Stripe app permissions
This page lists every permission Recoura requests from your Stripe account and their purpose. The list is the same whether you install Recoura from the Stripe App Marketplace or connect from your Recoura dashboard.
No keys or tokens. Stripe attaches these permissions to the app installation itself, so Recoura stores only your Stripe account ID, never a secret key or access token. Card numbers never reach our servers.
Finding failed payments
These permissions let Recoura find failed payments and show your revenue at risk and what's recoverable.
-
Charges
Readcharge_readFinds payments that failed, with the amount, the currency, the reason, and the email tied to each one. Successful payments are only read when needed and are never stored.
-
Invoices
Readinvoice_readFinds unpaid invoices and tracks each one until it's paid, so you can see what's still outstanding.
-
Subscriptions
Readsubscription_readFinds subscriptions whose renewal payment failed, so Recoura can recover the payment and show how much recurring revenue is at risk.
-
Prices
Readplan_readReads what each subscription costs, so Recoura can calculate your recurring revenue and how much of it is at risk.
-
Customers
Readcustomer_readShows who each failed payment belongs to, so you know which customer you're recovering from.
-
Events
Readevent_readAllows Stripe to notify Recoura as things happen in your account, like a payment failing, an invoice being paid, or a subscription changing, so your recovery data stays current.
Payment verification
Before any payment request goes out, Recoura checks that the payment hasn't already been made.
-
Payments
Readpayment_intent_readChecks whether a failed payment has been resolved, for example on one of Stripe's own retries, so a customer is never asked to pay twice. Recoura also uses it to see which card paid a recovered invoice.
Sending a payment request
These permissions let Recoura send your customer an invoice to pay on Stripe's hosted invoice page.
-
Invoices
Writeinvoice_writeCreates, finalizes, and sends the invoice your customer pays. For a failed subscription payment, Recoura uses the invoice Stripe already created. For a failed one-time payment, it creates a new invoice for the same amount.
Limit: Never changes the amount on an invoice, and never voids or deletes one.
-
Customers
Writecustomer_writeCreates a customer record when a failed one-time payment doesn't have one, since Stripe needs a customer to send an invoice to.
Limit: Never edits or deletes your existing customers.
-
Account details
Readconnected_account_readReads your business name to show in recovery emails and to confirm which Stripe account is connected. It also reads your public support email, so customer replies are sent to you.
No email on file
Some failed payments have no email attached, so there's no one to send an invoice to. For those, Recoura creates a Stripe payment link for you to share with the customer yourself.
-
Payment links
Writepayment_links_writeCreates a payment link for the exact amount of the failed payment.
Limit: Never changes or turns off your existing payment links.
-
Products
Writeproduct_writeCreates the one-time product the payment link charges for, named after the original payment.
Limit: Never edits your existing products.
-
Prices
Writeplan_writeCreates the one-time price the payment link charges, matching the amount that failed.
Limit: Never edits your existing prices or subscription plans.
-
Checkout sessions
Readcheckout_session_readSees when your customer pays through the link, so Recoura can mark the failed payment as recovered.
Setting the new payment method
Sets the customer's new card as a default for a failed subscription that has been paid and renewed.
-
Payments
Writepayment_intent_writeMarks the open recovery payment so Stripe saves the card your customer pays with, rather than treating the card as single-use.
Limit: Only changes a payment that's still waiting to be paid. Recoura never creates a payment or charges a card; your customer always pays on Stripe's page.
-
Payment methods
Readpayment_method_readConfirms that the card your customer paid with belongs to them before making it their subscription's default.
-
Subscriptions
Writesubscription_writeOnce your customer pays a recovered subscription invoice, Recoura sets the card they paid with as that subscription's default.
Limit: Only changes the default card on the subscription being recovered. Never cancels, pauses, or reprices a subscription, and never touches your customer's other subscriptions.
What Recoura can't do
Recoura's permissions don't cover any of these, so Stripe won't let it:
- Refund a payment
- Pay out or transfer money from your account
- See your Stripe balance
- See your customers' full card numbers, which Stripe never shares with apps
Recoura never cancels, pauses, or reprices a subscription, and never deletes or voids anything. It never edits your existing customers, products, or prices, and never charges a card itself. Your customers always pay on a page hosted by Stripe.
Questions
Questions about a permission? Email support@recoura.io. For what Recoura stores and how long it keeps it, see our Privacy Policy. Connecting Square instead? Square shows its own list of permissions when you connect, and How connecting your Stripe or Square account works walks through both.