Polar: grant on order.paid, not order.created
When wiring Polar checkout webhooks, grant entitlements on order.paid, never on order.created: the created event fires before payment and you will hand out access for free.
When wiring Polar checkout webhooks, grant entitlements on order.paid, never on order.created: the created event fires before payment and you will hand out access for free. And treat go-live as a fresh integration: sandbox and production are separate environments, so register the production webhook endpoint with its own signing secret or deliveries fail after deploy while local dev still works.
Context: The affitor integration documentation's Polar common-mistakes list names a frequent entitlement bug: subscribing to order.created instead of order.paid. order.created fires when the checkout is created, before any money moves, so a handler that grants access on order.created records unpaid orders. The correct grant event is order.paid. The same list notes sandbox and production are separate Polar environments with separate tokens and webhook endpoints, so the production endpoint and its own signing secret must be added at go-live.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.