--- name: billing description: "Review prices, credits, refunds, and entitlements as server-owned state transitions that preserve an auditable ledger invariant." --- # Billing and credits Review prices, credits, refunds, and entitlements as server-owned state transitions that preserve an auditable ledger invariant. Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question. ## Bring to the review - Pricing and entitlement rules - Payment and ledger state model - Authorized test transactions ## Review guide ### 1. Write the ledger invariant Define the server-authoritative amount, currency, owner, entitlement, and allowed transition for each business event. ### 2. Bind evidence to transition Ensure payment confirmations, webhooks, and refunds are authenticated and tied to one intended state change. ### 3. Protect concurrency Use atomic checks and consumption rules so retries or parallel processing cannot duplicate an entitlement or reversal. ### 4. Reconcile safely Make correction and recovery flows preserve legitimate concurrent changes and create a complete audit record. ## What to produce - Ledger invariant - State-transition map - Reconciliation and audit criteria ## Common mistakes - Trusting client totals - Separating evidence from entitlement creation - Using non-atomic balance updates ## Reading and source context ### Resources - [OWASP Transaction Authorization](https://vulns.co/research/resources/owasp-transaction-authorization-state-integrity/) - [Stripe webhooks: authentic delivery and business-state integrity](https://vulns.co/research/resources/stripe-webhook-delivery-state-integrity/) - [Paymenter: refund entitlement and ledger changes need one atomic transition](https://vulns.co/research/resources/paymenter-2026-refund-transition-atomicity/) ### Diagrams - [Approval stays attached to the reviewed version](https://vulns.co/research/diagrams/approval-version-integrity/) ### Reports - [Cloud Build approval was not bound to immutable code](https://vulns.co/research/reports/google-cloud-build-approval-toctou-2025/) - [GitHub Actions trust depended on invalid repository references](https://vulns.co/research/reports/github-actions-reference-validation-2021/) ## Provenance Editorial guide by vulns.co / GK Data. Updated 2026-10-11. Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3. The guide is an editorial synthesis. Linked records preserve their own sources and review dates. Reader: https://vulns.co/skills/billing/