Stripe provides financial infrastructure to millions of merchants with APIs.
Developers use Stripe’s APIs to integrate payment processing, recurring billing, subscription management, and payouts directly into their applications.
Over the summer, I joined Stripe's Identity Access Management (IAM) team to enhance API security for developers.
Time
2 months
Team
Designer (Me) Software Engineers
Skills
Systems thinking Interaction design Product strategy
This piece of work is under NDA
Please email me if you'd like to chat and learn more!
Today, merchants are exposed to fraudulent activity on their account.
Merchants have no visibility when a key is potentially compromised by an attacker. This leads to suspicious API activity, resulting in fraudulent payments and transactions.
Solution
I led the design of an anomaly detection feature that flags fraudulent API requests to merchants.
Throughout my internship, I owned end-to-end design of alerting, reviewing and resolving fraudulent API requests. I collaborated cross-functionally with three engineering teams inside the IAM organization to define how anomalies are detected and what are the remediation actions.
Grateful for the journey! Here's what I learned....
Building taste and craft with AI tools
This summer, I used Claude code to generate designs for rapid explorations. However, without having an eye for visual craft, I would not have been able to make a judgement on what design direction to move forward with.
Understand the lay of land before diving in
In order to design for developers, I spent a lot of time understanding API security principles such as leaked, quarantined, and dormant keys. This was the key to building in-depth knowledge in the space and context about users.