Getting started and choosing an integration
What's the difference between hosted checkout and Elements?
What's the difference between hosted checkout and Elements?
Can I switch between hosted checkout and Elements later?
Can I switch between hosted checkout and Elements later?
Do I need to build my own payment page?
Do I need to build my own payment page?
Which integration paths support 3D Secure?
Which integration paths support 3D Secure?
Accounts, keys and environments
How do I get sandbox and production API keys?
How do I get sandbox and production API keys?
What's the difference between a secret key and a publishable key?
What's the difference between a secret key and a publishable key?
r1sk_…) is server-only and can create and manage transactions. A publishable key (r1pk_…) is browser-safe and can only create or bind a session — never a payment. See Key types.Are sandbox and production completely separate?
Are sandbox and production completely separate?
_test_ key only ever works against sandbox, and a _prod_ key only against production. See Environments and hosts.What scopes does a secret key have by default, and is a scope enough to perform an operation?
What scopes does a secret key have by default, and is a scope enough to perform an operation?
Can a key be bound to a specific store or outlet?
Can a key be bound to a specific store or outlet?
outlet_id on a request uses the key’s bound outlet; sending an outlet_id the key isn’t bound to fails with a 403. See Outlet-scoped keys.Payments and refunds
What's the difference between void and refund?
What's the difference between void and refund?
Are refunds enabled by default?
Are refunds enabled by default?
REFUND operation explicitly enabled before a referenced or standalone refund succeeds. See Refunds require enablement.Can I issue a partial refund, or refund a payment more than once?
Can I issue a partial refund, or refund a payment more than once?
What's a standalone refund, and when should I use it?
What's a standalone refund, and when should I use it?
Which payment methods does RadiumOne support today?
Which payment methods does RadiumOne support today?
Duplicates, timeouts and reliability
What should I do if a payment request times out?
What should I do if a payment request times out?
request_id — resend the identical body with the same request_id, or wait for the confirming webhook; RadiumOne replays the stored result whatever it turned out to be. See Retry safely after a timeout.What happens if I reuse a request_id with a different body?
What happens if I reuse a request_id with a different body?
409 body-mismatch error instead of creating a new transaction or applying your change — resend the stored original body, or mint a genuinely new key for a new attempt. See How RadiumOne reacts to a repeated request.Is order_reference a reliable way to prevent duplicate orders?
Is order_reference a reliable way to prevent duplicate orders?
order_reference uniqueness at the gateway, so you must check your own order record before creating a new session or retrying a payment. See The defence layers.Are webhooks or the synchronous API response the source of truth?
Are webhooks or the synchronous API response the source of truth?
PENDING or time out entirely, so treat webhooks — deduped on the event id — as authoritative for reconciliation, not just a convenience notification. See Webhooks are the source of truth.How do I check a transaction's status directly instead of guessing?
How do I check a transaction's status directly instead of guessing?
id you already have — it asks the acquirer directly and writes nothing. See Check a transaction’s status.Hosted checkout
Should I use redirect or embedded checkout?
Should I use redirect or embedded checkout?
allowed_domains first. See Redirect vs embedded.Is embedded hosted checkout available today?
Is embedded hosted checkout available today?
allowed_domains — session create returns 422 embed:origins_not_configured if none is configured. See Embed hosted checkout.How long does a checkout session last?
How long does a checkout session last?
ttl_minutes explicitly (5–60); if you omit it, the session uses your environment’s default — 10 minutes in production, 25 in sandbox. See Expiry (TTL).How do I verify a hosted checkout payment result?
How do I verify a hosted checkout payment result?
GET request — never from the redirect query string or a postMessage event alone. See Verify the payment result.Can I cancel a checkout session?
Can I cancel a checkout session?
pending. Cancelling a session that’s already processing or reached a terminal state returns a 409. See Merchant cancellation.What if the shopper closes the tab instead of completing checkout?
What if the shopper closes the tab instead of completing checkout?
pending until it expires — closing the tab or clicking back doesn’t cancel it. Call the cancel endpoint yourself if you need it cancelled sooner. See Merchant cancellation.Elements SDK
Does Elements reduce my PCI scope?
Does Elements reduce my PCI scope?
Which browsers does Elements support?
Which browsers does Elements support?
Is 3D Secure available with Elements?
Is 3D Secure available with Elements?
What Content Security Policy does Elements need?
What Content Security Policy does Elements need?
connect-src. Adding 3D Secure needs your API origin in connect-src, scoped to your checkout and 3DS-return routes only. See Content Security Policy.Webhooks
How do I verify a webhook signature?
How do I verify a webhook signature?
X-RadiumOne-Signature header against the raw request body with HMAC-SHA256 and a constant-time comparison, before you trust anything in the payload. See Verify webhook signatures.Are webhook deliveries ordered and exactly-once?
Are webhook deliveries ordered and exactly-once?
id, and use created_at (or a fresh status read) if you need the true sequence. See Retries, ordering, and duplicates.What happens if my webhook endpoint is down or broken?
What happens if my webhook endpoint is down or broken?
410) can be suspended and receives nothing until support reactivates it. See Endpoint suspension.Testing and going live
Can I use real card numbers in sandbox?
Can I use real card numbers in sandbox?
What should I check before requesting production access?
What should I check before requesting production access?
Security and compliance
How do I keep my API keys safe?
How do I keep my API keys safe?
Do the webhook signature and the redirect signature use the same key encoding?
Do the webhook signature and the redirect signature use the same key encoding?
whsec_; the redirect signature’s key is the full rsec_… string used directly. Using the wrong encoding makes every signature fail to verify. See Verify webhook signatures.Support and versioning
How do I contact support or request a gated feature?
How do I contact support or request a gated feature?
How does RadiumOne version its APIs and SDKs?
How does RadiumOne version its APIs and SDKs?
/v1/...), with additive-only changes shipping inside a version. The Elements SDK follows semantic versioning — pin to a specific version rather than always loading latest. See Versioning and deprecation.