REST apps (client_id / client_secret)
Allow-list of app credentials for POST /v1/oauth2/token. Unknown pairs get the documented 401 {error: invalid_client} (§2.2).
Overrides
Webhook listener URL and the webhook subscription id receivers verify signatures against (§6.3).
Orders
CREATED orders can be approved headlessly (what the Hosted Page does); terminal ones re-notified.
Captures / authorizations / refunds
Webhook deliveries
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults