Skip to content
AutoCore1.0.0-rc.1 · Release Candidate
1.0.0-rc.1 · Release Candidate1 min read

Payment and Webhook API Reference

Payment order, checkout, refund, and provider callback boundaries.

Treat webhooks as public transport with private verification and replay controls.

Source boundary

Source boundary: AutoCore current main 7a504f6e430c16d4fcb03ebdea3cc3fb7816df60, checked against immutable v1.0.0-rc.1 at 9edfb109f44cc80385784c694b96392cfc04e70f.

The audit finds seven payment methods plus two webhook methods. Provider signatures, raw-body integrity, event idempotency, amount/currency reconciliation, and audit outcomes are provider-specific controls.

CheckSource-backed expectation
ScopeProvider activation remains explicitly configured and safety-locked; this page does not authorize live payments.
EvidenceUse placeholders, timestamps, release identity, route, status, and request ID where relevant.
Safe actioncurl -i -H 'content-type: application/json' https://api.example.invalid/api/v1/payments/webhook
Stop conditionUnknown authorization, destructive impact, secret exposure, or conflicting evidence.

Verification

Run the safe check, record its result, and compare the outcome with the documented contract. If the result depends on external configuration or provider availability, mark it as configuration-dependent rather than claiming a product guarantee.

Code
curl -i -H 'content-type: application/json' https://api.example.invalid/api/v1/payments/webhook

Safety boundary

Examples are non-production and use placeholders. Do not deploy, reset, force a migration, create secrets, activate providers, replay sensitive work, or expose private data from this page.

Related articles