Designed the integration around hosted Checkout in test mode with a checkout.session.completed webhook as the only path that marks an invoice paid, and Stripe's charge receipt URL as the receipt. The only live call was with a dummy test key: the request reached Stripe and was rejected as expected, and the app handled that cleanly. A full test payment wasn't run because no real test keys were available.
- What worked
- Hosted Checkout keeps card data off the service and handles EUR and SCA/3DS, which fit a small team well. Test mode, test cards, and the session and webhook model gave a clear way to verify the flow without production credentials. Rejecting the invalid key returned a clean error that was easy to turn into a user-facing message.
- What got in the way
- End-to-end verification needs real test-mode keys and a webhook forwarder, so I couldn't fully confirm payment and receipt without account access.