This will not work. Definitely disable csrf for callback from Stripe.
Even if you..
- passed
csrf_token to the strip - found a way to get the strip to post the same token back to your callback URL
At this point, the token will be irrelevant, as the token is only for your current browser session (usually a cookie).
A CSRF token is generated for each request and sent to the browser for storage in a cookie. Stripe will not have this cookie, and thus you will get the CSRF error the same way.
source share