> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Glossary - Resources

> Key prefixes and terms used across RadiumOne's hosted checkout, Elements, 3D Secure, and Payments API documentation.

## Prefixes

RadiumOne identifiers are prefixed by type, so you can tell what an ID is from its shape alone.

| Prefix | Identifier | Where it's used |
| - | - | - |
| `r1sk_test_…` / `r1sk_prod_…` | Secret key | Server-only Payments API and Checkout API requests |
| `r1pk_test_…` / `r1pk_prod_…` / `r1pk_mock_…` | Publishable key | Browser-safe: Elements, hosted-checkout session verification |
| `r1rt_…` | Refresh token | Server-only; exchanges for a new access token |
| `rsec_…` | Redirect secret | Signs and verifies hosted-checkout redirect callbacks |
| `whsec_…` | Webhook secret | Verifies webhook signatures |
| `chk_` + 32 lowercase hex chars | Checkout session ID | Hosted-checkout session, returned from session create and used in the payment URL |
| `evt_…` | Webhook event ID | Envelope `id` on every webhook delivery, used for dedup |

See [Sandbox and API keys](/get-started/sandbox-and-api-keys#key-types) for the full key-type table and [Authentication](/get-started/api-basics/authentication) for the token exchange.

## Terms

| Term | Meaning |
| - | - |
| **Outlet** | A store or location within your merchant account. A key can be bound to a specific outlet; omitting `outlet_id` on a request uses the key's bound outlet. |
| **Channel** | How the payment was initiated: `CARD_PRESENT`, `ECOMMERCE`, `MOTO`, `PAYMENT_LINK`, `IN_APP`, or `RECURRING`. |
| **Scope** | A permission on a secret or publishable key (for example, `payment-gateway:transaction-create`, `transaction-refund-unreferenced`). See [Sandbox and API keys](/get-started/sandbox-and-api-keys#least-privilege-keys). |
| **Idempotency key** | A caller-supplied value (`request_id` or `operation_id`) that makes a create or follow-up request safely retryable. See [Prevent duplicate payments](/get-started/api-basics/prevent-duplicate-payments). |
| **Replay** | Sending the same idempotency key and body a second time. RadiumOne returns the original transaction instead of creating a new one — whatever its status, including `PENDING` or `DECLINED`. |
| **`request_id`** | A caller-supplied idempotency key (8–64 characters) on create-type requests (purchase, authorize, standalone refund, balance inquiry). Reusing the same `request_id` with the same body replays the original result; a different body under the same key fails with `409 idempotency-body-mismatch`. |
| **`operation_id`** | The idempotency key used to reference an existing transaction for capture, void, or referenced refund. A replay with the same operation type returns the original result **without comparing the body** — a changed amount is silently ignored, not rejected. Reusing it for a different operation type fails with `409 duplicate-operation`. |
| **`order_reference`** | Your own reference for a checkout session. RadiumOne deduplicates on it only for the session's TTL (5–60 minutes; default 10 minutes in production, 25 in sandbox) — after it expires, the same value creates a **new** session. Not a durable order ID: store the resulting `transaction_id` in your own order record instead. |
| **Bind / tokenization** | The process by which Elements exchanges raw card details for a `card.token`, without the card number ever reaching your server. |
| **Card token** | The opaque, digit-only reference returned by tokenization. Not a PAN — see [Security and PCI scope](/resources/security-and-pci#card-tokens). |
| **Settlement batch** | The window during which a terminal's captured transactions can still be voided; once it closes, only a refund can reverse a transaction. See [Void or refund, never both](/payments-api/void#void-or-refund-never-both). |
| **Capture window** | The number of days after authorization within which a capture is still allowed. |
| **3DS arm (`three_ds`)** | One of three mutually exclusive request shapes for supplying 3D Secure evidence to a charge: a `ref` from RadiumOne's own 3DS flow, `{mode: "non_payer_auth"}`, or external-provider evidence (`cavv`, `eci`, `ds_transaction_id`, `version`). |
| **ECI (electronic commerce indicator)** | The scheme-specific code returned by a 3DS authentication that determines whether liability shifts to the card issuer. See [Use your own 3DS provider](/payments-api/three-d-secure/use-your-own-provider#eci-values). |
| **CAVV / AAV** | The cryptographic authentication value a 3DS provider returns as evidence that a challenge was completed. |
| **MPI (merchant plug-in)** | A merchant's own 3D Secure authentication component, as opposed to RadiumOne's built-in 3DS. See [Use your own 3DS provider](/payments-api/three-d-secure/use-your-own-provider). |
| **URN** | The structured error identifier RadiumOne returns in error responses, for example `urn:radiumone:auth:insufficient-scope`. See [Problem format and retries](/payments-api/errors/problem-format-and-retries). |
| **Loyalty redemption / net payable amount** | The portion of an order paid with loyalty points versus card. `amount` on a purchase is always the gross order total; `net_payable_amount` (Beta) pins the card-payable remainder that 3DS authenticates. See [UOB Rewards](/payments-api/payment-methods/uob-rewards/overview). |
| **Discovery** | The mechanism by which a checkout surface advertises which payment methods and loyalty programmes are potentially available — advisory only, not a guarantee the method will complete. |
| **Enablement** | Support-provisioned account configuration required before certain features work in production — see [Request enablement](/resources/support#request-enablement). |

## Next steps

<Columns cols={2}>
  <Card title="Sandbox and API keys" icon="key" href="/get-started/sandbox-and-api-keys">
    Key types, prefixes, and scopes in full.
  </Card>

  <Card title="Problem format and retries" icon="triangle-alert" href="/payments-api/errors/problem-format-and-retries">
    URN error shapes and HTTP codes.
  </Card>
</Columns>
