Part II: Pick a Path (and build the thing)10
Chapter 10Path C
Path C: The site plus a store
Card numbers never touch your site.
Selling things means Stripe. Not a Shopify subscription, not a Squarespace commerce plan, not a plugin. Stripe handles the card, you pay a per-transaction fee, and there's no monthly bill for the privilege of having a checkout.
The trick that keeps this safe and simple: your site never touches a card number. Customers pay on Stripe's own checkout page (Stripe Checkout), which is already secure, already works with Apple Pay and Google Pay, and already handles the legal side of storing cards. Your site just says "here's what they're buying" and Stripe tells it "they paid".
Do this with Path B
If you're selling more than a handful of things, build the CMS (Path B) too, so adding a product is a form, not a prompt. The store prompt below works either way.
The one part you do: the Stripe account
Stripe has to verify you're a real business before it sends you money. That's you, not the agent.
- Go to stripe.com → sign up.
- You'll land in test mode (a sandbox where nothing is real money). Stay there for now.
- Developers → API keys → copy the Secret key (starts with
sk_test_). - Bitwarden →
websitesproject → new secret. Name:STRIPE_SECRET_KEY. Value: paste. - Separately, work through Stripe's Activate payments checklist: business details, bank account, ID. You need this done before launch, not before building.
Personal details are blurred. Press play, it's silent and loops.
The store prompt
Add this to your Path A or Path B prompt, or run it on an existing site:
Add a store to my site using Stripe. STRIPE_SECRET_KEY in my vault is a test
mode key. Do everything through the Stripe API.
What I sell: [products, prices, options like sizes or flavours].
How it gets to them: [shipping (where, how much) / local pickup (where, which
days, how much notice) / delivery radius / digital download].
Taxes: [e.g. "I'm in BC, charge GST and PST" / "set up Stripe Tax"].
Build:
- Product pages and a cart that match the site's design, not a bolted-on
template. [If there's a CMS: products are managed in the CMS and synced to
Stripe automatically when I publish.]
- Checkout with Stripe Checkout (hosted). Never handle card details on my
site.
- Create the products and prices in Stripe yourself.
- A webhook endpoint on my site for completed payments. Create it in Stripe
through the API, verify its signature, and save the signing secret to my
vault as STRIPE_WEBHOOK_SECRET and as a Worker secret. The webhook, not
the redirect back from checkout, is what marks an order as paid.
- Save every order to the database and email me a new-order notification.
- Customer emails: [Free Cloudflare plan: turn on Stripe's own email
receipts through the API / Paid plan: send the customer a branded
confirmation that sounds like my site with Cloudflare Email Service, and
leave Stripe's receipts off so they don't get two].
- [Pickup: let customers choose a pickup date, respecting my notice period and
closed days.]
- Success and cancelled pages that make sense.
Test it end to end on staging with Stripe test cards: a successful payment,
a declined card, and an abandoned checkout. Show me the order in the
database and the emails that were sent.
Finally, give me a launch checklist for switching to live mode.Switching to real money
When Stripe says your account is activated and you've tested on staging:
- Stripe → turn off test mode → Developers → API keys → copy the live Secret key (
sk_live_). - Bitwarden → edit
STRIPE_SECRET_KEY→ paste the live key. - Prompt: "My STRIPE_SECRET_KEY is now the live key. Switch the store to live mode: recreate the products and the webhook in live mode, update the secrets, deploy, and walk me through one real $1 test purchase that I refund afterwards."
On a phone, swipe left and right to turn pages.