{
  "slug": "billing",
  "name": "Billing and credits",
  "category": "Application",
  "summary": "Review prices, credits, refunds, and entitlements as server-owned state transitions that preserve an auditable ledger invariant.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Pricing and entitlement rules",
    "Payment and ledger state model",
    "Authorized test transactions"
  ],
  "review": [
    {
      "title": "Write the ledger invariant",
      "body": "Define the server-authoritative amount, currency, owner, entitlement, and allowed transition for each business event."
    },
    {
      "title": "Bind evidence to transition",
      "body": "Ensure payment confirmations, webhooks, and refunds are authenticated and tied to one intended state change."
    },
    {
      "title": "Protect concurrency",
      "body": "Use atomic checks and consumption rules so retries or parallel processing cannot duplicate an entitlement or reversal."
    },
    {
      "title": "Reconcile safely",
      "body": "Make correction and recovery flows preserve legitimate concurrent changes and create a complete audit record."
    }
  ],
  "outputs": [
    "Ledger invariant",
    "State-transition map",
    "Reconciliation and audit criteria"
  ],
  "pitfalls": [
    "Trusting client totals",
    "Separating evidence from entitlement creation",
    "Using non-atomic balance updates"
  ],
  "references": {
    "resources": [
      {
        "id": "owasp-transaction-authorization-state-integrity",
        "title": "OWASP Transaction Authorization",
        "url": "https://vulns.co/research/resources/owasp-transaction-authorization-state-integrity/"
      },
      {
        "id": "stripe-webhook-delivery-state-integrity",
        "title": "Stripe webhooks: authentic delivery and business-state integrity",
        "url": "https://vulns.co/research/resources/stripe-webhook-delivery-state-integrity/"
      },
      {
        "id": "paymenter-2026-refund-transition-atomicity",
        "title": "Paymenter: refund entitlement and ledger changes need one atomic transition",
        "url": "https://vulns.co/research/resources/paymenter-2026-refund-transition-atomicity/"
      }
    ],
    "diagrams": [
      {
        "id": "approval-version-integrity",
        "title": "Approval stays attached to the reviewed version",
        "url": "https://vulns.co/research/diagrams/approval-version-integrity/"
      }
    ],
    "reports": [
      {
        "id": "google-cloud-build-approval-toctou-2025",
        "title": "Cloud Build approval was not bound to immutable code",
        "url": "https://vulns.co/research/reports/google-cloud-build-approval-toctou-2025/"
      },
      {
        "id": "github-actions-reference-validation-2021",
        "title": "GitHub Actions trust depended on invalid repository references",
        "url": "https://vulns.co/research/reports/github-actions-reference-validation-2021/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/billing/",
  "markdown_url": "https://vulns.co/skills/billing/SKILL.md"
}
