Your Stripe Secret Key and Publishable Key MUST be from the SAME Stripe account.
Your keys are from different accounts:
- Secret Key Account:
51SWeEDRX4IBy2EmN(lowercase 'e' in "WeED") - Publishable Key Account:
51SWEEDRX4IBy2EmN(uppercase "EED")
This mismatch causes 401 authentication errors because:
- Backend creates payment intent with Account A's secret key
- Frontend tries to confirm with Account B's publishable key
- Stripe rejects it (keys don't match)
Your secret key starts with: sk_test_51SWeEDRX4IBy2EmNjxued...
The account identifier is: 51SWeEDRX4IBy2EmN
- Go to: https://dashboard.stripe.com/test/apikeys
- Make sure you're logged into the account that has your secret key
- Look for the Publishable key on the SAME page
- It should start with:
pk_test_51SWeEDRX4IBy2EmN...(matching your secret key's account ID)
Replace the publishable key in client/.env:
REACT_APP_STRIPE_PUBLISHABLE_KEY=pk_test_51SWeEDRX4IBy2EmN[rest of matching key]Important: The account identifier (51SWeEDRX4IBy2EmN) must match your secret key exactly!
Both keys should have the same account identifier:
✅ Correct:
- Secret:
sk_test_51SWeEDRX4IBy2EmN... - Publishable:
pk_test_51SWeEDRX4IBy2EmN...(same account ID)
❌ Wrong:
- Secret:
sk_test_51SWeEDRX4IBy2EmN... - Publishable:
pk_test_51SWEEDRX4IBy2EmN...(different account ID)
After updating client/.env:
# Stop React (Ctrl+C)
cd client
npm startThe account identifier is the part after sk_test_ or pk_test_ and before the rest of the key.
Example:
sk_test_51SWeEDRX4IBy2EmNjxued...→ Account ID:51SWeEDRX4IBy2EmNpk_test_51SWeEDRX4IBy2EmNabc123...→ Account ID:51SWeEDRX4IBy2EmN✅ MATCHES
If you can't find matching keys:
-
Option 1: Create new API keys in the same account
- Go to Stripe Dashboard → API Keys
- Click "Create new key" (if needed)
- Copy both keys from the same page
-
Option 2: Use the account that has your current publishable key
- Get the secret key from that account
- Update
server/.envwith the matching secret key
Run this to verify your keys match:
cd /Users/youseftahoon/VibeCoderz
echo "Secret account: $(grep 'STRIPE_SECRET_KEY' server/.env | cut -d'=' -f2 | cut -c8-25)"
echo "Publishable account: $(grep 'REACT_APP_STRIPE_PUBLISHABLE_KEY' client/.env | cut -d'=' -f2 | cut -c8-25)"If they don't match, you'll see different account IDs!