
By Cristian Daron
A dental membership sold alongside product subscriptions sounds like a storefront feature. Most of the work turned out to be making sure that the people covered by the plan and the people paying for it were always the same list.
The gap
Customers get the membership with their product subscription, either free or at $20 a month, and it is fulfilled by a third-party provider, Careington. Nothing connected subscription billing in Recharge to the provider's member records. Enrolments and cancellations were handled by hand, so there was no reliable way to confirm that the people being covered were the people actually paying.
The pipeline
I built a Node service on Railway that sits between Shopify, Recharge and Careington. It generates the provider's eligibility file in their 29-field format, validates it before anything leaves, assigns each member to the right billing group, and delivers it automatically over SFTP. Effective and term dates are set to the first of the month, so the provider's billing cycle lines up with ours.
Cancellations run off a single Recharge webhook. It sets the term date, tags the customer record, logs the reason, and only ends dental access once the customer has no qualifying subscription left. Pricing is worked out from the member's current subscriptions on every webhook and again on a schedule, so a missed webhook costs a delay rather than a wrong charge.
The detail in the file format
The provider's full-file format treats each file as the complete member list. Anyone missing from it is cancelled. So an incomplete file is not a partial update: it is a mass cancellation. With around 22,000 existing members, one bad upload would have ended cover for nearly all of them at once.
I caught it mid-build and put the safeguards in before anything could reach production. Every file is now checked against the provider's eligibility guide before it is sent, and any error stops the upload instead of sending a best effort.
What I took from it
Read an integration spec for what the receiving system does with your data, not just for the fields it wants. A format that cancels by omission needs a pipeline that fails closed: when in doubt, send nothing and say so.
Every member's status now traces back to an actual billing event instead of someone updating a spreadsheet, and enrolment, renewal and cancellation are one path rather than three manual ones.