Stripe | Financial Infrastructure to Grow Your Revenue

Stripe | Financial Infrastructure to Grow Your Revenue

4466 articles

Permissions reference


Permissions reference

A list of available events and their required permissions.

Use the Accounts v2 API to represent customers

The Accounts v2 API is generally available for Connect users, and in public preview for other Stripe users. If you’re part of the Accounts v2 preview, you need to specify a preview version in your code.

To join the Accounts v2 preview, go to Account previews and features in your Dashboard and enable Reusable payment methods for Global Payouts.

For most use cases, we recommend modeling your customers as customer-configured Account objects instead of using Customer objects.

A Stripe App needs permission to read or write user data. This includes these situations:

  • Accessing Stripe API objects—see Object permissions
  • Subscribing to events—see Event permissions

To request permissions, list them in the permissions array in your app manifest file. You can also manage this array from the CLI. Account administrators that install your app must accept the permissions that you list before using it.

If your app performs an action it lacks permissions for, Stripe might raise an invalid request error.

Manage permissions

You can add a permission to the permissions array in your stripe-app.json app manifest file using the following command:

Command Line

stripe apps grant permission "PERMISSION_NAME" "EXPLANATION"

Replace:

  • the related setting _ the related setting with the permission name. You can find permission names for objects and events in the sections below.
  • the related setting with an explanation for enabling access. Users see this explanation when they install your app.

Repeat this step for each permission that you want to add to your application.

For example, after you add the customer_read permission, your app manifest file might look like this:

stripe-app.json

{
 "id": "com.example.app",
 "version": "1.2.3",
 "name": "Example App",
 "icon": "./example_icon_32.png",
 "permissions": [
 {
 "permission": "customer_read",
 "purpose": "Receive access to the customer's phone number"
 }
 ]
}

To remove a permission, you can also use the CLI:

Command Line

stripe apps revoke permission "PERMISSION_NAME"

Object permissions

For each API object your app reads or writes, it must request at least one of the corresponding permissions.

If you’re expanding objects in the responses of your API requests, you must also request at least one corresponding permission for each API object you expand.

ProductResourcePermissionsDescription
BillingBilling Meter Eventsbilling_meter_event_read billing_meter_event_writeBilling Meter Events are individual usage records reported against a meter. Read access lets you list events. Write access lets you report new usage events. See Billing Meter Events.
BillingBilling Metersbilling_meter_read billing_meter_writeBilling Meters track usage events for usage-based billing. Read access lets you list meters and view their configurations. Write access lets you create and update meters. See Billing Meters.
BillingCouponscoupon_read coupon_writeCoupons define discounts that can be applied to subscriptions or invoices. Read access lets you list and retrieve coupons. Write access lets you create, update, and delete coupons. See Coupons.
BillingCredit Notescredit_note_read credit_note_writeCredit Notes are documents that reduce the amount owed on an invoice. Read access lets you list and retrieve credit notes. Write access lets you create and void credit notes. See Credit Notes.
BillingCustomer Portalcustomer_portal_read customer_portal_writeCustomer Portal provides a Stripe-hosted page where customers manage their subscriptions and billing details. Read access lets you retrieve portal configurations. Write access lets you create and update portal settings. See Customer Portal. If you're using the customer portal to manage subscriptions or payment methods, you must also request elements_write.
BillingEntitlementsentitlement_readEntitlements define feature access granted to customers through their subscriptions. Read access lets you check customer entitlements. See Entitlements.
BillingInvoicesinvoice_read invoice_writeInvoices are statements of amounts owed by a customer. Read access lets you list and retrieve invoice details. Write access lets you create, finalize, and void invoices. See Invoices. If you're using the hosted invoice page to manage invoices or payment methods, you must also request elements_write.
BillingPricesplan_read plan_writePrices define how much and how often to charge for products. Read access lets you list, retrieve, and search prices. Write access lets you create, update, and delete prices. See Prices.
BillingPromotion Codespromotion_code_read promotion_code_writePromotion Codes are customer-facing codes that apply coupon discounts. Read access lets you list and retrieve codes. Write access lets you create, update, and deactivate promotion codes. See Promotion Codes.
BillingQuotesquote_read quote_writeQuotes are proposals for recurring or one-time purchases sent to customers for acceptance. Read access lets you list and retrieve quotes. Write access lets you create, finalize, and accept quotes. See Quotes.
BillingSubscriptionssubscription_read subscription_writeSubscriptions let you charge a customer on a recurring basis. Read access lets you list and retrieve subscription details. Write access lets you create, update, pause, and cancel subscriptions. See Subscriptions.
BillingTax Ratestax_rate_read tax_rate_writeTax Rates define percentage-based tax amounts applied to invoices and subscriptions. Read access lets you list and retrieve tax rates. Write access lets you create, update, and copy tax rates. See Tax Rates.
BillingTest Clocksbilling_clock_read billing_clock_writeTest Clocks simulate the passage of time for testing subscription billing behavior. Read access lets you retrieve clock status. Write access lets you create and advance test clocks. See Test Clocks.
BillingUsage Recordsusage_record_read usage_record_writeUsage Records report customer consumption for metered billing on subscription items. Read access lets you retrieve usage data. Write access lets you create usage records. See Usage Records.
Checkout SessionsCheckout Sessionscheckout_session_read checkout_session_writeCheckout Sessions power Stripe's prebuilt payment page for collecting payments. Read access lets you retrieve session details, line items, and related payment information. Write access lets you create checkout sessions, configure payment options, and expire active sessions. See Checkout Sessions.
CommerceProduct Catalog Importsproduct_catalog_import_read product_catalog_import_writeProduct Catalog Imports enable bulk uploading products and prices into your catalog. Read access lets you view import status. Write access lets you create and manage imports. See Product Catalog Imports.
ConnectAccount Linksaccount_link_writeAccount Links are short-lived URLs that redirect connected account holders to Stripe-hosted onboarding or management pages. Write access lets you create account links. See Account Links.
ConnectApplication Feesapplication_fee_read application_fee_writeApplication Fees are charges collected by platforms on payments made through connected accounts. Read access lets you list and retrieve fee details. Write access lets you create refunds on application fees. See Application Fees.
ConnectCapital Financing Offerscapital_for_platforms_financing_offer_read capital_for_platforms_financing_offer_writeFinancing Offers are Capital loan offers extended to connected accounts. Read access lets you list and retrieve offers. Write access lets you manage offer configurations. See Capital Financing Offers.
ConnectCapital Financing Summariescapital_for_platforms_financing_summary_readFinancing Summaries provide an overview of a connected account's active financing, including outstanding balance and repayment progress. Read access lets you retrieve summaries. See Capital Financing Summaries.
ConnectCapital Financing Transactionscapital_for_platforms_financing_transaction_readFinancing Transactions record individual repayments and disbursements related to Capital financing. Read access lets you list and retrieve transactions. See Capital Financing Transactions.
ConnectLogin Linksedit_link_writeLogin Links generate single-use URLs for connected account holders to access their Express dashboard. Write access lets you create login links. See Login Links.
ConnectTop-Upstop_up_read top_up_writeTop-ups add funds to your Stripe balance from a bank account. Read access lets you list and retrieve top-ups. Write access lets you create and cancel top-ups. See Top-Ups.
ConnectTransferstransfer_read transfer_writeTransfers move funds from your Stripe account to a connected account. Read access lets you list and retrieve transfer details. Write access lets you create, update, cancel, and reverse transfers. See Transfers.
CoreAccountsconnected_account_readAccounts represent Stripe accounts or connected accounts on your platform. Read access lets you retrieve account details and settings. Write access lets you update account information. See Accounts.
CoreApple Pay Domainsapple_pay_domain_read apple_pay_domain_writeApple Pay Domains are web domains registered for Apple Pay. Read access lets you list registered domains. Write access lets you register and delete domains. See Apple Pay Domains.
CoreBalancebalance_readBalance represents the current funds available in your Stripe account. Read access lets you retrieve your current balance and pending amounts. See Balance.
CoreBalance Transaction Sourcesbalance_transaction_source_readBalance Transaction Sources are the underlying objects (Charges, Refunds, and Transfers) that create Balance Transactions. Read access lets you expand the source attribute when retrieving Balance Transactions. This also implies Application Fees (Read), Balance (Read), Financing Transactions (Read), Payouts (Read), Transfers (Read), and Balance Transfers (Read). See Balance Transaction Sources.
CoreCharges and Refundscharge_read charge_writeCharges represent completed or attempted payments, and Refunds return funds to a customer. Read access lets you list and retrieve charges and refunds. Write access lets you create, update, capture, and redact charges, and create, update, and cancel refunds. See Charges and Refunds.
CoreClient Confirmation Tokensconfirmation_token_client_read confirmation_token_client_writeClient Confirmation Tokens enable creating and reading tokens from the client during checkout flows. Write access lets you create tokens from the client side. See Client Confirmation Tokens.
CoreConfirmation Tokensconfirmation_token_readConfirmation Tokens securely pass payment details from the client to your server for confirming payments. Read access lets you retrieve token details server-side. See Confirmation Tokens.
CoreCustomer Sessionscustomer_session_read customer_session_writeCustomer Sessions enable authenticated customer interactions with embedded components. Read access lets you retrieve session details. Write access lets you create sessions. See Customer Sessions.
CoreCustomerscustomer_read customer_writeCustomers store payment methods and transaction history for repeat buyers. Read access lets you list and retrieve customer details. Write access lets you create, update, and delete customers. See Customers.
CoreEventsevent_readEvents represent changes to Stripe objects, delivered via webhooks. Read access lets you list and retrieve all event types. See Events.
CoreFee Domain Resourcesfee_domain_resources_readFee Domain Resources provide access to fee-related APIs for pricing and fee structures. Read access lets you retrieve fee details.
CoreFilesfile_read file_writeFiles are documents uploaded to Stripe, such as dispute evidence or identity documents. Read access lets you list and retrieve files and file links. Write access lets you upload files and create, update, and expire file links. See Files.
CoreMandatesmandate_read mandate_writeMandates are authorization records from customers approving future debits to their payment method (for example, for direct debit). Read access lets you retrieve mandate details and status. Write access enables creating mandates when confirming payments with debit payment methods like the related setting and Bacs Direct Debit. See Mandates.
CorePayment Disputesdispute_read dispute_writePayment Disputes occur when a customer questions a payment with their bank. Read access lets you list and retrieve disputes. Write access lets you update, close, and escalate disputes and submit evidence. See Payment Disputes.
CorePayment Intentspayment_intent_read payment_intent_writePayment Intents track a payment from creation through confirmation and capture. Read access lets you list and retrieve Payment Intents and their events. Write access lets you create, update, confirm, capture, cancel, redact, increment authorizations, decrement authorizations, and reauthorize Payment Intents. See Payment Intents. If you're managing PaymentIntents with Stripe.js Elements, you must also request elements_write.
CorePayment Linkspayment_links_read payment_links_writePayment Links are shareable URLs that take customers to a hosted payment page. Read access lets you retrieve and list payment links and their line items. Write access lets you create and update payment links. See Payment Links.
CorePayment Method Configurationspayment_method_configurations_read payment_method_configurations_writePayment Method Configurations control which payment methods are available for checkout experiences. Read access lets you list and retrieve configurations. Write access lets you create and update payment method configurations. See Payment Method Configurations.
CorePayment Method Domainspayment_method_domain_read payment_method_domain_writePayment Method Domains are web domains registered for wallet-based payment methods like Apple Pay and Link. Read access lets you list and retrieve registered domains. Write access lets you register new domains and validate their status. See Payment Method Domains.
CorePayment Methodspayment_method_read payment_method_writePayment Methods represent a customer's payment instrument (cards, bank accounts, wallets). Read access lets you list and retrieve payment method details. Write access lets you create, update, attach, and detach payment methods. See Payment Methods.
CorePayment Recordspayment_records_read payment_records_writePayment Records capture payment attempt data reported outside of Stripe. Read access lets you list and retrieve payment records. Write access lets you create and report payment attempts. See Payment Records.
CorePayoutspayout_read payout_writePayouts move funds from your Stripe balance to your bank account or debit card. Read access lets you list and retrieve payout details. Write access lets you create, update, cancel, and reverse payouts. See Payouts.
CoreProductsproduct_read product_writeProducts represent goods or services you sell. Read access lets you list and retrieve product details. Write access lets you create, update, and delete products. See Products.
CoreSetup Intentssetup_intent_read setup_intent_writeSetup Intents guide the process of saving a customer's payment method for future use without charging them. Read access lets you list and retrieve Setup Intents and setup attempts. Write access lets you create, update, confirm, cancel, and redact Setup Intents. See Setup Intents. If you're managing SetupIntents with Stripe.js Elements, you must also request elements_write.
CoreShipping Ratesshipping_rate_read shipping_rate_writeShipping Rates define delivery costs that can be applied to checkout sessions and orders. Read access lets you list and retrieve rates. Write access lets you create and update shipping rates. See Shipping Rates.
CoreSourcessource_read source_writeSources represent payment methods created via the legacy Sources API. Read access lets you retrieve source details. Write access lets you create and update sources. See Sources.
CoreTokenstoken_read token_writeTokens securely transmit sensitive card or bank account details from the client to your server. Read access lets you retrieve token details. Write access lets you create tokens. See Tokens.
IssuingIssuing Authorizationsissuing_authorization_read issuing_authorization_writeIssuing Authorizations represent pending card transactions that may be approved or declined. Read access lets you list and retrieve authorizations. Write access lets you approve or decline pending authorizations. See Issuing Authorizations.
IssuingIssuing Cardholdersissuing_cardholder_read issuing_cardholder_writeIssuing Cardholders represent individuals authorized to use issued cards. Read access lets you list and retrieve cardholder details. Write access lets you create and update cardholders. See Issuing Cardholders.
IssuingIssuing Cardsissuing_card_read issuing_card_writeIssuing Cards are virtual or physical payment cards you create and manage. Read access lets you list cards and view their details. Write access lets you create, update, and deactivate cards. See Issuing Cards.
IssuingIssuing Credit Ledgerissuing_credit_ledger_read issuing_credit_ledger_writeIssuing Credit Ledger tracks credit balances, entries, and adjustments for Issuing credit programs. Read access lets you view ledger entries and summaries. Write access lets you create adjustments.
IssuingIssuing Dashboardissuing_read issuing_writeIssuing Dashboard provides the full set of Issuing permissions scoped to the dashboard interface. Read access lets you view all Issuing resources. Write access lets you manage them. See Issuing Dashboard.
IssuingIssuing Disputesissuing_dispute_read issuing_dispute_writeIssuing Disputes represent chargebacks filed on transactions made with your issued cards. Read access lets you list and retrieve disputes. Write access lets you create and submit disputes. See Issuing Disputes.
IssuingIssuing Token Network Dataissuing_token_network_data_readIssuing Token Network Data provides network-level details about provisioned tokens, including device and wallet information. Read access lets you retrieve network-specific token data. See Issuing Token Network Data.
IssuingIssuing Tokensissuing_token_read issuing_token_writeIssuing Tokens represent network tokens (device tokens for Apple Pay and Google Pay) provisioned for issued cards. Read access lets you list and retrieve tokens. Write access lets you manage token lifecycle. See Issuing Tokens.
IssuingIssuing Transactionsissuing_transaction_read issuing_transaction_writeIssuing Transactions represent completed purchases made with issued cards. Read access lets you list and retrieve transaction details. Write access lets you update transaction metadata. See Issuing Transactions.
IssuingIssuing Verificationsissuing_verification_writeIssuing Verifications request one-time verification codes for issued cards. Write access lets you create verification requests that send a code to the cardholder.
Money ManagementMoney Management Payout Intentspayout_intent_readMoney Management Payout Intents schedule or immediately execute outbound payments. Read access lets you list and retrieve payout intents. Write access lets you create and cancel payout intents. See Money Management Payout Intents.
Money ManagementMoney Management Recipient Verificationsrecipient_verification_readMoney Management Recipient Verifications confirm the identity and bank details of payment recipients. Read access lets you view verification status. Write access lets you initiate verifications.
OrdersOrdersorder_read order_writeOrders represent purchases of products through the legacy Orders API. Read access lets you retrieve order details. Write access lets you create and manage orders.
OrdersTerminal SKUssku_read sku_writeTerminal SKUs represent hardware product variants available for purchase. Read access lets you list available SKUs and their details. Write access lets you manage SKU configurations. See Terminal SKUs.
ProvisioningProvisioning Account Requestsprovisioning_account_request_read provisioning_account_request_writeProvisioning Account Requests track requests for new Stripe accounts within a provisioning workflow. Read access lets you view request status. Write access lets you create and manage requests.
ProvisioningProvisioning Projectsprovisioning_project_read provisioning_project_writeProvisioning Projects organize groups of account requests and their configurations. Read access lets you view project details. Write access lets you create and manage projects.
ProvisioningProvisioning Resourcesprovisioning_resource_read provisioning_resource_writeProvisioning Resources are account components allocated through the provisioning workflow. Read access lets you view resource details. Write access lets you manage resources.
RadarReviewsreview_read review_writeReviews are flagged payments requiring human evaluation before approval. Read access lets you list and retrieve reviews. Write access lets you approve or reject flagged payments. See Reviews.
ReportingFinancial Reportsreport_runs_and_report_types_readFinancial Reports provide automated reporting data. Read access lets you list report types and retrieve generated reports. Write access lets you create report runs. See Financial Reports.
Stripe AppsSecretssecret_read secret_writeSecrets provide secure storage for sensitive values used by Stripe Apps. Read access lets you retrieve secrets your app has stored. Write access lets you create and update secrets. See Secrets.
Stripe AppsUser Emailuser_email_readUser Email provides access to email addresses of team members on your Stripe account. Read access lets you retrieve user email addresses.
TaxTax Calculations, Transactionstax_calculations_and_transactions_read tax_calculations_and_transactions_writeTax Calculations and Transactions represent computed tax amounts and recorded tax events. Read access lets you retrieve calculations and transactions. Write access lets you create calculations and record transactions. See Tax Calculations, Transactions.
TaxTax Locationstax_locations_read tax_locations_writeTax Locations represent physical locations used for tax calculation purposes. Read access lets you list and retrieve locations. Write access lets you create and manage tax locations. See Tax Locations.
TaxTax Settings, Registrationstax_settings_read tax_settings_writeTax Settings and Registrations configure how Stripe Tax calculates and collects taxes for your account. Read access lets you view settings and registrations. Write access lets you update configurations. See Tax Settings, Registrations.
TerminalTerminal Configurationsterminal_configuration_read terminal_configuration_writeTerminal Configurations define device behavior like tipping, receipts, and offline settings. Read access lets you list and retrieve configurations. Write access lets you create and update configurations. See Terminal Configurations.
TerminalTerminal Connection Tokensterminal_connection_token_writeTerminal Connection Tokens authenticate your POS application's connection to a Terminal reader. Write access lets you create connection tokens. See Terminal Connection Tokens.
TerminalTerminal Locationsterminal_location_read terminal_location_writeTerminal Locations represent physical addresses where Terminal readers are deployed. Read access lets you list and retrieve locations. Write access lets you create, update, and delete locations. See Terminal Locations.
TerminalTerminal Readersterminal_reader_read terminal_reader_writeTerminal Readers are physical devices for accepting in-person payments. Read access lets you list readers and view their status. Write access lets you register, update, and delete readers. See Terminal Readers.
TreasuryTreasury Transactionstreasury_transaction_readTreasury Transactions record all money movements within a Treasury financial account. Read access lets you list and retrieve transaction details. See Treasury Transactions.
Webhook EndpointsWebhook Endpoints, Event Destinationswebhook_read webhook_writeWebhook Endpoints and Event Destinations receive real-time notifications from Stripe APIs. This is a sensitive permission because it allows subscribing to events across your entire account. Read access lets you list endpoints. Write access lets you create and manage destinations. See Webhook Endpoints, Event Destinations. For most apps, you don't need to include webhook_write. Instead, set up a webhook to listen to events from your connected accounts. If you still need webhook_write, contact Stripe Support.

Event permissions

For each Event your app subscribes to, it must request at least one of the corresponding permissions.

Loading...

See also

Last verified 2026-09-24

Is this helpful?