API keys (secret / publishable)
Allow-list of key pairs. Requests use Authorization: Bearer <secretKey>; a missing/unknown key → the documented 401 envelope. The secretKey also keys the webhook hashstring (§2/§7).
Overrides
Default charge post.url (webhook) used when a charge omits its own.
Charges
capture / decline / authorize / void / refund / re-notify / corrupt-sig — lifecycle actions auto-fire the signed webhook.
Refunds
Webhook deliveries
Requests from the backend
Danger zone
wipes payments, logs and every runtime override — back to configured defaults