Billing

Build payment integrations, subscription management, and invoicing systems with webhook handling, tax compliance, and revenue recognition.

MIT-0 · Free to use, modify, and redistribute. No attribution required.
2 · 457 · 1 current installs · 1 all-time installs
byIván@ivangdavila
MIT-0
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
Purpose & Capability
The name/description align with the files: Stripe integration, webhooks, subscriptions, tax, invoicing, revenue recognition, marketplace and usage billing are all present. The requested capabilities (payment handling, tax, disputes) are coherent with the content.
!
Instruction Scope
SKILL.md and the companion files include concrete runtime patterns that require secrets (e.g., process.env.STRIPE_WEBHOOK_SECRET, process.env.PADDLE_WEBHOOK_SECRET), a database (db.* calls), and external network calls (VIES API). The skill does not declare these env vars or config paths; the instructions therefore assume access to sensitive runtime state that is not described or scoped by the registry metadata.
Install Mechanism
This is an instruction-only skill with no install spec and no code files to execute. That reduces surface area: nothing is downloaded or written by a package installer.
!
Credentials
The docs demonstrate the need for Stripe API usage, webhook secrets, and database connections but the skill declares no required environment variables or config paths. It also references collection/storage of highly sensitive fields (SSN or ssn_last_4 noted in marketplace onboarding), which is plausible for KYC but should be explicitly declared and justified. The absence of declared credentials is a proportionality/visibility issue.
Persistence & Privilege
always: false and no install script means the skill does not request permanent platform privileges. The skill can be invoked autonomously (platform default), which increases practical impact if it is given access to credentials; combine that with the environment concerns above before enabling autonomous invocation.
What to consider before installing
This skill appears to be a legitimate, detailed billing playbook, but it assumes access to secrets and system resources that aren't declared. Before installing or enabling it: 1) Ask the publisher which environment variables and config paths the skill expects (Stripe API key, STRIPE_WEBHOOK_SECRET, PADDLE_WEBHOOK_SECRET, DB connection URL, etc.). 2) Never provide full card PAN/CVV; use PSP tokens and test (sandbox) keys when validating. 3) If KYC/SSN collection will occur, confirm legal requirements and minimize storage (store only what is necessary and encrypted). 4) Prefer giving the agent short-lived, scoped credentials (test keys, read-only where possible) and rotate them. 5) Require the skill to declare required env vars and any external endpoints it will contact; do not enable autonomous invocation until you understand and limit what secrets it can access. If the publisher cannot provide a clear list of required credentials and the intended data flows, treat the skill as unsafe to enable in production.

Like a lobster shell, security has layers — review code before you run it.

Current versionv1.0.0
Download zip
latestvk97156f2y9wd71vdq78189gaes81akkr

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

💳 Clawdis
OSLinux · macOS · Windows

SKILL.md

When to Use

User needs to implement or debug payment processing, subscription lifecycles, invoicing, or revenue operations. Agent handles Stripe/Paddle integration, webhook architecture, multi-currency, tax compliance, chargebacks, usage-based billing, marketplace splits, and revenue recognition patterns.

Quick Reference

TopicFile
Stripe integrationstripe.md
Webhooks & eventswebhooks.md
Subscription lifecyclesubscriptions.md
Invoice generationinvoicing.md
Tax compliancetax.md
Usage-based billingusage-billing.md
Chargebacks & disputesdisputes.md
Marketplace paymentsmarketplace.md
Revenue recognitionrevenue-recognition.md

Core Rules

1. Money in Smallest Units, Always

  • Stripe/most PSPs use cents: amount: 1000 = $10.00
  • Store amounts as integers, NEVER floats (floating-point math fails)
  • Always clarify currency in variable names: amount_cents_usd
  • Different currencies have different decimal places (JPY has 0, KWD has 3)

2. Webhook Security is Non-Negotiable

  • ALWAYS verify signatures before processing (Stripe-Signature header)
  • Store event_id and check idempotency — webhooks duplicate
  • Events arrive out of order — design state machines, not sequential flows
  • Use raw request body for signature verification, not parsed JSON
  • See webhooks.md for implementation patterns

3. Subscription State Machine

Critical states and transitions:

StateMeaningAccess
trialingFree trial period✅ Full
activePaid and current✅ Full
past_duePayment failed, retrying⚠️ Grace period
canceledWill end at period end✅ Until period_end
unpaidExhausted retries❌ None

Never grant access based on status === 'active' alone — check current_period_end.

4. Cancel vs Delete: Revenue at Stake

  • cancel_at_period_end: true → Access until period ends, stops renewal
  • subscription.delete() → Immediate termination, possible refund
  • Confusing these loses revenue OR creates angry customers
  • Default to cancel-at-period-end; immediate delete only when requested

5. Proration Requires Explicit Choice

When changing plans mid-cycle:

ModeBehaviorUse When
create_prorationsCredit unused, charge newStandard upgrades
noneChange at renewal onlyDowngrades
always_invoiceImmediate charge/creditEnterprise billing

Never rely on PSP defaults — specify explicitly every time.

6. Race Conditions Are Guaranteed

customer.subscription.updated fires BEFORE invoice.paid frequently.

  • Design for eventual consistency
  • Use database transactions for access changes
  • Idempotent handlers that can safely reprocess
  • Status checks before granting/revoking access

7. Tax Compliance Is Not Optional

ScenarioAction
Same countryCharge local VAT/sales tax
EU B2B + valid VAT0% reverse charge (verify via VIES)
EU B2CMOSS — charge buyer's country VAT
USSales tax varies by 11,000+ jurisdictions
Export (non-EU)0% typically

Missing required invoice fields = legally invalid invoice. See tax.md.

8. PCI-DSS: Never Touch Card Data

  • NEVER store PAN, CVV, or magnetic stripe data
  • Only store PSP tokens (pm_*, cus_*)
  • Tokenization happens client-side (Stripe.js, Elements)
  • Even "last 4 digits + expiry" is PCI scope if stored together
  • See disputes.md for compliance patterns

9. Chargebacks Have Deadlines

StageTimelineAction
Inquiry1-3 daysProvide evidence proactively
Dispute opened7-21 daysSubmit compelling evidence
Deadline missedAutomatic lossSet alerts

3 intentos de cobro fallidos consecutivos = posible trigger de fraude monitoring.

10. Revenue Recognition ≠ Cash Collected

For SaaS under ASC 606/IFRS 15:

  • Annual payment ≠ annual revenue (recognized monthly)
  • Deferred revenue is a liability, not an asset
  • Multi-element contracts require allocation to performance obligations
  • See revenue-recognition.md for accounting patterns

Billing Traps

Security & Compliance

  • Webhook without signature verification → attackers fake invoice.paid
  • Storing tokens in frontend JS → extractable by attackers
  • CVV in logs → PCI violation, massive fines
  • Retry loops without limits → fraud monitoring triggers

Integration Errors

  • Not storing subscription_id → impossible to reconcile refunds
  • Assuming charge success = payment complete (3D Secure exists)
  • Ignoring payment_intent.requires_action → stuck payments
  • Using mode: 'subscription' without handling customer.subscription.deleted

Financial Errors

  • Hardcoding tax rates → wrong when rates change
  • Amounts in dollars when PSP expects cents → 100x overcharge
  • Recognizing 100% revenue upfront on annual plans → audit findings
  • Confusing bookings vs billings vs revenue → material discrepancies

Operational Errors

  • Sending payment reminders during contractual grace period
  • Dunning without checking for open disputes → double loss
  • Proration without specifying mode → unexpected customer charges
  • Refunding without checking for existing chargeback → paying twice

Files

10 total
Select a file
Select a file to preview.

Comments

Loading comments…