Billing
Stripe-hosted runtime plans, entitlements, and operator setup.
Matrix OS hosted runtime billing is backed by Stripe Billing. Clerk remains the identity provider, but subscription checkout, coupons, tax, the customer portal, and webhooks are handled by Stripe.
Hosted Runtime Plans
| Plan | Monthly list price | Included machines |
|---|---|---|
| Starter | $20 | 1 |
| Builder | $100 | 1 |
| Max | $200 | 1 |
The first primary computer on a Matrix account can use Stripe's native 3-day trial for subscriptions. With the product default, Checkout sends trial_period_days: 3, requires a card, and charges $0 initially. Stripe automatically attempts the selected recurring price when the trial ends unless the user cancels first. Coupons remain independent marketing discounts and never implement the trial.
The offer is limited to one trial per Matrix account and excludes previous subscribers, additional computers, and subsequent subscriptions. The persisted checkout attempt records the eligibility decision and duration so an idempotent retry sends identical Stripe parameters. The MATRIX_CARD_TRIALS_ENABLED rollout flag controls only new offers; disabling it does not alter trials already underway.
Entitlements
Stripe subscription webhooks project every subscription independently into billing_subscriptions. Each row carries the Clerk user id and runtime slot from signed Stripe metadata. Provisioning and routing authorize that exact (clerk_user_id, runtime_slot) projection rather than a user-wide slot count. billing_entitlements remains a derived coarse summary for legacy and account-level views; it is not the authorization source for one computer.
The platform allows runtime proxying and provisioning while that computer's subscription is trialing or active. A first post-trial payment failure gates access immediately and schedules VPS suspension 24 hours later. Established paid renewal failures retain the three-day grace period. Successful recovery cancels a pending suspension or wakes an already stopped machine. Suspension powers the VPS off but does not delete its disk or owner data.
Internal engineers can receive a production or staging override entitlement for testing plan changes without paying. Overrides are audit records with an expiry or revocation path; they must not delete, downgrade, or recreate a user's existing machines.
Machine resize uses the same entitlement allowlist as provisioning. A running VPS may move only to a server type currently allowed by the effective entitlement. The resize path changes the Hetzner server type in place with disk growth disabled, so billing downgrades can move CPU/RAM down without replacing the machine or deleting owner data.
Additional Computers
Every additional computer purchases one standard Starter, Builder, or Max subscription through Stripe Checkout under the user's existing Stripe customer. Checkout and subscription metadata include clerk_user_id, matrix_runtime_slot, and the selected region. The Customer Portal manages existing subscriptions but does not purchase another computer.
Do not configure an extra-runtime Price or a focused Customer Portal subscription-update flow. Storage and future Hetzner-backed add-ons remain separate product decisions. Do not hardcode Hetzner prices into Stripe plan names; keep provider cost data in the Matrix runtime catalog so Hetzner price changes can be updated without renaming public plans.
Stripe Setup
Create recurring monthly Stripe Prices for the three plans. New first-time and additional-computer Checkout sessions use those Prices. Keep existing yearly Price IDs configured only so legacy annual subscriptions remain recognizable. Configure promotion codes in Stripe for launch discounts, time-limited percentage discounts, pay-X-get-Y campaigns, and referrals.
Required platform environment:
| Variable | Notes |
|---|---|
MATRIX_BILLING_PROVIDER=stripe or MATRIX_STRIPE_BILLING_ENABLED=true | Enables Stripe-backed entitlement enforcement. |
MATRIX_CARD_TRIALS_ENABLED=true | Enables the card-required trial for eligible first primary computers. |
MATRIX_CARD_TRIAL_DAYS=3 | Controls new trial duration; the product default is 3 days and the accepted range is 1 through 30. |
STRIPE_SECRET_KEY | Restricted key with checkout, portal, customer, subscription, and webhook needs. |
STRIPE_WEBHOOK_SECRET | Webhook signing secret for /billing/webhooks/stripe. |
STRIPE_PRICE_MATRIX_STARTER_MONTHLY / STRIPE_PRICE_MATRIX_STARTER_ANNUAL | Starter Price IDs. |
STRIPE_PRICE_MATRIX_BUILDER_MONTHLY / STRIPE_PRICE_MATRIX_BUILDER_ANNUAL | Builder Price IDs. |
STRIPE_PRICE_MATRIX_MAX_MONTHLY / STRIPE_PRICE_MATRIX_MAX_ANNUAL | Max Price IDs. |
PLATFORM_PUBLIC_URL | Used to build checkout and portal return URLs. |
Production Cloud Run deployments read the Price IDs from Secret Manager. The required secret names are:
| Environment variable | Secret Manager name |
|---|---|
STRIPE_PRICE_MATRIX_STARTER_MONTHLY | stripe-price-matrix-starter-monthly |
STRIPE_PRICE_MATRIX_STARTER_ANNUAL | stripe-price-matrix-starter-annual |
STRIPE_PRICE_MATRIX_BUILDER_MONTHLY | stripe-price-matrix-builder-monthly |
STRIPE_PRICE_MATRIX_BUILDER_ANNUAL | stripe-price-matrix-builder-annual |
STRIPE_PRICE_MATRIX_MAX_MONTHLY | stripe-price-matrix-max-monthly |
STRIPE_PRICE_MATRIX_MAX_ANNUAL | stripe-price-matrix-max-annual |
| The signed-in pre-VPS path defaults to Builder monthly checkout. Missing price | |
| secret access should block deployment rather than letting new users reach a | |
| broken billing gate. |
Webhook events to subscribe:
customer.subscription.createdcustomer.subscription.updatedcustomer.subscription.deletedcustomer.subscription.trial_will_endcheckout.session.completedcheckout.session.expiredinvoice.paidinvoice.payment_failed
Enable Stripe's trial-ending customer email as well. Stripe emits customer.subscription.trial_will_end three days before the deadline; Matrix uses that verified event for its reminder telemetry.
Stripe Checkout uses automatic tax, promotion codes, and an idempotency key derived from the persisted checkout attempt. Eligible trial Checkout also sets payment_method_types: ['card'] and payment_method_collection: always; immediate-payment sessions keep Stripe's normal dynamic-method behavior. Subscription and invoice webhooks remain the authorization source of truth; a Checkout redirect never grants access. The customer portal should remain enabled so users can update payment methods, apply supported coupons, and manage existing subscriptions through Stripe-hosted flows.
Billing FAQ
How long is the Matrix OS trial?
Eligible first primary computers receive a three-day, card-required trial. Stripe charges the selected monthly price when the trial ends unless the user cancels first.
Can one Matrix account receive more than one trial?
No. The offer is limited to one trial per Matrix account. Previous subscribers, additional computers, and later subscriptions are not eligible.
What happens after a payment failure?
A first post-trial payment failure gates access immediately and schedules VPS suspension 24 hours later. An established paid renewal receives a three-day grace period. Suspension powers off the VPS without deleting its disk or owner data.
Can customers manage billing without contacting support?
Yes. Stripe's customer portal lets customers update payment methods, apply supported coupons, and manage existing subscriptions. Purchasing an additional computer still uses a new Checkout session.
How is this guide?