> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Embedded checkout errors - Hosted checkout

> Failure events, origin rejection, and load failures in embedded (iframe) mode.

<Info>
  **TL;DR:** A session create that returns `422 embed:origins_not_configured`
  means no domain is registered at all. A blank iframe on a created session
  means the embedding domain isn't registered or the CSP doesn't allow
  framing. A registered iframe that never posts events means an origin
  mismatch. Neither `postMessage` event is authenticated — always confirm
  server-side.
</Info>

## Events that signal failure

Full payload shapes live on the [embedded events
reference](/hosted-checkout/reference/embedded-events) — this table only
covers the events that mean the attempt didn't succeed.

| Event | Meaning | What to do | Retry? |
| - | - | - | - |
| [`CHECKOUT_ERROR`](/hosted-checkout/reference/embedded-events#checkout-error) | A network or client-side error interrupted the payment attempt | See [Handle payment service outages during checkout](/hosted-checkout/handle-failures/payment-service-unavailable); confirm server-side before retrying | Confirm nothing was charged first |
| [`CHECKOUT_EXPIRED`](/hosted-checkout/reference/embedded-events#checkout-expired) | The session's TTL elapsed while the shopper was submitting payment | See [Handle expired checkout sessions](/hosted-checkout/handle-failures/session-expired) | Start a new session |
| [`CHECKOUT_DECLINED`](/hosted-checkout/reference/embedded-events#checkout-declined) | The payment was declined | See [Payment outcomes](/hosted-checkout/errors/payment-outcomes#decline) | Start a new session with a new `order_reference` |

<Note>
  There is no `CHECKOUT_CANCELLED` event — a shopper closing or navigating
  away from the iframe posts nothing at all. See [Handle abandoned
  checkouts](/hosted-checkout/handle-failures/shopper-abandons-checkout).
</Note>

## Origin rejection

| Signal | Cause | What to do |
| - | - | - |
| <a id="origin-rejection" />Iframe loads, but no `message` event ever arrives at your listener | Your embedding page's origin isn't in your registered `allowed_domains` — RadiumOne only posts to a registered origin | Register your exact embedding host — see [Sandbox and API keys](/get-started/sandbox-and-api-keys) |
| Events arrive on Chrome/Safari but not Firefox | Firefox doesn't expose `window.location.ancestorOrigins`; RadiumOne falls back to the origin derived from `success_url`, which must match your embedding page's real origin | Align `success_url`'s origin with your embedding page — see [Debug missing embedded checkout events](/hosted-checkout/handle-failures/embedded-events-not-received) |
| Listener attached but nothing received, even the initial `CHECKOUT_READY` | Listener attached after the iframe already posted its first event | Attach the `message` listener before setting the iframe's `src` |

Full walkthrough: [Debug missing embedded checkout events](/hosted-checkout/handle-failures/embedded-events-not-received).

## Not loading

| Signal | Cause | What to do |
| - | - | - |
| Session create returns [`422 embed:origins_not_configured`](/hosted-checkout/errors/api-errors#checkout-embed-origins-not-configured) | No `allowed_domains` entry is usable as a frame origin — the create is refused outright | Register at least one domain — see [Sandbox and API keys](/get-started/sandbox-and-api-keys) |
| <a id="not-loading" />Iframe stays blank, no card form | Your embedding domain isn't registered, or your page's CSP doesn't allow framing the checkout host | Register the domain and set `frame-src` — see [Fix embedded checkout that won't load](/hosted-checkout/handle-failures/embedded-checkout-not-loading) |
| Session create returns [`security:domain_not_allowed`](/hosted-checkout/errors/api-errors#checkout-security-domain-not-allowed) | Same allow-list check applies to `success_url`/`cancel_url` on create | Register the host |
| Blank iframe even after registering | Mixed content — embedding page served over plain HTTP; or the session predates this release's frame-origin fix | Serve the embedding page over HTTPS; create a new session if it's an old one |

Full walkthrough: [Fix embedded checkout that won't load](/hosted-checkout/handle-failures/embedded-checkout-not-loading).

## Next steps

<Columns cols={2}>
  <Card title="Embedded events reference" icon="webhook" href="/hosted-checkout/reference/embedded-events">
    Full event and payload reference.
  </Card>

  <Card title="Embed hosted checkout" icon="panel-top" href="/hosted-checkout/embedded-integration">
    The full embedded integration guide.
  </Card>

  <Card title="API errors" icon="triangle-alert" href="/hosted-checkout/errors/api-errors">
    Checkout API error codes, including `security:domain_not_allowed`.
  </Card>

  <Card title="Handle failures" icon="life-buoy" href="/hosted-checkout/handle-failures/overview">
    Ten common failure scenarios, each with the exact signal and what to do.
  </Card>
</Columns>
