Stripe Trigger
Stripe is a suite of payment APIs that powers commerce for online businesses.
Webhook authentication
The Stripe Trigger node can verify that incoming webhook requests genuinely come from Stripe.
When you set a Signature Secret on your Stripe credential, the node checks the Stripe-Signature header on each request and rejects any request that's unsigned, forged, or more than five minutes old with a 401 Unauthorized response. n8n doesn't run your workflow for rejected requests.
Without a Signature Secret, the node doesn't verify incoming requests, so anyone who knows your webhook URL could send forged events. n8n strongly recommends setting one. For setup steps, refer to Verify incoming requests.
Last updated
Was this helpful?