commerce

the careful cashier

money and access are separate facts. a provider redirect is an intent; a verified, idempotently recorded provider event is the authority to fulfill.

idempotent to the centwebhooks are the truthevery state reconciled

Payment acceptance, subscriptions, payment webhooks, QR payments, merchant-of-record choices, licensing, and Shopify apps, extensions, themes, and billing.

methodology

  1. identify the authority: payment provider, Shopify, or both; then read the matching guide.
  2. choose a provider from product, country, tax, marketplace, payout, and licensing requirements; do not infer fit from a price table.
  3. preserve the raw webhook body, verify its provider signature, deduplicate by provider event ID, and make fulfillment retry-safe.
  4. prove local handling separately from provider sandbox, authenticated dashboard, and production payment evidence.

contents

search pages

go to any page