TL;DR: Only a signed success return proves the URL wasn’t altered in
the browser — and even then, that’s not proof a charge happened. Every
other return carries no verifiable signal at all.
Params by outcome
state is only ever present on a success return, and only if you sent
one on create — it is never part of the signed payload (see below), so
verify it independently if you rely on it for CSRF-style correlation.Signature errors
Next steps
Verify the payment result
The full trust hierarchy and redirect secret rotation semantics.
Reject invalid redirect signatures
Step-by-step handling for a missing or invalid signature.
Payment outcomes
What a decline, expiry, or cancellation looks like at the redirect layer.
API errors
Checkout API error codes for create/retrieve/cancel.