Stripe
Connecting your own Stripe account gives big a read-only view of your sales: your customers, their payments and their subscriptions.
This is separate from anything else in big that involves Stripe. It has nothing to do with how you pay for your big plan, and it doesn't take payments. It only reads the Stripe account you connect.
Use a restricted key, never a secret key
Stripe's standard secret key (it starts sk_live_) can do everything in your Stripe account, including refunds and payouts. big refuses a secret key. Connecting one is rejected before anything is saved.
Instead, create a restricted key (it starts rk_live_) that can only read what big needs:
| Resource | Permission |
|---|---|
| Customers | Read |
| Charges | Read |
| Subscriptions | Read |
| Everything else | None |
Leave every other resource at None. A restricted key like this can't create, change or refund anything, and it can't see anything outside those three resources.
Create the restricted key
- Sign in to Stripe with a user allowed to manage API keys.
- In Stripe Dashboard → Developers → API keys → Create restricted key.
- Name it, for example "big", and set Customers, Charges and Subscriptions to Read. Leave everything else at None. Stripe's own documentation at docs.stripe.com has the current steps if the screens have moved.
- Create the key and copy it.
Connect it in big
Open Connect → Integrations → Browse catalog, choose Stripe, paste the restricted key and save. big tests it with one read-only call and shows the Stripe account once it is connected. The full walkthrough, including rotating and disconnecting, is Connect an integration.
In big, the key shows as its last 4 characters and a fingerprint, like every integration key. See Integration security.
When you rotate or disconnect
big can't revoke a Stripe key. After rotating or disconnecting in big, open Developers → API keys in Stripe and delete, or roll, the old restricted key.