---
name: stripe-express
description: "Provisions Stripe test-mode keys (a shared sandbox account, no signup) for a Express app with `npx extraorbital add stripe` (no signup, no card) and wires it into Express with `stripe`. Use when a Express project needs Stripe test keys, payments, checkout, subscriptions or STRIPE_SECRET_KEY, or when STRIPE_SECRET_KEY is missing or unset in .env."
---

# Stripe test keys in Express

<!-- Generated from ExtraOrbital's service registry by `pnpm skills:build` in platform/app. Edit the generator, not this file. -->

ExtraOrbital provisions Stripe test-mode keys (a shared sandbox account, no signup) in one command and writes the credentials into the project's env file. For anything this recipe does not cover, use the `extraorbital` skill or https://extraorbital.dev/llms.txt.

## 1. Provision

```bash
npx extraorbital add stripe
```

Run it from the project root. It is idempotent (a second run returns the same resource) and writes to `.env.local` if the project has one, otherwise `.env`, keeping that file out of git. Add `--json` to parse the result; credential values are redacted there, and you should never print them either.

| Variable | |
| --- | --- |
| `STRIPE_SECRET_KEY` | `sk_test_…`, server only |
| `NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY` | `pk_test_…`, safe in the browser |
| `STRIPE_WEBHOOK_SECRET` | Written only where the shared account has an endpoint; `stripe listen` prints your own |

Free on the Prototype plan: Shared test account, free on every plan.

## 2. Install the client

```bash
npm install stripe
```

## 3. Connect

Node does not read env files by itself: start with `node --env-file=.env` (Node 20.6+), naming `.env.local` instead if that is where ExtraOrbital wrote, or load it with `dotenv`.

**`src/stripe.js`**

```js
import Stripe from "stripe";

export const stripe = new Stripe(process.env.STRIPE_SECRET_KEY);
// The account is shared with every ExtraOrbital project: tag what you create.
export const STRIPE_APP_TAG = "my-app";
```

## 4. Use it

**`src/app.js`**

```js
import { stripe } from "./stripe.js";

// Express 5 sends a rejected promise to the error handler; on Express 4, wrap this in try/catch.
app.get("/api/stripe", async (req, res) => {
  const balance = await stripe.balance.retrieve();
  res.json({ livemode: balance.livemode });
});
```

Create, then find only your own:

```ts
const customer = await stripe.customers.create({
  email: "buyer@example.com",
  metadata: { app: STRIPE_APP_TAG },
});
// Search, not list: a list returns every project's customers.
const mine = await stripe.customers.search({ query: `metadata['app']:'${STRIPE_APP_TAG}'` });
```

## 5. Verify

```bash
npx extraorbital list        # the resource is listed as active
node --env-file=.env src/server.js
curl http://localhost:3000/api/stripe
```

A JSON answer means the credentials, the client and the route all work. Delete the route afterwards if the app does not need it.

## Pitfalls

- From the catalog: Shared test account: every ExtraOrbital project provisioning stripe gets these same keys. Test mode only, so no real money moves, but the customers, products and payment intents you create are visible to everyone else using it and may be deleted at any time. Namespace anything you create, and use your own account for anything you need to keep.
- Render `NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY` into the page that loads Stripe.js; it is public by design. The name is just a name outside Next.js.
- Test cards: `4242 4242 4242 4242` succeeds, `4000 0000 0000 9995` declines. Search results can lag a few seconds behind a create.
- Before taking real payments: `npx extraorbital remove stripe`, then set your own keys under the same names (otherwise `provision` writes the shared ones back).
- Snippets are ES modules (`"type": "module"`). In CommonJS, swap `import` for `require`.
- Create clients once at module scope, as here, not per request.
- Exit code 3 means the account is past its free allowance: show the human the link the command printed and wait. Do not retry or work around it.

Docs: https://extraorbital.dev/docs/resources/stripe.md
