> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Missing embedded events - Hosted checkout

> Why embedded checkout events might not arrive, and how to debug the listener.

<Info>
  **TL;DR:** If the iframe loads but events never arrive, it's almost always a listener-timing or origin mismatch.
</Info>

RadiumOne Checkout only posts `CHECKOUT_*` events to your page's origin if that origin is one you've registered — even if the iframe itself loaded successfully. A registered-but-mismatched origin, or a listener attached too late, both look the same: the iframe works, but your page never hears from it.

## When this happens

* Your listener is attached after the iframe has already posted its first event (most commonly `CHECKOUT_READY`).
* The origin RadiumOne resolves for your page doesn't match what you expect — on browsers that expose `window.location.ancestorOrigins` (Chrome, Safari), that's used directly; **Firefox** doesn't expose it, so RadiumOne falls back to the origin derived from your `success_url` instead.
* Your `success_url` origin doesn't match your embedding page's real origin, so the Firefox fallback resolves to the wrong host and every message is silently dropped rather than sent to the wrong place.

## What you see

| Signal | Value |
| - | - |
| Iframe | Loads and renders normally |
| `message` events | Never arrive at your listener |
| Network | No error — a mismatched target origin is dropped silently, by design, rather than sent anywhere |

## What to do

<Steps>
  <Step title="Attach your listener before the iframe loads">
    Add the `message` event listener before setting the iframe's `src`, not after — a `CHECKOUT_READY` posted before your listener exists is simply missed, with no way to replay it.
  </Step>

  <Step title="Check event.origin matches the checkout host">
    ```javascript theme={null}
    window.addEventListener("message", (event) => {
      if (event.origin !== CHECKOUT_ORIGIN) return; // confirm this isn't rejecting everything
      // ...
    });
    ```

    See [Embed hosted checkout](/hosted-checkout/embedded-integration#steps) for the full listener example.
  </Step>

  <Step title="On Firefox, make sure success_url shares your embedding page's origin">
    Since Firefox doesn't expose the real parent-frame origin, RadiumOne derives the target from `success_url` instead. If that origin doesn't match your actual embedding page, every event is dropped rather than misdirected — align `success_url`'s origin with your embedding page's origin to fix it.
  </Step>

  <Step title="Never fulfil on the event, once it does arrive">
    A received event is a UX signal only — confirm the outcome server-side regardless. See [Verify the payment result](/hosted-checkout/verify-payment-result).
  </Step>
</Steps>

## Related

<Columns cols={2}>
  <Card title="Embedded checkout events" icon="webhook" href="/hosted-checkout/reference/embedded-events">
    The full event and payload reference.
  </Card>

  <Card title="Embed hosted checkout" icon="panel-top" href="/hosted-checkout/embedded-integration">
    The full embedded integration guide.
  </Card>

  <Card title="Fix embedded checkout that won't load" icon="rectangle-ellipsis" href="/hosted-checkout/handle-failures/embedded-checkout-not-loading">
    When the iframe itself doesn't render.
  </Card>

  <Card title="Handle failures" icon="triangle-alert" href="/hosted-checkout/handle-failures/overview">
    All ten failure scenarios, symptom → page.
  </Card>
</Columns>
