Subscription billing infrastructure is the set of systems that takes a subscriber’s money, decides what they can access, and keeps both facts true over months and years. For a media company it sits underneath every paywall, members’ newsletter and private podcast feed. When it works, nobody notices. When it fails, subscribers are locked out of things they paid for, or reading for free things they did not. This guide sets out what that infrastructure has to get right, plainly enough for a publisher and in enough detail for the engineers who build it.
Payments provider and billing logic are different jobs
A payments provider such as Stripe, Adyen or Braintree moves money: it stores cards, charges them, handles bank declines and pays out. Many providers, and billing platforms such as Recurly or Chargebee, also manage subscriptions: plans, renewals, invoices and proration.
Your billing logic is the part specific to your business: which plans exist, what each includes, how gifts, group subscriptions, student rates and bundles work, what happens on upgrade or cancellation, and how a subscription maps to access across your site, apps, newsletters and feeds. Some of this can live in the provider’s subscription features. Some of it always lives with you.
The practical rule is to let the provider be the source of truth for money, and keep your own record of subscribers and their entitlements. Treating the provider’s dashboard as your subscriber database makes reporting, support and migrations harder than they need to be. Keeping your own copy means keeping the two in step, which is what webhooks and reconciliation are for.
Entitlements and sign-in
An entitlement is a statement of what a person can access right now, such as “this account can read paid articles and receives the members’ edition”. Subscriptions create entitlements, and entitlements, not subscriptions, should drive what the product shows. That separation lets you handle gifts, complimentary access for contributors, group plans and trials without special cases scattered through the code.
- Fast checks. Every page view or feed request may ask whether this person is entitled. The answer should come from a cache or a signed token, not a live call to your payments provider.
- Clear states. Active, in trial, past due, cancelled but paid to period end, expired. Each needs defined behaviour in the product.
- Sign-in that suits readers. Many subscribers rarely sign in, so emailed links or one-time codes tend to cause fewer support requests than passwords. A subscriber should get from an email to signed-in content in one step.
- One identity across surfaces. The same person should be recognised on the website, in the app, in their inbox and in a private podcast feed, with each of those mapped to one account.
Webhooks and reconciliation
Your provider tells your system what has happened through webhooks: a renewal succeeded, a card failed, a subscription was cancelled. Webhooks keep entitlements current, and they are less reliable than they look.
- Verify every signature so nobody can forge a “payment succeeded” event.
- Make handlers idempotent. Providers retry deliveries and can send the same event twice. Processing it twice must not grant double credit or send two welcome emails.
- Expect events out of order. An update can arrive before the creation it depends on. Fetch the current object from the provider rather than trusting the payload as the latest state.
- Acknowledge quickly, process later. Put events on a queue and return success straight away, so slow work does not cause timeouts and redelivery.
Then reconcile. Run a scheduled job, at least daily, that compares every active subscription at the provider with the entitlements in your system and flags differences. Webhooks will occasionally be missed, through outages on either side or a bad deployment. Reconciliation finds the gap before a subscriber writes in to say they were charged and locked out.
Uptime under traffic spikes
Media traffic is uneven. A story breaks, an episode spreads, a newsletter lands in a large list, and sign-in and checkout are hit at once by people who will not wait. Before founding Malahide Studio, Stephen Han led subscription infrastructure at Vox Media for The Verge and New York Magazine, a platform serving 15 brands and $50M in subscription revenue, and took its uptime from 99% to 99.99%. That is the difference between more than three days of downtime a year and under an hour, and most of it comes from a few habits:
- Keep the payments provider off the critical path for entitlement checks, so a provider slowdown does not lock out existing subscribers.
- Decide in advance whether to fail open or closed. If the entitlement service is down, letting signed-in subscribers read is usually better than blocking everyone.
- Cache anonymous pages at the edge, so a spike in readers does not become a spike in database load.
- Load-test checkout and sign-in before big launches, and alert on drops in completed checkouts, not only on server errors.
Card-testing attacks and fraud controls
Card testers use stolen card numbers to make small charges on checkout pages, to learn which cards still work. A subscription checkout with a low entry price is an attractive target. The costs are real: fees on every attempt, disputes, standing with the card networks and, in bad cases, a suspended merchant account.
- Rate-limit payment attempts per IP address, per device and per email address.
- Add a bot challenge to checkout, ideally one that appears only when traffic looks suspicious.
- Turn on your provider’s fraud screening and review its rules, including blocking charges that fail security code or postcode checks.
- Alert on sudden rises in declined payments, which are often the first sign of an attack.
- Keep the statement descriptor recognisable, so real subscribers do not dispute charges they cannot place.
Fraud controls interact with failed payment recovery. Rules that are too strict will decline real renewals, so review the two together.
Tax
Digital subscriptions are generally taxed where the subscriber lives. In the UK and EU that means VAT at the customer’s local rate, many US states tax digital goods, and other countries set their own rules and thresholds. Some digital publications qualify for reduced or zero rates, and which products qualify varies by country. Use your provider’s tax calculation or a dedicated tax service, collect location evidence at checkout, and ask an accountant to confirm how your products are classified. Decide early whether displayed prices include tax, because changing it later is awkward for existing subscribers.
Analytics and events
Billing data is the most reliable data a subscription business has. Send clean events from it into your analytics: subscription started, renewed, payment failed, payment recovered, cancelled with reason, plan changed, refunded. Attach the plan, price, currency, entry point and a pseudonymous subscriber ID to each. With that in place, cohort retention, revenue reporting and engagement analysis all draw on one source and agree with each other.
Migrating subscription billing infrastructure
At some point you will move providers, platforms or both. Prepare from the start by keeping your own subscriber records and storing provider IDs as references rather than primary keys. When the move comes:
- Ask about transferring card data directly between providers. Most large providers support secure transfers on request, which spares every subscriber from re-entering a card.
- Carry renewal dates across exactly, so nobody is charged twice or skipped.
- Run old and new systems side by side for at least one billing cycle, reconciling daily.
- Tell subscribers what will change on their bank statement before it changes.
Malahide Studio designs, builds and runs this layer month to month for independent media brands, alongside the media products it supports, so billing, sign-in and analytics sit with the same people who think about retention and subscription revenue. If your billing set-up has grown by accident, start a conversation about where to begin.