#corwindev
1 messages · Page 1 of 1 (latest)
How are they being created? Can you share an example cus_xxx ID?
Can you paste the ID
cus_OK6AmYzDTkPam8
Looks like you use some kind of plugin? https://www.whmcs.com/
Yes
Using whmcs stripe
Hmm, your hands are likely tied from our perspective
Those requests are initiated by I assume that plugin if the user performs some kind of action. Normally you could re-roll your secret key if it had leaked, but that's not the case here
Equally I doubt restricting API key access by IP address will help. I'd recommend speaking to your hosting provider/plugin creator (https://stripe.com/docs/keys#limit-api-secret-keys-ip-address)
Okayy, so just contact WHMCS about this?
👋 taking over for my colleague. Let me catch up.
yes I guess that's the only choice you have here
But what can they do?
the plugin maintainers need to do some work from their side
And what work
that's for them to do, if they need help they will reach out
you can