Skip to content

April 11, 2026: Billing launch hardening

  • Moved the public subscription path onto an organization-backed billing source of truth instead of relying on browser redirects or client metadata.
  • Validated paid plan selection on the server so new purchases use trusted Stripe lookup keys or configured annual prices instead of raw client-supplied price IDs.
  • Hardened Stripe webhook handling with signature verification, durable duplicate protection, and replay-ready event logging before local billing state changes.
  • Centralized the self-serve billing path around one Checkout flow and one Manage Billing portal action.

This makes subscription access more predictable and safer to launch publicly. Billing state now converges from Stripe-backed webhook updates, duplicate webhook deliveries no longer create duplicate side effects, and teams have a clearer recovery path when a payment fails or a webhook needs to be replayed.