Skip to main content
Payment-provider webhooks and callbacks must terminate at an HTTPS endpoint in your backend. AvraAPI helps verify gateway-specific evidence, but your application remains the system of record for orders and fulfilment.

Required callback design

Verification rules

  • Use an HTTPS callback endpoint you control.
  • Preserve the raw request form/body only for the immediate verification workflow; never send it through browser code.
  • Validate the provider signature, original merchant order reference, amount, currency, gateway environment, and any provider transaction binding.
  • Use the signed completion context created with the original checkout session.
  • Make order fulfilment idempotent. Providers may retry a callback or a browser may revisit a return page.
  • Return a safe acknowledgement according to the provider’s documentation, but do not claim success before verification finishes.

Browser returns are informational

A return URL may be used to show a pending or confirmation screen, but it is not authoritative payment proof. A gateway overlay event, query parameter, or success-looking browser redirect is also not enough.
Do not log callback signatures, full raw provider payloads, card data, or Vault credentials. Store only the minimum order evidence required by your own retention and reconciliation policy.
For the UPG completion contract and result shape, see Webhooks & Completion.
Last modified on October 1, 2026