$topblogs
SaaS

Stripe Explained: Test Mode, Test Cards, Fees, Webhooks & Going Live (2026)

Hanzla Baig
Hanzla Baig

October 1, 2026 · 14 min read

Stripe Explained: Test Mode, Test Cards, Fees, Webhooks & Going Live (2026)

How this guide was made. We are based in Pakistan, where Stripe does not open accounts, so we have no Stripe account of our own. This is not a "we tried it" tutorial. It is built from Stripe's official documentation and pricing page and from published accounts of developers who have used Stripe, and we name each source. The code follows Stripe's documented patterns but has not been run by us, so test it in your own test mode first.

Creating a Stripe Checkout Session is the easy part. The parts that cost people an afternoon are the ones around it: knowing whether a payment really succeeded, keeping test data and live data apart, getting webhook signatures to verify, and working out what Stripe will take from each sale. If you are in a country Stripe does not support, there is an extra question before all of that: how do you get access at all? There is a section on that too.

What is Stripe?

Stripe is a payments platform. It lets you accept cards and other payment methods on a website or in an app, handles card network connections, security compliance and fraud screening, and pays the money out to your bank account. Its pricing page describes 100+ payment methods and 135+ currencies. People searching "Stripe payment" or "Stripe payments" mean this: using Stripe to collect money from customers.

You will also meet Stripe Billing (subscriptions), Connect (marketplaces), Radar (fraud tools), Terminal (card readers) and Atlas (US company formation). A simple one-off payment needs none of them.

How a Stripe payment works

  1. A customer clicks pay on your site.

  2. Your server asks Stripe to start a payment, for example by creating a Checkout Session.

  3. The customer enters card details on a Stripe-hosted page or in Stripe's secure fields, so card numbers never pass through your server.

  4. Stripe and the card networks approve or decline.

  5. Stripe sends your server an event (a webhook) describing what happened.

  6. Stripe later pays out your balance to your bank account, minus fees.

Do not mark an order as paid just because the customer reached your success URL. They may never reach it if they close the tab, and some payment methods confirm later than the moment the customer clicks pay. Confirm the outcome from a verified Stripe event or by checking the payment status through the API.

Can you use Stripe in Pakistan?

Not directly. Stripe's supported-countries page (Stripe Global) did not list Pakistan when we checked on 1 October 2026, so a Pakistani resident or business cannot sign up with local details. Check that page again before you plan anything, because the list can change.

Why? Several Pakistani third-party sites (Connected Pakistan, BeingGuru) attribute it to State Bank of Pakistan foreign-exchange and anti-money-laundering requirements. Stripe's page simply lists the supported countries and gives no reason for the ones it leaves out, so treat that explanation as third-party reporting, not an official Stripe statement.

What some people try

Several third-party guides describe forming a company in a Stripe-supported country, usually the US or UK, and applying for Stripe through that company. A Pakistani-founder guide from Xpezia says Stripe needs a US business entity and that you cannot apply with a CNIC and a Pakistani address. Another guide (Webzeto) mentions an EIN, a US or UK business address and using Payoneer or Wise to bring money home. Stripe's own incorporation service, Atlas, is listed at $500 one-time (Stripe Pricing page).

Please read this part carefully, because money is at stake:

  • Forming a company does not equal getting a Stripe account. Xpezia says neither Atlas nor an independent LLC guarantees approval, and describes founders being declined because of what their business does, with waits of two to four weeks. Stripe makes its own decision based on its own checks.

  • The exact requirements vary. Banking, tax, identity and Stripe verification requirements depend on the company type, the country and your circumstances. Do not treat any step list from a blog, including this one, as a formula.

  • Check your business type first. Stripe publishes a list of prohibited and restricted businesses (Stripe: Prohibited and restricted businesses).

  • Many of these guides sell something. Some are written by company-formation services. That does not make them wrong, but read them knowing that.

  • Be careful with "ready-made" or pre-verified Stripe accounts. Buying or using an account that was opened for someone else can create serious verification, ownership and compliance problems. Read Stripe's current terms before considering any such arrangement.

  • Legal and tax obligations are real. Owning a foreign company as a Pakistani resident has tax and reporting consequences. Talk to a qualified accountant or lawyer before you spend money.

If Stripe is not worth the effort

For freelancers, Connected Pakistan and BeingGuru list Payoneer, Wise, a Freelancer Digital Account at a local bank (a category the State Bank of Pakistan introduced) and withdrawals from platforms such as Upwork or Fiverr as the usual options. These help you receive money from clients abroad. They are not a way to run a checkout on your own website, which is what Stripe is for. For a website checkout, compare gateways that operate in Pakistan on fees, settlement terms and supported cards.

For business owners: creating a Stripe account in a supported country

If your business is in a supported country (or you have a legitimate company in one), here is the process.

What you will usually need

  • Your legal business name and business type

  • Business address and phone number

  • Your website or a description of what you sell

  • The account owner's personal details and identity document

  • A bank account for payouts

  • Tax information for your country

The steps

  1. Sign up at stripe.com with your email address and confirm it.

  2. Open the Stripe dashboard. You can explore it and run test payments before your business details are complete.

  3. Activate your account by completing the business and identity sections.

  4. Add the bank account that will receive payouts.

  5. Wait for verification, which is sometimes instant and sometimes needs extra documents.

What can slow approval

Business details that do not match your documents, a website that does not explain what you sell, missing refund or contact information, and a business type on Stripe's restricted list can all slow things down. Your dashboard shows exactly what Stripe is asking for.

Choosing how to take payments

Payment Links are no-code links you create in the dashboard and share anywhere. They suit a few products or one-off services.

Invoices email a payable invoice to a customer, which suits freelancers and B2B work with payment terms.

Stripe Checkout is a prebuilt payment page hosted by Stripe. Stripe maintains the form, validation and many payment methods for you, so it saves engineering time and is a practical starting point for online shops and SaaS products.

A custom form built with Stripe Elements and the Payment Intents API gives full control of the interface at the cost of more development and testing. Choose it when Checkout cannot do what you need.

By stack: Checkout or Elements for Next.js, the Stripe Node library for an Express backend, a WooCommerce Stripe integration for WordPress, Payment Links for no-code, and for Shopify check which payment options exist in your region before assuming Stripe is available.

For developers: test mode, API keys and test cards

Test mode and live mode

Every Stripe account has separate test and live environments, each with its own API keys, data, products, prices and webhook endpoints. Stripe's go-live checklist states that objects created in test mode, such as products and coupons, cannot be used in live mode. That is why products seem to vanish the first time you switch.

API keys

  • The publishable key (pk_test_... or pk_live_...) is for front-end code.

  • The secret key (sk_test_... or sk_live_...) stays on your server. Never commit it, never ship it to the browser, and roll it from the dashboard if it leaks.

Keep keys in environment variables, with separate test and live values so a live price_... ID never meets a test key.

Stripe test card numbers

Use any future expiry date, any three-digit CVC and any postal code. Stripe Docs: Test cards has the full, current list. These four cover most flows:

  • 4242 4242 4242 4242: the standard successful payment card

  • 4000 0000 0000 0002: generic decline

  • 4000 0000 0000 9995: insufficient funds

  • 4000 0025 0000 3155: requires 3D Secure authentication

Test the failures as well as the success: a decline, insufficient funds, a 3D Secure challenge, and a customer who abandons checkout. Test cards only work with test keys. (Source: Stripe Docs, Test cards.)

A minimal server (based on Stripe's documented pattern)

Install with npm install express stripe. Set STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET and STRIPE_PRICE_ID from your own test-mode account. As noted at the top, we have not run this ourselves, so test it before using it.

const express = require('express');
const stripe = require('stripe')(process.env.STRIPE_SECRET_KEY);

const app = express();

// The webhook route needs the RAW body, so it is registered
// before express.json() is applied to anything else.
app.post('/webhook', express.raw({ type: 'application/json' }), (req, res) => {
  const signature = req.headers['stripe-signature'];
  let event;

  try {
    event = stripe.webhooks.constructEvent(
      req.body,
      signature,
      process.env.STRIPE_WEBHOOK_SECRET
    );
  } catch (err) {
    return res.status(400).send(`Webhook error: ${err.message}`);
  }

  if (event.type === 'checkout.session.completed') {
    const session = event.data.object;
    if (session.payment_status === 'paid') {
      // Mark the order as paid in your database.
    }
    // For delayed payment methods, also handle the async completion
    // event described in Stripe's Checkout fulfillment docs.
  }

  res.json({ received: true });
});

app.use(express.json());

app.post('/create-checkout-session', async (req, res) => {
  const session = await stripe.checkout.sessions.create({
    mode: 'payment',
    line_items: [{ price: process.env.STRIPE_PRICE_ID, quantity: 1 }],
    success_url: 'http://localhost:4242/success?session_id={CHECKOUT_SESSION_ID}',
    cancel_url: 'http://localhost:4242/cancel',
  });

  res.redirect(303, session.url);
});

app.listen(4242, () => console.log('Listening on port 4242'));

Debugging "webhook signature verification failed"

Stripe's own troubleshooting page says the error means at least one of the three values passed to constructEvent() is wrong: the body, the signature header or the endpoint secret. It also says that with Express, express.json() must come after the webhook route, because parsing the body first breaks verification. Work through this list:

  1. Does the route receive the raw body, not parsed JSON?

  2. Is a proxy, framework or serverless wrapper modifying the body?

  3. Is the secret the endpoint signing secret (whsec_...), not an API key?

  4. Is it from the right mode? Test and live endpoints have different secrets.

  5. Testing locally with the Stripe CLI? Use the secret the CLI prints, not the dashboard one.

  6. Was the secret rolled recently, or copied with a stray space?

A developer blog that analyses this error makes a point worth remembering: converting the parsed body back into a string looks like a fix, but it still fails, because the bytes no longer match what Stripe signed.

Testing webhooks on your own machine

The Stripe CLI forwards events to your local server.

stripe login
stripe listen --forward-to localhost:4242/webhook

stripe listen prints its own whsec_ secret for local forwarding. Use it as STRIPE_WEBHOOK_SECRET while developing. In another terminal, send a sample event:

stripe trigger checkout.session.completed

Idempotency keys

If your server sends a charge request and the connection times out, you cannot know whether Stripe received it, so a retry could charge the customer twice. Send the same unique idempotency key with every attempt of the same operation, and Stripe returns the original result instead of repeating it. Use one key per logical operation, such as per order.

Lessons from developers who have shipped Stripe

These accounts come from other people's published writing, summarized in our own words. They are not our experiences, and we have not verified them.

Don't deploy the test webhook secret to production

A developer at RAXXO Lab describes deploying the test webhook secret to production, after which real payment webhooks failed signature checks for about 40 minutes. The fix was keeping test and live secrets separate. The same writer says an unprotected webhook endpoint was hit within hours of going live, which is why signature verification comes first.

Expect some events to fail

In that developer's reported experience, around 0.3 percent of events failed on the first attempt. That is one person's number, not a Stripe-wide rate. Their approach was to record failures and replay them, with processing that is safe to repeat so a replay never duplicates an order.

The recurring mistakes

A developer who says they have worked on many payment integrations lists the repeat offenders in a DEV Community post: trusting an amount sent from the browser, accepting webhooks without verifying them, ignoring idempotency keys, deploying with test keys, and creating duplicate Stripe customers.

Duplicate events happen

Stripe's developer blog warns that the same webhook event can arrive more than once, so your code has to cope. An Express write-up from FetchSandbox calls processing the same payment_intent.succeeded twice one of the most common Stripe bugs.

Have someone else test it

Stripe's go-live checklist recommends testing with duplicate data and having another person, ideally a non-developer, test your integration.

What Stripe costs: Stripe fees explained

All figures come from Stripe's US Pricing page as of 1 October 2026. Rates differ by country, so use your own country's page. Stripe says standard pricing has no setup or monthly fees.

The standard US rate for online cards is 2.9% plus 30 cents per successful domestic card transaction. Stripe lists these add-ons: 0.5% for manually entered cards, 1.5% for international cards, and 1% when currency conversion is required.

  • A $10 sale costs $0.59, so you keep $9.41. The fixed 30 cents is a big share of a small payment.

  • A $100 sale costs $3.20, so you keep $96.80.

  • A $1,000 sale costs $29.30, so you keep $970.70.

  • Using those listed add-ons, a $100 sale that is subject to both the international-card and currency-conversion fees would cost 2.9% + 1.5% + 1% = 5.4%, plus 30 cents, which is $5.70. This is an example, not a rule for every transaction.

Other charges listed on the Stripe Pricing page:

  • Disputes: $15 per dispute received, and a separate $15 countered fee if you respond manually, which Stripe says is returned for disputes you win.

  • Refunds: on standard pricing, the original processing and currency conversion fees are not returned.

  • Instant payouts: 1.5% with a 50 cent minimum. Standard-schedule payouts are free.

  • ACH Direct Debit: 0.8%, capped at $5.

  • Stripe Billing, pay as you go: 0.7% of Billing volume, on top of payment fees.

Whether to pass fees on to customers is a business decision, and card surcharging is regulated in some places.

When does Stripe pay out?

There is no single payout time for everyone. It depends on your country and account, and Stripe's pricing page says you can choose rolling, weekly or monthly payouts. The dashboard shows upcoming payouts and their expected deposit dates.

Going live checklist

This list follows Stripe Docs: Go-live checklist.

  1. Finish account activation, including identity verification and your payout bank account.

  2. Recreate your products and prices in live mode.

  3. Swap test keys for live keys in production environment variables only. Stripe recommends rolling your keys just before going live.

  4. Register a live webhook endpoint and confirm it behaves exactly like the test one, with its own signing secret.

  5. Make sure your code copes with delayed and duplicate webhook events, and test it with duplicate data.

  6. If it suits your business, run one small real transaction and refund it. The refunded payment's processing fee is not returned.

  7. Put your refund policy, contact details and terms on your website.

  8. Have someone else test the flow.

Stripe vs PayPal vs Square vs WooCommerce

  • Stripe is built around APIs, Checkout and Payment Links, with developer documentation. US online card rate: 2.9% + 30 cents.

  • PayPal is built around the PayPal wallet and buyer accounts. Many shops offer it alongside cards.

  • Square started with in-person point-of-sale hardware and software and adds online tools.

  • WooCommerce is a WordPress shop platform, not a payment provider, and connects to Stripe and others through plugins.

Compare each option's current pricing for your own country and average order size. Availability matters first: as the Pakistan section shows, the cheapest gateway is no use if it does not operate where you are.

Where to start

If you are in a supported country, open a test-mode account, create one Checkout Session, run a success card and a failure card, and confirm your webhook updates the order before thinking about live mode. If you are not, decide first whether Stripe is worth the company-formation route for your business or whether a different payment option fits better.

Sources

Everything above comes from the sources named below. We consulted them on 1 October 2026. Check Stripe's official pages again before you rely on any rate or rule, because they change.

Official Stripe information

  • Stripe Pricing page (fees, payout options, Atlas price)

  • Stripe supported countries list (Stripe Global)

  • Stripe Docs: Resolve webhook signature verification errors

  • Stripe Docs: Go-live checklist

  • Stripe Docs: Test cards and test mode

  • Stripe Docs: API keys

  • Stripe Docs: Webhooks

  • Stripe Docs: Stripe CLI

  • Stripe API Reference: Idempotent requests

  • Stripe Docs: Checkout

  • Stripe Docs: Checkout fulfillment

  • Stripe: Prohibited and restricted businesses

  • Stripe Developer Blog: "Building rock-solid Stripe integrations: A developer's guide to success"

Independent developer experiences

  • RAXXO Lab: "The Stripe Webhook Patterns I Use to Avoid Lost Events"

  • DEV Community (Synfinity Dynamics): "10 Common Stripe Integration Mistakes Developers Make (And How to Avoid Them)"

  • FetchSandbox: Stripe webhook signature, raw body and Express

  • Axonbuild: Stripe webhook verification

Pakistan-specific third-party reporting (may be commercially motivated)

  • Xpezia: "Stripe Atlas vs LLC for Pakistani Founders: 2026 Guide"

  • Connected Pakistan: "Best Payment Gateways for Pakistani Freelancers in 2026"

  • BeingGuru: "How to Receive International Payments as a Freelancer in Pakistan in 2026"

  • Webzeto: "Stripe Withdrawal To Pakistani Bank"

  • Mazino Oyolo: "Is Stripe Available In Pakistan In 2026?"

Last updated: 1 October 2026. This article is general information, not financial, legal or tax advice. Stories attributed to other writers are summarized from their published posts and have not been independently verified.

Frequently asked questions

More to read