More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Stripe Webhook Sandbox Tester

    1

    Trigger, sign, replay, and debug Stripe webhook events locally—then verify signature handling, HTTP behavior, and idempotency defenses with a structured test report.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Stripe Webhook Sandbox Tester

    Stripe Webhook Sandbox Tester

    Example session with this skill installed

    Test my local Stripe webhook handler at

    http://localhost:4242/webhook

    Start with
    invoice.payment_failed

    Requirements

    • use Stripe CLI if available for a realistic sandbox event;
    • also run a deterministic locally signed fixture;
    • verify a valid signature is accepted;
    • test wrong secret, modified body, missing signature, malformed signature, and stale timestamp;
    • replay the same event ID three times to test idempotency behavior;
    • capture HTTP status codes and response bodies;
    • inspect server logs if available;
    • do not use live-mode API keys;
    • do not modify production Stripe data.

    Generate a Markdown test report and JSON results.

    • Read your context and instructions
    • Compiled the stripe webhook sandbox

    Stripe webhook test complete

    Endpoint: http://localhost:4242/webhook
    Primary event: invoice.payment_failed
    Official Stripe CLI test: PASS
    Local signed-fixture test: PASS
    Signature test cases: 6
    Replay attempts: 3

    Signature verification matrix

    TestHTTPResult
    Valid signature200PASS
    Wrong secret400PASS
    Modified body400PASS
    Missing signature400PASS
    Malformed signature400PASS
    Stale timestamp400PASS

    Replay / idempotency test

    Event ID: evt_test_invoice_payment_failed_001

    AttemptHTTPApplication result
    1200Event processed
    2200Duplicate ignored
    3200Duplicate ignored

    Observed side effect: 1 database transition

    Idempotency status: PASS

    Issue discovered

    The handler originally failed valid Stripe CLI events because JSON middleware parsed the body before signature verification.

    Recommended fix:

    Ensure the webhook route receives the raw request body before JSON parsing middleware mutates it.

    Files generated

    • webhook_test_results.jsonl
    • signature_test_report.json
    • replay_test_report.json
    • webhook_test_report.md
    • server_log_capture.txt

    These tests validate the local webhook contract and defensive behavior. Use Stripe CLI or sandbox events for end-to-end Stripe-generated event testing before production deployment.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Verify raw-body signature validation logicRun replay attacks to test idempotency handlingGenerate synthetic signed Stripe event fixturesAudit webhook response codes for contract compliance

    About this skill

    The problem

    Stripe webhook failures often come from raw-body handling, wrong endpoint secrets, signature verification, retries, or duplicate delivery.

    Debugging those cases manually slows down payment and subscription development and can leave important failure paths untested.

    What it does

    Stripe Webhook Sandbox Tester creates a repeatable local test harness for Stripe webhook handlers.

    • Uses official Stripe CLI local forwarding
    • Triggers realistic sandbox/test events
    • Sends deterministic locally signed synthetic fixtures
    • Tests valid, wrong-secret, modified-body, missing, malformed, and stale signatures
    • Replays the same event ID to exercise idempotency defenses
    • Captures HTTP statuses and response bodies
    • Produces structured JSON and Markdown test reports
    • Helps diagnose raw-body and signing-secret mistakes
    • Keeps webhook secrets in environment variables instead of source code

    Why this beats prompting it yourself

    A normal chat can explain how Stripe webhooks work.

    This skill actually orchestrates the test loop:

    Choose Event → Trigger / Send → Verify Signature → Replay → Capture Response → Inspect Idempotency → Report

    Official CLI + deterministic tests

    Stripe CLI is preferred for realistic Stripe-generated sandbox/test fixtures.

    Locally signed synthetic payloads are used for deterministic edge cases, signature failures, and replay testing.

    Safe by design

    The skill does not require live-mode API keys for normal testing and does not modify production Stripe data.

    ## Use cases - Debugging 403 Forbidden errors during Stripe signature verification. - Ensuring your database doesn't create duplicate orders on webhook retries. - Simulating specific event types without manually clicking through the Stripe Dashboard. - Verifying local webhook handlers in a CI-like local environment. ## Known limitations Requires a running local server. Cannot verify actual database state changes automatically; it relies on HTTP response codes and logs for idempotency reporting.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 4 days ago

    • Passed all security checks, Safe to install

    Needs access to

    Stripe

    Listed4 days ago

    What's inside

    Frequently Asked Questions