Skip to main content
When a checkout session runs in mode: "embed", RadiumOne Checkout posts messages to the parent page via window.postMessage. Every message shares one envelope:
These events are not authenticated — any page can attempt to post a same-shaped message. Always check event.origin against the RadiumOne Checkout host and event.data.source === "radiumone-checkout" before handling a message, and never fulfil an order from an event alone. Confirm server-side — see Verify the payment result.

Origin rules

  • Listen for message events and filter on event.origin equal to the RadiumOne Checkout host your session’s checkout_url was served from.
  • RadiumOne only posts to your page’s origin if that origin is in your registered allowed_domains. On browsers that expose window.location.ancestorOrigins (Chrome, Safari), the real parent-frame origin is used; Firefox doesn’t expose it, so RadiumOne falls back to the origin derived from your success_url — make sure that origin matches your embedding page.

Events

event
The card form has finished loading in the iframe.
event
The iframe’s content height changed — resize your <iframe> element to match.
event
The payment was approved. Advisory only — confirm with your server before fulfilling.
event
The payment outcome isn’t known yet (asynchronous processing). Wait for a webhook or poll your server.
event
The payment was declined.
event
The session’s TTL elapsed while the shopper was submitting payment.
event
A network or client-side error interrupted the payment attempt — see Handle payment service outages during checkout.
There is no CHECKOUT_CANCELLED event today — a shopper closing or navigating away from the iframe does not post a message. See Handle abandoned checkouts for how to detect this case instead.

Example listener

See Embed hosted checkout for the full integration guide, or Embedded checkout errors if your listener never fires or the iframe won’t load.
Last modified on September 15, 2026