webhook deliveries fail: compare the full endpoint URL, including its token, and verify that it was not regenerated without updating Stripe. Check the event source, environment, selected events, and delivery response.
- Payment succeeded but status or access is missing: match the existing Stripe payment to the Cedros record and check event delivery and the purchased entitlement before initiating another checkout.
After fixing a webhook-delivery cause, you can use Stripe's event Resend action for the relevant failed event where available. Then verify the existing Cedros record; resending an event is not another customer payment. Stripe documents delivery troubleshooting and retries in its webhook guide.
For help, collect the public page URL, event or payment reference, time, environment, and visible error or delivery status. Exclude API keys, full webhook URLs, and card details. Use Getting help and reporting a problem.