What you need before connecting Stripe
An Estonian company, including an e-resident's OÜ, can open a Stripe account. To activate it Stripe asks for company details, identity verification of the representative and a bank account for payouts. After that the dashboard shows API keys for test mode and live mode.
- Company details and the representative's ID document
- A bank account for payouts
- A website that makes clear what you sell, with terms and contacts
- A decision on what you need: one-off payments, subscriptions or both
Fees depend on card type and the country of issue. Current pricing is published on Stripe's website.
How a card payment works for the buyer
- The buyer clicks pay and sees Stripe's hosted payment page or a payment form embedded in your site
- They enter card details or choose Apple Pay or Google Pay
- The bank asks for extra confirmation when required (3-D Secure), in Estonia mostly via Smart-ID or the bank's app
- Stripe returns the buyer to your site and sends your server a notification (webhook) that confirms the order
Card details never pass through your server: the buyer types them into Stripe's form. That keeps the security requirements on your side small.
WooCommerce, Shopify and custom builds
On WooCommerce we use the official Stripe plugin: enter the keys, enable the payment methods you need and set up notifications. On Shopify, card payments generally run through the platform's own payment solution, so a separate Stripe integration is usually not built there.
Stripe pays off most in a custom Next.js project: we create the payment on the server, receive notifications on a dedicated endpoint and verify their signature. For subscriptions we add a customer portal where the client changes their card or cancels on their own.
Testing and typical problems
Stripe has a test mode with test cards. We run a successful payment, a declined card, a card that requires extra confirmation and a refund. When going live we swap the keys and register the notification endpoint again, because test and live settings are separate.
- Signature verification fails because the framework alters the request body before the check
- The notification endpoint is registered in test mode only
- The same event arrives more than once and the order is confirmed twice if processing ignores repeats
- A subscription charge fails on an expired card but the user keeps access