When you ask the assistant to add payments, subscriptions, or a checkout to your app, it now follows a Stripe playbook by default:
- Stripe Checkout over custom card forms. The hosted payment page converts better - Apple Pay, Google Pay, one-click Link, and local payment methods appear automatically - and Stripe's own card-testing defenses stand in front of it. Playcode sells its own plans the same way.
- Fraud protection armed from day one. Stripe.js loads on every page of your site so Stripe Radar can tell real customers from bots, and the assistant reminds you to keep Radar on. An unprotected payment form gets found by card-testing bots within days, and the disputes that follow can get a Stripe account blocked.
- Keys handled safely. Secret keys stay on the server, never in page code. On browser-only projects the assistant uses Payment Links, which need no keys at all.
- Real fulfillment. Purchases unlock through verified Stripe webhooks, not just "the buyer landed on the success page".