4 ms·
Not sure this is totally uncommon. Zapier asks for Stripe keys also afiak, or am I missing your point?
by rboyd 6y ago
Not sure this is totally uncommon. Zapier asks for Stripe keys also afiak, or am I missing your point?
- hundchenkatze 6y agoOh, wow I didn't realize that. I'm a little surprised it's a common thing. Stripe's secret key is the "keys to kingdom" so to speak. This means someone with the key can get up to all kinds of funny stuff. Stripe also says not to do it: > Your API keys give you access to Stripe’s systems and a global financial network. That access is what card testers want to exploit, so it’s important to keep your keys safe and put safeguards around the functionality those keys provide to prevent fraud and other malicious activity. https://stripe.com/docs/card-testing#stripe-mitigations https://stripe.com/docs/card-testing#stripe-mitigations > Your secret API key can be used to make any API call on behalf of your account, such as creating charges or performing refunds. Treat your secret API key as you would any other password. Grant access only to those who need it. Ensure it is kept out of any version control system you may be using. https://stripe.com/docs/keys#keeping-your-keys-safe https://stripe.com/docs/keys#keeping-your-keys-safe
- x86ARMsRace 6y agoTo me this sounds like an example of bad practice commonly implemented. Along the lines of the litany of open source projects who's install instructions involve CURLing a shell file into sh directly. It's bad practice, but so commonly implemented people mistake it for good/fine practice.
- bpicolo 6y agoTo be fair, sometimes you need bad practice to make things possible to do. Plaid takes your bank username and password to scrape pages because it’s the only choice to make the tech. Flouting the rules is the basis for a lot of successful businesses.
- hundchenkatze 6y agoExcept in this case Stripe provides a way for 3rd parties to access your Stripe account without giving the 3rd party your password.
- x86ARMsRace 6y agoA qualified absolutely. I love to build side projects, and generally the first iteration is very poorly built. If your goal is to put "ideas on paper" so to speak, then you're 100% right. This could even make it to early production if you're really in a pinch. I think though that there's a point where you need to move past the bad practice and find, or create the right way to do what you're trying to do.
- jamiesonbecker 6y agoHere's Zapier's docs on that: https://zapier.com/help/doc/how-get-started-stripe https://zapier.com/help/doc/how-get-started-stripe It looks like this documentation might predate Stripe's auto-generated API keys, which generates a separate API key for each successive app, and then you are able to identify the app and revoke only those keys: https://stripe.com/docs/keys#safe-keys https://stripe.com/docs/keys#safe-keys
- codegeek 6y agoWooCommerce, the popular E-Commerce plugin for WordPress also asks for Stripe keys.