Skip to main content
TL;DR: A session create that returns 422 embed:origins_not_configured means no domain is registered at all. A blank iframe on a created session means the embedding domain isn’t registered or the CSP doesn’t allow framing. A registered iframe that never posts events means an origin mismatch. Neither postMessage event is authenticated — always confirm server-side.

Events that signal failure

Full payload shapes live on the embedded events reference — this table only covers the events that mean the attempt didn’t succeed.
There is no CHECKOUT_CANCELLED event — a shopper closing or navigating away from the iframe posts nothing at all. See Handle abandoned checkouts.

Origin rejection

Full walkthrough: Debug missing embedded checkout events.

Not loading

Full walkthrough: Fix embedded checkout that won’t load.

Next steps

Embedded events reference

Full event and payload reference.

Embed hosted checkout

The full embedded integration guide.

API errors

Checkout API error codes, including security:domain_not_allowed.

Handle failures

Ten common failure scenarios, each with the exact signal and what to do.
Last modified on September 15, 2026