Integration · Paddle

Let your AI agent touch Paddle — safely.

Test refunds and cancellations against a simulated Paddle that fails on purpose. In production, COLVO holds a scoped Paddle API key, applies your limits and checks every result in Paddle.

How it works

Set it up in minutes

  1. Test without a Paddle account. In “Choose scenarios…”, pick Paddle: 12 scenarios run against a simulated Paddle with Paddle-shaped ids (ctm_, sub_, txn_), refunds that wait for review and no idempotency keys.
  2. Connect a scoped API key for production. In Paddle → Developer tools → Authentication: Transactions read, Subscriptions read and write, Adjustments read and write, Customers read. COLVO checks the permissions without creating anything, and refuses a key that can also change products, prices or discounts.
  3. Add the notification destination COLVO shows you, with the adjustment and subscription events. Signatures are verified; refunds made outside COLVO open an incident.
  4. Your agent proposes, COLVO executes. The agent never holds the key. Guard decides ALLOW, REVIEW, HOLD or DENY, creates the refund once and waits for Paddle to approve it before calling it verified.

Actions on Paddle today

refund.create              payment_id (txn_…), amount_minor, currency    → a Paddle refund adjustment
subscription.cancel        subscription_id, mode: period_end | immediate  → next_billing_period | immediately
subscription.pause         subscription_id, resumes_at?                   → pause from the next billing period
subscription.resume        subscription_id
subscription.cancel_undo   subscription_id                                → removes the scheduled cancel

Not yet on Paddle: subscription.change_plan, coupon.apply, refunds by invoice

The agent never holds your payment keys — it proposes, COLVO decides and executes.

What you get

Paddle + COLVO

Refunds wait for Paddle’s review

Paddle approves refunds before paying out. COLVO keeps the operation open, the agent says “requested”, and it turns VERIFIED only when Paddle approves — or opens an incident if Paddle rejects it.

A retry never doubles a refund

Paddle has no idempotency keys. COLVO tags every refund with its operation id and looks for it before any retry, so a lost response can’t become a second refund.

Tax included

Paddle is the merchant of record: limits count what the customer gets back, tax included.

Questions

Paddle FAQ

Does the agent need my Paddle API key?

No — remove it. Only COLVO’s executor uses the key, encrypted per organisation.

Which Paddle permissions?

Transactions read, Subscriptions read and write, Adjustments read and write, Customers read. Nothing else.

Plan changes and discounts?

Not on Paddle yet — they work on Stripe. A mandate on a Paddle connection that lists them is refused.

Paddle Classic?

No — Paddle Billing only (API keys starting with pdl_).

Reference: Mandates & connections · Webhooks

≠

Stop trusting the reply.

Test your agent before it ships — and guard every real action once it’s live. In a safe copy of your world first.

Paddle AI agent testing and guardrails — COLVO · COLVO