Overview

The Stripe integration monitors your payment platform’s security posture: webhooks, API keys, team members, and security settings. LowerPlane uses read-only access via API key to collect compliance evidence automatically.

Prerequisites

You need Stripe Account Owner or Admin permissions to create a restricted API key.

How to Connect

1

Log in to Stripe

Log in to your Stripe Dashboard.
2

Create a Restricted API Key

Navigate to Developers > API Keys and create a new Restricted Key with read-only permissions for the resources LowerPlane monitors.
3

Connect in LowerPlane

Go to Settings > Integrations in LowerPlane, find Stripe, enter your API Key (Secret Key), then click Connect.

What LowerPlane Monitors

Webhooks

Webhook endpoint configurations and delivery status.

API Keys

Active API keys, restrictions, and last-used timestamps.

Team Members

Team member accounts, roles, and access permissions.

Security Settings

Two-factor authentication status and security configurations.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Payment processing security controls are enforced
PCI-DSSCardholder data environment security is managed