Webhooks
Signed, deduplicated events are your source of truth for asynchronous rails.
PayFlow signs every webhook and delivers it with retries and backoff. Validate the signature, deduplicate by event id, and make your handler idempotent.
Payment success, failure, pending, cancellation and expiry are all delivered as events. Never fulfil on a browser redirect alone.
Events
payment.succeeded, payment.failed, payment.pending, payment.cancelled, payment.expired — plus delivery diagnostics you can replay from the Merchant portal.