#un!t

1 messages ยท Page 1 of 1 (latest)

granite gobletBOT
steel snow
#

hello! when you try to create a restricted API key, you should select these permissions for the webhook

pseudo magnet
#

Thats just it? Because i am getting a 403, even with a key under STRIPE_WEBHOOK_SECRET env key

#

With webhook permission

#

this is the current api key

steel snow
#

do you have the request id where you're getting a 403?

pseudo magnet
#

webhook id: we_1LrJkLLwDjSXOsgWyWUAmYaZ

#

eventg id: evt_1Ls1KFLwDjSXOsgWuE1TlU58

#

does this help? ๐Ÿ˜„

steel snow
#

sorry, gimme a while, still looking into it

pseudo magnet
#

ok np

open venture
#

๐Ÿ‘‹ taking over this thread. looking into it now

#

After having a look at evt_1Ls1KFLwDjSXOsgWuE1TlU58, 403 (forbidden) error is returned from your webhook endpoint to Stripe

pseudo magnet
#

Correct, can you show me what api key is getting returned?

#

I use one with the permission which alex said

#

but i am getting 403

#

but i dont get why i am getting 403

open venture
#

could you explain how you use this restricted key?

#

API key doesn't play a role of returning 403 in this case

pseudo magnet
#

Oh okay, hmm i will take a look.

open venture
pseudo magnet
#

yes, but i dont get a "error" server side

#

POST stripe/webhook ..................................... cashier.webhook โ€บ Laravel\Cashier โ€บ WebhookController@handleWebhook

#

the webhook route is registered

#

server time is Thu Oct 13 09:45:33 CEST 2022

#

what "time" does the webhook send?

#

because i saw, that there can be a issue with not matching timezones?

open venture
pseudo magnet
#

or i once got a error, that it cant verify the request because of time validation error of the request

open venture
#

403 is forbidden, so it's not even reaching to the verification part

pseudo magnet
#

okay, i will try to find why its not reaching the laravel application

#

can we leave this open, so i can comeback?

#

No signatures found matching the expected signature for payload

#

does this ring any bells?

open venture
#

Ah yes! This means that the event signature mismatch

#

Does 403 relate to this error?

pseudo magnet
#

got it resolved

open venture
#

great to see that it got resolved!

pseudo magnet
#

if you see that error again: tell the customer to use this

#

not the api key

open venture
#

Yes! Webhook should use webhook secret instead of API key

#

Sorry that I didn't notice this earlier

pseudo magnet
#

no problem ๐Ÿ™‚ "event signature mismatch" and a stack overflow post guided me in the right direction ๐Ÿ˜„

#

so thanks anyways ๐Ÿ™‚

open venture
#

no problem! happy to see the issue got resolved!

pseudo magnet
#

nice support so far ๐Ÿ˜› i cant recall by anymeans what that crypto dude says

#

maybe its his shady business? ๐Ÿ˜„

open venture
#

glad that you have nice experience with us ๐Ÿ˜„

pseudo magnet
#

only one thing thats bad ๐Ÿ˜„ someone from you said that paypal will come some day, and after half a year we get the info, that it will never come ๐Ÿ˜„

#

but apart from that, both customer support and the dev support here is good ๐Ÿ™‚