TL;DR: A session create that returns
422 embed:origins_not_configured
means no domain is registered at all. A blank iframe on a created session
means the embedding domain isn’t registered or the CSP doesn’t allow
framing. A registered iframe that never posts events means an origin
mismatch. Neither postMessage event is authenticated — always confirm
server-side.Events that signal failure
Full payload shapes live on the embedded events reference — this table only covers the events that mean the attempt didn’t succeed.There is no
CHECKOUT_CANCELLED event — a shopper closing or navigating
away from the iframe posts nothing at all. See Handle abandoned
checkouts.Origin rejection
Full walkthrough: Debug missing embedded checkout events.
Not loading
Full walkthrough: Fix embedded checkout that won’t load.
Next steps
Embedded events reference
Full event and payload reference.
Embed hosted checkout
The full embedded integration guide.
API errors
Checkout API error codes, including
security:domain_not_allowed.Handle failures
Ten common failure scenarios, each with the exact signal and what to do.