> ## Documentation Index
> Fetch the complete documentation index at: https://docs.avraapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Webhook verification

> Receive payment-provider callbacks on your server, preserve raw evidence safely, and verify before fulfilling an order.

Payment-provider webhooks and callbacks must terminate at an HTTPS endpoint in your backend. AvraAPI helps verify gateway-specific evidence, but your application remains the system of record for orders and fulfilment.

## Required callback design

```text theme={null}
Payment provider
        ↓ raw callback
Your HTTPS backend endpoint
        ↓ validate provider evidence + call AvraAPI completion server-side
Normalized verified result
        ↓
Your order database / fulfilment decision
```

## Verification rules

* Use an HTTPS callback endpoint you control.
* Preserve the raw request form/body only for the immediate verification workflow; never send it through browser code.
* Validate the provider signature, original merchant order reference, amount, currency, gateway environment, and any provider transaction binding.
* Use the signed completion context created with the original checkout session.
* Make order fulfilment idempotent. Providers may retry a callback or a browser may revisit a return page.
* Return a safe acknowledgement according to the provider’s documentation, but do not claim success before verification finishes.

## Browser returns are informational

A return URL may be used to show a pending or confirmation screen, but it is not authoritative payment proof. A gateway overlay event, query parameter, or success-looking browser redirect is also not enough.

<Warning>
  Do not log callback signatures, full raw provider payloads, card data, or Vault credentials. Store only the minimum order evidence required by your own retention and reconciliation policy.
</Warning>

For the UPG completion contract and result shape, see [Webhooks & Completion](/universal-payment-gateway/advanced-setup/webhooks-and-completion).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.