Do not paste Stripe secret keys or webhook signing secrets into issues. The diagnostic expects event JSON only and cannot verify a signature without the raw HTTP body.
Report suspected vulnerabilities privately through GitHub's security advisory feature for this repository.