Start watching free

Error library · Stripe publishable key missing

Stripe “Invalid API Key provided: pk_…”

The payment form can't connect to Stripe because the app's Stripe key is missing or wrong on the live site. Stripe refuses, so nobody can pay.

Who it affects

Everyone who tries to pay is stopped — 5 sessions so far. This is lost revenue.

Numbers here are from an example app where 5 visitors hit it. How serious: Critical — it stops people using the app, or costs you money.

How to fix it

Give this to the AI that builds your app. It’s the prompt Vigilia writes for this error — shown here for an example app (an orders table, a /checkout page); for your app, Vigilia fills in the real details from what your visitors hit.

For Lovable
Lovable: Bug: Stripe.js fails with "IntegrationError: Invalid API Key provided: pk_live_****1234" on the live site.

Evidence: "IntegrationError: Invalid API Key provided: pk_live_****1234" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Set the Stripe publishable key (pk_live_… for production) in the live site's environment variables — the build is using a missing, test, or mistyped value.
2. Use only the publishable key in the browser. The secret key (sk_…) must never be in front-end code.
3. Redeploy so the new value is built in.

Acceptance criteria: on the live site the payment form loads and a checkout reaches Stripe without key errors.
For Bolt
Bolt: Bug: Stripe.js fails with "IntegrationError: Invalid API Key provided: pk_live_****1234" on the live site.

Evidence: "IntegrationError: Invalid API Key provided: pk_live_****1234" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Set the Stripe publishable key (pk_live_… for production) in the live site's environment variables — the build is using a missing, test, or mistyped value.
2. Use only the publishable key in the browser. The secret key (sk_…) must never be in front-end code.
3. Redeploy so the new value is built in.

Acceptance criteria: on the live site the payment form loads and a checkout reaches Stripe without key errors.
For Cursor
Cursor: Bug: Stripe.js fails with "IntegrationError: Invalid API Key provided: pk_live_****1234" on the live site.

Evidence: "IntegrationError: Invalid API Key provided: pk_live_****1234" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Set the Stripe publishable key (pk_live_… for production) in the live site's environment variables — the build is using a missing, test, or mistyped value.
2. Use only the publishable key in the browser. The secret key (sk_…) must never be in front-end code.
3. Redeploy so the new value is built in.

Acceptance criteria: on the live site the payment form loads and a checkout reaches Stripe without key errors.
For Claude Code
Claude Code: Bug: Stripe.js fails with "IntegrationError: Invalid API Key provided: pk_live_****1234" on the live site.

Evidence: "IntegrationError: Invalid API Key provided: pk_live_****1234" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Set the Stripe publishable key (pk_live_… for production) in the live site's environment variables — the build is using a missing, test, or mistyped value.
2. Use only the publishable key in the browser. The secret key (sk_…) must never be in front-end code.
3. Redeploy so the new value is built in.

Acceptance criteria: on the live site the payment form loads and a checkout reaches Stripe without key errors.
For any other tool
Bug: Stripe.js fails with "IntegrationError: Invalid API Key provided: pk_live_****1234" on the live site.

Evidence: "IntegrationError: Invalid API Key provided: pk_live_****1234" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Set the Stripe publishable key (pk_live_… for production) in the live site's environment variables — the build is using a missing, test, or mistyped value.
2. Use only the publishable key in the browser. The secret key (sk_…) must never be in front-end code.
3. Redeploy so the new value is built in.

Acceptance criteria: on the live site the payment form loads and a checkout reaches Stripe without key errors.

Vigilia catches this automatically

When this happens on your live app, Vigilia recognises it at once — no waiting, no AI credits — tells you who it affects, hands your AI the fix, and confirms it held with real visitors.

More errors, explained