API keys (key_id / key_secret)
HTTP Basic allow-list. A missing/unknown key → HTTP 401 {"error":{"code":"BAD_REQUEST_ERROR","description":"Authentication failed"}} (§1/§9).
Overrides
Webhook URL, the X-Razorpay-Signature secret, and a switch to corrupt outbound signatures (bad-signature tests, §8.1).
Orders
Pay against an order to mint a payment (authorize / capture / fail bypass the checkout page).
Payments
Payment links
Refunds
Webhook deliveries
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults