Учётная запись Stripe и ключи API
Создайте учётную запись разработчика Stripe и безопасно настройте ключи API для своего приложения.
«Учётная запись Stripe и ключи API» — бесплатный урок AI Powered SaaS: Stripe + Auth + Billing + Deploy на CoddyKit. Это урок 1 из 4. Ты можешь прочитать весь урок бесплатно ниже — а потом практиковать его прямо в браузере с встроенным редактором кода и ИИ-репетитором 24/7. Это часть пути обучения AI Powered SaaS: Stripe + Auth + Billing + Deploy, и твой прогресс синхронизируется между веб-версией и приложением CoddyKit. Курс AI Powered SaaS: Stripe + Auth + Billing + Deploy содержит 4 уроков всего.
Части этого урока еще не переведены и отображаются на английском.
Welcome to Stripe Payments
Welcome to the world of secure online payments! In this lesson, we'll kickstart our journey by setting up your Stripe developer account and understanding the essential API keys.
Stripe is a powerful platform that allows businesses to accept payments over the internet. It handles everything from processing credit cards to managing subscriptions, making it a cornerstone for many SaaS applications.
Signing Up for Stripe
Before we can integrate Stripe into our application, we need an account. It's free to sign up and explore the developer features.
- Visit the official Stripe website.
- Click on 'Sign Up' or 'Start now'.
- Provide your email, name, and create a password.
- Confirm your email address.
Once registered, you'll gain access to the Stripe Dashboard, which is your central hub for managing payments and configurations.
Navigating Your Dashboard
The Stripe Dashboard is where you'll manage your payment operations. Take a moment to familiarize yourself with its layout.
Key areas include:
- Home: An overview of your recent activity and balance.
- Payments: View and manage all transactions.
- Customers: Manage your customer profiles.
- Developers: Access API keys, webhooks, and logs (this is where we'll spend a lot of time!).
You can switch between 'Test mode' and 'Live mode' easily, which is crucial for development.
Understanding API Keys
API keys are like digital passwords that allow your application to securely communicate with Stripe's services. They tell Stripe who is making the request and grant permission to perform actions like creating charges or managing customers.
Stripe uses two main types of API keys:
- Publishable keys
- Secret keys
Each serves a distinct purpose and has different security requirements.
Publishable vs. Secret Keys
It's vital to understand the difference between these two key types:
- Publishable Key (e.g.,
pk_test_...): This key is safe to embed in your client-side code (e.g., JavaScript in your website or mobile app). It's used to collect payment information securely and create tokens. It cannot be used to make charges directly. - Secret Key (e.g.,
sk_test_...): This key must NEVER be exposed in client-side code. It grants full access to your Stripe account's API and can be used to create charges, process refunds, and manage subscriptions. It should only be used on your server.
Locating Your API Keys
You can find your API keys in the Stripe Dashboard:
- Log in to your Stripe account.
- Navigate to the 'Developers' section in the left sidebar.
- Click on 'API keys'.
Here you'll see both your 'Publishable key' and 'Secret key' for both test and live modes. You can also generate new secret keys or revoke existing ones for security reasons.
Test Mode & Live Mode
Stripe provides two environments: 'Test mode' and 'Live mode'.
- Test Mode: Use test API keys to simulate transactions without moving real money. This is perfect for development and debugging.
- Live Mode: Use live API keys to process actual payments with real customers.
Always ensure you're using the correct keys for the environment you're working in. You can toggle between modes in the Dashboard and your API requests.
API Key Security Best Practices
Protecting your secret keys is paramount to prevent unauthorized access to your Stripe account.
- Never hardcode secret keys: Store them as environment variables or in a secure configuration service.
- Do not commit to version control: Exclude configuration files containing secret keys from Git repositories (e.g., using
.gitignore). - Rotate keys regularly: Periodically generate new secret keys and update them in your application.
- Restrict access: Limit who has access to your production secret keys.
Loading Keys in Your App
Here's a simple Python example showing how your application might load Stripe API keys securely from environment variables. This keeps sensitive information out of your codebase.
import os
# In a real application, these keys
# would be loaded from environment variables
# or a secure configuration management system.
# Attempt to get the publishable key
stripe_publishable_key = os.getenv("STRIPE_PUBLISHABLE_KEY")
# Attempt to get the secret key
stripe_secret_key = os.getenv("STRIPE_SECRET_KEY")
print("Stripe Key Loading Status:")
if stripe_publishable_key:
print(" Publishable key detected.")
else:
print(" Publishable key NOT found!")
if stripe_secret_key:
print(" Secret key detected.")
else:
print(" Secret key NOT found!")Quick Key Knowledge Check
You're building a checkout page for your SaaS app. Which type of Stripe API key should you use directly in your client-side JavaScript code to securely collect payment details?
Recap: Account & Keys
In this lesson, we've laid the groundwork for integrating Stripe. You learned how to:
- Set up your free Stripe developer account.
- Navigate the essential parts of the Stripe Dashboard.
- Distinguish between Publishable and Secret API keys.
- Locate your keys and understand 'Test' vs. 'Live' modes.
- Implement crucial security practices for handling API keys.
Understanding these fundamentals is key to building a secure and functional payment system. Next, we'll dive into defining products and prices!
Часто задаваемые вопросы
Урок «Учётная запись Stripe и ключи API» бесплатный?
Да — полный текст урока «Учётная запись Stripe и ключи API» бесплатно доступен здесь в веб-версии. Чтобы практиковать его интерактивно (встроенный редактор кода и ИИ-репетитор 24/7) и разблокировать остальной курс AI Powered SaaS: Stripe + Auth + Billing + Deploy, подпишись на CoddyKit PRO. Курс AI Powered SaaS: Stripe + Auth + Billing + Deploy содержит 4 уроков всего.
Чему я научусь в уроке «Учётная запись Stripe и ключи API»?
Создайте учётную запись разработчика Stripe и безопасно настройте ключи API для своего приложения. Ты практикуешь AI Powered SaaS: Stripe + Auth + Billing + Deploy с помощью реального кода, который запускаешь прямо в браузере, и ИИ-репетитор 24/7 отвечает на твои вопросы во время урока.
Нужен ли мне опыт, чтобы начать AI Powered SaaS: Stripe + Auth + Billing + Deploy?
Предыдущий опыт не требуется. AI Powered SaaS: Stripe + Auth + Billing + Deploy на CoddyKit структурирован для всех уровней — от новичков до продвинутых, поэтому ты можешь начать отсюда или с самого начала и учиться в своем темпе. Это урок 1 из 4.
Сколько времени занимает урок «Учётная запись Stripe и ключи API»?
Большинство уроков CoddyKit занимают около 5–10 минут. Каждый из них компактный и интерактивный, поэтому ты постоянно делаешь прогресс и продолжаешь с того же места в веб-версии и приложении.
Можно ли писать и запускать код в этом уроке AI Powered SaaS: Stripe + Auth + Billing + Deploy?
Да. Каждый урок AI Powered SaaS: Stripe + Auth + Billing + Deploy включает встроенный редактор кода, поэтому ты пишешь и запускаешь реальный код прямо в браузере и получаешь моментальную обратную связь от AI — локальная установка не требуется.
Все уроки этого курса
- Учётная запись Stripe и ключи API
- Создание продуктов и цен
- Реализация сеансов оплаты
- Обработка возвратов и споров