> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Support - Resources

> Contact channels, emergency key revocation, what to include in a support request, and how to request enablement for gated features.

<Tip>
  Before you contact support, check the [frequently asked questions](/resources/faq) — many common questions about keys, refunds, duplicates, and hosted checkout are answered there.
</Tip>

## Contact channels

Support channels, hours, and response-time commitments are still being finalized. Until then, reach out through your onboarding contact or account representative.

## What to include

To resolve your request faster, include:

* Your merchant/outlet ID and environment (sandbox or production).
* The `request_id` or `operation_id` of the affected transaction, if any.
* The exact error `type` (URN) and HTTP status you received — see [Problem format and retries](/payments-api/errors/problem-format-and-retries).
* Timestamps (with time zone) of when the issue occurred.

## What to never send

Never include the following in a support request, ticket, or attached log file:

* Full card numbers (PANs), CVVs, or track data.
* Secret keys, access tokens, refresh tokens, webhook secrets, or redirect secrets.
* Raw customer payment credentials of any kind.

Support can look up transactions and keys by their prefix or ID alone — you never need to share the underlying secret.

## Emergency key revocation

If you suspect a secret or publishable key has leaked — committed to a public repository, exposed in a client-side bundle, or logged somewhere you don't control — treat it as a security incident:

1. Contact support immediately and request emergency revocation of the affected key.
2. Issue a replacement key scoped to only what you need (see [least-privilege keys](/get-started/sandbox-and-api-keys#least-privilege-keys)) and roll it out before the old key is revoked, to avoid downtime.
3. Review recent activity on the leaked key — refunds first, since those move money — and reconcile anything unexpected. See [monitoring](/resources/security-and-pci#key-safety).

## Security and vulnerability reports

If you believe you've found a security vulnerability in RadiumOne's platform (not a leaked key of your own — see above), report it through the same support channel rather than filing a public issue. See [Security and PCI scope](/resources/security-and-pci) for what never to include in the report itself.

## Request enablement

Some features require support to configure your account before they work in production. `<RequiresEnablement>` notices throughout this documentation link here.

| Feature | What support configures |
| - | - |
| [Your own 3DS provider](/payments-api/three-d-secure/use-your-own-provider) | Per-outlet enablement for the external-3DS evidence arm |
| [3DS with Elements](/elements/three-d-secure/add-three-d-secure) | Per-channel/outlet enablement for RadiumOne 3DS |
| [3DS return URL registration](/elements/three-d-secure/challenge-presentation#how-it-works-the-redirect-path) | Allow-listing your `returnUrl` for the redirect challenge fallback |
| [Refund a payment](/payments-api/refund#refunds-require-enablement) | Acquirer channel enablement for the `REFUND` operation — disabled by default, unlike most gateways |
| [Standalone refunds](/payments-api/standalone-refunds) | Acquirer/terminal enablement, plus a key scoped to `transaction-refund-unreferenced` |
| [UOB Rewards](/payments-api/payment-methods/uob-rewards/overview) | Loyalty-acquirer pairing, loyalty product enablement, terminal provisioning, and BIN routing rules |
| Extra outlets or currencies | Adding outlets or enabling additional settlement currencies on your account |
| Webhook endpoints | Registering your endpoint URL and issuing its `whsec_…` signing secret — see [Webhooks overview](/payments-api/webhooks/overview#register-your-endpoint) |
| Allowed domains and redirect secret | Registering `allowed_domains` for embedded checkout and postMessage, and issuing/rotating your `rsec_…` redirect secret — see [Sandbox and API keys](/get-started/sandbox-and-api-keys#getting-keys) |
| Narrowed key scopes | Issuing a secret key with fewer than the full default scope set — see [least-privilege keys](/get-started/sandbox-and-api-keys#least-privilege-keys) |

## Next steps

<Columns cols={2}>
  <Card title="Security and PCI scope" icon="shield-check" href="/resources/security-and-pci">
    Key safety and callback verification.
  </Card>

  <Card title="Sandbox and API keys" icon="key" href="/get-started/sandbox-and-api-keys">
    Key types, scopes, and getting your first keys.
  </Card>
</Columns>
