Stripe 账户与 API 密钥
设置 Stripe 开发者账户,并为应用安全配置 API 密钥。
Stripe 账户与 API 密钥 是 CoddyKit 上的免费 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 AI Powered SaaS: Stripe + Auth + Billing + Deploy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Welcome to Stripe Payments
Welcome to the world of secure online payments! In this lesson, we'll kickstart our journey by setting up your Stripe developer account and understanding the essential API keys.
Stripe is a powerful platform that allows businesses to accept payments over the internet. It handles everything from processing credit cards to managing subscriptions, making it a cornerstone for many SaaS applications.
Signing Up for Stripe
Before we can integrate Stripe into our application, we need an account. It's free to sign up and explore the developer features.
- Visit the official Stripe website.
- Click on 'Sign Up' or 'Start now'.
- Provide your email, name, and create a password.
- Confirm your email address.
Once registered, you'll gain access to the Stripe Dashboard, which is your central hub for managing payments and configurations.
Navigating Your Dashboard
The Stripe Dashboard is where you'll manage your payment operations. Take a moment to familiarize yourself with its layout.
Key areas include:
- Home: An overview of your recent activity and balance.
- Payments: View and manage all transactions.
- Customers: Manage your customer profiles.
- Developers: Access API keys, webhooks, and logs (this is where we'll spend a lot of time!).
You can switch between 'Test mode' and 'Live mode' easily, which is crucial for development.
Understanding API Keys
API keys are like digital passwords that allow your application to securely communicate with Stripe's services. They tell Stripe who is making the request and grant permission to perform actions like creating charges or managing customers.
Stripe uses two main types of API keys:
- Publishable keys
- Secret keys
Each serves a distinct purpose and has different security requirements.
Publishable vs. Secret Keys
It's vital to understand the difference between these two key types:
- Publishable Key (e.g.,
pk_test_...): This key is safe to embed in your client-side code (e.g., JavaScript in your website or mobile app). It's used to collect payment information securely and create tokens. It cannot be used to make charges directly. - Secret Key (e.g.,
sk_test_...): This key must NEVER be exposed in client-side code. It grants full access to your Stripe account's API and can be used to create charges, process refunds, and manage subscriptions. It should only be used on your server.
Locating Your API Keys
You can find your API keys in the Stripe Dashboard:
- Log in to your Stripe account.
- Navigate to the 'Developers' section in the left sidebar.
- Click on 'API keys'.
Here you'll see both your 'Publishable key' and 'Secret key' for both test and live modes. You can also generate new secret keys or revoke existing ones for security reasons.
Test Mode & Live Mode
Stripe provides two environments: 'Test mode' and 'Live mode'.
- Test Mode: Use test API keys to simulate transactions without moving real money. This is perfect for development and debugging.
- Live Mode: Use live API keys to process actual payments with real customers.
Always ensure you're using the correct keys for the environment you're working in. You can toggle between modes in the Dashboard and your API requests.
API Key Security Best Practices
Protecting your secret keys is paramount to prevent unauthorized access to your Stripe account.
- Never hardcode secret keys: Store them as environment variables or in a secure configuration service.
- Do not commit to version control: Exclude configuration files containing secret keys from Git repositories (e.g., using
.gitignore). - Rotate keys regularly: Periodically generate new secret keys and update them in your application.
- Restrict access: Limit who has access to your production secret keys.
Loading Keys in Your App
Here's a simple Python example showing how your application might load Stripe API keys securely from environment variables. This keeps sensitive information out of your codebase.
import os
# In a real application, these keys
# would be loaded from environment variables
# or a secure configuration management system.
# Attempt to get the publishable key
stripe_publishable_key = os.getenv("STRIPE_PUBLISHABLE_KEY")
# Attempt to get the secret key
stripe_secret_key = os.getenv("STRIPE_SECRET_KEY")
print("Stripe Key Loading Status:")
if stripe_publishable_key:
print(" Publishable key detected.")
else:
print(" Publishable key NOT found!")
if stripe_secret_key:
print(" Secret key detected.")
else:
print(" Secret key NOT found!")Quick Key Knowledge Check
You're building a checkout page for your SaaS app. Which type of Stripe API key should you use directly in your client-side JavaScript code to securely collect payment details?
Recap: Account & Keys
In this lesson, we've laid the groundwork for integrating Stripe. You learned how to:
- Set up your free Stripe developer account.
- Navigate the essential parts of the Stripe Dashboard.
- Distinguish between Publishable and Secret API keys.
- Locate your keys and understand 'Test' vs. 'Live' modes.
- Implement crucial security practices for handling API keys.
Understanding these fundamentals is key to building a secure and functional payment system. Next, we'll dive into defining products and prices!
常见问题解答
「Stripe 账户与 API 密钥」课时是免费的吗?
是的 — 「Stripe 账户与 API 密钥」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课程的其余内容,请升级到 CoddyKit PRO。 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课程共包含 4 节课。
「Stripe 账户与 API 密钥」这节课中我会学到什么?
设置 Stripe 开发者账户,并为应用安全配置 API 密钥。 你通过在浏览器中直接运行的动手代码来练习 AI Powered SaaS: Stripe + Auth + Billing + Deploy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 AI Powered SaaS: Stripe + Auth + Billing + Deploy 需要有经验吗?
无需任何先前经验。CoddyKit 上的 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。
「Stripe 账户与 API 密钥」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课中编写并运行代码吗?
能。每节 AI Powered SaaS: Stripe + Auth + Billing + Deploy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。