# Add Stripe Keys to Config

**URL:** <https://discourse.sst.dev/t/add-stripe-keys-to-config/185>\
**Category:** Chapter Comments\
**Created:** [May 9, 2018, 11:22pm UTC](https://discourse.sst.dev/t/add-stripe-keys-to-config/185 "2018-05-09T23:22:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [May 9, 2018, 11:22pm UTC](https://discourse.sst.dev/t/add-stripe-keys-to-config/185/1 "2018-05-09T23:22:37Z")

</div>

Link to chapter - [https://serverless-stack.com/chapters/add-stripe-keys-to-config.html](https://serverless-stack.com/chapters/add-stripe-keys-to-config.html)

---

<div class="post-metadata">

**Author:** ![sincerelygeorge](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/sincerelygeorge/32/888_2.png) [@sincerelygeorge](https://discourse.sst.dev/u/sincerelygeorge)\
**Post date:** [May 28, 2020, 3:05am UTC](https://discourse.sst.dev/t/add-stripe-keys-to-config/185/2 "2020-05-28T03:05:41Z")

</div>

A comment regarding this chapter if people are having problems.

Make sure you include the “” around your Stripe key. A friend of mine said he had issues getting this part working, and it was because he didn’t have the quotes (“key”)

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [May 31, 2020, 8:18pm UTC](https://discourse.sst.dev/t/add-stripe-keys-to-config/185/3 "2020-05-31T20:18:28Z")

</div>

Yup! Thanks for sharing!

---

<div class="post-metadata">

**Author:** ![romaad](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/romaad/32/898_2.png) [@romaad](https://discourse.sst.dev/u/romaad)\
**Post date:** [June 13, 2020, 9:27pm UTC](https://discourse.sst.dev/t/add-stripe-keys-to-config/185/4 "2020-06-13T21:27:37Z")

</div>

why include strip in html and not use the object provided in react-stripe ?

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [June 13, 2020, 10:38pm UTC](https://discourse.sst.dev/t/add-stripe-keys-to-config/185/5 "2020-06-13T22:38:01Z")

</div>

There are two separate things to load here. The Stripe Elements and Strip.js. For Stripe.js you can either do it directly through the HTML. Or you can use:

```auto
import {loadStripe} from '@stripe/stripe-js';

const stripePromise = loadStripe('pk_test_ABCDEFGHI');

```

The HTML way is just simpler.

---

<div class="post-metadata">

**Author:** ![romaad](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/romaad/32/898_2.png) [@romaad](https://discourse.sst.dev/u/romaad)\
**Post date:** [June 15, 2020, 8:37pm UTC](https://discourse.sst.dev/t/add-stripe-keys-to-config/185/6 "2020-06-15T20:37:31Z")

</div>

I went through using the library and I have a class for that working if you need it.  
the thing is from security perspective, I don’t think it’s safe to load data from browser, imagine an attacker altering this js link that you use and provide their own library that steals client info. I know this can’t happen because of https but still isn’t a very smart thing to do. or that’s what I think

---

<div class="post-metadata">

**Author:** ![jayair](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sst.dev/jayair/32/9_2.png) [@jayair](https://discourse.sst.dev/u/jayair)\
**Post date:** [July 2, 2020, 8:42pm UTC](https://discourse.sst.dev/t/add-stripe-keys-to-config/185/7 "2020-07-02T20:42:33Z")

</div>

Hmmm there must be a misunderstanding here because both those ways load data from your browser. In one case it uses an external script. While in the `import` case it builds the script when you build your app.
