Merchants (Server Key / Client Key / Merchant ID)
Allow-list of merchant keys. Basic-auth username = Server Key (empty password). A bad/unknown key → the documented 401 (Core: status_code/status_message envelope; Snap: error_messages array). The Server Key is also the SHA512 signature key for notifications (§2/§7).
Overrides
Dashboard Payment Notification URL (per-transaction X-Override-Notification wins).
Core transactions (charges)
settle / deny / cancel / expire / refund / re-notify — buttons drive the same transitions the real API does, and auto-fire the HTTP notification with a verifiable signature_key.
Snap tokens
HTTP notifications delivered
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults