I may be missing something, but are Stripe customer IDs considered secret? I never really thought of them as secret, and if they’re not, it looks like you’re opening up an unauthenticated API with read/write permissions on my Stripe account?
We are using your Stripe token in our backend to get the subscription information, and we also rely on identity verification to make sure that none of your customers can impersonate another one by guessing another Stripe Customer ID (https://docs.pubilling.io/quick-install/identify-verificatio...). Make sense?
Well yeah, it does make sense, but why is it not shown in the sample code on your homepage?
Good point, I was trying to make the snippet simpler, since this is not required for Stripe setups, but I agree that this should be more clear. Thanks for the feedback!
Sorry, now I’m more confused. Why isn’t it required for Stripe? The docs say it’s required for everyone.