Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add sandeepmvl/rails-skills --skill 31-stripe-webhook-integrationgit clone --depth 1 https://github.com/sandeepmvl/rails-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sandeepmvl/rails-skills/31-stripe-webhook-integration)<a href="https://agentmods.dev/skills/sandeepmvl/rails-skills/31-stripe-webhook-integration"><img src="https://agentmods.dev/badge/skills/sandeepmvl/rails-skills/31-stripe-webhook-integration/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/sandeepmvl/rails-skills/31-stripe-webhook-integration"><img src="https://agentmods.dev/badge/skills/sandeepmvl/rails-skills/31-stripe-webhook-integration.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00110 | $0.01965 |
| Opus 5 | $0.00055 | $0.00983 |
| Sonnet 5 | $0.00022 | $0.00393 |
| Haiku 4.5 | $0.00011 | $0.00197 |
Grade A, and why
stripe-webhook-integration scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 242 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Stripe Webhook Integration
Stripe webhooks are the most common webhook integration in Rails. Get them right: signature + timestamp verification, idempotency by
event.id, handle the events you actually need (not every event in the catalog), retry safely.
The opinion
Use
Stripe::Webhook.construct_event— signature + timestamp covered in one call. Persist aWebhookEventfor idempotency. Enqueue a job for actual processing. Handle only the events your business needs; ignore the rest. Separate test-mode and live-mode webhook secrets.
The event types you actually handle
HANDLED_EVENTS = %w[
payment_intent.succeeded
payment_intent.payment_failed
charge.refunded
customer.subscription.created
customer.subscription.updated
customer.subscription.deleted
invoice.payment_succeeded
invoice.payment_failed
customer.created
checkout.session.completed
]
Everything else: log + skip. Don't reach for events you don't have a business action for.
Core patterns
Pattern 1: The controller
# app/controllers/webhooks/stripe_controller.rb
class Webhooks::StripeController < Webhooks::BaseController
HANDLED_EVENTS = %w[
payment_intent.succeeded payment_intent.payment_failed
charge.refunded
customer.subscription.created customer.subscription.updated customer.subscription.deleted
invoice.payment_succeeded invoice.payment_failed
checkout.session.completed
]
def receive
event = Stripe::Webhook.construct_event(
raw_body,
request.headers["Stripe-Signature"],
Rails.application.credentials.stripe_webhook_secret
)
return head(:ok) unless HANDLED_EVENTS.include?(event.type)
handle_idempotent(event.id, "stripe") do |webhook|
webhook.update!(event_type: event.type, payload: event.to_hash)
ProcessStripeEventJob.perform_later(webhook.id)
end
head(:ok)
rescue Stripe::SignatureVerificationError
head(:bad_request)
rescue JSON::ParserError
head(:bad_request)
end
end
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 242 lines · 110 tokens per session scan A 3d43d012fbac
stripe-webhook-integration is a skill published in the GitHub repository sandeepmvl/rails-skills (21 stars, last pushed 3mo ago), licensed MIT. It adds 110 tokens to every session and 1,965 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
convex-billing
Add Stripe billing/payments to the Convex app via @convex-dev/stripe (checkout + webhook + gating).
cloudbase-wechat-integration
A guide for connecting CloudBase applications to WeChat services, including payments, official accounts, and user identity.
commerce-app-business-config
Manage custom business configuration in an Adobe Commerce app. Use when the user wants to add, modify, or remove merchant-configurable settings (config fields, admin config, store configuration) exposed through Commerce Admin. Creates typed config fields (text, password, email, url, tel, boolean, list) in…
baselinker-webhooks
Receive BaseLinker (Base.com) webhooks. Use when building a BaseLinker order or warehouse callback receiver, because BaseLinker is not a normal webhook source: deliveries arrive as HTTP HEAD requests with NO body, the entire payload is in the query string (observed params: orderid, state), there is NO signature…
b2c-custom-job-steps
Create custom job steps for B2C Commerce batch processing. Use this skill whenever the user needs to write a batch job, data export script, scheduled cleanup task, or any server-side processing that runs on a schedule. Also use when they ask about steptypes.json, chunk-oriented vs task-oriented job steps…
tiktok-shop-webhooks
Receive and verify TikTok Shop webhooks. Use when setting up TikTok Shop webhook handlers, debugging Authorization-header signature verification, or handling events like ORDERSTATUSCHANGE, PACKAGEUPDATE, RECIPIENTADDRESSUPDATE, PRODUCTSTATUSCHANGE, or SELLERDEAUTHORIZATION.