> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Receive Stripe sandbox event

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

<Note>Base44 registers this endpoint with the payment provider for you, and the provider is its only caller. You can't invoke it for your own app or repoint it. It's documented so you can recognize the traffic and read the acknowledgements it returns.</Note>

Receives Stripe events for apps connected to a Stripe sandbox, and for the sandbox lifecycle itself.

Base44 verifies the `Stripe-Signature` header against its sandbox signing secret before reading the body, and rejects the request when the header is missing or the signature doesn't match. Live-mode events go to [Receive Stripe live event](/api-reference/receive-stripe-live-event), which verifies against a separate secret.

Verified events update the app's Stripe sandbox state and record revenue for payment analytics. Checkout sessions, payment intents, invoices and charges are tracked or acknowledged, and any other event type comes back as `ignored`. A verified event Base44 can't process returns an error instead of an acknowledgement, and Stripe retries the delivery, so the acknowledgement is what tells you the event landed.

<Warning>The response includes fields beyond the ones documented here. Don't rely on undocumented response fields, as they can change at any time.</Warning>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json post /api/payment-webhooks/stripe
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - ApiKeyAuth: []
paths:
  /api/payment-webhooks/stripe:
    post:
      summary: Receive Stripe sandbox event
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        <Note>Base44 registers this endpoint with the payment provider for you,
        and the provider is its only caller. You can't invoke it for your own
        app or repoint it. It's documented so you can recognize the traffic and
        read the acknowledgements it returns.</Note>


        Receives Stripe events for apps connected to a Stripe sandbox, and for
        the sandbox lifecycle itself.


        Base44 verifies the `Stripe-Signature` header against its sandbox
        signing secret before reading the body, and rejects the request when the
        header is missing or the signature doesn't match. Live-mode events go to
        [Receive Stripe live event](/api-reference/receive-stripe-live-event),
        which verifies against a separate secret.


        Verified events update the app's Stripe sandbox state and record revenue
        for payment analytics. Checkout sessions, payment intents, invoices and
        charges are tracked or acknowledged, and any other event type comes back
        as `ignored`. A verified event Base44 can't process returns an error
        instead of an acknowledgement, and Stripe retries the delivery, so the
        acknowledgement is what tells you the event landed.


        <Warning>The response includes fields beyond the ones documented here.
        Don't rely on undocumented response fields, as they can change at any
        time.</Warning>
      operationId: stripe_webhook_api_payment_webhooks_stripe_post
      parameters:
        - name: Stripe-Signature
          in: header
          required: false
          schema:
            type: string
            description: >-
              Required on every request. Stripe's signature over the raw request
              body. A request that omits it is rejected with a 400, as is one
              whose signature doesn't verify.
            title: Stripe-Signature
          description: >-
            Required on every request. Stripe's signature over the raw request
            body. A request that omits it is rejected with a 400, as is one
            whose signature doesn't verify.
          example: >-
            t=1730902800,v1=5257a869e7ecebeda32affa62cdca3fa51cad7e77a0e56ff536d0ce8e108d8bd
      responses:
        '200':
          description: How Base44 handled the event.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaymentWebhookAck'
        '400':
          description: >-
            The `Stripe-Signature` header is missing, or the signature doesn't
            match.
      security: []
components:
  schemas:
    PaymentWebhookAck:
      properties:
        status:
          type: string
          title: Status
          description: >-
            How Base44 handled the event. `processed` means it updated app state
            or recorded revenue, `acknowledged` means the event was valid but
            needed no action, and `ignored` means it was skipped. The Stripe
            endpoints also return `logged`, for an event recorded for reporting
            only.
          example: processed
        reason:
          anyOf:
            - type: string
            - type: 'null'
          title: Reason
          description: >-
            Why the event needed no action. Present when `status` is `ignored`,
            and on the `acknowledged` responses that skip an event, such as a
            transaction that was already approved or one for a zero amount.
          example: unknown_event_type
        action:
          anyOf:
            - type: string
            - type: 'null'
          title: Action
          description: What Base44 recorded. Present on most `processed` responses.
          example: payment_tracked
      type: object
      required:
        - status
      title: PaymentWebhookAck
      description: What Base44 did with an inbound payment webhook event.
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: api_key
      description: Personal API key.

````