Skip to content
savemyMRR
Guide · security

The Stripe restricted key, permission by permission

A restricted key is a Stripe API key limited to the resources you tick. It's the right way to give a third-party tool access: it can do its job and nothing else.

The six permissions SaveMyMRR asks for

ResourceLevelWhy
InvoicesWriteRead failed invoices and retry one with invoices.pay
ChargesReadRead the failed attempts
CustomersReadName and email of the customer to write to
SubscriptionsReadSpot subscriptions Stripe cancelled for non-payment
EventsReadNotice new failures and payments within minutes
PaymentIntentsReadThe decline code of each failed attempt

Nothing else: no payouts, no refunds, no balance, no new charges, no card numbers (Stripe never exposes full card numbers through the API anyway).

Create it with the pre-filled link

Stripe's Dashboard accepts a link that opens the “Create restricted key” form with a name and permissions already set. The scan page has the button: you land on the form, click Create key, confirm with your second factor, copy the key (it starts with rk_live_).

This link isn't a documented Stripe feature; if the form ever opens empty, tick the six resources above by hand.

Where it's stored

SaveMyMRR encrypts the key with AES-256-GCM as soon as it arrives. If you don't buy, the key is erased 14 days after the scan.

Revoking it

In Stripe: Developers → API keys → the key named SaveMyMRR → Delete. Access stops immediately; your dashboard will show the account as disconnected.