API keys (secret / public / shop)
Allow-list of fincode credentials. A missing/unknown Bearer (or Basic) secret key → the documented 401 envelope (§2). The public key mirrors fincode.js; shop_id is echoed in responses/webhooks.
Overrides
Fallback notification URL + its Fincode-Signature token, and a knob to corrupt every outbound signature (§6.2 negative tests).
Payments
Register→execute two-step card + konbini. Actions: execute, capture, cancel, complete-3DS, konbini-paid, re-notify.
Payment sessions (hosted pages)
Webhook subscriptions
Webhook deliveries
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults