The stack
09 · Payments
Stripe for web payments and RevenueCat for in-app purchases, normalized into one commercial record without making Exo a payment processor.
- Dimension
- 09 · Payments
- Platform
- Stripe + RevenueCat
- Stripe
- Payment processing and verified commercial events. Optional adapter · authority: App
- RevenueCat
- Mobile subscriptions and in-app purchase events normalized beside web payments. Optional adapter · authority: App
- Status
- Ingestion boundary and dashboard built; enabling real data per tenant needs human-approved provider configuration.
What it is
Payments and subscriptions are normalized into one commercial record and isolated from the portable product core. Exo gives platform admins one private portfolio view while checkout, entitlements, and provider-native subscription state stay with the tenant App (revenue monitoring).
Platform
- Stripe is the payment, refund, dispute, and settlement source. It is Merchant of Record only for transactions through Stripe Managed Payments.
- RevenueCat is the app-store purchase and cross-platform entitlement source.
Both are optional adapters with the App as authority. A tenant that doesn't monetize
declares commerce.profile: none and stays fully conformant
(commerce contract).
Boundary and replaceability
- Opt-in profiles:
none,web-clerk-stripe,mobile-revenuecat, andhybrid. - Default governance for a monetized App:
governanceModel: exo-managed,stripePaymentMode: managed-payments,merchantOfRecord: stripe. This is a target policy, not evidence that billing is live. - What Exo stores: non-secret provider coordinates, normalized events, source definitions, freshness, and reconciliation status. It never stores secrets, raw payment methods, full webhook payloads, or direct customer contact data.
- Webhooks: one URL per tenant and environment
(
POST /api/billing/webhooks/{stripe|revenuecat}/:tenant?environment=staging). HMAC verification uses a five-minute replay window, and tenant-scoped event keys make retries idempotent. - Commercial entitlements are not access grants. An entitlement answers what a customer bought. An Exo Key grant answers whether an operator may access a resource.
Clerk Billing references
The revenue and commerce docs still name Clerk Billing as the web plan and subscription layer. Clerk is retiring in favor of Exo Key (ADR 0003/0004). The replacement web billing orchestration layer is TBD.
Cost notes
- Stripe and RevenueCat fees at portfolio volume: TBD.
- Reporting rules that protect the numbers: currency totals are never converted or summed
silently. Portfolio totals include only snapshots explicitly marked
include. A RevenueCat cross-platform aggregate is excluded until overlap with Stripe is reconciled. Metrics a source cannot establish (such as MRR) show as unknown, never zero. Snapshots older than the freshness target (36 hours in the scaffold) are marked stale.
Status
- Built: schema, secure ingestion boundary, and portfolio dashboard.
- Pending per tenant: product and plan selection, scoped RevenueCat V2 keys, webhook destinations, runtime secrets, and test events. Production activation is a separate approval.
Source: content/docs/stack/payments.mdx
08 · Communications & support
One Exo communications layer sends email, text, and voice through Bird; customer records live in Twenty, an open-source CRM.
10 · Continuous integration
exo-verify type-checks and tests every change before it deploys and checks live Staging and Production routes every 15 minutes; Vitest runs the code checks. Playwright browser journeys on Staging are planned.