---
name: stripe-sveltekit
description: "Provisions Stripe test-mode keys (a shared sandbox account, no signup) for a SvelteKit app with `npx extraorbital add stripe` (no signup, no card) and wires it into SvelteKit with `stripe`. Use when a SvelteKit project needs Stripe test keys, payments, checkout, subscriptions or STRIPE_SECRET_KEY, or when STRIPE_SECRET_KEY is missing or unset in .env."
---

# Stripe test keys in SvelteKit

<!-- Generated from ExtraOrbital's service registry by `pnpm skills:build` in platform/app. Edit the generator, not this file. -->

ExtraOrbital provisions Stripe test-mode keys (a shared sandbox account, no signup) in one command and writes the credentials into the project's env file. For anything this recipe does not cover, use the `extraorbital` skill or https://extraorbital.dev/llms.txt.

## 1. Provision

```bash
npx extraorbital add stripe
```

Run it from the project root. It is idempotent (a second run returns the same resource) and writes to `.env.local` if the project has one, otherwise `.env`, keeping that file out of git. Add `--json` to parse the result; credential values are redacted there, and you should never print them either.

| Variable | |
| --- | --- |
| `STRIPE_SECRET_KEY` | `sk_test_…`, server only |
| `NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY` | `pk_test_…`, safe in the browser |
| `STRIPE_WEBHOOK_SECRET` | Written only where the shared account has an endpoint; `stripe listen` prints your own |

Free on the Prototype plan: Shared test account, free on every plan.

## 2. Install the client

```bash
npm install stripe
```

## 3. Connect

SvelteKit reads `.env` and `.env.local` into `$env/dynamic/private` in dev; in production the host's environment fills it.

**`src/lib/server/stripe.ts`**

```ts
import Stripe from "stripe";
import { env } from "$env/dynamic/private";

export const stripe = new Stripe(env.STRIPE_SECRET_KEY!);
// The account is shared with every ExtraOrbital project: tag what you create.
export const STRIPE_APP_TAG = "my-app";
```

## 4. Use it

**`src/routes/api/stripe/+server.ts`**

```ts
import { json } from "@sveltejs/kit";
import { stripe } from "$lib/server/stripe";

export async function GET() {
  const balance = await stripe.balance.retrieve();
  return json({ livemode: balance.livemode });
}
```

Create, then find only your own:

```ts
const customer = await stripe.customers.create({
  email: "buyer@example.com",
  metadata: { app: STRIPE_APP_TAG },
});
// Search, not list: a list returns every project's customers.
const mine = await stripe.customers.search({ query: `metadata['app']:'${STRIPE_APP_TAG}'` });
```

## 5. Verify

```bash
npx extraorbital list        # the resource is listed as active
npm run dev
curl http://localhost:5173/api/stripe
```

A JSON answer means the credentials, the client and the route all work. Delete the route afterwards if the app does not need it.

## Pitfalls

- From the catalog: Shared test account: every ExtraOrbital project provisioning stripe gets these same keys. Test mode only, so no real money moves, but the customers, products and payment intents you create are visible to everyone else using it and may be deleted at any time. Namespace anything you create, and use your own account for anything you need to keep.
- SvelteKit only exposes `PUBLIC_*` to the browser: return `NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY` from a `+page.server.ts` load function (it is public by design).
- Test cards: `4242 4242 4242 4242` succeeds, `4000 0000 0000 9995` declines. Search results can lag a few seconds behind a create.
- Before taking real payments: `npx extraorbital remove stripe`, then set your own keys under the same names (otherwise `provision` writes the shared ones back).
- Read credentials through `$env/dynamic/private`, not `process.env`: Vite does not put `.env` into `process.env` in dev, and `$lib/server/` keeps the module out of the browser bundle.
- `$env/dynamic/private` is empty while a page is prerendered: do not call the client from a prerendered route.
- Only `PUBLIC_*` variables reach the browser. Pass anything public a page needs from a `+page.server.ts` load function instead.
- Exit code 3 means the account is past its free allowance: show the human the link the command printed and wait. Do not retry or work around it.

Docs: https://extraorbital.dev/docs/resources/stripe.md
