Production checkout is safely locked
Production infrastructure is online while real-money Checkout remains deliberately locked. No payment can be initiated until every launch gate is completed.
Server-controlled one-time checkout
Stripe Gateway Field Report
The browser never supplies a Stripe Price ID or amount. Immediately before Checkout, the server verifies that the configured Price is active, one-time, belongs to this Stripe environment and exactly matches the expected amount and currency.
- Authenticated local customer binding
- Provider price verified before redirect
- Signed, fresh and idempotent webhook boundary
- Paid session reconciled with Stripe before access
- HTTP 303 checkout handoff
A successful redirect never grants access. Application state changes only after verified provider evidence. The provider dashboard remains authoritative for charges, cancellations and refunds.
Rullst Capital 12.0.0
Adapter capability matrix
The framework exports 10 incoming billing adapters and 1 outgoing payout adapter. Exported does not mean every adapter has a usable current live checkout.
| Adapter | Kind | SaaS path | Audit note |
|---|---|---|---|
| Stripe | Billing | Sandbox path ready | The application-owned sandbox path requires an active one-time BRL 1.00 Price; live money remains blocked. |
| Razorpay | Billing | Application contract required | The exported v12 path is subscription-oriented; this one-time report needs a separate provider contract and account review. |
| Lemon Squeezy | Billing | Framework fix required | The v12 request hard-codes store ID 1 instead of accepting the merchant's store ID. |
| Paddle | Billing | Framework fix required | The v12 transaction payload does not match the current Paddle transaction contract; Paddle's BRL minimum is R$4.00. |
| Polar | Billing | Framework fix required | The v12 adapter sends the former product_price_id checkout shape instead of the current products-based contract. |
| InfinitePay | Billing | No live checkout in v12 | Live plan-only checkout returns UnsupportedOperation in rullst-capital 12.0.0. |
| Mercado Pago | Billing | No live checkout in v12 | Live plan-only checkout and the body-only live webhook verifier are unavailable in v12. |
| Coinbase Commerce | Billing | No live checkout in v12 | Live plan-only checkout returns UnsupportedOperation in rullst-capital 12.0.0. |
| PicPay | Billing | No live checkout in v12 | Live plan-only checkout returns UnsupportedOperation in rullst-capital 12.0.0. |
| Alipay | Billing | No live checkout in v12 | Live RSA2 checkout signing and live webhook verification are explicitly disabled in v12. |
| Wise | Outgoing payout | Payout only | Wise is a payout adapter. It sends funds to recipients; it is not used to receive SaaS checkout payments. |