Skip to main content
TL;DR: Only a signed success return proves the URL wasn’t altered in the browser — and even then, that’s not proof a charge happened. Every other return carries no verifiable signal at all.

Params by outcome

state is only ever present on a success return, and only if you sent one on create — it is never part of the signed payload (see below), so verify it independently if you rely on it for CSRF-style correlation.

Signature errors

Fail closed. If a redirect secret is configured for your account and a return is missing sig, has an invalid sig, or a stale ts — never treat it as confirmation of payment. See Reject invalid redirect signatures for the full walkthrough.

Next steps

Verify the payment result

The full trust hierarchy and redirect secret rotation semantics.

Reject invalid redirect signatures

Step-by-step handling for a missing or invalid signature.

Payment outcomes

What a decline, expiry, or cancellation looks like at the redirect layer.

API errors

Checkout API error codes for create/retrieve/cancel.
Last modified on September 15, 2026