# Stripe Issuing webhook

Source: https://immiscible.fly.dev/docs/api/post-issuing-wid-stripe

`POST /issuing/:wid/stripe`

Real-time authorisation requests (`issuing_authorization.request`), stand-in notices, captures, refunds and closures, signed by Stripe. The answer to an authorisation is always `200` with `approved`. See [the card rail](https://immiscible.fly.dev/docs/guides/card-rail.md).

## Authentication

Issuer signature. No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read. Stripe Issuing's `stripe-signature` header, checked with the webhook secret you saved for the workspace's Stripe issuer.

## Path parameters

- `wid` (string, required): Workspace id

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/issuing/$IMMISCIBLE_WORKSPACE/stripe" \
  -H "stripe-signature: $SIGNATURE"
```

Node:

```ts
// signature: computed over the raw body, see the authentication note above
const res = await fetch('https://immiscible.fly.dev/issuing/$IMMISCIBLE_WORKSPACE/stripe', {
  method: 'POST',
  headers: {
    'stripe-signature': signature,
  },
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import requests

# signature: computed over the raw body, see the authentication note above
res = requests.post(
    "https://immiscible.fly.dev/issuing/$IMMISCIBLE_WORKSPACE/stripe",
    headers={
        "stripe-signature": signature,
    },
)
print(res.status_code, res.json())
```
