PP

PayPay emulator

admin — changes apply immediately, defaults come from config

Merchants (apiKey / secret / X-ASSUME-MERCHANT)

Allow-list of OPA credentials. A bad/missing/expired HMAC Authorization header, unknown apiKey, or disallowed X-ASSUME-MERCHANT → the documented 401 UNAUTHORIZED envelope (§2).

Overrides

Merchant notification (webhook) URL. Per-code webhookUrl on create wins over this.

QR codes / payments

Web Cashier sessions. Lifecycle buttons bypass the hosted page and fire the matching notification.

Refunds

Notification deliveries

Requests from the backend

Danger zone

wipes payments, logs and every runtime override — back to configured defaults