Sites (X-SITE-ID / secretKey / publicKey)
Allow-list of site credentials. Unknown X-SITE-ID or a bad X-REQUEST-SIGNATURE → the documented 400 envelope (Code 7038). publicKey also doubles as the HMAC key for /webpayments/* (§2.1).
Overrides
Cabinet "URL оповещения" (webhook URL) and the X-REQUEST-ID strictness switch (§2.3).
Transactions
Pay/Block/Rebill/Payout — lifecycle actions bypass the test-card matrix.
Subscriptions & rebill tokens
Paylinks / widget pages
Webhook deliveries
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults