# Take payments with Stripe

> The agent builds Stripe Checkout into your app, on your own Stripe account, with fraud protection and webhook fulfillment. What stays with you.
> Source: https://playcode.io/docs/add-to-your-app/payments-with-stripe - last reviewed 2026-10-10.
> Ask Playcode's agent: "Add Stripe Checkout so customers can buy my course for $49." It builds Checkout and the webhook into your app and tests them in Stripe's test mode; the Stripe account, its keys and the move to live payments stay with you.

Your app takes payments through your own Stripe account: the money goes to Stripe, then to you, under Stripe's rules and fees. The agent builds Stripe Checkout into your app, Stripe's hosted payment page, and unlocks each purchase only when Stripe confirms it.

## Do it yourself

1. Create an account at https://stripe.com, or open yours. Stay in test mode while you build.
2. In the Stripe Dashboard, copy the test keys: the publishable key (`pk_...`) and the secret key (`sk_...`).
3. In Playcode, open **Settings**, choose **Secrets** and, under **Development**, add the secret key under the name the agent asks for, like `STRIPE_SECRET_KEY`. Turn on **Secret**. Do not paste a secret key into the chat: the chat keeps it in its history.
4. Ask the agent for the payment: what you sell, the price, and whether it is a one-time payment or a subscription. It builds Checkout, loads Stripe.js on every page of the site, and creates the payment session on your server only when a buyer clicks.
5. In the Stripe Dashboard, add the webhook endpoint the agent gives you, with the events it names, like `checkout.session.completed`. Copy the endpoint's signing secret (`whsec_...`) into **Settings**, **Secrets** the same way.
6. Buy once with Stripe's test card, `4242 4242 4242 4242`. The agent checks that the webhook arrived and that the purchase unlocked in your app.
7. To go live, activate your Stripe account, copy the live keys and add a live webhook endpoint for the published app. Put the live values under **Production** in **Settings**, **Secrets**, then publish.

> [!IMPORTANT]
> Keep Radar, Stripe's fraud protection, on. A public payment page gets found by card-testing bots, and the disputes that follow can get a Stripe account blocked. Stripe.js on every page helps Radar tell your customers from bots.

### On a static site

A static site has no server to keep a secret key. Create a Payment Link in the Stripe Dashboard and ask the agent to add it as the buy button. No keys go into the project.

## If it doesn't work

### The buyer paid, but the purchase did not unlock

Your app unlocks a purchase from Stripe's webhook, never from the page the buyer returns to. Check the endpoint's address and events in the Stripe Dashboard, and that its signing secret is in **Settings**, **Secrets** for the right environment. Then ask the agent to read the app's log.

### It worked in test mode, but not live

Live payments use other keys and another webhook endpoint. Check that the live values are under **Production**, and publish again.

### The agent asks for a full-stack project

Checkout sessions, webhooks and subscriptions need a server for the secret key. Use a Payment Link, or make the project a Cloud app. See [Browser and Cloud projects](/docs/build/browser-and-cloud-projects).

## Limits

- Stripe decides whether your account can take payments. Its fees, payouts, tax rules and fraud checks apply; Playcode guarantees none of them.
- Card details go straight to Stripe's page. They never reach your app or Playcode.
- For subscriptions, the agent uses Stripe's own customer portal for cancelling and changing plans, instead of building those pages.
- Selling digital goods inside an iPhone or Android app falls under the app stores' rules, which differ by region. Payments on the website are not affected.
- This page is about payments in your app. Your Playcode plan is billed separately: see [Plans](/docs/account-and-billing/plans).
