Security
Recovra does not move payouts or transfer funds.
Recovra connects through Stripe OAuth to operate dispute handling. It can read dispute, payment, customer context, and limited account metadata, then submit dispute responses. It cannot move payouts, transfer funds, issue refunds, change bank details, or use customer payment methods.
Quick answer
What Stripe access does Recovra need?
Recovra connects through Stripe OAuth using the standard read_write scope so it can read dispute, payment, customer, and limited account context, then submit dispute responses. It does not use Stripe access to move payouts, transfer funds, issue refunds, change bank details, or use customer payment methods.
- Stripe OAuth, no API keys
- Encrypted tokens and revocable access
- No payout, refund, or bank-account control
Connection
Stripe OAuth, no API keys
Control
Revocable from Stripe anytime
Visibility
Decisions and outcomes logged
What Recovra does not do
- Move payouts or transfer funds
- Issue refunds or credits
- Change payout schedules or bank accounts
- Change Stripe account settings
- Use customer payment methods
- Manage subscriptions or invoices
What Recovra can access
- Dispute data when Stripe opens a case
- Payment and customer context needed for dispute recovery
- Evidence submission to open disputes
- Submission status and outcome tracking
- Limited Stripe account metadata needed for dispute handling, including account email, default currency, payout status, and business profile name
How access is controlled
- Connection
- Stripe OAuth. Tokens are stored encrypted. No API keys required.
- Scope
- Standard Stripe OAuth (read_write). Recovra reads dispute, payment, and customer context, reads limited account metadata, and submits dispute responses for recovery.
- Revocation
- Disconnect from your Stripe dashboard at any time. One click.
- Visibility
- Every decision, submission, and outcome visible in your workspace.
- Data
- Dispute data and limited account metadata are used only to operate dispute handling. Not sold. Not shared.
You stay in control.
Revoke access anytime. Every action logged. Every outcome visible.