Dev & Engineering

cmux Billing Runbook Skill

Gives AI coding agents an executable architecture map and ops runbook for Stripe billing, pricing, subscriptions, webhooks, and Pro entitlements in the cmux codebase.

50/ 100
Use with care

Useful, but reliability, evidence or controls still have material gaps.

See how it was scored ↓
Works as-is in
Codex · Claude Code
Stars
★ 28k
Last updated
1d ago
License
NOASSERTION
stripe-billingstripe-webhooksstripe-checkoutsubscription-management
+3entitlementsrunbookcmux

What does this skill do, and when should you use it?

cmux-billing is one of 25 skills bundled in the manaflow-ai/cmux monorepo, located at skills/cmux-billing/SKILL.md. It is a domain-knowledge document for AI coding agents covering Stripe Checkout, the customer portal, idempotent subscription recording, Pro entitlement resolution, admin routes, and test tooling. The skill performs no actions itself; its value is that an agent loads its constraints—idempotent recording, environment gates, the price catalog, and migration ordering—before touching billing code. It is useful to engineers or agents working on cmux server-side billing (web/) and has no applicability outside this repository.

  • Maps the billing architecture: responsibilities of /api/billing/checkout, portal, subscription, /api/stripe/webhook, and the shared idempotent recorder web/services/billing/purchase.ts
  • Explains entitlement resolution: the cmuxVmPlan operator override takes precedence over the Stripe-mirrored cmuxPlan; billingManagement stays Stripe-only
  • Lists the full price catalog with Stripe product/price/portal-configuration IDs for test and live modes, legacy grandfathered prices, and env override variable names
  • Documents the dev workflow: dev-stack.sh, dev-grant.sh, dev-reset.sh, the CMUXDEV100 test coupon, and Docker Postgres --db-port etiquette
  • Gives the production runbook: provision-live.sh, Vercel env additions, and migration order (preflight → staging → production)
  • Records gotchas: bun mock.module is process-global, DrizzleQueryError requires reading error.cause, and non-locale pages like /app-pricing need a proxy.ts bypass
Good fit
  • An engineer editing or debugging /api/billing/* or /api/stripe/webhook code in cmux who needs the idempotency and signature-verification constraints first
  • An operator granting, switching, or downgrading a paid plan who must understand cmuxVmPlan overrides and admin_plan_grants activation conditions
  • Someone investigating webhooks that fired but entitlements did not update, needing the insert-first idempotency and 2xx/500 return policy
  • A developer changing pricing or adding annual plans who must handle immutable Stripe amounts and LEGACY_PRICE_LOOKUP_KEYS correctly
  • A contributor standing up a local billing test environment who needs the dev scripts and the 100%-off coupon checkout flow
Not a fit
  • Stripe projects outside the cmux repo: every route, script, and env variable name is hard-bound to cmux and not reusable
  • cmux contributors not touching billing or entitlements: this document says nothing about end-user features, CLI, or notifications
  • Readers seeking a general Stripe integration tutorial: this is an internal runbook, not Stripe education

How do you install this skill?

Before you use it
  • This is a billing runbook for internal cmux contributors; it is not directly usable by outside users — invoke only when your task actually involves modifying or debugging cmux billing code.
  • The workflow depends entirely on overseas services (Stripe, Vercel, Stack); reachability and usability from mainland-China networks are unverified.
  • The document embeds many internal product/price/endpoint IDs (including a staging webhook endpoint); not secrets, but sensitive internal identifiers — mind exposure when reusing or quoting.
  • License metadata is NOASSERTION and web/ is under BUSL-1.1 (commercial license required for production use); verify licensing boundaries before any secondary use of billing-related code.
  • All script and implementation claims come from static document reading, not execution; cross-check referenced files before following the runbook.
Before you start
Your agent needs
  • Shell / CLI
  • Local filesystem
Install first
  • Bun
  • Stripe CLI
  • Docker (Postgres)

The source documents no separate install command; the skill ships inside the manaflow-ai/cmux repo. Obtain it by cloning and reading skills/cmux-billing/SKILL.md:

git clone https://github.com/manaflow-ai/cmux.git

Place it in your agent's skills directory (e.g. the Claude Code skills path) for automatic discovery; the exact directory path is not documented in the source.

How do you use this skill?

Try saying

Once installed, send your agent any of these to trigger it:

  • I need to change the team fallback logic in /api/billing/checkout — load the cmux-billing skill and map the current paths before editing
  • A paying customer's Pro status didn't activate; investigate stripe_webhook_events idempotency per the cmux-billing webhook section
  • Raise the Pro annual price from $480 to $528 and follow the skill's guidance on immutable Stripe amounts and LEGACY_PRICE_LOOKUP_KEYS
  • Simulate a Pro purchase for [email protected] locally and undo it, using the dev-grant and dev-reset flow from the cmux-billing skill

The skill is triggered by its description: any task involving editing or debugging billing, pricing, Stripe Checkout, subscription recording, Pro plan status, webhooks, entitlement metadata, or pricing dev/prod tooling should load this document first. The core usage is having the agent absorb its constraints before coding (e.g. idempotent recording, webhook returning 2xx only after durable writes) and following the Dev workflow scripts locally:

web/scripts/stripe/dev-stack.sh
web/scripts/stripe/dev-reset.sh <email>
web/scripts/stripe/dev-grant.sh <email>

Production operations follow the Prod runbook:

web/scripts/stripe/provision-live.sh
bun run cloud-vm:preflight
bun run cloud-vm:migrate -- staging
bun run cloud-vm:migrate -- production

What are this skill's strengths and limitations?

Pros
  • Exceptionally complete coverage: routing architecture, entitlement resolution, full price catalog IDs, env variables, and migration order in one place
  • Contains hard-won gotchas (mock.module globals, Drizzle error wrapping, proxy.ts bypass) that prevent rework directly
  • States security boundaries explicitly: webhook signature verification, idempotency, and never cross-granting on unverified email
Limitations
  • Tightly bound to the cmux repo; zero reuse value for other projects
  • Packed with internal IDs (products, prices, portal configs, staging webhook endpoint) that carry high staleness risk and must be maintained in sync with code
  • The skill itself is documentation only — no scripts or automation; correctness depends on the agent following it rather than enforcement

How does this skill compare with similar options?

Side by side with related skills; every score comes from the same FSRS standard.

Skill FS score Stars Last updated License
cmux Billing Runbook Skill this page 50 · Use with care ★ 28k 1d ago NOASSERTION
cmux Workspace Skill 64 · Recommended ★ 28k 1d ago NOASSERTION
cmux-browser: Browser Automation Skill for cmux 60 · Recommended ★ 28k 1d ago NOASSERTION
cmux Settings Management Skill (cmux-settings) 58 · Recommended ★ 28k 1d ago NOASSERTION
Stripe AI Developer Toolkit Not yet reviewed ★ 1.9k 3d ago MIT

How did FollowSkills review this skill?

FollowSkills review · FSRS-2.0
Use with care
50/ 100 5-point scale 2.5 / 5
1Trust14 / 25 · 2.8/5

The described billing flow shows real security engineering: signature-verified webhooks, insert-first idempotency, no cross-granting from unverified email, admin gating (requireAdmin plus domain/membership checks), 403 for non-admins, and fairly transparent data-flow disclosure. Deductions: the doc embeds many internal Stripe product/price IDs and a staging webhook endpoint (exposure surface, though not secrets); the local-dev auto-Pro grant depends on four env vars aligning, a fragile boundary; no explicit rollback guidance; publisher unverified.

2Reliability9 / 20 · 2.3/5

The document is self-consistent and describes abnormal paths well (Stripe 500 retries, 503 before migration, typed resource-pool errors, DrizzleQueryError cause unwrapping, Stripe CLI format compatibility). Deductions: static review cannot execute any referenced script (dev-stack.sh, dev-grant.sh, provision-live.sh not provided); key paths are not reproducible and failure-feedback quality rests on description alone, capping below the static ceiling.

3Adaptability8 / 15 · 2.7/5

Frontmatter trigger conditions are precise (editing/debugging billing, pricing, Stripe, webhooks, Pro status), with clear boundaries; the audience is contributors/agents working in this codebase. Deductions: this is an internal runbook skill of limited value to outside users; core function depends entirely on overseas services (Stripe, Vercel, Stack), a mainland-China reachability risk; no Chinese-language support.

4Convention9 / 15 · 3.0/5

Information architecture is well layered (architecture map, dev workflow, catalog, flags, prod runbook, gotchas) with known-limitation disclosure and migration steps. Deductions: the skill itself has no version/changelog; license metadata is NOASSERTION and the repo's licensing is complex (GPL plus BUSL-1.1 for web/), with no self-declared license for the skill; maintenance responsibility and update path are only inferable indirectly.

5Effectiveness6 / 15 · 2.0/5

For the target user (an agent or developer editing cmux billing code) the marginal value is clear: routes, scripts, price catalog, env vars and gotchas are centralized, avoiding scattered retrieval. Deductions: no verified representative outputs; several critical scripts and implementation files are outside the evidence set, so completeness and direct usability rest on description, capped at the static ceiling of 7.

6Verifiability4 / 10 · 2.0/5

All SKILL.md claims (IDs, scripts, migrations, gating logic) cannot be independently verified — the referenced source files are not in evidence. The repository has extensive real CI workflows and tests (app-host tests, auth tests), but none shown covering billing key paths. Deductions: single-source narrative with no fact/inference separation, yielding a low score under static review.

1 2 3 4 5 6

Open a dimension to read why it scored that way

Reviewed Oct 10, 2026 Reviewed revision d6ff14af8af1 Review evidence[1][2][3][4][5][6][7][8][9][10]

Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.

See the full review method →

FAQ

Does this skill execute anything?
No. It is pure knowledge (a SKILL.md document) that the agent reads and follows when editing billing code; the scripts (dev-stack.sh etc.) belong to the repository itself.
How does a local dev account get Pro?
When CMUX_LOCAL_DEV_PRO=1, NODE_ENV=development, VERCEL_ENV is unset, and the development Stack project is used, local accounts receive a non-persistent Pro entitlement automatically; or use dev-grant.sh to write cmuxVmPlan: "pro" directly, and the CMUXDEV100 coupon enables a $0 full checkout in test mode.
What matters most when changing a price?
Stripe amounts are immutable, so a price change must mint a new lookup key carrying the amount and add the old key to LEGACY_PRICE_LOOKUP_KEYS; env override names embed the amount, so a retired name fails env validation and must be deleted from Vercel before deploying.
What is the webhook return policy?
/api/stripe/webhook is signature-verified, insert-first idempotent via stripe_webhook_events, only handles events with metadata.app === "cmux", and returns 2xx only after durable writes; return 500 to make Stripe retry.

More skills from this repository

All from manaflow-ai/cmux

Dev & Engineering

cmux Workspace Skill

Lets an AI coding agent work safely inside the cmux workspace that invoked it, without disturbing the workspace or window the user is actually looking at.

★ 28k FS 64 Recommended 1d ago
Dev & Engineering

cmux-browser: Browser Automation Skill for cmux

Open sites, inspect browser surfaces, wait for page state, and extract data through the cmux CLI without stealing focus — built for parallel AI coding agent workflows.

★ 28k FS 60 Recommended 1d ago
Dev & Engineering

cmux Settings Management Skill (cmux-settings)

Safely view, edit, and roll back cmux's cmux. configuration with hot reload — changes apply on save, no app restart.

★ 28k FS 58 Recommended 1d ago
Dev & Engineering

cmux Testing Skill

Pick the right scoped local/CI verification for the cmux repo, add behavior-grounded tests, and keep Swift test targets correctly wired in the Xcode project.

★ 28k FS 60 Recommended 1d ago
Dev & Engineering

cmux Keyboard Shortcuts

Turns your key preferences into working cmux shortcut bindings, with templates, snapshots, and rollback instead of blind JSON edits.

★ 28k FS 58 Recommended 1d ago
Dev & Engineering

cmux Socket Policy Skill

Gives AI coding agents the threading and focus rules for cmux socket/CLI work, so telemetry stays off the main thread and automation never steals your app focus.

★ 28k FS 58 Recommended 1d ago
Dev & Engineering

cmux Customization

A skill for safely customizing the cmux terminal: edit cmux., Dock config and Ghostty preferences to tailor actions, layouts, shortcuts and notifications without breaking existing config.

★ 28k FS 55 Use with care 1d ago
Dev & Engineering

cmux Dev Workflow Skill

A standardized contributor workflow for cmux: tagged native builds, Xcode project normalization, and sidebar extensions — without disturbing a running cmux instance.

★ 28k FS 53 Use with care 1d ago
Productivity & Collaboration

cmux Markdown Viewer

Opens .md files in a formatted panel beside your cmux terminal with live reload, keeping plans, docs, and notes visible as they change.

★ 28k FS 52 Use with care 1d ago
Dev & Engineering

cmux Diagnostics

Collects support-safe, read-only diagnostics for cmux so you can pinpoint failing hooks, notifications, session restore, and CLI control without leaking secrets.

★ 28k FS 51 Use with care 1d ago
Automation & Ops

cmux Computer Use Skill

Lets AI coding agents inside cmux drive real macOS apps through a local computer-use engine, strictly on explicit user request.

★ 28k FS 50 Use with care 1d ago
Dev & Engineering

cmux Custom Sidebar

Turn a plain-language request into a hot-reloading custom cmux sidebar — no Xcode, no build step, no signing.

★ 28k FS 50 Use with care 1d ago
Dev & Engineering

cmux Shared Behavior Rules

Codifies one shared implementation and verification path for cmux behaviors exposed through multiple entrypoints, so fixes never land on one surface and leave others stale.

★ 28k FS 48 Use with care 1d ago
Automation & Ops

cmux Cloud VM Skill

Lets an AI agent operate cmux Cloud machines through the cmux CLI: run durable remote commands and coding agents on persistent terminals, then present verified results to the user.

★ 28k FS 56 Use with care 1d ago
Dev & Engineering

cmux Release Skill

A release-workflow skill for cmux maintainers covering version bumps, changelog assembly, pretag guard, tagging, and release asset verification.

★ 28k FS 53 Use with care 1d ago
Dev & Engineering

cmux Core Control

Deterministically control cmux terminal topology — windows, workspaces, panes, surfaces, focus, and attention cues — via the cmux CLI, built for AI coding agent automation.

★ 28k FS 47 Use with care 1d ago
Dev & Engineering

cmux Architecture Skill

Load cmux's package architecture, layering, dependency inversion, and Swift 6 concurrency rules before adding or heavily rewriting Swift files, packages, coordinators, services, or public APIs in the cmux repository.

★ 28k FS 63 Recommended 1d ago
Dev & Engineering

cmux Debugging Skill

Gives AI agents the project-specific debugging conventions for cmux — a Ghostty-based macOS terminal — so probes, profiling, and UI changes never break typing latency or live agent sessions.

★ 28k FS 56 Use with care 1d ago
Dev & Engineering

cmux Localization Rules & Audit Skill

Enforces localization rules and a verifiable audit workflow for every cmux user-facing string change, so no hardcoded English text ever lands.

★ 28k FS 56 Use with care 1d ago
Dev & Engineering

cmux-capture: Screenshot and Record cmux Windows

Capture screenshots or recordings of a cmux window from the CLI to supply real evidence for PRs, bug reports, and visual verification — with no screen recording permission required.

★ 28k FS 55 Use with care 1d ago

Related skills