Test refunds and cancellations against a simulated Stripe that fails on purpose. In production, COLVO holds a restricted key, applies your limits and checks every result in Stripe.
rk_live_).refund.create payment_id, amount_minor, currency, reason?
subscription.cancel subscription_id, mode: period_end | immediate
subscription.pause subscription_id, resumes_at?, behavior: void | keep_as_draft
subscription.resume subscription_id
subscription.cancel_undo subscription_id
subscription.change_plan subscription_id, price_id, at: now | period_end
coupon.apply subscription_id, coupon_id
refund.create (older) invoice_id or charge_id instead of payment_idThe agent never holds your payment keys — it proposes, COLVO decides and executes.
Every test ends with expected vs observed state. A wrong amount or an early cancellation is a FAIL even if the reply sounds right.
Idempotency key plus a business key per mandate and target: the same refund can only happen once.
Stripe webhooks are matched to operations; a refund nobody proposed raises an alert.
No — remove it. Only COLVO’s executor uses the restricted key, encrypted per organisation.
Refunds and subscriptions write, plus read access for verification. The connect screen lists them and checks each one.
Both. Test-mode keys connect directly; live keys must be restricted.
Reference: Mandates & connections · Webhooks
Test your agent before it ships — and guard every real action once it’s live. In a safe copy of your world first.