PP

PayPal emulator

admin — changes apply immediately, defaults come from config

REST apps (client_id / client_secret)

Allow-list of app credentials for POST /v1/oauth2/token. Unknown pairs get the documented 401 {error: invalid_client} (§2.2).

Overrides

Webhook listener URL and the webhook subscription id receivers verify signatures against (§6.3).

Orders

CREATED orders can be approved headlessly (what the Hosted Page does); terminal ones re-notified.

Captures / authorizations / refunds

Webhook deliveries

Requests from the backend

Danger zone

wipes payments, logs and every runtime override — back to configured defaults