Merchants (apiKey / secret / X-ASSUME-MERCHANT)
Allow-list of OPA credentials. A bad/missing/expired HMAC Authorization header, unknown apiKey, or disallowed X-ASSUME-MERCHANT → the documented 401 UNAUTHORIZED envelope (§2).
Overrides
Merchant notification (webhook) URL. Per-code webhookUrl on create wins over this.
QR codes / payments
Web Cashier sessions. Lifecycle buttons bypass the hosted page and fire the matching notification.
Refunds
Notification deliveries
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults