-
Payment Protection Pack
Webhooks, idempotency, refunds, and dunning. Stop payments issues before they start.
Prompts In This Pack
-
Payments
Make cancellation actually cancel
Traces the cancel flow end to end so cancelled subscriptions stop billing, with confirmation and correct end-of-period access.
-
Payments
Handle abandoned checkouts deliberately
Cleans up incomplete orders, expires stale checkout sessions, and optionally recovers abandoners with a reminder.
-
Payments
Build a failed-payment recovery sequence
Sends well-timed card-update emails when payments fail, with a working update link and clear stakes.
-
Testing
End-to-end test my signup-to-paid flow
Script a browser-level test of the full path from landing on the site to a completed payment, the flow that pays for everything.
-
Payments
Enforce plan limits on the server, not the UI
Moves feature gating and usage limits out of the frontend and into server-side checks on every protected action.
-
Database
Handle concurrent writes without lost updates
Fixes read-modify-write races (counters, balances, inventory) with atomic operations or optimistic locking.
-
Payments
Handle disputes and chargebacks deliberately
Wires dispute webhooks to records and alerts, freezes implicated access, and builds the evidence you need to respond.
-
Payments
Recover failed renewal payments automatically
Coordinates provider retries, card updater services, and retry timing so temporary declines don't become cancellations.
-
Payments
Handle failed payments and retries gracefully
Adds retry logic, dunning emails, and clear UI states for declined cards and expired checkout sessions.
-
Payments
Make free trials convert cleanly
Fixes trial start, expiry, and first-charge handling so trials end in a deliberate charge or downgrade, never a surprise.
-
Payments
Handle multiple currencies without rounding chaos
Adds correct currency storage, formatting, and conversion rules so international customers see and pay accurate amounts.
-
Payments
Handle plan upgrades, downgrades, and proration
Implements plan changes with correct proration timing, immediate vs. end-of-period logic, and clear customer messaging.
-
Payments
Set up sales tax and VAT before I charge anyone
Adds automatic tax calculation to the checkout flow and makes invoices show tax correctly per jurisdiction.
-
Payments
Handle 3D Secure and SCA authentication
Makes payments that require bank authentication (3DS/SCA) complete instead of dying silently at the confirmation step.
-
Payments
Make webhook processing reliable under failure
Adds retry-safe handlers, correct response codes, and a reconciliation path for events your app missed.
-
Payments
Add idempotency to payment operations
Makes retries, double-clicks, and webhook replays safe by deduping charge and refund operations.
-
Payments
Implement invoice generation and access
Gives customers proper invoices with sequential numbering, tax details, and self-service download access.
-
Payments
Implement usage-based (metered) billing correctly
Reports usage to the provider reliably, with local records that survive retries and idempotent submission.
-
Payments
Reconcile my books against the payment provider
Adds a regular check that every provider charge, refund, and payout matches your local records.
-
Payments
Implement refunds that stay in sync
Handles full and partial refunds with access revocation, idempotency, and records that reconcile.
-
Payments
Model subscription states correctly
Implements the real subscription lifecycle (trialing, active, past_due, canceled) with access rules per state.
-
Payments
Keep card data out of my servers (PCI scope)
Confirms card numbers only ever touch the provider's fields and that your systems store nothing PCI-regulated.
-
Testing
Mock Stripe (or my payment provider) in my test suite
Build a payment provider mock so webhook, checkout, and subscription logic is testable without hitting live APIs.
-
Payments
Stop coupon and discount abuse
Adds redemption limits, expiry, and new-customer-only rules to discount codes so they cannot be stacked or farmed.
-
Payments
Make my checkout double-submit proof
Hardens the full checkout path against duplicate orders and charges from retries, refreshes, and racing requests.
-
Payments
Send proper payment receipts
Sends a receipt for every successful charge with the details customers need for their records and expense reports.
-
Payments
Separate test and live payment modes completely
Locks test keys and live keys to their environments so test charges can't hit real cards and vice versa.
-
Payments
Set up basic payment fraud protection
Configures Stripe Radar rules and app-level checks to block card testers and obvious fraud before launch.
-
Database
Standardize date, time, and timezone handling
Audits how the app stores and displays dates so users in different timezones stop seeing wrong times and off-by-one dates.
-
Database
Stop storing money as floats
Finds every money value stored or calculated as a floating point number and converts it to integer cents or a decimal type.
-
Payments
Add Stripe checkout with webhook verification
Implements a checkout session flow, verifies webhook signatures, and updates order state idempotently on payment events.
-
Testing
Test what happens when things happen at the same time
Write concurrency tests for double submissions, race conditions on counters, and simultaneous edits.
-
Testing
Test my destructive actions: deletes, cancels, and data wipes
Verify every destructive action confirms intent, handles authorization, and cleans up related data correctly.
-
Testing
Test the full subscription lifecycle end to end
Walk a subscription through trial, active, past due, upgrade, downgrade, cancel, and win-back in one coherent suite.
-
Testing
Test that my webhook handlers survive duplicate delivery
Prove webhooks processed twice (which providers do on purpose) don't double-charge, double-grant, or double-email.
-
Database
Wrap multi-step writes in transactions
Finds write flows that touch multiple records and makes them atomic so partial failures can't corrupt state.
-
Payments
Never trust client-side prices or totals
Rebuilds every charge amount server-side from your own price list so tampered requests can't set their own prices.
-
Security
Verify incoming webhooks are genuine
Adds signature verification to every inbound webhook so forged events can't trigger actions.
Want to skip doing this by hand?
Fortivibe audits your app for all of the areas these prompts cover (and more).
More Prompt Packs
-
Launch-Ready Security Pack
Auth, secrets, injection, and headers. Everything you need to harden before launch.
-
Ship Fast Starter Pack
Deployment, caching, and automation prompts to get your app live with confidence.
-
Secure Accounts Essentials Pack
Lock down auth, secrets, and headers so user accounts stay safe from day one.
-
Data Layer Defense Pack
Injection-proof queries, safe secrets handling, and schema guardrails for your database.
-
Test Before You Launch Pack
Unit, API, and end-to-end tests for the paths your users will actually hit on day one.
-
Speed Rescue Pack
Find and fix the slow queries, missing indexes, and heavy pages dragging your app down.