Verifying callbacks
Your resultUrl is a public endpoint — anything on the internet can POST to
it. Treat the result callback as a signal
that something changed, and confirm the actual outcome with Pesepay before
you fulfil an order.
How to verify
Section titled “How to verify”-
Check the
Authorizationheader. Pesepay sends your application’s own integration key in it. Compare it against the key you hold and reject the request if it doesn’t match — this filters out casual forged posts cheaply. -
Confirm the outcome server-to-server. Take
referenceNumberfrom the payload and call Check Payment Status. That response is authenticated with your integration key and encrypted with your encryption key, so it can’t be forged. Act on that status, not on the status in the callback body. -
Match it to your own order. Look the
referenceNumberup in your database. If you don’t recognise it, return2xxand ignore it — never create an order from a callback you didn’t originate. -
Check the amount. Compare
amountDetails.amountandamountDetails.currencyCodeagainst what your order expects before fulfilling.
Idempotency
Section titled “Idempotency”Make the handler safe to run twice for the same referenceNumber —
record which references you’ve already processed and short-circuit on a
repeat. A duplicate delivery, a retried request from your own
infrastructure, or a reconciliation job catching up can all deliver the
same result more than once.