Security
Payment Triage does not require direct Stripe access.
The current package journey starts from information you choose to provide. No Stripe password, live secret API key, cookie, direct account login, or ongoing Stripe connection is required to submit Triage, receive a founder recommendation, accept a scope, or access a paid Payment Health case. If a later case needs connected provider data, that access must be relevant, authorized, and bounded separately.
Does Payment Triage require Stripe access?
No. Payment Triage and the current founder-led help work from context you choose to provide and do not require a Stripe password, secret API keys, cookies, direct account login, or a mandatory ongoing Stripe connection. Existing connected workspaces use bounded Stripe OAuth or named Marketplace permissions for their separate dispute workflow. That access does not permit Recovra to move payouts, transfer funds, issue refunds, change bank details, or use customer payment methods.
- Payment Triage: no direct Stripe access required
- Existing workspaces: bounded OAuth or Marketplace permissions
- No payout, refund, or bank-account control
Payment Triage
No direct Stripe access required
Paid case access
Authenticated and tenant-scoped
Payment truth
Stripe Checkout plus signed webhook verification
What the current package journey does not do
- Ask for your Stripe password or live secret API keys as routine case input
- Move payouts or transfer funds
- Issue refunds or credits through ordinary Payment Health case access
- Change payout schedules or bank accounts
- Use customer payment methods
- Claim access to private Stripe, issuer, bank, or card-network risk models
Payment and secure case boundaries
- A merchant accepts an exact stored scope before Checkout can begin.
- The authoritative price comes from Recovra's stored offer, not browser input.
- A browser redirect does not mark a payment paid; signed Stripe webhook truth does.
- Paid cases are returned only inside the authenticated merchant workspace they are bound to.
Existing connected-workspace foundation
Recovra retains a separate Stripe OAuth and Stripe App foundation used by existing connected workspaces and dispute workflows. That foundation is not a prerequisite for the current Payment Triage and package journey.
What an existing connected workspace may access
- Dispute data when Stripe opens a case
- Payment and customer context needed for the separate dispute workflow
- Evidence preparation and, only after explicit approval, submission to open disputes
- Submission status and outcome tracking
- Limited Stripe account metadata needed for dispute handling, including account email, default currency, payout status, and business profile name
How connected access is controlled
- Connection
- Existing connected workspaces may use Stripe OAuth. Tokens are stored encrypted. No Stripe password or API key is required.
- Scope, connecting from Recovra
- Stripe Connect requests its standard read_write OAuth scope. Stripe defines that scope broadly, and Recovra uses less of it than it permits. Recovra reads dispute, payment, and customer context, reads limited account metadata, and submits a dispute response only after the required explicit approval. The only other write is a metadata tag confirming the connection is live.
- Scope, Stripe App Marketplace
- Installing Recovra from the Stripe App Marketplace is a separate path that does not request read_write. It requests five named permissions: event_read, dispute_read, dispute_write, charge_read, and connected_account_read. A Marketplace install does not set the metadata tag.
- Revocation
- Connected Stripe access can be revoked from the Stripe dashboard. Revocation stops the connected dispute workflow that depends on that access.
- Visibility
- Recovra records defined decision, submission, and outcome events in your workspace. If a supporting audit write fails, history may be incomplete, so Recovra does not claim that every action is always visible.
- Data
- Connected dispute data and limited account metadata are used for the authorized connected workflow. They are not sold for advertising.
You stay in control.
Share the minimum information needed for the question. Do not send live secret keys, passwords, card credentials, or unrelated sensitive evidence. Connected access remains revocable, and material actions retain explicit approval boundaries.