API keys (Basic-auth allow-list)
secret key (sk_) = full access, publishable key (pk_) = pay-session only
Webhook settings
notification URL, X-Komoju-Signature secret, and the signature-corruption knob
Sessions
open the hosted checkout, then pay or cancel
Payments
settle konbini/bank asynchronously, capture, refund, cancel or expire
Events / webhooks
re-fire a delivery to test duplicate handling
Requests from the backend
Webhook deliveries
Danger zone
wipes payments, logs and every runtime override — back to configured defaults