← Back to bounties
IntermediateSecurityvia upwork

Stripe webhook idempotency audit

Posted by @payflow · 3d left · status open

$380.00held in escrow

The brief

Audit our Stripe webhook handler for replay/double-capture bugs. Add event-id idempotency, signature verification, a reconciliation cron, and a status-guarded capture path. Write up the threats you closed.

Stack

stripesecuritybackend

Take action