TransactKit-Prov1.0.0
TransactKit-Pro architecture
Understand TransactKit-Pro's direct Stripe client boundary, small local projections, managed subscription rules, transactions, and recovery behavior.
Updated
Package-by-feature modules
Each feature follows Controller -> Service -> StripeClient with small immutable application DTOs. There is no generic gateway, custom Stripe HTTP client, manual JSON mapping, retry loop, or webhook cryptography.
Payment foundation
├── checkout
├── customer
├── payment
├── refund
└── webhook
SaaS billing
├── catalog
├── subscription
├── portal
├── invoice
├── entitlement
└── usagePersistence and source of truth
Flyway owns V1-V3 schema changes. Hibernate validates the schema. The SQL supports default H2 MySQL mode and external MySQL.
| Owner | State |
|---|---|
| Stripe | Customers, Products, Prices, Checkout Sessions, PaymentIntents, Refunds, subscription lifecycle, invoices, Tax, Portal, Entitlement associations, Billing Meters, and hosted experiences |
| TransactKit-Pro | Logical Payment, RefundRecord, managed BillingSubscription, rebuildable active Entitlements, and durable WebhookEvent claims |
| Host application | Identity, tenant ownership, authorization, fulfillment, access policy, reconciliation, audit, and deployment operations |
Transactions, idempotency, and recovery
- Payment and subscription Checkout use local UUID plus attempt-reference idempotency keys.
- Refunds use Payment UUID plus refund reference.
- Meter Events use the caller's stable identifier.
- Refund and subscription mutation paths use database locking where implemented.
- Webhook claims, domain writes, and terminal event status use separate short transactions.
- Checkout recovery requires exact local UUID metadata plus a matching business reference.
Intentional limits
- Managed subscriptions contain exactly one Stripe Subscription Item.
- There is no authentication, authorization, tenant model, durable queue, distributed lock, or global reconciliation endpoint.
- Products, Prices, invoices, coupons, promotion codes, Meters, and Tax configuration are not mirrored locally.
- Connect, Terminal, Issuing, Treasury, Identity, Financial Connections, Capital, Crypto, Climate, and custom payment forms are outside scope.