Price comes from the server
The offer key, version, currency, item price, approved adjustment, tax, and total must come from one current quote. Static page numbers are not payment authority.
Changes need confirmation
An upgrade, downgrade, cancellation, or resume is complete only after the payment provider confirms it and your account shows the result.
Access follows confirmed payment
A browser redirect or pending charge does not unlock a room. Authoritative membership and entitlement records control access.
The screen must answer the important questions
| Required fact | What the person must see | Fail-closed rule |
|---|---|---|
| Offer identity | Room or course name, offer version, included access, billing interval, and any founding status. | Stop if the displayed offer does not match the active server record. |
| Money | Currency, base price, each approved discount or credit, tax treatment, and total due now. | Stop if a provider price, discount, tax rule, or displayed quote hash is missing or changed. |
| Timing | Charge date, access start, interval, next charge date or method for calculating it, and quote expiration. | Stop if the quote is expired or the next-charge disclosure cannot be grounded. |
| Renewal | Whether the offer renews automatically, how often, at what amount or calculation method, and what notice applies. | Stop until automatic-renewal rights and notice rules are approved for the buyer's location. |
| Exit and recovery | How to cancel, when cancellation takes effect, refund rule, support path, and what happens after payment failure. | Stop if an approved support path and policy versions are not available. |
Each term is its own exact offer
A monthly offer, annual offer, and founding offer must have separate versioned terms and provider price bindings. A page may explain the annual plan we are building, but we will not charge anyone annually until the exact amount, access period, renewal, cancellation, refund and tax rules are settled and shown to you first.
A founding rate is not a vague promise. The exact offer must state who qualifies, the protected price, what continuous membership means, which events end protection, whether a failed payment has a grace period, how upgrades or downgrades affect the rate, and what notice applies. The server must preserve the qualifying contract identity and event history.
Preview first, commit the same economics
- The account requests an upgrade preview for the exact active subscription item and target offer.
- The payment provider returns the immediate amount, future renewal amount, currency, proration details, and preview identity.
- The member sees and accepts the exact preview, policy versions, and expiration.
- The server commits the same target item and proration date. A different provider result must be rejected.
- If payment needs another action, the account shows pending status. It must not claim the higher tier yet.
- Access changes only after a current paid event and fresh subscription readback prove the pending update was applied.
Show the effective date and future access change
A downgrade preview must name the current and target room, current paid period, effective date, future renewal amount, features that will no longer be included, and what happens to separately purchased courses. The provider must mutate the exact subscription item and the server must read it back before saying the downgrade is scheduled.
The offer shown in your account explains whether an immediate downgrade, credit, or refund is available.
Cancellation must be easy to find and hard to fake
Cancel at period end
Cancellation normally takes effect at the end of the current paid period. Your account shows the request, effective date, access-until date, and confirmation state.
Resume before the effective date
If the provider and offer allow it, a member can request resume before cancellation takes effect. The account must show current readback and cannot erase the earlier cancellation event.
Immediate cancellation
When immediate cancellation is available, your account shows its access, refund, and data effects before you confirm.
Support-assisted cancellation
A published support channel and response process are required before live recurring billing. A support request must produce a receipt and must not be the only cancellation route when a direct account control is required.
A failed charge needs a visible state
The account should distinguish a pending payment, action-required payment, failed payment, grace period, canceled subscription, ended access, and recovered subscription. Grace duration, retry schedule, notices, access during grace, and final cancellation timing must come from an approved operating rule and current provider state.
An expired or failed checkout cannot be reused. Start a fresh checkout so the price, benefits, and expiration are current.
The billing portal and your account stay in sync
The account may open a payment-provider billing portal after current session, origin, CSRF, ownership, customer, and return-path checks. The portal URL must use an approved provider host. Changes made there become authoritative locally only after verified provider events and fresh server readback.
Bind the person to the exact displayed deal
Your billing record connects the signed-in account to the offer, term, displayed quote, price, tax, renewal, cancellation, policy versions, time, and expiration. Any change requires a fresh review and confirmation.