All modules
MODULE 08 · TAKING MONEY, PROPERLY
Payments
The webhook is the source of truth.
Never trust the browser to tell you someone paid. The provider's webhook — with its signature verified — is what marks an order paid. Everything else is UI.
WHEN YOU NEED IT
Tier 2. If you're charging at Tier 1, use payment links first.
THE CHOICE, PER TIER
- T1Payment links — no code, good enough to start
- T2Stripe / Razorpay checkout + verified webhooks
- T3+ subscriptions, invoices, reconciliation
SAY THIS TO YOUR AGENT
"Integrate checkout with a webhook endpoint that verifies the provider's signature before marking anything paid. Handle the payment-succeeded and payment-failed events. Test with the provider's test cards."
DONE WHEN
- Orders are marked paid only by the verified webhook
- A failed payment leaves the app in a sane state
- You did a full test-mode purchase end to end