basalt / subscriptions/src / BillingRoutesOptions
Interface: BillingRoutesOptions
Defined in: subscriptions/src/plugin.ts:163
Properties
allowedRedirectOrigins?
> optional allowedRedirectOrigins?: string[]
Defined in: subscriptions/src/plugin.ts:193
Extra origins a per-request successUrl/cancelUrl/returnUrl override may point to (e.g. ['https://www.example.com']). Overrides are otherwise limited to the origins of the configured URLs — anything else is a 400, so a checkout/portal link can never be turned into an open redirect. Entries must be https (http is accepted for localhost only).
auth?
> optional auth?: boolean
Defined in: subscriptions/src/plugin.ts:176
Require an authenticated user on checkout/portal (meta.auth, enforced by @basaltkit/auth's guard). Default: true — these routes mint live payment-management URLs for the current tenant and must never be anonymous. Set false ONLY when authentication happens at an outer edge (gateway/proxy) — a deliberate, documented opt-out.
cancelUrl
> cancelUrl: string
Defined in: subscriptions/src/plugin.ts:166
meta?
> optional meta?: RouteMeta
Defined in: subscriptions/src/plugin.ts:185
Extra route metadata merged into BOTH checkout and portal — use it to require a billing role, e.g. { teamRole: 'owner' } (@basaltkit/teams) or { can: 'billing:manage' } (@basaltkit/permissions). Without it, ANY authenticated member of the tenant can start checkouts and open the portal (change plan, card, or cancel). It cannot switch auth off — use the auth option for that.
portalReturnUrl?
> optional portalReturnUrl?: string
Defined in: subscriptions/src/plugin.ts:168
Where the Customer Portal returns the customer. Default: successUrl.
successUrl
> successUrl: string
Defined in: subscriptions/src/plugin.ts:165
Where Stripe returns the customer after Checkout.