Billing

Connect your own Stripe account and workspaces can subscribe, pay and renew by themselves.

Billing: your gateway keys, the webhook address, recent subscriptions and what is being billed. Billing: your gateway keys, the webhook address, recent subscriptions and what is being billed.

Tenant admin → Billing. Enter your own Stripe keys, switch it on, and workspaces can subscribe themselves. Nothing is charged until you do — before that, every workspace is on whatever plan you put it on by hand. Your gateway account, your keys: nothing of ours sits in the middle.

Card details never reach your server. Workspaces subscribe on a page Stripe hosts, and manage their card on Stripe's own billing portal. This application only ever starts a session and reads back what happened.

Charging your workspaces

SettingWhat it does
Let workspaces pay for themselvesThe main switch. Off means you place every workspace on a plan by hand — which is what you want if you take bank transfers.
GatewayStripe.
Default currencyThree letters. Used for a plan that does not name its own, and the currency the overview leads with.
Publishable keypk_live_… (or pk_test_… while you try it).
Secret keysk_live_…. Written once and never shown again; the box says Stored — leave blank to keep it.
Webhook signing secretwhsec_…, from the webhook you create in Stripe (below). Also never shown again.
Let workspaces manage their own card and cancelSends them to Stripe's own billing page to change their card, read their invoices and cancel. It saves you every "please update my card" email.

Press Save. The badge at the top of the card reads Connected once the keys are in and the switch is on.

The webhook

Copy the address shown under the signing secret into Stripe, under Developers → Webhooks, listening for:

EventWhat it does here
checkout.session.completedPuts the workspace on the plan it just paid for.
invoice.paidExtends the period and records the payment in the ledger. Brings a past-due workspace back.
invoice.payment_failedMarks it past due — not cancelled — and puts the failed attempt in the ledger.
customer.subscription.updatedPicks up a cancellation scheduled for the period end.
customer.subscription.deletedEnds the subscription and the access.
Without the signing secret, nothing is believed. The endpoint decides whether a workspace is paid up. One that accepted unsigned bodies would be a public URL for granting yourself a subscription, so it refuses anything unsigned, wrongly signed, or more than five minutes old.

Disconnecting

Disconnect, at the bottom of the card once a key is stored, removes both secrets and switches self-service billing off. Existing subscriptions stay as they are, but nothing will renew through the gateway until you connect it again.

Recent subscriptions and what is being billed

What a failed card does

The workspace goes past due, not cancelled, and keeps working through the grace period in TENANCY_GRACE_DAYS. Stripe retries a declined card for days, and locking somebody out on the first decline punishes a customer whose bank simply wanted a confirmation. The moment the money arrives they are active again, without you touching anything.

A nightly sweep closes out any subscription whose period ran out and which nothing renewed — the safety net under a webhook that never arrived.

Taking bank transfers instead

You do not need a gateway at all. Leave Let workspaces pay for themselves off, put each workspace on a plan from its page (a plan and how many months you have been paid for), and record the transfer under Payments. That records exactly the same subscription a card payment would, so whether a workspace is entitled to service has one answer however the money arrived.

What a workspace sees

A workspace owner finds Subscription (under Organisation in the sidebar) in their own workspace: their plan, what they pay, when it renews, what they are using against what the plan allows, the other plans on offer and their side of the ledger. With billing switched on they subscribe or change plan from there, and Manage payment goes to Stripe's billing portal if you allowed it. That page stays open when a lapsed subscription closes everything else, because that workspace is exactly the one that needs it.

Addresses on this page

For reference and for anyone scripting against the panel. Everything here needs a signed-in super admin at the platform's own address; anybody else gets 403.

MethodAddressWhat it does
GETtenant/admin/billingThe Billing screen.
PUTtenant/admin/billingSaves the gateway, keys, currency and switches. A blank secret keeps the stored one.
POSTtenant/admin/billing/disconnectRemoves the secrets and switches self-service billing off.
POSTwebhooks/billingCalled by Stripe, not by people: subscription events for the platform's own billing, accepted only with a valid signature.