API keys (Authorization: Basic)
Allow-list of API keys, format klarna_<live|test>_api_<random> (research §2). The optional username is the Merchant-Portal UUID for the legacy <UUID>:<API key> basic form. Wrong/missing credentials → 401.
Overrides
Fallback notification/push URLs (used when the session sets no merchant_urls) and the default new-gen webhook (URL + signing key + key id).
Payment sessions
Authorize headlessly or open the Hosted Page (widget stand-in).
Orders
PENDING orders can be resolved here — fires the FRAUD_RISK_* notification.
Registered webhooks (new facility)
Webhook & notification deliveries
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults