Money over an interface.
WHAT MAKES THEM DIFFERENT
Errors have financial consequences Outcomes may be uncertain Regulation applies
WHAT TO NEVER DO
Handle raw card details yourself, unless you are equipped for that obligation.
WHAT TO DO INSTEAD
Use the provider's hosted fields or redirect, so the details never reach your server.
WHAT AN IDEMPOTENCY KEY IS FOR HERE
Ensuring a retried charge does not charge twice.
WHAT TO TREAT A TIMEOUT AS
Unknown, never failure.
WHAT TO DO ABOUT IT
Query the transaction's status before acting.
WHAT TO RELY ON FOR THE FINAL OUTCOME
The provider's notification, not the immediate response.
WHY
Payments complete asynchronously, and the initial response is not the end.
WHAT TO VERIFY ON EVERY NOTIFICATION
The signature That the amount and currency match what you expected That you have not already processed it
WHY THE AMOUNT CHECK MATTERS
It prevents a forged or altered notification granting value.
WHAT TO RECORD
Every request and response, with identifiers.
WHY
Disputes are resolved from records.
WHAT TO RECONCILE
Your records against the provider's settlement reports.
HOW OFTEN
Daily.
WHAT TO BUILD
A way to see a transaction's full history.
WHAT TO TEST
Failed payments, refunds and disputes, not only success.