开启时会模糊预览图,关闭后正常显示

Marketer, self-taught developer, and founder of @Bento and https://t.co/lcsIohchEv. Designing a quiet family life in 福岡, Japan. DMs open if you need email help 🌿


making models learn • eXperiments lab • full of myself, but still hungry


opus 4.5 using occasional boost from gpt 5 pro consulting.


Market Design/Entrepreneurship Professor @HarvardHBS & Faculty Affiliate @Harvard Economics; Research @a16zcrypto; Editor @restatjournal; Econ @Quora; … | #QED

![Stripe changed their Restricted API keys flow.
It killed the onboarding of 6 of my startups.
It used to be possible to prefill permissions with query parameters like this "?permissions[0]=rak_charge_read" so users don't have to select each permission manually.
The easy alternative would be asking for the user's API key, but it's definitely not good for security.
The purpose of Restricted API keys is to allow granular access to specific ressources, so why not keep an easy way to prefill permissions with query parameters?
I love @stripe, and I wish they would restore this feature for all of us building apps on top of the platform.
@AzianMike @jeff_weinstein @jrfarr Stripe changed their Restricted API keys flow.
It killed the onboarding of 6 of my startups.
It used to be possible to prefill permissions with query parameters like this "?permissions[0]=rak_charge_read" so users don't have to select each permission manually.
The easy alternative would be asking for the user's API key, but it's definitely not good for security.
The purpose of Restricted API keys is to allow granular access to specific ressources, so why not keep an easy way to prefill permissions with query parameters?
I love @stripe, and I wish they would restore this feature for all of us building apps on top of the platform.
@AzianMike @jeff_weinstein @jrfarr](/_next/image?url=https%3A%2F%2Fpbs.twimg.com%2Fmedia%2FG7ekK0CWMAAUFFx.jpg&w=3840&q=75)
More context: On TrustMRR, people can verify a startup using a Stripe Restricted API key by clicking the following link: https://t.co/ooxMctYlnM It prefills the ressources access required for the key (READ Charges, READ Subscriptions, etc.) so that the users don't have to do it manually. It saves a lot of time for users and prevents them from mistakenly adding the wrong permissions, like WRITE Refund. That alone makes onboarding Stripe 10x easier than most other payment providers and adds a layer of security.


Market Design/Entrepreneurship Professor @HarvardHBS & Faculty Affiliate @Harvard Economics; Research @a16zcrypto; Editor @restatjournal; Econ @Quora; … | #QED
