UK software developers since 2006 · fixed-price quotes · you own the code01623 650333 · info@dijitul.uk
Free chat

Stripe Integration Developers UK

dijitul developments builds Stripe integrations for UK businesses: card and wallet payments using Payment Intents with Strong Customer Authentication, subscriptions and invoicing with Stripe Billing, verified webhooks, and reconciliation into Xero, QuickBooks or Sage. We build for websites, web apps and bespoke systems. Every project is a fixed-price quote after a free chat.

Updated 2026-10-10 · by the dijitul development team, Mansfield, UK

  • Stripe Payment Intents
  • Stripe Billing
  • Stripe webhooks
  • Stripe Connect
  • Laravel
  • Node.js

Sound familiar?

  • Payments sometimes fail at 3D Secure and you can't see why
  • Orders are marked paid in the browser redirect, so a closed tab means a lost order
  • Customers were charged twice after a timeout
  • Stripe payouts don't match anything in your accounts
  • Subscriptions, upgrades and failed renewals are handled by hand
  • An old Charges API integration needs bringing up to date

Key facts

  • We build on Stripe's Payment Intents API, which requests 3D Secure automatically when Strong Customer Authentication applies
  • UK SCA rules have applied to ecommerce payments since the FCA's deadline of 14 March 2022
  • Webhooks are verified with the Stripe-Signature header (HMAC-SHA256, 5-minute default tolerance)
  • Stripe retries undelivered live-mode webhooks for up to three days and doesn't guarantee event order, so our handlers are order-independent
  • Every create request carries an Idempotency-Key so a retry never charges twice
  • Payments, fees and payouts post to your accounts so bank feeds reconcile
  • Fixed-price quote after a free chat

What we build with Stripe

Stripe can be live on a simple website in an afternoon. The work we do is everything around it that makes payments dependable in a real business:

  • One-off payments for ecommerce, bookings and deposits, using Payment Intents with the Payment Element or Stripe Checkout.
  • Subscriptions and recurring billing with Stripe Billing: plans, trials, upgrades with proration, metered usage and automatic retries for failed cards.
  • Saved cards and later charges using Setup Intents, for no-show fees, usage billing or account top-ups.
  • Bacs Direct Debit through Stripe for UK customers who prefer to pay that way.
  • Marketplaces and platforms using Stripe Connect, where payments are split between you and sellers. See marketplace integration.

We integrate into bespoke systems, web applications, booking systems and customer portals, as well as WooCommerce and other platforms.

Payment Intents and Strong Customer Authentication

Strong Customer Authentication (SCA) comes from the second EU Payment Services Directive and was kept in UK law after Brexit. The FCA set 14 March 2022 as the deadline for full SCA compliance on UK ecommerce. In practice, many card payments need the customer to confirm in their banking app through 3D Secure.

Stripe's Payment Intents API handles this. Our server creates a PaymentIntent for the amount, the browser confirms it with the card details, and if the bank wants authentication, the intent moves to requires_action and Stripe shows the 3D Secure step. We handle each status properly, including the awkward ones: authentication abandoned, card declined after authentication, and payments that are still processing.

For later charges with the customer not present, such as subscriptions or usage billing, we save the card with a Setup Intent while the customer is there and authenticated. That lets later charges be flagged as merchant-initiated, which reduces how often banks ask for authentication again.

Webhooks: the source of truth for payments

The most common Stripe bug we fix is fulfilling orders on the browser redirect after payment. If the customer closes the tab, loses signal or their bank takes a moment, the order is never marked paid. The fix is to treat Stripe's webhooks as the source of truth. Our webhook handlers follow Stripe's own guidance:

  • Verify every event using the Stripe-Signature header and your endpoint's signing secret, using the raw request body. Stripe's libraries reject events older than a five-minute tolerance by default, which blocks replays.
  • Return 2xx quickly, then process the event from a queue, so slow work like posting to Xero never causes a timeout.
  • De-duplicate. Stripe can deliver the same event more than once, so we log processed event IDs and skip repeats.
  • Don't assume order. Stripe doesn't guarantee delivery order, so handlers fetch the current object state rather than trusting the sequence.
  • Survive outages. Stripe retries undelivered live events for up to three days, and we add a reconciliation job that catches anything missed.

On the way out, every create request carries an Idempotency-Key (Stripe accepts keys up to 255 characters on all POST requests), so a network retry can never create a second charge. More on our approach in webhook development.

Getting Stripe into your accounts

Stripe pays out in batches, net of fees, a few days after the payments. If your accounts just mark invoices as paid, the bank deposit matches nothing. We post each payment to a Stripe clearing account, record fees as an expense, and record each payout as a transfer to your bank. The bank feed then matches the payout exactly, and the clearing account balances. We build this for Xero, QuickBooks and Sage.

Security and keys

Stripe secret keys can move money, so we treat them like passwords. Keys live in server environment configuration, never in code or the browser. Where possible we use restricted keys limited to the API resources the integration needs. Webhook signing secrets are rolled periodically; Stripe lets the old secret stay active for up to 24 hours during a roll, so we switch without dropping events. Separate sandbox and live keys mean testing never touches real money.

How we deliver

After a free chat, we scope the payment flows, edge cases and accounting treatment, then give you a fixed-price quote. Everything is built and tested in a Stripe sandbox using Stripe's test cards, including the 3D Secure challenge cards and decline scenarios, before going live. You own the code, and the Stripe account stays in your name. Comparing Stripe with other providers? See payment gateway integration.

What we deliver

  • Checkout using Stripe's Payment Element or Checkout, including Apple Pay and Google Pay
  • Server-side Payment Intent creation with idempotency keys
  • A webhook handler with signature checks, de-duplication and a queue
  • Subscriptions, trials, proration and dunning with Stripe Billing
  • Refunds, disputes and partial captures handled in your admin
  • Accounting sync for payments, fees and payouts

How it works and what it costs

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data.

  1. Free chat

    Tell us the problem in plain English: what you do now, what goes wrong and what "better" looks like. No charge, no obligation.

  2. Scoping

    We map the processes, systems and data involved, agree what is in and out, and write it down so there are no surprises.

  3. Fixed-price quote

    You get a fixed price for the agreed scope, or a phased plan for bigger builds, so you can start small and prove it works.

  4. Build and test

    We build in short stages you can see and try, test against real data, then go live carefully with a rollback plan.

  5. Hand over and look after

    You own the code and the data. We can host it, support it and keep improving it, or hand it to your own team.

Frequently asked questions

Does a Stripe integration handle Strong Customer Authentication?

Yes, if it uses Stripe's Payment Intents API, which dijitul developments builds on. When the customer's bank requires authentication, Stripe triggers 3D Secure and our code handles each outcome. SCA has applied to UK ecommerce payments since the FCA's 14 March 2022 deadline.

Why should orders be confirmed by webhook, not the payment redirect?

Because the redirect depends on the customer's browser. If they close the tab or lose connection, the order isn't recorded. Stripe's webhooks are sent server to server and retried for up to three days if undelivered, so dijitul uses them, verified by signature, as the source of truth for payment status.

Can you stop customers being charged twice?

Yes. dijitul sends an idempotency key with every Stripe create request, so if a request is retried after a timeout Stripe returns the original result instead of creating a second charge. Webhook handlers also record processed event IDs, so a duplicate event never triggers fulfilment twice.

Can you build subscriptions with Stripe?

Yes. dijitul builds subscriptions with Stripe Billing, including trials, plan changes with proration, metered usage, coupons and automatic retries for failed payments. Customers can manage cards and plans through Stripe's customer portal or a portal built into your own application.

Can Stripe payments reconcile in Xero automatically?

Yes. dijitul posts Stripe payments to a clearing account, fees to an expense account and payouts as transfers to your bank account, so each payout matches the bank feed line exactly. The same approach works for QuickBooks and Sage.

We use the old Stripe Charges API. Do we need to upgrade?

If you take payments from UK or European cards, yes, in practice. The older Charges API doesn't handle 3D Secure authentication the way Payment Intents does, which leads to more declines under SCA. dijitul developments can migrate your integration and test it against Stripe's authentication test cards.

Related

Tell us what you need to build

Free chat, clear scope, fixed-price quote. You own everything we build.

Call usFree chat