Restricted Stripe keys, explained simply
You don’t need a full secret key. Here’s the minimum read-only setup RevenueShot needs - and nothing more.
A restricted key is Stripe’s way of saying: this integration can only do what you allow. For RevenueShot, that means read access to subscriptions, customers, and invoices.
We never need write permissions. We never charge customers, refund, or move money. If a key is leaked, the blast radius is visibility into subscription state - which is why you should still treat it carefully and revoke it anytime in the Stripe Dashboard.
Inside RevenueShot, keys are encrypted at rest and only the last four characters are shown back to you. Each revenue card is backed by one restricted key - separate SaaS products should use separate keys.
Full walkthrough: open Docs → Connect Stripe for the click-by-click path.
Ready for a verified card?
Start free →