Skip to content
CAI
Software that uses CAICheck a score

stripe/stripe-php

60.5

Adequate · 19 September 2026

38.5k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the official Stripe PHP SDK, providing a comprehensive library for interacting with the Stripe payment platform. It supports both the legacy v1 API and the modern v2 API, offering typed resources and service classes for payments, billing, identity verification, issuing, treasury, and financial connections. The library includes infrastructure for handling webhooks, OAuth flows, and test-mode simulation, along with an extensible HTTP client and robust error handling.

How it got here

2011–2017 — Stripe API v2 migration and infrastructure overhaul

13 changes.

This period focused on modernizing the Stripe PHP library to support the V2 API, introducing a new extensible HTTP client architecture with HTTP/2 and streaming capabilities. The work included a comprehensive rewrite of utility classes, the implementation of V2 webhook event handling infrastructure, and the expansion of the test suite to cover these new features and core resources.

2018–2020 — Service layer expansion and API v2 preparation

15 changes.

This period focused on expanding the SDK's coverage by adding generated resource and service classes for new APIs including Issuing, Terminal, Radar, Checkout, Billing Portal, and Reporting. Concurrently, the codebase underwent significant architectural refactoring, extracting API operations into shared traits and introducing a new service layer with factory patterns. These changes also modernized the exception hierarchy and implemented API version-aware parameter handling to support upcoming v2 semantics.

2021–2023 — New API resource and service generation

12 changes.

This period focused on expanding the library's coverage by generating PHP resource and service classes for several new Stripe APIs, including Identity, Financial Connections, Treasury, Tax, and Apps. It also enhanced test capabilities by adding comprehensive test helper services for Issuing, Test Clocks, and other test-mode operations.

2024–2025 — Stripe API v2 SDK implementation

5 changes.

This period focused on implementing comprehensive support for the Stripe API v2 by introducing strongly typed event classes, service layers, and resource models. The work established foundational infrastructure for Billing, Commerce, and Core namespaces, including new collection handling and event notification parsing to improve type safety and developer experience.

Features

Add support for Reporting resources

Added new \ReportRun\ and \ReportType\ classes in the \lib/Reporting\ namespace, enabling users to interact with Stripe's Reporting API. The \ReportType\ resource allows listing and retrieving available report definitions (such as balance summaries), while \ReportRun\ supports creating new report executions, retrieving their status, and listing past runs.

lib/Reporting · high confidence

Add support for ScheduledQueryRun API resource

Users can now interact with Sigma scheduled query runs via the new \ScheduledQueryRun\ class. This addition provides \all\ and \retrieve\ methods to list and fetch details of scheduled query executions, allowing you to programmatically access query results and status information directly from the SDK.

lib/Sigma · high confidence

Added Billing Portal service classes for managing configurations and sessions

The library now includes generated service classes for the Billing Portal API, allowing users to manage customer portal configurations and sessions. Specifically, \ConfigurationService\ provides methods to list, create, retrieve, and update portal configurations (including features like customer updates, subscription management, and billing history), while \SessionService\ enables the creation of portal sessions for customer self-service. These classes are wired through a new \BillingPortalServiceFactory\ that maps API resource names to their respective service implementations.

lib/Service/BillingPortal · high confidence

Added Financial Connections service classes for Accounts, Sessions, and Transactions

New service classes have been generated for the Financial Connections API, enabling developers to manage connected bank accounts and data. The AccountService provides methods to list accounts, retrieve details, disconnect access, and subscribe or unsubscribe to periodic data refreshes. The SessionService allows creating and retrieving authorization sessions to launch the Financial Connections flow via Stripe.js. The TransactionService enables listing and retrieving individual transaction records. A corresponding service factory has also been added to wire these services together.

lib/Service/FinancialConnections · high confidence

Added Reporting API service classes

New service classes have been added to interact with the Stripe Reporting API. Users can now access report runs via \ReportRunService\ (supporting listing, creating, and retrieving runs) and report types via \ReportTypeService\ (supporting listing and retrieving types). These services are exposed through the \ReportingServiceFactory\, allowing access to \$stripe-\>reporting-\>reportRuns\ and \$stripe-\>reporting-\>reportTypes\.

lib/Service/Reporting · high confidence

Added TestClock resource for deterministic test time control

A new \TestClock\ resource has been added to the \lib/TestHelpers\ namespace, enabling developers to create and manage test clocks that freeze time for test mode objects. This allows for deterministic testing by creating objects at a specific past or future time and advancing the clock to observe state changes and webhooks. The resource supports standard CRUD operations (\create\, \retrieve\, \all\, \delete\) and includes a specific \advance\ method to move the clock forward to a target frozen time.

lib/TestHelpers · high confidence

Added V2 Billing meter event resources

The library now includes new API resource classes for usage-based billing in the V2 API: \MeterEvent\ for recording billable activity, \MeterEventAdjustment\ for canceling or modifying previously recorded events, and \MeterEventSession\ for obtaining temporary authentication tokens for high-throughput event submission. These classes extend \ApiResource\ and define the specific object types and properties required for tracking and managing usage data.

lib/V2/Billing · high confidence

Added V2 Collection and DeletedObject classes

Introduced new classes in the V2 namespace to support the updated API structure. The Collection class provides paginated iteration capabilities, including forward and reverse iteration, as well as automatic paging across all pages for V2 list endpoints. The DeletedObject class represents the response structure for deleted objects in the V2 API.

lib/V2 · high confidence

Added V2 service classes for Billing, Commerce, and Core API resources

The library now includes generated service classes for the Stripe API v2, enabling access to new capabilities in the Billing, Commerce, and Core namespaces. In Billing, you can now manage meter events and adjustments via \MeterEventService\, \MeterEventAdjustmentService\, and related session/stream services. Commerce support includes \ProductCatalogImportService\ for managing product catalog imports. Core services provide new endpoints for managing Accounts (\AccountService\), Account Links (\AccountLinkService\), Account Tokens (\AccountTokenService\), and Event Destinations (\EventDestinationService\), along with nested services for managing Persons associated with accounts.

lib/Service/V2 · high confidence

Added strongly typed V2 event classes and notifications

The SDK now includes specific, strongly-typed classes for V2 events and their corresponding notifications (e.g., \V2CoreAccountCreatedEvent\, \V2CommerceProductCatalogImportsFailedEventNotification\). These classes extend the new \V2/Core\ base types and provide type-safe access to event data and related objects, replacing the previous generic handling. This allows developers to handle specific event types with precise properties and methods, such as \fetchRelatedObject()\, improving code reliability and developer experience when working with the V2 API.

lib/Events · high confidence

Initial project scaffolding and configuration files

The repository is initialized with essential configuration and documentation files, including \.editorconfig\ for consistent code formatting, \.gitattributes\ and \.gitignore\ for version control hygiene, and \.php-cs-fixer.php\ to enforce PSR-2 and PhpCsFixer coding standards. It also includes a \Makefile\ for build automation, \CODE\_OF\_CONDUCT.md\ and \CONTRING.md\ for community guidelines, and version tracking files (\CODEGEN\_VERSION\, \OPENAPI\_VERSION\) to manage the state of the code generator and OpenAPI specification.

(repo-wide) · high confidence

Introduce Financial Connections API resource classes

Added new PHP resource classes for the Financial Connections API, including Account, AccountOwner, AccountOwnership, Authorization, Session, and Transaction. These classes provide structured access to financial account data, enabling users to manage account connections, retrieve owner details, handle authorizations, and track transactions through dedicated methods like create, retrieve, all, disconnect, and refresh.

lib/FinancialConnections · high confidence

Introduce V2 webhook event handling infrastructure

The library adds a new \AbstractEventNotificationHandler\ class in the \lib\ directory to support the V2 webhook event model. This abstract base class provides shared registration and dispatch machinery for handling Stripe V2 events, including methods to register specific event type handlers, define fallback callbacks for unhandled events, and register pre-handle hooks. It manages client configuration extraction to create context-aware client instances for each event, ensuring that event handling operates with the correct Stripe account and version context. This infrastructure enables developers to build strongly-typed handlers for V2 events, such as \v1.billing.meter.error\_report\_triggered\ and \v2.commerce.product\_catalog.imports.failed\, which are now exposed as specific registration methods on the handler.

lib · high confidence

Introduces extensible HTTP client architecture with streaming and HTTP/2 support

The library now exposes an extensible HTTP client layer via the new \ClientInterface\ and \StreamingClientInterface\, allowing users to replace the default cURL implementation with custom clients. The default \CurlClient\ has been updated to support HTTP/2 (enabled by default where cURL permits), persistent connections, and configurable default cURL options. Additionally, users can now monitor request status via a callback and utilize streaming responses for large payloads, while the client automatically handles network retries and respects server retry headers.

lib/HttpClient · high confidence

Major library overhaul with new v2 API support and utility classes

The \lib/Util\ directory has been completely rewritten to support the new Stripe API v2, introducing several new utility classes and updating existing ones. Key additions include \AgentPluginHint\ for Claude Code integration, \ApiVersion\ defining the current API version as '2026-08-26.dahlia', \CaseInsensitiveArray\ for HTTP header handling, \DefaultLogger\ and \LoggerInterface\ for PSR-3 compatible logging, \EventNotificationTypes\ and \EventTypes\ for v2 event mapping, \Int64\ for handling v2's int64 string encoding, \ObjectTypes\ for v1 and v2 object mapping, \RandomGenerator\ for UUID generation, \RequestOptions\ for request configuration, \Set\ for unique element collections, and \Util\ for core utility functions like UTF-8 encoding and secure comparison. The \Util\ class now supports v2 API mode and v2 deleted objects.

lib/Util · high confidence

New Checkout Session resource with comprehensive API support

The \lib/Checkout/Session.php\ class has been added to the \Stripe\\Checkout\ namespace, providing a dedicated resource for managing Checkout Sessions. This change introduces full support for creating, retrieving, and listing Checkout Sessions, along with extensive property definitions covering payment modes (payment, setup, subscription), UI modes (hosted, embedded, elements), and detailed configuration options for payment methods, shipping, taxes, and custom fields. It also includes constants for session statuses, submit types, and other enum values, enabling developers to build and manage modern checkout flows with precise control over the customer experience.

lib/Checkout · high confidence

New Configuration and Session resources for the Billing Portal

The Billing Portal library now includes generated classes for \Configuration\ and \Session\. The \Configuration\ class allows you to create, retrieve, update, and list portal configurations that define the functionality and behavior of the customer portal. The \Session\ class enables the creation of short-lived portal sessions, providing a URL that customers can use to manage their subscriptions and billing details.

lib/BillingPortal · high confidence

New Identity VerificationSession and VerificationReport resources

Added \VerificationSession\ and \VerificationReport\ classes in the \lib/Identity\ namespace, enabling developers to programmatically manage user identity verification flows. \VerificationSession\ supports creating, listing, retrieving, updating, canceling, and redacting sessions, while \VerificationReport\ allows listing and retrieving the results of verification checks such as document, ID number, email, phone, and selfie validations.

lib/Identity · high confidence

New Identity verification services for managing verification sessions and reports

Added new service classes in the Identity namespace to interact with Stripe's Identity API. The \IdentityServiceFactory\ now exposes \verificationReports\ and \verificationSessions\ endpoints. Developers can use \VerificationReportService\ to list and retrieve verification reports, and \VerificationSessionService\ to create, retrieve, update, cancel, and redact verification sessions, enabling programmatic management of user identity verification workflows.

lib/Service/Identity · high confidence

New Issuing resource classes for card lifecycle management

Added generated PHP classes for Issuing resources, including Authorization, Card, CardDetails, Cardholder, Dispute, PersonalizationDesign, PhysicalBundle, and Token. These classes provide the API surface for managing issued cards, authorizations, disputes, and digital wallet tokens, enabling users to create, retrieve, update, and list these resources directly from the SDK.

lib/Issuing · high confidence

New Issuing service classes and factory for managing cards, authorizations, and disputes

The lib/Service/Issuing directory now contains dedicated service classes (AuthorizationService, CardService, CardholderService, DisputeService, PersonalizationDesignService, PhysicalBundleService, TokenService, TransactionService) and an IssuingServiceFactory. These generated classes provide methods to list, create, retrieve, update, and submit Issuing resources (such as authorizations, cards, cardholders, disputes, tokens, and transactions) via the Stripe API, enabling developers to manage virtual and physical card programs directly from the SDK.

lib/Service/Issuing · high confidence

New Radar API resources for fraud management and value lists

The library now includes generated classes for four new Radar API resources: \EarlyFraudWarning\ (to retrieve and list early fraud warnings), \PaymentEvaluation\ (to request fraud risk scores for externally processed payments), \ValueList\ (to create, update, and delete lists of values used in Radar rules), and \ValueListItem\ (to manage individual items within those lists). These additions enable developers to integrate Stripe's advanced fraud detection and custom rule list management directly into their applications.

lib/Radar · high confidence

New Secret Store API for Stripe Apps

Stripe Apps developers can now securely persist secrets for use by UI Extensions and app backends using the new Secret Store API. The \lib/Apps/Secret.php\ resource introduces methods to create, list, find, and delete secrets, which are scoped to either the account or specific users to control access permissions.

lib/Apps · high confidence

New Stripe Tax API resource classes for PHP

The library now includes generated PHP classes for the Stripe Tax API, adding \Association\, \Calculation\, \CalculationLineItem\, \Registration\, \Settings\, \Transaction\, and \TransactionLineItem\ to the \Stripe\\Tax\ namespace. These classes provide the specific methods and object shapes required to interact with the Tax API, such as calculating tax, managing registrations, and recording transactions.

lib/Tax · high confidence

New Stripe Treasury API resource classes for financial accounts and money movement

The \lib/Treasury\ directory now includes generated PHP resource classes for the Stripe Treasury API, enabling platform developers to manage financial accounts and move money. New classes include \FinancialAccount\ (with methods to create, update, list, close, and manage features), \CreditReversal\ and \DebitReversal\ for reversing incoming funds, \InboundTransfer\ for adding funds via ACH debit, \OutboundPayment\ for sending funds to external parties, \OutboundTransfer\ for sending funds to the same entity's accounts, \ReceivedCredit\ and \ReceivedDebit\ for tracking incoming money movements, and \Transaction\ for balance changes. These classes provide standard CRUD operations and specific actions like canceling transfers or retrieving features, all generated from the OpenAPI specification.

lib/Treasury · high confidence

New Tax API service classes for calculations, transactions, and registrations

Added new service classes in the \lib/Service/Tax\ directory to support the Stripe Tax API, including \CalculationService\ for creating and retrieving tax calculations, \TransactionService\ for creating transactions from calculations and handling reversals, \RegistrationService\ for managing tax registrations, \SettingsService\ for merchant tax settings, and \AssociationService\ for finding tax associations. A \TaxServiceFactory\ is also provided to wire these services together, enabling users to interact with the full suite of tax-related resources.

lib/Service/Tax · high confidence

New Terminal resource classes for fleet management and configuration

This change introduces new PHP classes in the \lib/Terminal\ namespace—\Configuration\, \ConnectionToken\, \Location\, \OnboardingLink\, and \Reader\—generated from the OpenAPI specification. These classes provide the API surface for managing terminal fleets, allowing users to create, retrieve, update, and delete locations and reader devices, configure reader settings (such as tipping, offline mode, and splashscreens), generate connection tokens for SDK integration, and create onboarding links for Tap to Pay on iPhone.

lib/Terminal · high confidence

New Test Helpers services for Confirmation Tokens, Customers, Refunds, and Test Clocks

The library now includes generated service classes in the \Stripe\\Service\\TestHelpers\ namespace, enabling developers to interact with Stripe's test-mode-specific APIs. This update adds \ConfirmationTokenService\ for creating test confirmation tokens, \CustomerService\ for funding customer cash balances, \RefundService\ for expiring refunds requiring action, and \TestClockService\ for managing test clocks (creating, listing, retrieving, deleting, and advancing time). A \TestHelpersServiceFactory\ is also provided to wire these services together, allowing access to issuing, terminal, and treasury test helpers.

lib/Service/TestHelpers · high confidence

New Treasury API service classes for financial accounts and reversals

This update adds generated service classes for the Stripe Treasury API, enabling developers to manage financial accounts, credit/debit reversals, and transfers. The new files include \FinancialAccountService\ (with methods to create, close, and update accounts and features), \CreditReversalService\ and \DebitReversalService\ (for reversing received credits and debits), and services for inbound/outbound payments and transfers (\InboundTransferService\, \OutboundPaymentService\, \OutboundTransferService\). It also introduces services for listing and retrieving transactions and transaction entries (\TransactionService\, \TransactionEntryService\), along with \ReceivedCreditService\ and \ReceivedDebitService\ for viewing incoming funds. A \TreasuryServiceFactory\ is provided to wire these services together, allowing access via \$stripe-\>treasury-\>financialAccounts\, etc.

lib/Service/Treasury · high confidence

New V2 Core API resource classes and EventNotification support

This update introduces the initial set of generated resource classes for the V2 Core API, including Account, AccountLink, AccountPerson, AccountPersonToken, AccountToken, Event, and EventDestination, enabling developers to interact with these entities. It also adds the EventNotification base class, which allows parsing of thin event notifications from Event Destinations and provides methods to fetch full event details or related objects, including support for singleton related objects.

lib/V2/Core · high confidence

New examples for event notifications, meter event streaming, and OAuth

The examples directory now includes new demonstration files: EventNotificationHandlerEndpoint.php and EventNotificationWebhookHandler.php show how to process Stripe event notifications (including deduplication via preHandle hooks and handling unverified payloads from cloud providers), MeterEventStream.php demonstrates reporting billing meter events using the v2 billing API, and oauth.php provides a complete OAuth flow for connecting Stripe accounts. Additionally, ExampleTemplate.php and IteratorExample.php are added to guide new example creation and verify iterator type safety, while README.md documents how to run and add examples.

examples · high confidence

New test-mode Issuing services for authorizations, cards, and transactions

Developers can now use the new \Stripe\\Service\\TestHelpers\\Issuing\ service classes to simulate Issuing card lifecycle events in test mode. The \AuthorizationService\ adds methods to create, capture, expire, finalize, increment, reverse, and respond to fraud challenges on test authorizations. The \CardService\ provides helpers to update card shipping status (submit, ship, deliver, fail, return). The \PersonalizationDesignService\ allows activating, deactivating, or rejecting test personalization designs. Finally, the \TransactionService\ enables creating force-capture transactions, unlinked refunds, and standard refunds, giving testers finer control over Issuing transaction scenarios without needing real card network interactions.

lib/Service/TestHelpers/Issuing · high confidence

Removals

Removal of legacy Stripe PHP SDK and bundled CA certificates

The legacy \src/stripe.php\ file (version 1.5.0) and the bundled \src/data/ca-certificates.crt\ have been removed from the source tree. This eliminates the deprecated, single-file PHP SDK and its static CA certificate bundle, which were previously used for Stripe API communication and SSL verification.

src · high confidence

Architecture

Refactor API operations into reusable traits

The API operation methods (create, retrieve, update, delete, all, and save) have been extracted from individual resource classes into a set of shared traits in the \lib/ApiOperations\ directory. This refactoring standardizes how resources interact with the API, ensuring consistent request handling, parameter validation, and response parsing across all resource types while maintaining the same public API surface for users.

lib/ApiOperations · high confidence

Behavioural changes

Modernized exception hierarchy and interfaces

The exception classes in lib/Exception have been restructured to implement a new ExceptionInterface that extends PHP's native Throwable (with a fallback for older PHP versions). The base ApiErrorException now serves as the common abstract parent for API-related errors, while specific exceptions like CardException, InvalidRequestException, and SignatureVerificationException have been updated to align with this new structure, providing clearer type safety and consistent error handling for users.

lib/Exception · high confidence

New service architecture with API version-aware parameter handling

The library introduces a new service layer structure, including \AbstractService\ and \AbstractServiceFactory\, which standardizes how API requests are constructed and executed. A key behavioral change is the introduction of API mode awareness: the \formatParams\ method now distinguishes between v1 and v2 API modes. For v1 requests, null parameter values are converted to empty strings to maintain backward compatibility with form-encoded bodies. For v2 requests, null values are preserved as-is, allowing them to serialize to JSON null, which is the correct mechanism for clearing fields in the v2 API. This ensures that existing integrations continue to work correctly while enabling proper support for the new v2 API semantics.

lib/Service · high confidence

Updated CA certificate bundle

The bundled CA root certificates in data/ca-certificates.crt have been updated to the version from Mozilla as of December 2, 2025. This ensures that SSL/TLS connections verify against the latest set of trusted public Certificate Authorities, including entries such as Entrust, QuoVadis, DigiCert, and SwissSign.

data · high confidence

Test coverage

Added test coverage for Stripe Util components; Added unit tests for Stripe exception classes; Added unit tests for Stripe service layer components; Added unit tests for the CurlClient HTTP client; Expanded PHPUnit test coverage for Stripe PHP SDK resources and client behavior; New test infrastructure for V2 API and PHPUnit compatibility; Removed legacy SimpleTest-based test suite.

Dependencies

Initial composer.json for Stripe PHP Library

The project now includes a composer.json manifest defining the Stripe PHP Library. It sets a minimum PHP version of 7.2.0 and requires the curl, json, and mbstring extensions. Development dependencies include PHPUnit (versions 8.0 or 9.0), PHP-CS-Fixer (version 3.94.0), and PHPStan (version 1.2+). Autoloading is configured via PSR-4 for the Stripe namespace, mapping to the lib/ directory for production and tests/ directories for development.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 61.

Lenses

  • Code Health 93
  • Architecture 99
  • Maturity 57
  • Readiness 75
  • Security 49

Changes since last survey

  • 300 commits — 286 feature/other, 14 fixes

By area

  • (root) — 151 commits
  • lib/Service — 45 commits
  • tests/Stripe — 16 commits
  • lib/ApiRequestor.php — 10 commits
  • .github/workflows — 7 commits
  • (repo) — 6 commits
  • lib/ApiOperations — 5 commits
  • lib/BaseStripeClient.php — 5 commits
  • lib/Events — 5 commits
  • lib/Util — 5 commits
  • .hark/changes — 4 commits
  • lib/Treasury — 4 commits
  • lib/V2 — 4 commits
  • lib/Billing — 3 commits
  • lib/HttpClient — 3 commits
  • lib/Tax — 3 commits
  • .github/pull_request_template.md — 2 commits
  • examples/EventNotificationHandlerEndpoint.php — 2 commits
  • examples/README.md — 2 commits
  • lib/Identity — 2 commits

Notable commits

  • fix: Add justfile, remove coveralls, and fix AUTOLOAD in CI (#1801)
  • fix: Fix 2D array parameter encoding (#2052)
  • fix: Fix \Stripe\Tax\Settings::update (#1647)
  • fix: Fix event handler account scoping (#2151)
  • fix: Fix partner id name (#1703)
  • fix: Fix test
  • fix: Fix v2 timestamp phpdoc type annotations (#2115)
  • fix: Fixed changelog (#1819)
  • fix: Fixed: Change type of metadata and other map parameters to array<K, V> (#1869)
  • fix: Merge pull request #1602 from stripe/richardm-fix-normalizing-non-string-ids
  • fix: Revert "added new example template and instructions on how to create more"
  • fix: Support discriminated unions in the V2 runtime and fix array coercion (#2113)
  • fix: fix type annotations (#2132)
  • fix: minor justfile fixes (#1807)
  • change: Add Changelog section to PR template (#2078)
  • change: Add PR disclaimer to README (#2085)
  • change: Add Stripe-Request-Trigger header (#2024)
  • change: Add TStripeObject to iterator PHPDoc comments (#2093)
  • change: Add TaxIds API (#1650)
  • change: Add .preHandle method to EventNotificationHandler (#2131)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

stripe/stripe-php was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1030d71d0937e51e7951a98fc2b7ee0128b0c71a — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.