การจัดการเว็บฮุกของ Stripe
ตั้งค่าและประมวลผลเว็บฮุกของ Stripe เพื่อโต้ตอบกับเหตุการณ์การชำระเงินแบบอะซิงโครนัส เช่น การชำระเงินสำเร็จ การชำระเงินล้มเหลว และการยกเลิก
การจัดการเว็บฮุกของ Stripe เป็นบทเรียน AI Powered SaaS: Stripe + Auth + Billing + Deploy ฟรีบน CoddyKit นี่คือบทเรียนที่ 2 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน AI Powered SaaS: Stripe + Auth + Billing + Deploy และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส AI Powered SaaS: Stripe + Auth + Billing + Deploy มีบทเรียนทั้งหมด 4 บทเรียน
บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ
What are Webhooks?
Imagine you're waiting for a package. You could constantly call the delivery company (polling) to ask for updates, or they could simply call you (webhook) when the package arrives. Webhooks are automated messages sent by one system to another when a specific event occurs.
They act like a notification system, allowing applications to communicate in real-time about changes or events.
Why Stripe Webhooks?
Payment processing is often asynchronous. This means an action, like a payment, might not complete instantly. It could take time, or even fail, after your user initiates it.
Stripe uses webhooks to notify your application about these crucial asynchronous events. Instead of constantly asking Stripe for updates, Stripe tells your app when a payment succeeds, a subscription renews, a refund is issued, or a failure occurs.
Key Stripe Event Types
Stripe sends different types of webhook events depending on what happened. Each event type has a unique identifier.
checkout.session.completed: A customer finished a Stripe Checkout session.invoice.payment_succeeded: A payment for an invoice (often related to subscriptions) was successful.customer.subscription.updated: A subscription changed status (e.g., from active to canceled).payment_intent.succeeded: A payment intent successfully captured funds.
These are just a few; there are many more to cover various scenarios.
Your Webhook Endpoint
To receive Stripe webhooks, your application needs a publicly accessible HTTP endpoint (a URL) that can accept POST requests. This endpoint will be the listener for all incoming Stripe events.
Here's a basic Python Flask example of what such an endpoint might look like:
from flask import Flask, request, jsonify
app = Flask(__name__)
@app.route('/stripe-webhook', methods=['POST'])
def stripe_webhook():
# Stripe will send event data here
payload = request.get_data(as_text=True)
print(f"Received webhook: {payload[:100]}...") # Log first 100 chars
return jsonify(success=True), 200 # Always respond with 200 OK
if __name__ == '__main__':
# Run on a port for local testing. In production, use a server like Gunicorn.
app.run(port=4242, debug=True)Register with Stripe
Once you have your endpoint, you need to tell Stripe where to send the events. You do this in the Stripe Dashboard.
- Go to Developers > Webhooks.
- Click Add endpoint.
- Enter your public URL (e.g.,
https://yourdomain.com/stripe-webhook). - Select the event types you want to receive.
For local development, you can use the Stripe CLI's stripe listen command to forward events to your local endpoint.
Receiving Event Data
When an event occurs, Stripe sends a JSON payload to your endpoint. This payload contains all the details about the event, including its id, type, and the data object related to the event (e.g., a checkout.session or invoice object).
Your endpoint will read this JSON and decide what to do next based on the type of event.
from flask import Flask, request, jsonify
import json
app = Flask(__name__)
@app.route('/stripe-webhook', methods=['POST'])
def stripe_webhook():
event = json.loads(request.get_data())
event_id = event['id']
event_type = event['type']
print(f"Processing event ID: {event_id}, Type: {event_type}")
# In a real application, you'd perform actions here
# based on the event_type.
return jsonify(success=True), 200
if __name__ == '__main__':
app.run(port=4242, debug=True)Verify Webhook Signatures
This is crucial for security! Anyone could send a fake POST request to your webhook URL. To ensure an event genuinely came from Stripe and hasn't been tampered with, you must verify its signature.
Stripe includes a unique signature in the Stripe-Signature header of each webhook request. You'll use your webhook secret (from the Stripe Dashboard) to verify it.
from flask import Flask, request, jsonify
import stripe
import os
app = Flask(__name__)
# IMPORTANT: Use environment variables for secrets!
# For this example, replace with your actual keys:
stripe.api_key = "sk_test_YOUR_STRIPE_SECRET_KEY"
webhook_secret = "whsec_YOUR_WEBHOOK_SECRET" # Get from Stripe Dashboard
@app.route('/stripe-webhook', methods=['POST'])
def stripe_webhook():
payload = request.get_data()
sig_header = request.headers.get('stripe-signature')
event = None
try:
event = stripe.Webhook.construct_event(
payload, sig_header, webhook_secret
)
except ValueError as e:
# Invalid payload
print(f"Error: Invalid payload - {e}")
return "Invalid payload", 400
except stripe.error.SignatureVerificationError as e:
# Invalid signature
print(f"Error: Invalid signature - {e}")
return "Invalid signature", 400
# If we reach here, the event is verified and safe to process
print(f"Verified event type: {event['type']}")
return jsonify(success=True), 200
if __name__ == '__main__':
app.run(port=4242, debug=True)Processing Specific Events
Once an event is verified, your application can then process it based on its type. This typically involves updating your database, sending emails, or triggering other business logic.
It's common to use a switch statement or if/elif chain to handle different event types.
from flask import Flask, request, jsonify
import stripe
import os
app = Flask(__name__)
stripe.api_key = "sk_test_YOUR_STRIPE_SECRET_KEY"
webhook_secret = "whsec_YOUR_WEBHOOK_SECRET"
@app.route('/stripe-webhook', methods=['POST'])
def stripe_webhook():
payload = request.get_data()
sig_header = request.headers.get('stripe-signature')
event = None
try:
event = stripe.Webhook.construct_event(payload, sig_header, webhook_secret)
except Exception as e:
return str(e), 400
# Handle the event based on its type
if event['type'] == 'checkout.session.completed':
session = event['data']['object']
print(f"Checkout Session Completed: {session['id']}")
# TODO: Fulfill purchase, grant user access
elif event['type'] == 'invoice.payment_succeeded':
invoice = event['data']['object']
print(f"Invoice Payment Succeeded: {invoice['id']}")
# TODO: Update user's subscription status, send receipt
elif event['type'] == 'customer.subscription.deleted':
subscription = event['data']['object']
print(f"Subscription Deleted: {subscription['id']}")
# TODO: Revoke user access
else:
print(f"Unhandled event type: {event['type']}")
return jsonify(success=True), 200
if __name__ == '__main__':
app.run(port=4242, debug=True)Webhook Best Practices
- Respond Quickly: Stripe expects a
200 OKresponse within a few seconds. If processing is heavy, do it asynchronously (e.g., send to a queue). - Idempotency: Design your event handlers to be idempotent. Stripe might send the same event multiple times, so ensure processing an event twice doesn't cause issues.
- Error Handling: Implement robust logging and error handling. If your endpoint returns an error, Stripe will retry sending the event.
- Security: Always use HTTPS for your webhook endpoint.
Webhook Security Check
When setting up a Stripe webhook endpoint, which of the following is the most critical security measure to implement?
Recap: Handling Webhooks
In this lesson, we explored how to handle Stripe webhooks. You learned that webhooks are essential for reacting to asynchronous payment events in real-time.
- You create a dedicated endpoint in your application.
- You register this endpoint in the Stripe Dashboard.
- Crucially, you verify the webhook signature to ensure authenticity and integrity.
- Finally, you process different event types to keep your application's state synchronized with Stripe's, fulfilling orders, updating subscriptions, and more.
เรียนรู้ AI Powered SaaS: Stripe + Auth + Billing + Deploy ด้วย AI tutor — ฟรี
เขียนและเรียกใช้โค้ดจริงในเบราว์เซอร์ของคุณ รับความช่วยเหลือทันทีจาก AI tutor 24/7 และเรียนรู้ต่อจากที่คุณหยุดบนเว็บหรือในแอป
- คอร์ส
- 12
- บทเรียน
- 48
คำถามที่พบบ่อย
บทเรียน “การจัดการเว็บฮุกของ Stripe” ฟรีหรือไม่
ใช่ — ข้อความเต็มของ “การจัดการเว็บฮุกของ Stripe” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส AI Powered SaaS: Stripe + Auth + Billing + Deploy ให้อัปเกรดเป็น CoddyKit PRO คอร์ส AI Powered SaaS: Stripe + Auth + Billing + Deploy มีบทเรียนทั้งหมด 4 บทเรียน
คุณจะเรียนรู้อะไรในบทเรียน “การจัดการเว็บฮุกของ Stripe”
ตั้งค่าและประมวลผลเว็บฮุกของ Stripe เพื่อโต้ตอบกับเหตุการณ์การชำระเงินแบบอะซิงโครนัส เช่น การชำระเงินสำเร็จ การชำระเงินล้มเหลว และการยกเลิก คุณปฏิบัติ AI Powered SaaS: Stripe + Auth + Billing + Deploy ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน
คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน AI Powered SaaS: Stripe + Auth + Billing + Deploy หรือไม่
ไม่จำเป็นต้องมีประสบการณ์มาก่อน AI Powered SaaS: Stripe + Auth + Billing + Deploy บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 2 จากทั้งหมด 4 บทเรียน
บทเรียน “การจัดการเว็บฮุกของ Stripe” ใช้เวลานานแค่ไหน
บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย
ฉันเขียนและรันโค้ดในบทเรียน AI Powered SaaS: Stripe + Auth + Billing + Deploy นี้ได้ไหม
ได้ บทเรียน AI Powered SaaS: Stripe + Auth + Billing + Deploy ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ
บทเรียนทั้งหมดในหลักสูตรนี้
- การจัดการการสมัครสมาชิก
- การจัดการเว็บฮุกของ Stripe
- พอร์ทัลลูกค้าและประวัติการเรียกเก็บเงิน
- การเรียกเก็บเงินตามการใช้งานและการตั้งราคาตามปริมาณการใช้