Skip to main content
TL;DR: A missing or invalid sig means don’t trust the redirect — confirm the result another way.
If you’ve configured a redirect secret, a successful return to success_url carries checkout_id, status, transaction_id, ts, and sig. Anything wrong with sig — missing, malformed, or not matching — means you can no longer trust that the URL wasn’t altered in the shopper’s browser.

When this happens

  • No redirect secret is configured for your account — the redirect is unsigned by design, not by defect.
  • The shopper’s browser (or something in front of it) altered the query string.
  • ts is older than 5 minutes when you verify it — treat this the same as an invalid signature, even if sig itself would otherwise check out.
  • You verify with the wrong key encoding — the redirect signature’s HMAC key is the full rsec_… string, used directly. This is different from the webhook signature’s key, which is hex-decoded after stripping whsec_. Using either encoding for the wrong signature makes it fail every time.

What you see

Treat any client-side redirect or callback as a hint only. Always confirm the final payment status from your server, using an authenticated GET request or a webhook — never from a query parameter or browser postMessage alone.

What to do

1

Fail closed

If a redirect secret is configured for your account and the redirect is missing sig, or sig doesn’t verify, or ts is stale — treat the return as unverified. Never treat it as confirmation of payment.
2

Verify with the correct key and payload

Also confirm that checkout_id in the URL matches the ID your server stored for that order before trusting anything else in the URL — state is not part of the signed payload, so verify it independently if you rely on it.
3

Confirm the real outcome regardless

Whether or not sig verifies, get the authoritative result before fulfilling (API reference):

Prevent it

  • Keep the previous redirect secret in your own verifier for up to 65 minutes after rotating one (the 60-minute maximum session lifetime, plus the 5-minute ts tolerance) — see Redirect secret: rotate, don’t delete.
  • Don’t delete your redirect secret as a routine operation — doing so removes sig from every redirect going forward, not just the ones you intend.

Verify the payment result

The full decision table and the redirect secret’s rotation semantics.

Redirect and signature errors

Every signal reference, with a stable anchor per case.

Handle failures

All ten failure scenarios, symptom → page.
Last modified on September 15, 2026