Receiving asynchronous updates.
WHAT A NOTIFICATION IS
A message from the provider reporting a transaction's outcome.
WHY IT EXISTS
The customer may never return to your site, so the redirect cannot be relied upon.
WHAT TO NEVER DO
Fulfil based on the redirect alone.
WHAT TO VERIFY
The signature, proving the message came from the provider The transaction, by querying the provider directly
WHY BOTH
Signatures can be misimplemented, and querying is definitive.
WHAT TO MAKE THE HANDLER
Idempotent, since notifications are retried and may arrive several times.
HOW
Record processed references, and ignore repeats.
WHAT TO RESPOND WITH
Success, quickly.
WHY QUICKLY
Providers time out and retry, producing duplicates.
WHAT TO DO WITH SLOW WORK
Queue it, and respond immediately.
WHAT TO HANDLE
Notifications arriving before your own record exists Notifications for transactions you do not recognise Status changes after initial success, such as a later reversal
WHAT TO LOG
Every notification received, raw.
WHY
It is the evidence when a payment is disputed internally.
WHAT TO MONITOR
Notifications failing to process, which silently lose orders.