#1pix1

1 messages · Page 1 of 1 (latest)

fresh glenBOT
somber violet
#

hi! I suppose you could create a Restricted key and give it all permissions except the ones for refunds.

upbeat cairn
#

Unfortunately that isn’t an option for some reason

#

It falls under the category of charges, and without enabling that you can’t call a payment to be attempted, accepted, or processed

somber violet
#

ah, I see that now. Then I don't think there is a great solution here.

upbeat cairn
#

Aw alright, thank you

somber violet
#

I guess sometimes what people do is the developer uses their own separate API keys for their own Stripe accout, and then you change to your own account's keys when deploying.

#

but that's not perfect since there are settings or objects that apply to each account and they'd have to be replicated etc

upbeat cairn
#

Well they are managing the code, so they would be able to see the key either way

#

It confuses me why refunds isn’t an option for a restricted key, especially when Stripe strives for security and merchant assurance