#ddmm_api
1 messages ¡ Page 1 of 1 (latest)
đ Welcome to your new thread!
â˛ď¸ We'll be here soon! Typically we respond in a few minutes, but sometimes we might take a bit longer if the server is busy or if you have a particularly tricky question.
âąď¸ We close idle threads, which makes them read-only. Once a thread is closed it won't be reopened, but you can always start a new thread if you have another question.
đ This thread will always be available, even after it's closed. You can find it again using Discord's search, or you can save this link: https://discord.com/channels/841573134531821608/1344180349986410506
đ Have more to share? Add more details, code, screenshots, videos, etc. below.
We were recently attacked whereby the hacker was able to Onboard Express account onto our platform due to leaked Secret Key. We only want to allow Standard accounts to onboard. How can we use a Restricted Key to prevent this in the future in case our key is ever leaked?
Yeah I am afraid we don't have that much of a granular level settings. I would recommend limiting the list or range of IP addresses
thats annoying - i was told we should use restricted key to prevent this from happening
We are getting this error when using the restricted key - what setting do we have to use?
i dont see kyc id numbers as an option in restricted key setup
?
Um can you find this request id (req_xxx) from the request log? https://dashboard.stripe.com/test/logs
Sign in to the Stripe Dashboard to manage business payments and operations in your account. Manage payments and refunds, respond to disputes and more.
https://dashboard.stripe.com/logs for Livemode log
Sign in to the Stripe Dashboard to manage business payments and operations in your account. Manage payments and refunds, respond to disputes and more.
yes
Having the 'rak_accounts_kyc_id_numbers_read' permission would allow this request to continue.
is that what you need @oak sail
No the req_xxx on the "ID" field
req_UaER5SN0BBBxes
req_GVV7f...
req_GVY7Fjq7eidxBD
What was this Id?
Thanks looking closer
Yes I work for Stripe
All member with "Stripe Staff" on this Discord server work for Stripe
thanks
Yeah I see this Restricted Key is missing a few permisisons, but not sure which one on the UI can be sufficient. Could you write to Support? We will continue there